Privacy
Short version: PeakDew stores what it needs to annotate your activities, and nothing else.
What is stored
- Your Strava athlete ID, name, country, profile image URL and unit preference.
- Your Strava access and refresh tokens, encrypted at rest.
- For each activity processed: its ID, name, sport, start time, distance, moving time, elevation gain, and the analysis results.
- The peaks you have bagged, with their coordinates and when you first crossed them.
- If you subscribe, a Stripe customer and subscription ID. Card details never touch this server.
What is not stored
- Your full GPS tracks. They are fetched, analysed in memory and discarded.
- Heart rate, power, or any other stream beyond location, time and altitude.
- Your Strava password — OAuth means this app never sees it.
Who else sees it
Coordinates rounded to about a kilometre are sent to Open-Meteo to look up weather, and a bounding box around your route is sent to the OpenStreetMap Overpass API to look up peaks. Neither request carries your identity. Nothing is sold, and there is no advertising or analytics tracking.
Deleting your data
Settings → Disconnect revokes the tokens and removes your athlete record, activities and peak list. Revoking from Strava's apps page triggers the same deletion via the deauthorization webhook.