Trakr — every track tells a story

Privacy policy

Last updated: July 21, 2026

Trakr turns your activities into cinematic replay videos. This policy explains exactly what data Trakr touches, where it lives, and how you stay in control. The short version: your data stays on your device — Trakr has no server database and no accounts.

1. What Trakr stores, and where

Activities you import (from Strava or a GPX file), the Stories you create and your customization settings are stored only in your browser's local storage (IndexedDB) on your device. They are never uploaded to a Trakr server, never shared, and never sold. Rendered videos are created on your device and saved wherever you choose.

2. The Strava connection

You authenticate on strava.com through OAuth — Trakr never sees your Strava password. Trakr requests read-only access (scopes “read” and “activity:read_all”) so it can list your own activities, including private ones, and read their GPS streams. Trakr only ever accesses the activities of the account you connected — never another athlete's data — and it can never write, modify or post anything to Strava. You can limit the permissions on Strava's consent screen; Trakr only uses the scopes you actually grant. Trakr never uses your Strava data to train artificial-intelligence or machine-learning models, never sells it, and never shares it with third parties. Activities imported from Strava are stored only in your browser, on your device, for as long as you keep them — Trakr keeps no copy on any server. Strava may collect usage data about API applications as described in Strava's own privacy policy.

3. GPX uploads

GPX files you upload are parsed entirely in your browser. The resulting activity is stored in the same on-device library as Strava imports. Nothing is sent to a server.

4. Cookies

Trakr uses three cookies, none of them for advertising or tracking: “trakr_strava” holds your Strava access tokens, encrypted (AES-256-GCM) and readable only by the server that talks to Strava on your behalf; “trakr_strava_state” is a 10-minute security cookie protecting the OAuth flow; “trakr_locale” remembers your language.

5. Disconnecting Strava

You can disconnect at any time from My Activities or Settings. Disconnecting revokes Trakr's access at Strava (Trakr disappears from Settings → My Apps on strava.com) and deletes the token cookie. You can also revoke access directly on strava.com — Trakr detects it and returns to the disconnected state.

6. Deleting your data

Settings offers two one-click deletions: remove every activity imported from Strava (and the Stories built from them), or erase everything Trakr stores on your device. Because the data lives only in your browser, deletion is immediate and permanent. You can also email hello@trakr.club for any deletion request or question.

7. Your rights

Under the GDPR and similar laws you have the right to access, correct, export and erase your data, and to withdraw consent at any time. With Trakr these rights are exercised directly: everything Trakr stores is visible in the app, sits on your own device, and can be deleted from Settings in one click. For anything else, contact hello@trakr.club.

8. Changes

If Trakr's data practices ever change (for example if optional cloud features arrive in a future version), this policy will be updated first and the “last updated” date revised. Significant changes will be announced in the app.

Questions, or a data request? Write to hello@trakr.club

← Back home
Privacy policy — Trakr · Trakr