← Back to Stride MCPMCP Connector Privacy Policy
Last updated: September 2026 · Stride (“we”, “us”) · Melbourne, Victoria, Australia · privacy@runstri.de
This policy covers the
Stride MCP connector, the integration that lets Claude or ChatGPT read your Strava and WHOOP data on demand. If you use the full Stride app at
app.runstri.de, see the
Stride Privacy Policy instead.
1. What the connector does
The Stride MCP connector is a read-only bridge between your AI assistant (Claude or ChatGPT) and your Strava and WHOOP accounts. When you ask the assistant a question about your training, it calls the connector to fetch the relevant data in real time and returns it to your conversation. No background sync, no AI processing on our side, no data stored beyond what is needed to authenticate your requests.
2. Data we store
We store only what is necessary to operate the connector:
- Your Stride account: email address and name, via Google sign-in (Better Auth). Used to identify you and secure your connector token.
- Strava OAuth tokens: the access and refresh tokens that allow the connector to call the Strava API on your behalf. Stored encrypted at rest (AES-256-GCM).
- WHOOP OAuth tokens (if connected): same as above, stored encrypted, used only to fetch data when your AI assistant requests it.
- Your MCP bearer token: a randomly generated token that identifies your session to the connector. Stored as a SHA-256 hash; the raw token is never persisted.
We do not store your Strava activity data, WHOOP recovery scores, or any other athletic data. Each time your assistant asks a question, the connector fetches the data live from Strava or WHOOP, returns it, and discards it. Nothing is cached or written to a database.
3. Data we do not collect
- Your conversation content or AI prompts
- Your Strava or WHOOP activity records (fetched live, not stored)
- Location or GPS data
- Analytics, session replay, or tracking of any kind
- Advertising identifiers
4. How your data flows
When your AI assistant calls the connector:
- It presents your MCP bearer token to authenticate the request.
- The connector validates the token, then calls the Strava or WHOOP API using your stored OAuth tokens to fetch the requested data.
- The data is returned directly to your AI assistant and is not written to any database.
- Your AI provider (Anthropic or OpenAI) then processes it according to their own privacy policy and your conversation context.
5. Third parties
- Strava: source of your activity data. You authorise the connector scope during setup and can revoke access in Strava at any time.
- WHOOP: source of your recovery, sleep, and physiological data (if connected). Revoke access in WHOOP at any time.
- Anthropic / OpenAI: your AI assistant processes the data returned by the connector. See their respective privacy policies for how they handle it.
- Railway: the connector runs on Railway's infrastructure (hosted in the United States). Request logs may be retained briefly for reliability purposes.
- Neon: hosted PostgreSQL that stores your account, OAuth tokens, and MCP token hash. Data is stored in the United States.
6. Retention and deletion
Your account and stored tokens are retained while your connector is active. You can disconnect Strava or WHOOP at any time from app.runstri.de This immediately revokes the stored OAuth tokens and stops the connector from fetching new data. To delete your account entirely, email privacy@runstri.de and we will remove your data within 30 days.
7. Security
OAuth tokens are stored encrypted at rest using AES-256-GCM. MCP tokens are stored only as SHA-256 hashes. All traffic between your AI assistant, the connector, and Strava/WHOOP is served over TLS.
8. Your rights
You may access, correct, or request deletion of your data at any time. Disconnect integrations via app.runstri.de or email privacy@runstri.de. You may also lodge a complaint with the Office of the Australian Information Commissioner.
9. Changes
We may update this policy when the connector's data practices change. Material changes will be reflected by updating the date above.
Questions? privacy@runstri.de · Full Stride Privacy Policy · Terms of Service