Data Ethics, Privacy and Humans · worked example
A personal harm analysis of Strava's privacy agreement — not a summary of what it says, but a reading of where the flows it authorizes could work against the person on the other end: you. And with Strava, the crown-jewel risk is unusually literal — the data it collects is a map to your front door.
Strava is, on its face, a fitness tracker — a place to log a run or a ride and see how you did. You open the relationship expecting one thing: it records your activity and shows you your numbers. The policy authorizes a great deal more than that. What makes Strava distinctive is what the data is: not your taste or your browsing, but the precise, timestamped path your body takes through the physical world — and by default, that path is public. Below are the specific places where the flows the policy permits could cause you harm, each tagged with the lifecycle stage the risk lives in and how serious it is.
Before the harms, the raw material. To use the core of the app, you must hand over your precise location:
“For our core features to function (e.g., GPS activity tracking, routes, segments), you must grant us permission through your device to track your device's precise location.”Information From Using the Services — Location Information
That produces Activity Data — “geolocation information” plus “date, time, distance, speed, pace, perceived exertion, power, cadence” — and, if you connect a sensor, health data: “Activity Data can also include health data, such as heart rate, if you choose to provide it.” Strava also records your social graph (“users you follow and who follow you”) and, from your activity, generates its own metrics: “Relative Effort, Fitness Score, Fitness & Freshness, and Performance Predictions.”
What the policy allows: precise-location tracking is mandatory for the core features (quoted above), and the resulting map — “where you run or ride” — is shareable. Most runs and rides begin and end at home. A route that repeatedly starts and finishes at the same point draws a circle around your address.
Why it could harm you: a GPS trace is not an abstraction of your life; it is your life, plotted. Anyone who can see your activities can infer your home, your workplace, your gym, your child's school — and the exact times you are at each. This is the risk that made Strava's public heatmap notorious for exposing the layout of military bases and the homes of the people who use it. The danger is not hypothetical; it is geometric.
What the policy allows:
“If you are 18 years or older, certain information, including your profile and your activities, is set by default to be viewable by ‘Everyone.’”How We Share Your Information — Information Visible to Others
Why it could harm you: the policy defines “Everyone” as “Strava users and the public, including search engine results.” So the location data from #01 is, out of the box, not shared with friends you chose — it is published to the open internet and indexable. You are opted in to broadcasting your movements to strangers unless you actively find and change the setting. For an adult, the most sensitive data the app holds has the most exposed default.
What the policy allows: activities carry “date, time” and are viewable by “Everyone” by default (#02). Post a 6am run every weekday, a long ride every Saturday morning, and a race in another city this weekend, and you have published a schedule of your absences.
Why it could harm you: the same data that shows where you live (#01) shows when that home is empty and when your routine is predictable. That is precisely the information a burglar, a stalker, or an abusive ex-partner needs. Combining location with timing and regularity turns a fitness log into a surveillance feed about a single person: you.
What the policy allows: “Activity Data can also include health data, such as heart rate, if you choose to provide it.” To Strava's credit, the policy adds a real carve-out for data pulled from connected apps: “If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising… we do not disclose it to third parties without your prior consent.”
Why it could harm you: heart-rate and effort data over time can hint at cardiac issues, stress, pregnancy, illness, or fitness decline — categories most people consider medical. The advertising carve-out is meaningful but bounded: it names data “from these integrations,” and does not by its terms cover every path, nor breach, nor legal compulsion (#08). Sensitive data that exists can still leak or be demanded.
What the policy allows:
“We generate metrics from your information to help you analyze your performance, such as Relative Effort, Fitness Score, Fitness & Freshness, and Performance Predictions.”Information From Using the Services — Performance Metrics
Why it could harm you: these are inferences — Strava's model of your body and its trajectory, derived rather than declared. A scored, predicted picture of your fitness is the kind of attribute that could matter to an insurer, an employer, or a future data buyer. You can see the numbers, but you don't control the modeling, and inferred health scores are a category the law is only starting to reckon with.
What the policy allows: Strava “may use cookies and other tracking technologies to support targeted advertising,” and provides an opt-out — which tells you the sharing is on by default:
“You have the right to opt out of sharing your personal information for targeted advertising. You can click the ‘Do Not Share My Personal Information’ link on the website footer… or broadcast an Opt-Out Preference Signal, such as the Global Privacy Control.”Notice For Individuals Residing In Certain US States
Why it could harm you: the “Do Not Share” framing is the language U.S. state laws use for what they define as selling or sharing your data. It is opt-out, not opt-in — it runs until you turn it off — and it feeds your information into an ad-tech network that can combine it with data from elsewhere.
What the policy allows: “You can choose to share your information and content with third-party apps, plugins, or websites that integrate with the Services.” Strava also “may also license or share deidentified or aggregated information with third parties” — e.g. via Strava Metro — and “may also share aggregated or deidentified information, such as usage or demographics.”
Why it could harm you: every app you authorize is a copy of your route and activity data leaving Strava's control and living under someone else's policy — and old connections you forgot are still open pipes. “Deidentified or aggregated” location data is also notoriously re-identifiable: a small number of start points can single out one household.
What the policy allows:
“We may preserve and share your information with third parties, including law enforcement, public or governmental agencies, or private litigants… if we determine that the law compels or reasonably requires such disclosure.”How We Share Your Information — Legal Requirements and Prevention of Harm
Why it could harm you: your minute-by-minute location history is exactly what a subpoena or investigation wants. Where you were, and when, becomes evidence — in a case you may not even be party to. Data that exists can be compelled; data that was never public and was minimized is far harder to reach.
What the policy allows: Strava “generally keep[s] information associated with your account until you delete it,” and after deletion “it may take up to 45 days to delete your personal information and system logs.” If the company changes hands — “a business combination, acquisition… bankruptcy, reorganization” — “we may share or transfer your information in connection with such transaction.” Data is also “transferred, processed, and stored in the United States.”
Why it could harm you: your route archive only grows for as long as you stay, and the company you chose to trust is not necessarily the one that ends up holding it. A future owner inherits your location history under whatever policy they adopt. (This is the 23andMe problem, applied to a map of your movements.)
Where the risks concentrate, named in the field's own vocabulary:
Strava is unusual in that the heat starts at collection — the raw material is precise, physical, and about a real body in real places — and peaks at disclosure, because the default sends that material to “Everyone.” The gap between those two ends is the whole story.
The test
Context you entered: a fitness-tracking relationship — you log a run or ride, it shows you your stats and maybe your friends'.
Expected flow: your location and effort data used to record and analyze the workout you asked it to record.
Boundaries crossed: that precise route data is published to “Everyone,” including search engines, by default (#02); the map reveals your home (#01) and, through timing, your absences (#03); health signals are collected (#04); a fitness model of your body is derived (#05); the data is shared for targeted advertising unless you opt out (#06), sent to third-party apps (#07), reachable by authorities (#08), and kept until you delete it, movable in a sale (#09).
None of these are what “log my run” implies. That gap — between the flow you expected and the flows the policy authorizes — is where the harm lives, and with location data it is unusually sharp.
Consequences
The upside is real: social motivation, segments, kudos. The downside is a published map of where you live, work, and are absent — enabling burglary, stalking, and harassment. The benefit is felt daily; the harm is catastrophic but rare, and lands on a single person all at once.
Duty & rights
Agreeing to “track my run” is not agreeing to broadcast your address to the public web. Making “Everyone” the adult default treats the right to locational privacy as something you must reclaim, not something you hold by default. A duty to protect users points the other way.
Virtue
What kind of service ships the most dangerous exposure as the factory setting because it drives engagement? A trustworthy one would make the safe choice the easy one — private by default, public by deliberate act — not the reverse.
Justice
The burden falls hardest on those most endangered by exposure — women, abuse survivors, public figures, service members — and on the less technical who never find the visibility settings. Strava and viewers see the map; the person on it often doesn't realize it is public.
The policy and its linked controls grant real levers. In rough order of value:
Bottom line
Strava's policy is not unusually predatory in its words — but the data it governs is unusually dangerous, and the defaults point the wrong way. The most sensitive thing the app holds — a precise, timestamped map of your body moving through the world, starting and ending at your door — is set to be visible to “Everyone,” including search engines, unless you intervene. The harm here isn't a hidden clause; it's a setting. The most consequential decision Strava made on your behalf is one you have to actively undo.