← Back
Privacy Policy
Effective date: March 2026
Tawa ("Tawa", "we", "us")
is a personal endurance analysis application. This policy describes what data we collect, how we use it, and your rights.
Data we collect
- Account data - your email address and display name, used to identify your account.
- Authentication credentials - hashed passwords (bcrypt). We never store passwords in plain text.
- Strava activity data - when you connect a Strava account, we retrieve your activity history including GPS streams, heart rate, pace, and elevation. This data is sourced from the Strava API.
- Derived training metrics - values computed from your activity data, including training load, aerobic efficiency, and fitness/fatigue estimates.
- Preferences - your timezone and unit preferences.
How we use your data
- To compute and display your training metrics and charts.
- To authenticate you and maintain your session.
- To send a password reset email if you request one.
We do not sell your data. We do not use your data for advertising.
Strava data and the Strava API
Tawa uses the
Strava API
to access your activity data. By connecting your Strava account you agree to
Strava's API Agreement
and Privacy Policy.
Strava may collect usage data related to API use as described in their privacy policy.
You can revoke Tawa's access to your Strava account at any time from
Strava's app settings.
When access is revoked, your Strava activity data is deleted from Tawa automatically.
Data retention and deletion
- Activity data sourced from Strava is deleted when you disconnect Strava or delete your account.
- You can delete all imported activity data at any time from the Account page without deleting your account.
- You can delete your entire account and all associated data from the Account page.
Data security
Passwords are hashed with bcrypt. OAuth tokens are stored in the database and used only
to refresh your Strava data. All connections use HTTPS.
Third-party services
- Strava - activity data source. See Strava Privacy Policy.
- Google Fonts - typography (Inter, DM Serif Display, IBM Plex Mono) loaded from Google's CDN.
Contact
Questions about this policy? Reach out via the
project repository.
Tawa - Personal use