Privacy Policy
Version 1.3 - Effective 5 September 2026
This Privacy Policy explains how Afterlap handles information when you use the Afterlap iOS app, the Afterlap backend, and the website at afterlap.app together, the Service.
Privacy questions, data-access requests, and deletion requests can be sent to afterlap.app@gmail.com.
1. Privacy summary
- Afterlap accesses Strava only after you explicitly authorize the connection through Strava.
- Afterlap processes only the connected athlete's own Strava data for the activity-title, description, and optional weekly-summary features requested by that athlete.
- Afterlap uses webhook events instead of continuously polling Strava for new activities.
- To write the text you request, Afterlap sends a compact, sanitized workout context — not your name, email address, Strava athlete ID, OAuth credentials, precise GPS route coordinates, raw Strava streams, or raw lap arrays — to a third-party AI provider that processes it only to generate your title or description.
- Afterlap does not use Strava data to train, develop, or improve artificial-intelligence or machine-learning models, and its AI providers are contractually restricted from training their models on the data Afterlap submits through their API.
- The Strava activity data Afterlap fetches to do the work is processed transiently in Worker memory and is not stored as a durable raw activity, stream, lap, or route record; Afterlap retains only a minimal processing record afterwards, which it deletes on request (see Retention).
- Afterlap does not display your Strava data to other Afterlap users.
- Afterlap does not sell Strava data, use it for targeted advertising, or use it for cross-user analytics or product analytics.
- You can disconnect Strava, request access to data held by Afterlap, and request deletion at any time.
- Because Strava limits app connection capacity, Afterlap may automatically disconnect Strava after the free allowance is exhausted, after subscription entitlement ends, or after long Pro inactivity, as described in Retention.
- The website is static and does not use advertising pixels or non-essential cookies.
2. Strava authorization and consent
Afterlap does not access your Strava data until you choose to connect Strava and approve Strava's authorization screen. That screen shows the permissions requested by Afterlap.
You can withdraw authorization at any time by disconnecting Strava inside Afterlap or by revoking Afterlap from Strava's My Apps settings. After authorization is withdrawn, Afterlap stops fetching new Strava data and handles deletion as described below.
3. Information we process
3.1 Strava connection data
When you connect Strava, Afterlap receives authorization credentials needed to maintain the connection and identify the authorized athlete. These credentials are stored server-side and are not exposed to other Afterlap users.
3.2 Strava activity data
For a newly created authorized activity, Afterlap may process the activity ID, activity type, existing activity name and description, distance, moving time, elapsed time, start time, pace or speed, heart rate, elevation, cadence, laps for Coach-mode structure detection, splits, and similar workout metrics made available by Strava and needed for the selected feature. Afterlap does not fetch Strava streams or precise route geometry for normal activity processing.
If you enable the optional weekly summary, Afterlap additionally reads a list of your own recent activities (covering roughly the past week) to compute weekly totals and a per-day breakdown, and writes the resulting recap into the description of your most recent activity for that week.
Afterlap uses this information only to analyze your own activities and create the title, description, weekly summary, or combination requested by you. The resulting update is written back to the same athlete's activity.
3.3 AI text generation
Afterlap analyzes your activity on its backend first and computes a compact set of workout facts (a sanitized summary such as distance, pace or speed, elevation, detected workout structure, and similar metrics). To turn those facts into readable text, Afterlap sends this sanitized workout context — not your name, email address, Strava athlete ID, OAuth credentials, profile information, precise GPS route coordinates, raw Strava streams, or raw lap arrays — to a third-party AI provider (currently Google Gemini and/or Anthropic Claude, accessed through their APIs).
The AI provider processes the summary solely to return the requested title, description, or weekly summary for you. Afterlap does not use Strava data to train, develop, or improve AI or machine-learning models, and Afterlap's AI providers are contractually restricted, under their API terms, from using data submitted through their API to train their models. The generated text is written back only to your own Strava activity.
3.4 Afterlap settings and service metadata
Afterlap stores your selected mode, rewrite target, output language, tone options, weekly-summary preference, app-signature preference, app language, theme, onboarding state, and similar preferences. The backend may also retain non-Strava service metadata needed to operate Afterlap, such as an internal user identifier, app-integrity (device attestation) identifiers, subscription entitlement, free-tier processing counter, and security or job-status information that does not contain cached Strava activity data or workout-derived content.
3.5 Subscription and entitlement data
Purchases are handled by Apple through the App Store. Afterlap does not receive your payment-card number, Apple Account password, or full billing credentials. The backend may store Apple transaction identifiers, subscription status, expiration dates, and entitlement records needed to provide paid features.
3.6 Support messages
If you contact support, Afterlap receives your email address and the information you choose to include. We use it to respond to you, diagnose the issue, and maintain an appropriate support record. Please never send Strava access tokens, refresh tokens, authorization codes, or passwords.
3.7 Website requests
afterlap.app is a static website. Hosting and network providers may process standard request information such as IP address, user agent, requested URL, timestamp, and security events to deliver the site and protect it from abuse.
4. How we use information
- To establish, maintain, and disconnect the Strava connection you authorized.
- To receive Strava webhook events for your activities.
- To fetch the minimum authorized activity data needed for the requested Afterlap feature.
- To analyze workout facts and detect useful workout structure where possible.
- To send a compact, activity-derived summary to a third-party AI provider that generates the requested text.
- To create the title, description, or both according to your settings.
- To compile the optional weekly summary from your own recent activities when you enable it.
- To update those fields on the same authorized Strava activity.
- To provide subscription entitlement and free-tier functionality.
- To secure the Service, prevent abuse, and diagnose operational failures.
- To respond to support, privacy, access, and deletion requests.
Afterlap does not use Strava activity data or data derived from Strava activity data to build public datasets, perform cross-user analytics, generate advertising audiences, benchmark Strava, or improve products through analytics based on Strava data.
5. Legal bases for EEA and UK users
- Contract: to provide the Afterlap functionality you request, including activity processing and subscription access.
- Consent: for the Strava authorization you initiate and other optional permissions or settings where consent is the appropriate basis.
- Legitimate interests: to secure the Service, prevent abuse, maintain non-Strava operational logs, respond to support requests, and improve reliability without using Strava activity data for product analytics.
- Legal obligation: where limited records must be kept for tax, accounting, consumer-protection, or other legal requirements.
6. Service providers and sharing
Afterlap does not sell personal information and does not disclose Strava activity data for advertising, data-broker, or unrelated commercial purposes.
Information may be processed by service providers that are necessary to operate the Service and are used only for their stated operational role, including:
- Apple: App Store distribution, StoreKit purchases, subscription management, and platform services.
- Strava: authorization, activity data access, webhook delivery, and activity updates requested through the Strava API.
- Cloudflare: backend hosting, network delivery, database/queue infrastructure, security, and operational logging used to run Afterlap.
- AI text-generation providers (Google Gemini and/or Anthropic Claude): generation of the requested title, description, or weekly summary from a compact, activity-derived summary. These providers process the submitted summary only to return the generated text and are contractually restricted from using it to train their models.
- Email provider: support correspondence sent to or from afterlap.app@gmail.com.
Afterlap does not sell Strava data or disclose it to advertisers or data brokers, and does not use Strava data to train, develop, or improve AI or machine-learning models. The only sharing of activity-derived data for text generation is the purpose-limited processing by the AI providers described above.
7. Retention
- Strava authorization credentials: kept only while needed to maintain the connection you authorized and deleted when you disconnect, when access is revoked, or on deletion.
- Raw Strava activity data (activity details, original activity text, and any laps fetched to run a Coach-mode processing job): used transiently to produce your requested title, description, or weekly summary and not stored as a durable record. Afterlap does not fetch Strava streams or precise route geometry for normal activity processing.
- Processing records: to avoid re-writing the same activity, keep your activity history accurate, and protect the integrity of the free-activity allowance, Afterlap retains a minimal per-activity record — the Strava activity ID, the selected mode, processing status and timestamps, and a copy of the title or description Afterlap generated for you. These are kept until you request deletion. By design, the free-allowance count is not reset by disconnecting and reconnecting the same Strava account.
- Activity-derived summary sent for AI generation: transmitted to the AI provider only for the duration of the generation request and not stored by Afterlap as a separate record. The provider's own handling and retention are governed by its API terms, which restrict training on submitted data.
- Afterlap settings and non-Strava service metadata: kept while needed to provide the Service, until reset, deleted, or no longer necessary.
- Subscription records: kept as needed to provide entitlement and satisfy applicable accounting, consumer-protection, or legal obligations.
- Support messages: kept only as long as reasonably needed to resolve and document the support request or meet a legal obligation.
- Website and backend security logs: kept only as long as reasonably needed for security, abuse prevention, and operational reliability, and are not used to build analytics from Strava activity data.
To preserve limited Strava connection capacity for active users, Afterlap may automatically disconnect Strava in these cases: 7 days after the last successfully processed free activity exhausts the 20-activity free allowance if Pro is not started; 7 days after paid entitlement expires or is revoked when no remaining entitlement is available; or 90 days after the last Strava activity seen for an active Pro account. Automatic disconnect deletes the Strava connection and stored authorization credentials, and purges stored Strava-derived generated text and direct activity identifiers where applicable. It does not cancel an App Store subscription, reset free-trial accounting, or erase subscription history that Afterlap must retain for entitlement, legal, accounting, or abuse-prevention purposes.
8. Your data rights, access, and deletion
You can request a copy of personal data held by Afterlap by emailing afterlap.app@gmail.com with the subject “Afterlap data access”.
Disconnecting Strava — in the app or through Strava's My Apps settings — immediately stops further processing, revokes access where possible, and deletes your stored Strava authorization credentials. Raw Strava activity data is transient and is not kept as a durable record. The app also provides a Delete Afterlap Data action that disconnects Strava and removes backend account data under Afterlap's control.
To also remove the minimal processing records described in Retention, request permanent deletion using the instructions on Data Deletion. Following a valid deletion request, Afterlap deletes the connected athlete's remaining Strava-derived personal data — including the retained activity identifiers and generated text — from systems under Afterlap's control, except for the minimum records Afterlap must keep to meet a legal obligation (for example, tax, accounting, or fraud-prevention records). Afterlap provides written confirmation when a user-requested deletion has been completed.
Depending on where you live, you may also have rights to correct, export, restrict, or object to processing of your personal information and to lodge a complaint with a data-protection authority.
9. Strava usage data
Strava may monitor and collect usage information relating to use of the Strava API and may use that information for purposes described in Strava's API terms, including platform operation, support, security, compliance, and improvements to the Strava platform or API.
10. Children
Afterlap is not directed to children under 13. If you believe a child has provided personal information through the Service, contact us so we can take appropriate action.
11. Security
Afterlap uses technical and organizational measures intended to protect data, including server-side credential handling, access controls, transport security, app-integrity (device attestation) checks on sensitive requests, and infrastructure security controls. No system can be guaranteed completely secure.
12. International transfers
Service providers may process information in countries other than where you live. Where required, Afterlap relies on applicable transfer safeguards or other lawful transfer mechanisms.
13. Changes
Afterlap may update this Privacy Policy as the product, backend implementation, law, or third-party platform requirements evolve. The effective date above shows when this version became effective.