Legal version 19

Privacy Notice

Effective August 22, 2026

Scope and controller

This notice describes the current iPhone version of StrideCircuit. StrideCircuit is provided by Bryan Joseph Demarco, an individual developer. Bryan Joseph Demarco is responsible for StrideCircuit’s own data practices. Contact grew_spout0u@icloud.com for privacy questions or requests.

This website

These public pages are delivered using Cloudflare Pages. Cloudflare may process ordinary website request and network information to deliver them under its privacy policy. These pages include no StrideCircuit analytics, advertising, forms, cookies, or third-party assets. This website hosting is separate from app routing: Cloudflare supplies authoritative DNS in DNS-only mode for routing HTTPS and does not receive route payloads as a proxy.

Location and map requests

With your iOS permission, StrideCircuit uses precise location to choose a start, show your position, and provide navigation. During an active run, it can continue receiving location updates while the app is in the background; iOS may show its location-use indicator. Addresses, search terms, geocoding, map-display viewports, and Look Around imagery requests may be processed through Apple’s MapKit, Maps, and Look Around services; this shipping private beta does not use Apple Directions for route generation. To generate a route, StrideCircuit sends the start, ordered planning waypoints, route preferences, and ordinary network metadata over direct authenticated HTTPS to the developer-operated Valhalla service. When Route Details loads, it also sends a bounded, downsampled copy of that planned route geometry, containing no more than 220 points, to the same authenticated service to calculate the elevation profile. The service checks route geometry against a same-source OpenStreetMap crossing index. The crossing-check object contains completeness, version, and count metadata plus accepted event entries. Each event entry adds only opaque event and site identifiers, route-leg and route-shape indexes, coarse road class, and accepted mapped-control status; the route response separately contains the requested geometry, instructions, and strict edge evidence. The service is hosted on OVHcloud infrastructure in Vint Hill, Virginia, United States; it processes these requests transiently, keeps no route-request or access logs, and does not receive active-run GPS history. Cloudflare supplies authoritative DNS in DNS-only mode and does not proxy or terminate routing HTTPS. Strict Valhalla routing fails closed when required route-edge or crossing evidence is unavailable.

Planning weather and daylight

When StrideCircuit displays planning conditions, it sends the selected start coordinate and expected departure time to Apple Weather to request a forecast. StrideCircuit keeps only a coarse-area, hourly forecast in memory for approximately 15 minutes, does not send it to the developer-operated routing service, and does not retain a weather history. Route generation remains available when WeatherKit is unavailable.

RunSignup and event courses

Native RunSignup catalog and event-detail requests are disabled in this build. StrideCircuit does not send a ZIP code, radius, date range, race identifier, precise GPS coordinate, saved route, imported GPX geometry, or active-run history to RunSignup. Saved and user-imported event courses remain local. Only when you deliberately choose Browse RunSignup or a saved official link does your browser open the provider’s website; the provider then receives the browser request and normal network information under its own terms and privacy practices.

Optional community trail requests

If you turn on Show and Allow Trails, StrideCircuit rounds outward to an area of approximately one-kilometer map cells around the planned route and sends that area—not your exact start coordinate, name, or saved route—to the Private.coffee OpenStreetMap Overpass service. The response contains public trail geometry and tags and is cached temporarily in app memory. Private.coffee receives normal network information; its published policy says it retains a truncated IP prefix and limited request metadata for up to 48 hours for technical operation.

Information stored on your device

Your legal acknowledgement, preferences, saved routes, route geometry, turn guidance, mapped crossing evidence, a previously saved event-search ZIP code, favorite event identifiers, user-imported event-course geometry and file metadata, optional safety-contact name and phone number, safety-sharing choices, and route feedback may be stored locally. If you identify an unsafe crossing in route feedback, you can select one exact point on the route; that coordinate and an optional opaque mapped-site identifier stay in the protected, backup-excluded feedback file on this iPhone and are excluded from feedback email and export. While an off-route safety check is unresolved, protected, backup-excluded app storage can temporarily contain its identifier, deadline, escalation status, and—only if you enabled location in safety messages—one recent coordinate, timestamp, and accuracy estimate. This safety-check record does not contain route geometry, message text, or the contact’s phone number. Imported event courses are also stored in protected, backup-excluded app storage and are not uploaded to a developer-operated service. Previously saved event records may remain available locally, including calendar details that you chose to add through iOS. StrideCircuit does not automatically add the starting coordinate to generation-failure feedback.

Optional Apple Health saving

When you end a run, StrideCircuit writes that run’s workout summary and available GPS route to Apple Health using your Apple Health permission. If you choose to add an Apple Watch workout goal, Apple’s Workout app receives the selected distance, estimated time, and schedule. If you send a route to the paired StrideCircuit Watch app, the route geometry and turn cues are transferred directly between your paired devices and the Watch retains the most recent route locally. The Watch can use its own GPS, heart-rate, distance, energy, and motion-based cadence signals to record and display that outdoor run. StrideCircuit does not read unrelated or historical Health records, retain a developer-side copy, or send Health information to a developer-operated server. Apple handles information stored in Apple Health under its own terms and privacy practices.

Optional completed-workout sharing

For an eligible iPhone-recorded workout, StrideCircuit can generate a share-card image locally from the recorded distance, active time, average pace, elevation gain, mile splits, and planned-versus-recorded distance. Stats Only is selected by default each time. You can select an actual recorded GPS trace with 1/4-, 1/2-, or 1-mile masking around both endpoints, or separately confirm Full Route, which includes the recorded start and finish. Masking removes every recorded point inside the selected radius of both endpoints and leaves route gaps disconnected, but it does not guarantee anonymity: the remaining shape, distance, statistics, or context may still reveal a location or routine. The preview omits street names, addresses, exact workout time, safety information, and embedded GPS metadata. StrideCircuit does not upload the card or route to a developer-operated service, save the image to a developer database, or post it automatically. The selected share destination receives the rendered image only after you review the preview and choose that destination in the iOS share sheet.

Motion & Fitness cadence

If you allow Motion & Fitness access, StrideCircuit can use live cadence from the device recording an active run—your iPhone or Apple Watch. This version displays cadence in the app but does not retain it in a developer-operated service or use it for advertising.

Purposes and legal bases

StrideCircuit uses this information to provide requested route planning and navigation, remember choices, save routes you select, diagnose route quality, protect the service, and meet legal obligations. Depending on local law, processing may rely on your request, contract, consent, legitimate interests, or legal obligations.

Sharing and sales

This version has no advertising network, StrideCircuit account, or developer analytics service. The private Valhalla engine receives route-planning coordinates and preferences and, when Route Details requests elevation, a bounded, downsampled copy of the planned route geometry. It does not receive active-run GPS history and retains no route-request or access logs. The engine uses OpenStreetMap route data. OVHcloud supplies the United States server infrastructure and may process ordinary infrastructure and service data under its terms and data-processing agreement. Cloudflare supplies authoritative DNS only and does not receive the routing HTTPS payload as a proxy. StrideCircuit does not sell personal information or share it for cross-context behavioral advertising, track you across other companies’ apps or websites, or request Apple’s App Tracking Transparency permission. Apple processes map display, search, geocoding, Look Around, WeatherKit, Calendar, and related requests under Apple’s own terms and privacy practices. Native RunSignup catalog and event-detail requests are disabled, so this build does not send ZIP, radius, date-range, or race-identifier requests to RunSignup. RunSignup receives a browser request only if you deliberately choose Browse RunSignup or another saved provider link, under its own terms and privacy practices. When you enable trails, a rounded map area is sent to the selected OpenStreetMap Private.coffee Overpass service to return public trail data. Optional start and finish safety notices are drafts handled by Messages only after you choose to review and send them. If you enabled the location option, a safety message includes one last-known location and timestamp—not continuous or live tracking. Where Apple Critical Messaging is available, enabled, and separately authorized for your selected phone number, an unanswered safety check may ask Apple’s messaging service and your carrier to deliver one background critical SMS. Apple, your carrier, the recipient, and the recipient’s service provider process the phone number and message contents under their respective terms and privacy practices; message and data rates may apply. StrideCircuit does not retain a developer-side copy. Data is otherwise shared only between your paired iPhone and Apple Watch when you explicitly send a route, when you choose Send Feedback, when you preview and intentionally share a completed-workout card through the iOS share sheet, or when legally required. A workout card can contain the displayed fitness statistics and, only if you select a route option, the displayed privacy-processed GPS shape. The destination you select and its service providers control their processing, retention, redistribution, and any social account involved under their own terms and privacy practices. StrideCircuit has no social SDK or social account connection; its developer and server receive no shared image or delivery record. Send Feedback includes only structured bug details and privacy-safe device diagnostics; it excludes names, addresses, notes, precise location, route geometry, Health data, and contact details. Apple Mail may add the sender address or signature, which you can review before sending.

Retention and deletion

Local information remains until you delete an item, clear the relevant history, or uninstall the app. The securely stored safety contact may remain in this iPhone’s Keychain after uninstall, so remove it in Run Safety first if you want it deleted. A pending safety-check record is deleted when the check resolves before an automatic attempt; after an attempt or interrupted app session, any stored coordinate is removed and the remaining status is retained until you dismiss it or a later safety check replaces it. Exported copies are controlled by you and the destination you select, including a workout-card destination, a safety-message recipient, or an email recipient when you choose Send Feedback. The monitored developer support inbox deletes feedback emails and their attachments within 90 days after receipt, or sooner after a verified deletion request. Deleting a local feedback report does not retract an email you already sent; you can delete local reports and history separately in StrideCircuit. A locally selected unsafe-crossing point remains only until you delete that feedback report, clear its history, or uninstall the app; it is not included in the email or export copy. StrideCircuit keeps the completed-workout sharing summary only in memory for the current completed-run session and creates the preview image in memory; it does not maintain a developer-side workout-card history. Apple, carriers, recipients, social platforms, and their service providers control retention of information you send to them. The private Valhalla service does not retain route requests or access logs. OVHcloud controls retention of any infrastructure and service data it processes under its terms; Cloudflare handles authoritative DNS under its terms but does not proxy routing HTTPS traffic. Private.coffee’s published Overpass policy permits retention of a truncated IP prefix and limited request metadata for up to 48 hours. Apple controls retention for data processed by its services. StrideCircuit’s planning-weather cache expires from memory after a short interval.

Your choices and rights

You can deny or revoke location access in iOS Settings, use a searched start instead, keep a workout share card on Stats Only, choose an endpoint-masking radius, separately confirm Full Route, cancel the share sheet, turn off safety sharing, change or remove the safety contact and its Critical Messaging authorization, delete saved items and feedback, or uninstall StrideCircuit. You may separately ask the developer to delete a feedback email and its attachments sooner than 90 days; the developer may verify the request before deleting mailbox records. Depending on where you live, you may also have rights to know, access, correct, delete, restrict, object, withdraw consent, obtain a portable copy, appeal a decision, or complain to a regulator. Because StrideCircuit has no account or persistent developer database, most StrideCircuit-held data is directly controlled on your device.

Children

StrideCircuit is not directed to children under 13 and the developer does not knowingly operate a service that collects their personal information. A parent or guardian should supervise a minor’s routes and exercise.

International use and security

Apple service processing may occur in locations described by Apple. The private Valhalla beta service is developer-operated and hosted on OVHcloud infrastructure in Vint Hill, Virginia, United States. OVHcloud and its authorized subprocessors may access infrastructure or service data from other locations as described in OVHcloud’s terms and data-processing agreement. Cloudflare supplies authoritative DNS in DNS-only mode and does not carry the app’s routing HTTPS payload as a proxy. StrideCircuit minimizes developer access by keeping its own saved data on the device, but no device or service can be guaranteed completely secure.

Changes and contact

Material changes will be shown in the app and may require renewed acknowledgement. Use the Support link on StrideCircuit’s App Store listing for privacy requests or questions.