SubRunGear
SubRunGear

Privacy Policy

Effective 29 August 2026

1. Who we are

SubRunGear (subrungear.com) is owned and operated by To When Pty Ltd, Sydney, Australia, and handles personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). This policy explains what we collect, why, where it lives, and how to get it corrected or deleted.

2. What we collect

  • Account: email address, username, display name, and avatar.
  • Locker content: the gear you add (shoes, nutrition, apparel, accessories), sizes, nicknames, notes, kits, retirement history, comments, and photos you upload.
  • Activities: date, distance, duration, and sport — whether logged manually, uploaded as FIT/GPX/TCX files, or synced from Strava. We never store or display GPS routes or start locations.
  • Strava connection: your Strava athlete ID and OAuth tokens (encrypted with AES-256-GCM), plus the shoes on your Strava profile for gear sync.
  • Onboarding photos: shelf or flat-lay photos you submit are downscaled, sent to our AI provider to identify gear, and are not retained afterwards.
  • AI chats: your Gear Advisor and Training Coach messages and saved recommendations, plus per-user usage counters.
  • Billing: if you subscribe, payment is handled by Stripe; we store only your Stripe customer reference, never card details.
  • Clicks & analytics: affiliate link clicks recorded with a salted, non-reversible visitor hash (no raw IP stored), and product analytics (PostHog) and error reports (Sentry) to keep SubRunGear working.

3. What is public and what is private

Public locker pages show only what you choose to publish: visible gear, public mileage totals, kits, and retirement history. Runs synced from Strava are visible to you alone — never on public pages, never in public mileage totals, and never exported. Your email address is never displayed anywhere. You can set your locker to public, unlisted, or private at any time on your profile.

4. AI processing (Anthropic)

AI features are powered by Anthropic's Claude models via Anthropic's API, with processing in the United States. What gets sent depends on the feature:

  • Photo onboarding sends the photo you submit.
  • Gear Advisor sends your questions, your locker contents, and catalog data — never Strava-sourced activities.
  • Training Coachis off until you explicitly opt in. When opted in, your questions, locker, and recent activities (including Strava-sourced ones) are used, and Anthropic's servers may query Strava's MCP server on your behalf using your own Strava access token to answer questions about your training. Opting out stops this immediately and can be done at any time in the coach settings.

We use Anthropic as a processor via its API: data sent this way is not used to train Anthropic's models. The never-Strava-in-AI rule outside the opted-in coach is enforced in code and covered by automated tests.

5. Who else receives data

We do not sell personal information. It is shared only with service providers that run SubRunGear, some of which are located overseas (primarily the United States): Anthropic (AI), Strava (when you connect it), Stripe (payments), Vercel (application hosting), PostHog (analytics), Sentry (error monitoring), and Resend (transactional email). Each receives only what its function requires. Affiliate retailers receive no personal information from us — outbound links carry no identifiers beyond the destination URL.

6. Where your data lives, and security

Our primary database and file storage are hosted in Sydney, Australia (AWS ap-southeast-2, via Supabase). Strava tokens are encrypted at rest with AES-256-GCM, database access is restricted with row-level security, and private data (like Strava activities) has no public access path at the database level.

7. Retention and deletion

  • Disconnecting Strava deletes all Strava-sourced activities and your Strava tokens within 24 hours.
  • Deleting your account (button on your profile page) permanently removes your profile, locker, gear, photos, activities, chats, and connections — immediately and irreversibly. Records our payment processor must keep for tax and audit purposes are retained by Stripe as required by law.
  • Aggregated, non-identifying analytics may be retained.

8. Cookies

We use cookies for sign-in sessions (required) and analytics. We do not run third-party advertising cookies.

9. Access, correction, and complaints

You can view and edit almost everything in the app itself. For a copy of your data, a correction we don't expose in the UI, or any privacy complaint, email hello@subrungear.com — we respond within 30 days. If you are unsatisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

10. Changes

We will update this policy as SubRunGear evolves and note the new effective date above. Material changes will be flagged on the site or by email.