Privacy

Your data stays on your route.

Startline uses the minimum information needed to provide accounts, saved plans and optional provider features. Connected Strava and COROS data is private to the account that authorized it.

What the Strava connection reads

Startline requests basic read, activity:read_all and profile:read_all permissions. These allow private activity summaries, streams and athlete zones to support training analysis. Startline does not request any Strava write permission. Existing connections see a clear reauthorization step before these expanded permissions are requested.

What the COROS connection reads

COROS provides read-only MCP and offline access so users do not have to reconnect every few hours. When the user presses Sync now, Startline imports activity summaries, daily health, sleep, recovery, fitness assessments and planned workouts. The first sync covers the previous 12 weeks; later syncs update a rolling overlap so corrected records are retained.

COROS storage and control

COROS access and refresh tokens are encrypted before database storage. The connection is owned by the Startline user who authorized it and is never exposed on public pages. Disconnecting attempts to revoke COROS authorization and always deletes the local connection, tokens and imported COROS training dataset.

How it is stored and displayed

OAuth access and refresh tokens are encrypted before storage in the Startline database. Route information fetched from Strava is shown only inside the connected user’s private account page and is not published to the public Bucket List.

Optional private AI coach

The coach is off until a signed-in user explicitly opts in after reviewing its data notice. A question sends only the minimum relevant numeric training, recovery, goal, workout and versioned projection context to OpenAI; identity, tokens, raw provider payloads, GPS traces, names and notes are omitted. Calls are stateless, while private conversation content stays in Startline until the user deletes it. Disabling the coach stops provider calls immediately. Standard provider abuse-monitoring retention may be up to 30 days, and this launch does not claim EU-only processing.

Disconnect and delete

The account page can export a secret-free JSON copy of private account data, erase imported and derived training data while keeping the account, or delete the complete member account. Disconnecting a provider attempts remote deauthorization and always removes its local tokens and imported records. Provider webhook deauthorization is also reconciled automatically.

Retention and operational records

Raw provider replay records are retained for 90 days by default so mappings can be repaired, then pruned by the scheduled maintenance job. Normalized summaries remain until the member deletes training data or the account. Operational logs contain event names, outcomes, durations and pseudonymous subject hashes—not tokens, provider payloads or health values.

Public links and embeds

Public Bucket List entries may contain a Strava URL supplied deliberately by their author. Those links and embeds are separate from the private OAuth connection and remain hosted by Strava.