Privacy Policy

This policy explains what personal data we collect, why, and your rights under GDPR.

Data Controller

Steeev is operated by Allergomat AB, a company registered in Sweden. For questions about your data or to exercise your GDPR rights, contact us at the email address below.

Data We Collect

Account info (name, email), running profile (age, weight, fitness level, personal bests), workout data (completed workouts, feedback), activities imported from connected services (Strava, Garmin Connect — distance, time, pace, heart rate, splits), and basic usage analytics.

Legal Basis & Purpose

We process your data to provide our service (contract) and improve it (legitimate interest). We only collect what's necessary for personalized training.

Connected Services (Strava, Garmin)

If you link your Strava or Garmin Connect account, we use OAuth to request read-only access to your running activities. We store the access tokens needed to sync your data and the activities we import (distance, time, pace, heart rate, splits). We do not post to your Strava feed, modify your activities, or share your activity data with third parties. Disconnecting from Settings immediately revokes our access and deletes the stored tokens; imported activities remain on your Steeev account until you delete them or your account.

Data Sharing

We share data with: Stripe (payments), AI providers (workout generation — anonymized where possible), Strava and Garmin Connect (read-only activity import on your behalf, only when you connect the integration). We never sell your data.

Data Retention

Active account data is kept while you use the service. After account deletion, data is removed within the retention period stated below, except where legal obligations require longer retention.

Your Rights (GDPR)

You have the right to: access your data, correct inaccuracies, delete your account, export your data, and withdraw consent. Contact us to exercise any right.

Coach Check-ins by Email

If you provide an email address at signup, your coach will email you when you've been inactive for several days. The legal basis is your consent (collected at signup) and you can withdraw it at any time — every email contains a one-click unsubscribe link, and you can also disable check-ins from your settings page.

Data retention period after account deletion: 90 days.

Email us at: