Privacy Policy
This policy explains the personal data processed by Stridu (the “App”) under Turkey's Personal Data Protection Law No. 6698 (KVKK) and the European Union General Data Protection Regulation (GDPR).
Contents
1. Data controller
The Stridu team. Contact: privacy@stridu.com
2. Data we process
- Account: email address, display name.
- Activity and health: daily steps, distance, calories, location trace (GPS route), and activity records. Location data is collected only during active tracking and on your device.
- Device and diagnostics: push notification token. If you separately opt in, Stridu also processes bounded crash and performance diagnostics. Firebase Analytics and advertising tracking are disabled. The Google Maps SDK may collect a device identifier, map product interaction, and limited crash, performance, and other technical data for analytics and app functionality, as declared in its Apple privacy manifest.
- Purchase history: the selected subscription product, trial and renewal state, Premium entitlement, and limited metadata derived from Apple's transaction record. RevenueCat receives an opaque Stridu account UUID, not your email address or social sign-in identity.
- Social and safety: posts, likes, comments, challenge participation, content reports, and blocked accounts.
3. Purposes and legal basis
- Providing the service (performance of a contract): account, activity synchronisation.
- Providing and restoring Premium (performance of a contract): purchase history and subscription entitlement.
- Optional notifications (explicit consent): streak reminders, social interaction.
- Security and abuse prevention (legitimate interest).
- Optional diagnostics (explicit consent): improving app stability and performance. These controls are off by default and can be withdrawn in the App.
Health and location data is treated as a special category of personal data. It is processed only with your explicit consent and only for the App's own functionality.
Stridu uses no advertising SDK. It does not use or sell health, fitness, or location data for advertising, cross-app tracking, or any data mining unrelated to health.
4. Local-first architecture
An account is required for first use and for synchronisation. Once you have signed in, data is stored primarily on your device (Isar); if the connection drops, existing step and activity records continue to work locally. Cloud synchronisation transmits your data to the server (Microsoft Azure, North Europe).
5. Transfer and retention
- Hosting: Microsoft Azure (North Europe region).
- Push notifications: Apple Push Notification service (APNs) — used solely to deliver notifications. Stridu sends iOS notifications directly through APNs and does not use Firebase Cloud Messaging.
- Maps: Google Maps Platform renders map content and may process map requests or viewport information, a device/app identifier, product interaction, and limited technical diagnostics. Stridu does not use this information for advertising or cross-app tracking.
- Payments and subscriptions: Apple processes payment and StoreKit transaction records. RevenueCat processes the Apple purchase and entitlement metadata needed to verify access, restore purchases, and evaluate introductory-offer eligibility against an opaque Stridu account UUID. Stridu does not send email, social sign-in identity, Health data, routes, locations, activity content, or Coach messages to RevenueCat.
- Optional diagnostics: Firebase Crashlytics and Firebase Performance may process bounded crash and timing information only after separate opt-in. Routes, Health data, messages or prompts, email, tokens, request URLs/bodies, and advertising identifiers are excluded. Firebase Analytics is disabled.
- Live data: account and sync data is kept until the account is deleted. When an account is deleted, live domain data in Azure is deleted; the Supabase Auth identity is deleted immediately or queued for retry depending on server configuration.
- Subscription records: Apple retains transaction records under its own legal and contractual obligations. RevenueCat retains the subscription record as needed for purchase verification, restore, and legal obligations. An account deletion request also applies to data Stridu associates with the RevenueCat customer identifier; Stridu cannot delete Apple's independent transaction records.
- Backups: the Azure PostgreSQL deployment is currently configured with a 7-day backup retention window. Deleted rows may remain in these recovery backups until that window expires; backups are not accessible to users.
- Deletion log: a limited record of the deletion operation is kept so the deletion can be completed and re-creation prevented.
6. Your rights (KVKK art. 11 / GDPR)
You have the right to access, rectify, and erase your data, to restrict or object to processing, to data portability, and to withdraw consent. The Export my data action on the Profile screen provides your local-first data on this device together with your synced account data as a versioned JSON file. Requests: privacy@stridu.com
7. Account and data deletion
You can sign out from inside the App, or permanently delete your account after re-authenticating and giving explicit confirmation. Account and cloud data is deleted in every case; keeping or erasing the activity history stored on your device is offered as a separate choice. Retained local history is accessible only after you sign in again, and can later be synchronised to the account you sign in with.
8. Children's privacy
The App is not directed at users under the age of 13.
9. Changes
This policy may be updated; material changes are announced inside the App.
Questions about your data? Write to privacy@stridu.com — the same address handles access, export, and deletion requests.