Last updated October 9, 2026
activart turns your Strava activities into shareable route posters, inside an AI assistant such as Claude or ChatGPT. This policy explains what the activart connector collects, how it is used, who else handles it, and how to have it removed. It covers the connector at mcp.activart.pro and this website. It does not cover the activart web app at activart.pro.
The operator of this service is Kyle Roth. You can reach us at hello@corunner.io.
| Data | Why | How long |
|---|---|---|
| Your Strava athlete ID, and the access and refresh tokens Strava gives us (read access to your activities only) | To call Strava on your behalf when you ask for a poster | Until you ask us to delete it |
| Sign-in records for your AI assistant: its registration, short-lived authorization codes, and the access and refresh tokens we issue it | To let your assistant use the connector as you, without a separate password | Codes expire in minutes and access tokens in an hour; refresh tokens last until deletion |
| Standard server and network logs kept by our hosting provider, which can include IP addresses and request times | Operating and securing the service | Per our provider's retention |
We do not collect your name, email address, or payment information, and the connector has no account or password of its own. Sign-in happens on Strava's own consent screen.
We ask Strava for the activity:read permission only. When you ask your assistant to list your activities, show an activity's details, or make a poster, we call Strava live and use the result for that one request: the title, date, distance, time, elevation, location if Strava has one, and the GPS route. The route is drawn onto a map and returned to your assistant as an image. None of it is saved.
Because the poster and any activity details are returned to your assistant, they are visible to the AI service you are using (for example Anthropic for Claude, or OpenAI for ChatGPT). That service's own terms and privacy policy apply to them.
We do not share your data with anyone else, except where the law requires it.
Traffic to the connector is encrypted with HTTPS. Stored tokens sit in a private database that is not reachable through any public API; the connector reaches it over a direct, authenticated connection. No system is perfectly secure, and if we learn of a breach affecting you we will tell you and Strava.
activart is not directed at children under 16, and Strava requires its users to meet its own age minimums. We do not knowingly collect data from children.
Depending on where you live you may have the right to access, correct, delete, or export the personal data we hold, or to object to how we use it. Because we keep very little, the practical way to use these rights is the email above. We will not treat you differently for asking.
If we change this policy we will update the date above, and for material changes we will say so on this page.
Kyle Roth · hello@corunner.io