Strava provides privacy controls allowing you to set who can see your activities, adjust map visibility, create privacy zones, and manage what data is shared with other users and third parties.
This analysis describes what Strava's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The existence of granular privacy controls means users have meaningful ability to limit data exposure, but these controls must be actively configured — the defaults may expose more data than users expect.
Strava collects highly sensitive personal data including precise GPS routes, heart rate, sleep data, and other health metrics, which may be used to train AI/ML models and contribute to publicly accessible features like the Global Heatmap. Health data from connected devices will not be sold or used for advertising, but activity data can be shared in aggregated or de-identified form and used for AI development. You can adjust your privacy and visibility controls in the Strava app under Settings > Privacy Controls to limit how your data is shared and used.
Cross-platform context
See how other platforms handle User Privacy Controls and Visibility Settings and similar clauses.
Compare across platforms →Monitoring
Strava has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Provision of privacy controls supports GDPR data subject rights compliance and CCPA opt-out obligations. However, compliance teams should assess whether default settings align with data minimisation and privacy-by-default requirements under GDPR Article 25.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The existence of granular privacy controls means users have meaningful ability to limit data exposure, but these controls must be actively configured — the defaults may expose more data than users expect.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Strava.