Privacy
Your data stays on your route.
Startline uses the minimum information needed to provide accounts, saved plans and optional provider features. Connected Strava and COROS data is private to the account that authorized it.
What the Strava connection reads
Startline requests basic read, activity:read_all and profile:read_all permissions. These allow private activity summaries, streams and athlete zones to support training analysis. Startline does not request any Strava write permission. Existing connections see a clear reauthorization step before these expanded permissions are requested.
What the COROS connection reads
COROS provides read-only MCP and offline access so users do not have to reconnect every few hours. When the user presses Sync now, Startline imports activity summaries, daily health, sleep, recovery, fitness assessments and planned workouts. The first sync covers the previous 12 weeks; later syncs update a rolling overlap so corrected records are retained.
COROS storage and control
COROS access and refresh tokens are encrypted before database storage. The connection is owned by the Startline user who authorized it and is never exposed on public pages. Disconnecting attempts to revoke COROS authorization and always deletes the local connection, tokens and imported COROS training dataset.
How it is stored and displayed
OAuth access and refresh tokens are encrypted before storage in the Startline database. Route information fetched from Strava is shown only inside the connected user’s private account page and is not published to the public Bucket List.
No external AI processing
Startline sends no training, recovery, goal or activity data to an external AI provider. Metrics and workouts are produced by deterministic Startline code running on Startline’s own infrastructure. The only third parties that receive private data are the providers you explicitly connect, and they receive it only to fulfil your own read-only import.
Offline copies on your device
The installable app keeps previously viewed race details and private training pages in a device-local offline cache. Private copies are separated by an opaque athlete scope and are cleared on sign-out, training-data deletion, or account deletion. Anyone with access to an unlocked device may still be able to read pages saved there, so sign out before sharing a device and clear the browser’s site data if a session ends unexpectedly.
Disconnect and delete
The account page can export a secret-free JSON copy of private account data, erase imported and derived training data while keeping the account, or delete the complete member account. Disconnecting a provider attempts remote deauthorization and always removes its local tokens and imported records. Provider webhook deauthorization is also reconciled automatically.
Retention and operational records
Raw provider replay records are retained for 90 days by default so mappings can be repaired, then pruned by the scheduled maintenance job. Normalized summaries remain until the member deletes training data or the account. Operational logs contain event names, outcomes, durations and pseudonymous subject hashes—not tokens, provider payloads or health values.
Public links and embeds
Public Bucket List entries may contain a Strava URL supplied deliberately by their author. Those links and embeds are separate from the private OAuth connection and remain hosted by Strava.