← Back to login

Privacy Policy

Last updated: May 11, 2026

What nitimini does

nitimini is a personal athletic profile that transforms your Strava activity data into statistics and visualizations. Your data is displayed only to you — there are no public profiles, no social features, and no way for other users to see your information.

Data we collect from Strava

When you connect your Strava account, we request the following OAuth scopes: read, activity:read_all, and profile:read_all. We do not request any write permissions.

From your Strava account, we store:

  • Profile information: name, profile image URL, city, state, country
  • Activity summary data: sport type, distance, moving time, elapsed time, elevation gain, average speed, average heartrate, max heartrate, suffer score, and similar aggregate metrics
  • Gear information: gear name, type, and distance

We store only the data needed to generate your training insights and visualizations. All stored data is deleted when you disconnect your Strava account.

How we use your data

Your data is used solely to generate your personal athletic profile:

  • Statistical summaries (totals, averages, year-over-year comparisons)
  • Visualizations (season shape charts, activity pulse heatmaps)
  • Gear usage tracking
  • A shareable profile card (which includes "Powered by Strava" attribution)

All computations are standard statistical aggregation — sums, averages, counts, and cumulative totals. We do not use your data for AI, machine learning, or model training of any kind.

Data storage and security

Your data is stored in an encrypted database with industry-standard hosting providers. All connections use HTTPS/TLS encryption in transit.

Your Strava OAuth tokens are stored securely and are used only to sync your data. We do not share your tokens with any third party.

Data sharing

We do not sell, rent, or share your personal data with any third party. Your data is displayed only to you when you are authenticated. The only exception is the shareable profile card, which you explicitly choose to export and share yourself.

Data deletion

Your data is deleted in the following scenarios:

  • Revoking access on Strava: If you disconnect nitimini from your Strava settings, we receive a deauthorization webhook and immediately delete all your data — profile, activities, gear, sessions, and account records. No data is retained.
  • In-app disconnect: You can disconnect your Strava account from within nitimini, which triggers the same immediate and complete data deletion.
  • Activity deletion: If you delete an activity on Strava, we receive a webhook and remove it from our database immediately.

There is no grace period or data retention after deletion. All related records are cascade-deleted from the database.

Cookies and sessions

We use a session cookie for authentication (JWT-based). This cookie is essential for the application to function and identifies your authenticated session. We do not use advertising cookies or third-party tracking cookies.

Analytics

nitimini uses Vercel Web Analytics and Vercel Speed Insights to understand how the application is used and to monitor page performance. These services collect anonymous data about page views and Core Web Vitals metrics. Vercel Web Analytics is cookieless and does not track you across sites or build a personal profile. No personally identifiable information is sent to Vercel.

A small set of anonymous custom events (such as sport filter changes and profile loads) are tracked to help us understand which features are used. These events contain no personal data beyond what is described above.

Access control

nitimini is currently in private beta. Access is restricted to an invite-only allowlist of Strava athlete IDs. Only approved athletes can sign in and use the application.

Changes to this policy

If we make material changes to this privacy policy, we will update the "Last updated" date at the top of this page.

Contact

For questions about this privacy policy or your data, contact us at privacy@nitimini.io.

nitimini uses the Strava API but is not endorsed or certified by Strava.