Strava · Strava Privacy Policy · View original document ↗

Health Data Collection and Non-Sale Commitment

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Strava Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Strava promises not to sell health data it receives from connected devices like Garmin or Apple Health, and says it will not use that data for advertising, but it can still use it for other purposes described in the policy including AI development.

This analysis describes what Strava's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This commitment offers meaningful protection for sensitive health metrics like heart rate and VO2max collected from wearables, but the carve-out for 'specific purposes described in this Policy' means AI training and service improvement uses may still apply.

Interpretive note: The interaction between the health data non-sale commitment and the broader AI development authorization elsewhere in the policy creates ambiguity about which uses of connected-device health data are permitted under this specific commitment.

Consumer impact (what this means for users)

Your heart rate, HRV, sleep, and VO2max data from connected devices will not be sold or used for ads, but the policy reserves the right to use this data for AI model training and service improvement purposes described elsewhere in the document.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Open the Strava app, go to Settings, select My Account, then Connected Apps. Review which devices and apps have health data access and revoke permissions for any integrations you no longer want sharing data with Strava.

How other platforms handle this

PlanetScale Medium

When you visit the Careers portion of our websites, we collect the information that you provide to us in connection with your job application. This includes but is not limited to business and personal contact information, professional credentials and skills, educational and work history and other in...

American Airlines Medium

American does not knowingly collect personal information directly from children – persons under the age of 13, or another age if required by applicable law – other than when required to comply with the law or for safety and security reasons. Due to the nature of our Services, we may collect travel i...

GOAT Medium

We may collect information about your location, including precise geolocation information, when you use our Services. We use this information to provide location-based services, such as showing you products available in your area, and for other purposes described in this Privacy Policy.

See all platforms with this clause type →

Monitoring

Strava has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising or other similar purposes; we do not disclose it to third parties without your prior consent; and we will only use it for the specific purposes described in this Policy.

— Excerpt from Strava's Strava Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Article 9 (special categories of personal data, including health data), CCPA's sensitive personal information provisions, and Washington State's My Health MY Data Act, which imposes heightened consent requirements for collection and use of consumer health data. The FTC Act is also relevant given the specific commitments made. Enforcement authority includes the FTC, state attorneys general, and the Washington State AG under MHMD. GOVERNANCE EXPOSURE: Medium. The non-sale and non-advertising commitment is explicit, but the qualifier 'specific purposes described in this Policy' creates ambiguity because the policy separately authorizes AI development using health and location data. Compliance teams need to map whether AI training uses of connected-device health data fall within or outside this commitment, as an inconsistency could constitute a deceptive practice under FTC Act standards. JURISDICTION FLAGS: Washington State's My Health MY Data Act creates the highest exposure, as it imposes opt-in consent requirements for collection and sharing of consumer health data that go beyond CCPA. EEA users benefit from GDPR Article 9 protections requiring explicit consent for processing special category health data. California's CPRA sensitive personal information provisions also apply. Illinois and other states with emerging health data frameworks should be monitored. CONTRACT AND VENDOR IMPLICATIONS: Service providers who receive health data from Strava for AI training or analytics purposes must be assessed against this commitment. Data processing agreements with these vendors should reflect the non-sale and non-advertising restriction and include appropriate use limitations and audit rights. COMPLIANCE CONSIDERATIONS: Compliance teams should map all downstream uses of connected-device health data to verify they fall within the stated non-sale and non-advertising commitment. Consent mechanisms for Washington State users should be reviewed against MHMD opt-in requirements. Data retention policies for health data collected via integrations should be reviewed and documented.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive trade practices, including whether health data commitments are honored in practice
    File a complaint →
  • State AG
    State attorneys general in Washington, California, and other states with health data privacy laws may have enforcement authority over violations of health data commitments
    File a complaint →

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Strava Privacy Policy
Entity
Strava
Document last updated
May 5, 2026
Tracking information
First tracked
May 9, 2026
Last verified
May 9, 2026
Record ID
CA-P-007783
Document ID
CA-D-00272
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1f04cde7030a965e9a65ea78be50fec4717b7bbf6a378112228c49d14a8f6010
Analysis generated
May 9, 2026 22:52 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Strava
Document: Strava Privacy Policy
Record ID: CA-P-007783
Captured: 2026-05-09 22:52:22 UTC
SHA-256: 1f04cde7030a965e…
URL: https://conductatlas.com/platform/strava/strava-privacy-policy/health-data-collection-and-non-sale-commitment/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Strava's Health Data Collection and Non-Sale Commitment clause do?

This commitment offers meaningful protection for sensitive health metrics like heart rate and VO2max collected from wearables, but the carve-out for 'specific purposes described in this Policy' means AI training and service improvement uses may still apply.

How does this clause affect you?

Your heart rate, HRV, sleep, and VO2max data from connected devices will not be sold or used for ads, but the policy reserves the right to use this data for AI model training and service improvement purposes described elsewhere in the document.

Is ConductAtlas affiliated with Strava?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Strava.