Strava uses your personal information including health data and GPS location to train its AI and machine learning systems, though the extent depends on your in-app privacy settings.
This analysis describes what Strava's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause authorizes use of sensitive data categories including health metrics and precise location for AI development, which is a broad permission that goes beyond basic service delivery and may not be fully intuitive to users who think of Strava as a workout tracker.
Interpretive note: The policy states that AI training uses depend on 'privacy controls and sharing permissions' but does not specify exactly which settings limit AI training uses of health data, making it difficult for users to know precisely what to adjust.
Your location history, heart rate, and other health data may be used to train Strava's AI models, with the scope depending on your privacy controls; users who do not actively adjust these settings may be contributing more data to AI development than they realize.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified data for this purpose. We also use personal information, including health and Location Information, for AI Features, depending on your privacy controls and sharing permissions.Excerpt from Strava's Privacy Policy
REGULATORY LANDSCAPE: This provision engages GDPR Article 6 (lawful basis for processing) and Article 9 (health data as special category), CCPA and CPRA sensitive personal information provisions, and emerging EU AI Act requirements for AI …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This clause authorizes use of sensitive data categories including health metrics and precise location for AI development, which is a broad permission that goes beyond basic service delivery and may not be fully intuitive to users who think of Strava as a workout tracker.
Your location history, heart rate, and other health data may be used to train Strava's AI models, with the scope depending on your privacy controls; users who do not actively adjust these settings may be contributing more data to AI development than they realize.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Strava.