Strolly Deutsch

Privacy policy

Effective: 7 October 2026

This page explains in plain words what data Strolly processes, why, for how long, and what you can do yourself.

Who is responsible?

Simon Steindl, Währinger Straße 146, 1180 Vienna, Austria
Email: [email protected]

Your account

On first launch, Strolly quietly creates an anonymous account. It has only a random ID, no name and no email address. Your progress is tied to it.

With "Save your progress" you link the account to Apple or Google. Then we store the provider's ID, your email address and your name. For Google, Strolly shows your profile picture. The address of the picture sits with Firebase Authentication, and we do not store the picture ourselves.

Sign-in runs through Firebase Authentication by Google.

What we process and why

The legal basis is performing our agreement with you (Art. 6(1)(b) GDPR): Strolly cannot work without this data. For location and notifications your consent also applies (Art. 6(1)(a) GDPR), which you can withdraw at any time in your operating system.

No tracking, no ads

Strolly contains no analytics tools, no ads and no third-party trackers. We never sell your data. Our server keeps technical logs to find errors (legitimate interest, Art. 6(1)(f) GDPR). They hold no coordinates, access keys, email addresses or plain user IDs. Google Cloud also keeps its own request logs (time, address of the request, IP address). The server also keeps anonymous daily totals of how many people use Strolly and which steps they take (sums with no link to a person; numbers under 5 are not stored).

Who else sees something

Where your data lives

Cloud Run, BigQuery and Cloud Storage run in the EU region Frankfurt (europe-west3). Firestore and Firebase Authentication also run at Google.

This website

The website strolly.online sets no cookies, uses no analytics and loads nothing from third parties: fonts and images are on the same server. It is hosted by Cloudflare, which technically has to process your IP address to deliver the page. We keep no logs of our own about this and store no visitor data.

How long we keep data

For as long as your account exists, unless it says otherwise here:

When you disconnect Strava, Garmin or COROS, we revoke our access at the provider and delete the access keys. You decide whether the walks already imported stay or are deleted. If you delete them, we recalculate your map, badges and stats.

If Strava, Garmin or COROS end the access themselves, your walks stay at first. Strolly then asks you whether they should stay or be deleted.

Your rights

You also have the right to restrict processing and to object. Write to us at [email protected].

Complaints

You can complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde): Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

Security

All connections are encrypted (HTTPS) and the stored data is encrypted too. Every request for your data needs you to be signed in, and nobody can see anyone else's data. Only our server can read the access keys for Strava, Garmin and COROS.

Age

Strolly is meant for people aged 16 and over.