We handle sensitive health and training data. Here's how we protect it.
All data is stored on Supabase servers in Sydney, Australia (ap-southeast-2). Your data never leaves the country.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Database connections use SSL.
Every database query is filtered by user ID at the database level. Users can only access their own data — enforced by PostgreSQL policies, not application code.
We don't use Google Analytics, Facebook Pixel, or any advertising trackers. No data is sold to third parties. Ever.
All payment processing is handled by Stripe. We never store or see your full card number. Stripe is PCI DSS Level 1 certified.
We comply with the Australian Privacy Act 1988, GDPR (for EU users), and Apple's App Store data handling guidelines.
When you connect with a coach on Stride, they can see:
You can disconnect from a coach at any time in Settings. When you disconnect, the coach loses access to your data.
If you discover a security vulnerability, please report it responsibly to support@stride-app.com. We take all reports seriously and will respond within 48 hours.
See also: Privacy Policy · Cookie Policy · Terms of Use