← Back to Stride

Privacy Policy

Last updated: August 2, 2026

Who we are

Stride is a personal productivity app made by Stride. This policy explains what information Stride collects when you use the app, why we collect it, who else it reaches, and what control you have over it. It's written to describe what the app actually does — not to cover us with vague language. If anything here is unclear, email us at support@strideapp.uk.

What we collect

  • Account information: your email address, a username, and a password. We never see or store your password in plain text — it's hashed and handled by our authentication provider.
  • The content you create: pages, tasks, notes, habits, journal entries, food and nutrition logs, financial entries, and every other block of content you add to Stride. This is the core of what the app stores on your behalf.
  • Messages and collaboration data: direct messages, group chats, page comments, and file attachments you send through Stride's messenger, along with who you've added as a friend, which groups you're in, and which pages you've shared and with whom. See "Encryption" below — direct messages and group chats are end-to-end encrypted, page comments are not.
  • Profile information: a display name and, if you choose to add one, a profile picture.
  • Billing information: we know whether you have an active subscription and what state it's in. We never collect or store your card details — those go directly to our payment processor and never touch our systems.
  • Voice recordings: audio you record with the Voice Notes block. See "Microphone" below.
  • Location: only if you use the Weather block's "use my location" button. See "Location" below.
  • Technical and diagnostic information: basic operational data needed to keep the app working (such as when your data last synced), plus crash and error reports. See "Crash reporting" below.

Microphone

Stride's Voice Notes block records audio, which requires microphone access. Your operating system will ask for permission the first time, and Stride only ever opens the microphone while you are actively recording a voice note — never in the background, and never to listen passively. Recordings are stored like any other attachment you create, and you can delete them at any time. If you don't use the Voice Notes block, Stride never requests the microphone at all.

Location

The Weather block can show local conditions. If you press its "use my location" button, your device provides approximate coordinates, which are sent to our weather and place-name providers (Open-Meteo and BigDataCloud, listed below) to look up a forecast and a nearby place name. We don't store a location history, and we don't use your location for anything other than filling in that block. You can type a location manually instead, and if you never press that button, Stride never asks for your location.

Encryption

Direct messages and group chats are end-to-end encrypted. Their contents are encrypted on your device before they're sent, and can only be decrypted on the devices of the people in that conversation. We cannot read them. Our servers only ever hold the ciphertext, your public key, and per-recipient encrypted copies of each conversation's key. Your private key is generated on your device, stored only on that device, and never sent to us.

Because of that design, there is no recovery path for encrypted conversations. This is the same trade-off made by apps like Signal and WhatsApp: if you lose access to a device and have no other device signed in, that account's copies of past conversation keys are gone permanently, and neither we nor anyone else can restore them. We think that's the right trade for private messages, but you should know it before you rely on Stride's messenger for something irreplaceable.

Comments left on a page are not end-to-end encrypted, and neither is the rest of your content — pages, notes, tasks, logs, attachments, and so on. That content is encrypted in transit and encrypted at rest by our infrastructure provider, but it is technically possible for us or that provider to access it (for example, to investigate abuse or to comply with a valid legal request). Access is restricted internally, and database-level access rules mean other users can only ever see what you've explicitly shared with them.

How your data is stored

Stride is local-first: your content is cached on your own device so the app keeps working offline, and syncs in the background to our cloud database when you're connected. That means a copy of your data lives on every device you use Stride on, in addition to our servers.

Third-party services we use

We use a small number of outside services to run Stride. Each one only receives what it needs to do its job. We don't sell your data to any of them, and none of them are advertising or profiling services.

  • Supabase — our database, authentication, file storage, and realtime sync. This is where your account and your content are stored. Our database is hosted in the EU (Stockholm).
  • Stripe — payments and subscriptions. Stripe receives your billing details directly; we receive only your subscription status. Card numbers never pass through Stride.
  • Sentry — crash and error reporting, so we can find and fix bugs. Sentry receives error messages, stack traces, and basic app/version information. We have deliberately configured it to exclude console output, typed input, and the text of anything you click, specifically so that decrypted message content can't leak into a crash report. See "Crash reporting" below.
  • Resend — transactional email. Used to send invitation and notification emails; it receives the recipient's email address and the contents of that email.
  • Anthropic — powers the in-app "Ask AI" help assistant. When you ask it a question, the question you typed (and the earlier turns of that same chat) are sent to Anthropic's API to generate an answer. Your pages, notes, and messages are not sent — the assistant answers questions about how to use Stride, and has no access to your content. If you never use Ask AI, nothing is ever sent to Anthropic.
  • Open Food Facts — food and nutrition lookups, including barcode scans, in the Food Log. It receives the search term or barcode you enter, not your identity.
  • Open-Meteo and BigDataCloud — weather forecasts and place-name lookups for the Weather block. They receive the location being looked up. See "Location" above.
  • YouTube and Vimeo — if you embed a video in a page, the video is loaded from YouTube or Vimeo when that page is viewed, and those services may set their own cookies and receive your IP address, as they would on any website embedding a video. This only happens on pages where you've added an embed.

Crash reporting

When the app hits an error, we send a report so we can fix it. Those reports contain the error and where in the code it happened — not your content. We've explicitly turned off the parts of our crash reporter that would otherwise record console output, what you type, and the text of elements you click, because in an app with encrypted messaging those would capture message contents after decryption and defeat the point of encrypting them.

What we don't do

We don't sell your data. We don't run advertising. We don't share your content or messages with third parties for marketing. There's no analytics or behavioural-tracking SDK in the app beyond the crash reporting described above.

Who can see your data

By default, only you can see your own pages and content. Content becomes visible to someone else only when you explicitly share a page with them, share it with a group they're in, message them, join a group chat, or comment on a shared page. This is enforced by access rules in the database itself, not merely hidden in the app's interface.

Legal basis for processing

If you're in the UK or the EU, we rely on these lawful bases under the UK GDPR and GDPR:

  • Performance of a contract — to give you the account, storage, sync, sharing, and messaging features you signed up for, and to bill you for them.
  • Legitimate interests — to keep the service secure and reliable, prevent abuse, and fix crashes. We've balanced this against your privacy, which is why crash reports are configured to exclude your content.
  • Consent — for microphone and location access, which are optional, requested by your operating system at the moment you use the relevant feature, and revocable in your system settings at any time.
  • Legal obligation — to keep the limited billing and tax records we're required to keep.

International data transfers

Our database is hosted in the European Union (Stockholm, eu-north-1). Some of the services listed above are based in, or process data in, the United States — Stripe, Sentry, Anthropic, and Resend in particular. Where data is transferred outside the UK/EEA, it's done under the transfer mechanisms those providers offer, such as the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum and the EU–US Data Privacy Framework.

Your controls and your rights

  • You can reset all of your data back to a fresh account at any time from Settings.
  • You can permanently delete your account and all associated data from Settings — this also cancels any active subscription.
  • You can remove friends, leave groups, and revoke page sharing at any time.

If you're in the UK or the EU, you also have the right to access your personal data, to correct it, to have it erased, to restrict or object to how we process it, and to receive a copy of it in a portable format. Most of this you can do yourself in the app. Stride does not currently have a self-service data export feature — if you want a copy of your data, email support@strideapp.uk and we'll provide one. We'll respond to any of these requests within one month.

Note that we cannot produce the contents of your end-to-end encrypted conversations in response to any request, including your own — we don't have the keys. Those live only on your devices.

Data retention

We keep your data for as long as your account is active. If you delete your account, we permanently delete your data, except for limited records (such as billing history) that we're required to keep for legal, tax, or accounting reasons. Locally cached copies on your own devices are removed when you sign out or delete the app.

Complaints

If you think we've handled your personal data improperly, please contact us first at support@strideapp.uk — we'd rather fix it directly. You also have the right to lodge a complaint with a data protection supervisory authority. In the UK that's the Information Commissioner's Office (ico.org.uk); in the EU it's the authority in the country where you live or work.

Children's privacy

Stride is not directed at children under 13, and we don't knowingly collect information from anyone under that age. If you believe a child has given us personal data, contact us and we'll delete it.

Changes to this policy

If we make material changes to this policy, we'll notify you in the app or by email before they take effect.

Governing law

This policy is governed by the laws of England and Wales.