Last updated: October 7, 2026

Overview

RunFit is a hobby project designed to process your own running data. It does not provide user accounts and does not operate an application database containing your Strava activities.

Data obtained from Strava

When you connect Strava, the app requests access to your own activity data through Strava's OAuth authorization flow. RunFit first uses activity summaries to build an estimated history quickly. For detailed analysis it may temporarily retrieve laps, elapsed time, heart rate, smoothed speed, and moving status. The app does not request GPS or latitude/longitude streams from Strava.

Where your data is stored

Your activity data is stored only on this device and is not stored in RunFit's servers. Activity summaries, calculated RFI results, lap summaries and compact derived analysis segments are stored in IndexedDB in your browser. After a Strava activity is refined, RunFit discards the second-by-second streams it retrieved and retains the smaller derived information needed to display the result and recalculate it when settings change. App settings, race-goal settings, Strava access and refresh tokens, and small UI preference timestamps are stored in localStorage in your browser.

The Cloudflare Worker used by this site handles Strava OAuth token exchange, refresh and revocation requests. It does not intentionally persist your Strava tokens or activity data in a server-side application database.

Local file import

You can optionally select Strava activities.csv or TCX/GPX activity files exported from Strava, Garmin, or another provider. These files are read and analysed locally in your browser and are not uploaded to RunFit's servers. Locally imported activities can remain available even if you later disconnect the Strava API connection.

How the data is used

Your Strava data is used to calculate and display your RFI, classify runs, analyse selected workout laps, and calculate race-goal values. The app does not sell your data or use it for advertising.

Export and deletion

You can export a weekly RFI trend from the Runs section. That CSV contains only the week start and average RFI; it does not export Strava activity records, laps, streams, heart rate, pace, distance, or OAuth tokens.

Selecting Disconnect Strava asks Strava to revoke RunFit's authorization and then deletes activity data that was downloaded through the Strava connection. Activity files you explicitly imported from your device, RunFit settings and your race goal are kept.

Selecting Delete all local data deletes locally stored runs, settings, race goal, tokens and app state. If Strava is connected, RunFit also attempts to revoke the connection first. You can independently review or revoke connected applications from Strava My Apps.

Third-party services

Strava provides the activity data and OAuth authorization used by this app. Strava may collect usage data relating to access to its API under its own policies.

Cloudflare hosts and serves this site and its Worker. Cloudflare may process ordinary network and request information as part of providing and securing its infrastructure.

Ko-fi is used only for optional project support. The app does not load a Ko-fi overlay or payment script. If you choose the Support on Ko-fi link, you leave this site and Ko-fi's own privacy practices apply.

Cookies and local browser storage

RunFit does not require an application account or use advertising cookies. It uses browser storage as described above so that your locally stored analysis and preferences can persist between visits.

RunFit counts daily and weekly active devices and clicks on the Ko-fi support button using a randomly generated identifier. No runs, scores, athlete identifiers or analytics IP-address records are stored with these counts.

Changes to this policy

This policy may be updated if the app's data handling changes. The date at the top of this page will be updated when that happens.