Reviewed Jun 2026 · policies are checked weekly for changes · stated — every cell is read from Strava's published policy; none has been tested (run by us) yet.
1Deletionstated
Self-serve account deletion, but public segments and routes you created remain on Strava, and some activity data is retained up to 90 days after deletion for operational purposes.
Strava Privacy Policy · accessed Jun 2026 ↗
1Sells / sharesstated
Strava does not sell personal data and its API agreement bars third parties from selling or sharing Strava data, but Strava itself shares aggregated location data (Metro) with city-planning and transportation agencies.
Strava Privacy Policy · accessed Jun 2026 ↗
1Trains AIstated
As of Jan 1 2026 Strava may use aggregated and de-identified activity data to train AI models for route and safety features, and personal data for opt-in "AI Features"; its API agreement prohibits third parties from using Strava data in AI.
Strava Privacy Policy · accessed Jun 2026 ↗
1API access — feeds Agent Readiness, not the /12stated
Strava's API v3 lets an athlete authorize an app via OAuth (with refresh tokens) to read their own activity data, but as of June 2026 the Standard developer tier requires the developer to hold a paid Strava subscription and bars routing data through third-party intermediary platforms.
Strava — Developer Program Update (Jun 2026) · accessed Jun 2026 ↗
Source-verified Jun 2026 from Strava's own support and policy pages, including the Jan 2026 privacy-policy and API-agreement updates. All cells are "stated"; none yet "tested" via a live export or deletion.