Runcraft is an independent project by Digital Outsider. It is a game that reads your finished runs from Strava and turns them into a character's progress. This policy explains, in plain words, what we read, why, who can see it, how long we keep it and how you can make us delete it. It will be updated before any public release.
Digital Outsider, an independent software developer. Contact for anything in this policy: support@digitaloutsider.xyz. Runcraft is not affiliated with or endorsed by Strava, Inc.
Runcraft has no account system of its own. You sign in with Strava, and Strava asks you to approve the access below. We request the minimum the game needs.
| Data | Source | Why we need it |
|---|---|---|
| Your Strava athlete ID, first name, profile picture | Strava, on sign-in | To recognise you when you return and to show your own profile in the app |
| Your running activities: type, distance, moving and elapsed time, start time and time zone, splits per kilometre, laps, average cadence, average heart rate if your device recorded it, elevation gain, a summary route line | Strava, after each run | To simulate the run for your character: skill triggers, loot, experience, quests. Cadence and start time drive racial passives; heart rate and elevation drive optional quests |
| Game data: characters, levels, items, coins, quests, the results of each simulated run | Created by Runcraft | This is the game itself |
| Technical data: a session cookie, server logs with IP addresses and request times (kept up to 14 days), basic usage events such as "run processed" or "item bought" | Your browser and our servers | To keep you signed in, keep the service running and understand which parts of the game are used |
We do not read activities that are not runs (rides, swims, hikes). We do not read your Strava followers, clubs, segments or other athletes' data. We do not read second-by-second GPS streams. If you allow "activity:write" in a future version, it will be used only to add a Runcraft line to the description of your own activity, and only after you switch that option on.
Data obtained through Strava is never used to train artificial intelligence or machine learning models. A future version may offer an optional in-game commentator that describes your own run to you using a language model; if we add it, the request will contain only your own run summary, you will be told before it is switched on, and the provider will be contractually barred from training on the data.
The game uses one strictly necessary session cookie to keep you signed in. This website uses none. GoatCounter counts visits without cookies.
Strava access tokens are stored encrypted. All traffic is over HTTPS. Access to the database is restricted to the developer. No system is perfectly secure; if a breach ever affects your data we will tell you and Strava without undue delay.
Runcraft is not intended for anyone under 16. We do not knowingly collect data from children.
We will change this policy as Runcraft grows, and will show a notice in the game and on this page when we do. The version and effective date at the top tell you which text applies.