Legal

Last updated: 2026-05-27

PrivacyTermsDelete dataReport

Privacy Policy

Who we are

Stranager is operated by Jack Cohen, an independent developer. Jack is the data controller for the purposes of this policy. Contact: jackbcohen2@gmail.com.

Stranager is in closed beta. This policy describes how it handles your data today; if anything material changes you'll see a banner in the dashboard the next time you sign in, and the "Last updated" date at the top of this page will move.

What Stranager stores

Stranager is built to edit your Strava activities with information from other apps you already use — your COROS watch's workout data, Spotify or Last.fm listening history, and Runna training plans. To do that, it needs to keep a small amount of information about you and your connected accounts.

  • From Strava: your athlete ID, first and last name, profile URL, email (when provided by Strava), measurement preference (km vs mi), and your OAuth access + refresh tokens.
  • From COROS: the OIDC client ID Stranager registered on your behalf, your display name and email (from the COROS ID token), an MCP session ID, and your OAuth access + refresh tokens.
  • From Spotify (if you connect it): your Spotify user ID, email, the OAuth scopes granted, and your OAuth access + refresh tokens. Stranager also caches the public name and URL of playlists it's seen referenced in your activities.
  • From Last.fm (if you connect it): your Last.fm username, an encrypted session key, and the timestamps when the connection was created and last used.
  • From Runna (if you connect it): the encrypted ICS calendar URL you provided and a small in-memory cache of parsed workouts (cleared every 30 seconds).
  • Activity rename history: for each Strava activity Stranager has processed, the Strava activity ID, the original and new title and description, any per-activity overrides you set, and the processing state.
  • Settings: your per-element AUTO/CONFIRM/OFF choices, your custom signature text, your timezone, your description element ordering, and your selected quote bank.

How OAuth tokens are protected

Strava, COROS, and Spotify access and refresh tokens, the Last.fm session key, and the Runna ICS URL are encrypted at rest with AES-256-GCM before they touch the database. The encryption key never leaves the server's environment. Tokens are decrypted in memory only at the moment they're used to make an API call on your behalf.

What Stranager does NOT store

Stranager fetches your COROS workout data, your Spotify play history, your Last.fm scrobble history, and your Runna scheduled workouts at the moment it processes an activity, uses it to compute the rename, and discards the raw response. The fetched workout details, lap data, per-track listen history, and calendar payloads are not persisted to Stranager's database — only the final renamed title and description are kept.

Who sees your data

Stranager does not sell or share your personal information with anyone for any purpose. The only outbound traffic carrying your data is the API calls Stranager makes to Strava, COROS, Spotify, and (if connected) Runna and Last.fm — those calls are necessary for the service to function.

Sub-processors

Stranager runs on a virtual private server located in the United States. SSL certificates are issued by Let's Encrypt / ISRG. That's it — Stranager deliberately does not use third-party analytics, advertising networks, marketing tools, or hosted error-monitoring services. The full sub-processor list is reproduced here in the policy and will be kept up-to-date.

Strava-specific commitments

Stranager complies with the Strava API Agreement. Specifically:

  • Stranager prunes activity rename rows seven (7) days after the rename was recorded, via a daily cleanup job in the worker process. This matches the Strava API Agreement's caching limit. The new titles Stranager wrote remain on Strava's side — they're yours.
  • When you revoke Stranager's access on Strava's side or disconnect from your Stranager dashboard, all of your data is deleted from Stranager within forty-eight (48) hours — in practice within seconds.
  • Stranager does not use Strava data, Spotify data, or any other connected-service data to train artificial intelligence or machine learning models, and does not share any such data with anyone who might.
  • If Stranager ever suffers a data breach affecting your personal data, you and Strava will be notified within twenty-four (24) hours of discovery.

Strava's own privacy policy is at strava.com/legal/privacy. Note that Strava collects usage data about Stranager's API calls (rate-limit counters, error rates, etc.) as part of operating the Strava API; this is independent of the data Stranager itself stores and is governed by Strava's policy.

Spotify-specific commitments

Stranager uses the Spotify Web API only to fetch your recently played tracks for the purpose of enriching activity titles and descriptions. Stranager does not derive recommendations from Spotify data, does not build user-profile metrics, does not feed any advertising network, and does not train any model on Spotify content. Spotify's privacy policy is at spotify.com/legal/privacy-policy.

Retention and deletion

You can disconnect at any time from your dashboard:

  • Disconnecting Strava deletes your Stranager account entirely. All associated tokens, settings, activity rename history, cached playlist names, and any connected COROS / Spotify / Last.fm / Runna data are removed within seconds, and your Strava OAuth grant is revoked at Strava's side.
  • Disconnecting COROS, Spotify, Last.fm, or Runna individually deletes only that service's tokens or URL; your Stranager account and Strava-side state remain.

For a manual data-deletion or data-export request — including the case where you can no longer sign in to your account — see the Delete data section below.

Your rights

Stranager considers itself bound by the California Consumer Privacy Act (CCPA) for all users regardless of where they live, and intends this policy to comply with the EU and UK General Data Protection Regulation (GDPR) for users in those jurisdictions. You have the right to:

  • Know what personal data Stranager has about you (just ask)
  • Have that data deleted (disconnect, or email the address above)
  • Opt out of having your data sold or shared — though we do neither

We do not sell or share your personal information, full stop. Stranager has no advertising relationships, no data-broker relationships, and no shared-audience integrations. There is nothing to opt out of, but the right is yours regardless.

Cookies

Stranager sets a single first-party HTTP-only session cookie (stranager-session) to remember you while you're logged in. No tracking cookies, no third-party analytics, no cross-site cookies, no consent banner needed.

Changes to this policy

Stranager is in beta and operated by one person. If this policy changes, the "Last updated" date at the top of this page will change too. Material changes will be flagged in the dashboard the next time you log in, with at least fourteen (14) days' notice before they take effect.

Terms of Service

Who you're agreeing with

Stranager is operated by Jack Cohen, an independent developer. By connecting your Strava account, you're entering into an agreement with Jack personally. Contact: jackbcohen2@gmail.com.

The basics

Stranager is a free hosted tool that edits your Strava activities using information from other apps you already use: the workout names from your COROS watch, optional Runna calendar workouts, and optional music enrichment from Spotify or Last.fm (Apple Music is a planned future connection and not yet available). By connecting your accounts, you grant Stranager permission to read your COROS workout data, read your Runna calendar (if you provide the URL), read your Spotify recently-played and saved-playlist data (if you connect Spotify), read your Last.fm scrobble history (if you connect Last.fm), and read and update your Strava activity names and descriptions on your behalf.

This is beta software

Stranager is in closed beta and offered as is, with all faults and without warranty of any kind, express or implied, including any warranty of merchantability, fitness for a particular purpose, or non-infringement. There is no service-level agreement and no uptime guarantee. Bugs happen. Activity renames may occasionally fail, get delayed, or produce unexpected output. If you rely on Strava activity titles for anything mission-critical (coaching records, racing results, etc.), keep your own copies.

Eligibility

You must be at least eighteen (18) years old (or the age of majority in your jurisdiction, whichever is higher) and hold a valid Strava account in your own name. One Stranager account per person.

What Stranager will not do

  • Stranager will never write to a Strava activity element you have set to OFF in your settings.
  • Stranager will never overwrite a Strava activity title that appears to have been edited by you (titles that don't match Strava's auto-generated patterns are left alone).
  • Stranager will never sell, share, or transmit your data to a third party. See the Privacy section above for what is stored and for how long.
  • Stranager will never use your Strava, COROS, Spotify, Runna, or any other connected-service data to train artificial intelligence or machine learning models.

Your responsibilities

  • Don't use Stranager to abuse the Strava, COROS, Spotify, or Runna APIs — Stranager has per-account rate limits, but they aren't the only safeguard.
  • Don't use Stranager on an account that isn't yours.
  • Don't attempt to reverse-engineer, scrape, or otherwise access parts of Stranager you weren't given access to.
  • Tell Jack at jackbcohen2@gmail.com if you find a bug, a security issue, or behavior that surprises you. See Report an issue below.

Termination and data deletion

You can disconnect your Strava account from your dashboard at any time, which deletes your Stranager account, all associated tokens, and your activity rename history within seconds. Stranager may also suspend or terminate accounts that abuse the service or violate these terms — in that case, the same deletion applies. For a manual data deletion request, see the Delete data section below.

Limitation of liability

To the maximum extent permitted by applicable law, Stranager and Jack Cohen will not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of profits, revenue, data, or use, arising out of or related to your use of Stranager. Stranager's total liability for any direct damages is capped at the greater of one hundred US dollars ($100) or the fees you have paid Stranager in the twelve (12) months preceding the event giving rise to the claim. Stranager is currently free, so for beta users today that cap is $100.

Affiliations and trademarks

Stranager is not affiliated with, endorsed by, or sponsored by Strava, Inc., COROS Wearables Inc., Spotify AB, or Runna Limited. Strava, COROS, Spotify, and Runna are trademarks of their respective owners. Stranager uses each platform's official OAuth flow.

Governing law and disputes

These terms are governed by the laws of the State of California, without regard to its conflict-of-laws provisions. Any dispute arising out of or related to these terms or your use of Stranager will be brought exclusively in the state or federal courts located in California, and you consent to personal jurisdiction there. If any provision of these terms is held unenforceable, the rest remain in effect.

Changes to these terms

If these terms change, the "Last updated" date at the top of this page will change too. Material changes will be flagged in the dashboard the next time you log in, with at least fourteen (14) days' notice before they take effect.

Delete your Stranager data

If you can sign in

Open your dashboard, scroll to the Account section, and click Disconnect Strava. This deletes your Stranager account immediately — all OAuth tokens, settings, activity rename history, and any connected COROS, Spotify, Last.fm, or Runna data are removed within seconds. Stranager also revokes the Strava OAuth grant upstream, so the connection is fully cut on both sides.

If you only want to disconnect a single service (say, Spotify) while keeping the rest of your Stranager account, use the per-service Disconnect button on the dashboard instead.

If you can't sign in

Email jackbcohen2@gmail.com from the email address you have on file with Strava (so we can verify it's actually you) and say you'd like your Stranager data deleted. Stranager will confirm the deletion within thirty (30) days — in practice within a day or two.

What gets deleted

  • Your Stranager account row and all per-account settings
  • All encrypted OAuth tokens for Strava, COROS, Spotify, the Last.fm session key, and (if applicable) the Runna calendar URL
  • All activity rename history rows tied to your account
  • Any cached playlist names, preview rows, and connected-source metadata

What does NOT get deleted

  • The titles and descriptions Stranager wrote to your Strava activities — those live on Strava's side and are now yours (you can edit them on Strava at any time).
  • Server logs may briefly retain your account ID after deletion, purely for debugging. Logs are rotated and retained for no more than thirty (30) days.

Strava-side revocation

Stranager calls Strava's oauth/deauthorize endpoint as part of the deletion flow, so your Strava OAuth grant is removed in the same operation. You can also independently revoke Stranager's access from your Strava connected apps page — this triggers Stranager's deauthorize webhook handler, which does the same cleanup automatically.

Report an issue

Bug, surprising behavior, or a security concern? Email jackbcohen2@gmail.com and Stranager will respond as soon as possible — typically within a day or two.

For suspected security vulnerabilities, please use the subject line [security] so the report is triaged immediately, and include enough detail to reproduce the issue. Coordinated disclosure is appreciated; Stranager will acknowledge the report within 72 hours.

Legal
Compatible with StravaPowered by COROS MCP

Not affiliated with Strava, Inc., COROS Wearables Inc., Spotify AB, or Runna Limited.