Privacy Policy
Last updated: July 2026
What we collect
When you connect your Strava account, we receive and store:
- Your Strava athlete ID
- Strava OAuth access and refresh tokens (used only to read and update your activities)
- Activity data needed to generate names, distance, duration, heart rate, pace, elevation, sport type
- Approximate start location (city and region level only), derived from GPS coordinates when available, used solely to enrich the activity description with a place name
If you submit the waitlist form, we collect your name, email address, and the reason you provided, via our form provider.
We use Google Analytics and Google Tag Manager to understand site traffic — this includes anonymised usage data such as page views, device type, and approximate location (country/city level, not precise GPS).
What we do not collect
- We never see or store your Strava password - authentication happens entirely through Strava's official OAuth flow
- We do not store precise GPS coordinates - start coordinates are used transiently at processing time to derive an approximate city name, then immediately discarded. Raw coordinates are never stored, logged, or sent to any AI model
- We do not access route maps, GPS tracks, or full activity polylines
- We do not collect payment information - this service is currently free
How we use your data
Your activity data is used for exactly one purpose: generating an AI-written name and description for that specific activity, which is then written back to your Strava account. Where GPS coordinates are present, they are used transiently to determine an approximate city-level start location via AWS Location Service. This enriches the activity description with a place name and is not retained beyond the processing of that single activity. Activity data is not used to train any AI model, is not shared with any third party beyond the AWS infrastructure that powers the service, and is not retained longer than necessary for debugging (90 days for processed activity records, 7 days for raw webhook logs).
Where your data is stored
All data is stored on Amazon Web Services infrastructure in the Asia Pacific (Sydney) region, with encryption applied by default through AWS's managed services.
Third-party services
- Strava — OAuth authentication and activity data, governed by Strava's Privacy Policy
- Amazon Web Services — hosting, processing, AI generation (Amazon Bedrock), and reverse geocoding (AWS Location Service with Esri data). GPS coordinates are processed transiently for location lookup and are not stored by AWS Location Service under the SingleUse configuration used
- Formspree — waitlist form submissions, governed by Formspree's Privacy Policy
- Google Analytics / Tag Manager — anonymised site usage analytics
How to disconnect and delete your data
You can revoke access at any time through Strava directly: go to strava.com/settings/apps and remove the Endorphins AI connection. This immediately invalidates our access tokens.
To request full deletion of your stored data, use the contact form on the homepage. Your record will be deleted within 7 days of a verified request.
Changes to this policy
As this project moves from beta to a wider release, this policy may be updated. Material changes will be reflected on this page with an updated date.
Contact
Please Reach out via the request access form.