Privacy Policy

Last updated: August 22, 2026

Introduction

ourpr is a service of Cordonate Labs LLC, a Texas company. This policy says what we collect, what we do with it, and how to take it back.

What we never do

  • We never sell, rent, or trade your personal data.
  • We never use your training data to train or prompt an AI model.
  • We never show your data to another person unless you publish it.
  • We never track a visitor across visits. Our own analytics cannot do it.
  • We never put your route on a public page unless you share that run.

What we collect

Your account

We collect your email address. You can add a display name. We need them to make your account and sign you in.

Your training archive

You can import a data export from Strava, Garmin, or another service. It carries your activities, their measurements, and any photos. Your browser scans the file first and shows you what is inside. Anything you deselect never reaches us.

Where you ran

A recorded run carries GPS coordinates. We store the route and its elevation and time profile. This is the most sensitive data we hold, because a route can show where you live. Your routes are private. One reaches another person only when you share that run.

Photos

We store your photos privately and serve them through links that expire. A photo appears on your map only after you place it. You can hide any photo from the map.

Body measurements

A Garmin export can carry heart rate, running power, VO2 max, and training load. Some laws treat these as health data. We store them to draw your training. The rules on this page apply to them.

What you write

We store the personal records, goals, planned runs, logged runs, and group memberships you enter.

Notifications

We store a subscription for each device you turn notifications on for, with its timezone. The timezone sends your morning message in your morning. Turn notifications off and we delete it.

Strava (existing connections only)

ourpr no longer builds on Strava. If you connected it before, we hold a read-only copy of the activities you authorized, and we encrypt the tokens. You can disconnect at any time. Import an export instead — that copy is yours to keep.

What becomes public, and when

Nothing is public until you make it public.

SurfaceDefaultWhat another person sees
Your runner cardPrivateNothing, until you publish it
A club pagePublic pageYour name and figures only if your card is public. If it is private, you appear as "Member" with no figures.
A shared run or blockPrivateOnly what you share, at a link you create
A shared week (pod)Invite onlyYour week, to the people in that pod
Your history and mapPrivateNothing. These are yours alone.

A public page never shows activities that came from the Strava API.

How we use your data

  • Draw your runs, your training, and your history back to you
  • Match your runs to courses and places, and build your map
  • Show the pages and groups you choose to share
  • Send notifications you turned on
  • Send account and service messages
  • Find and fix faults, and improve the product

Measurement

We count visits to public course pages, so we can tell a race organizer how many people their link brought. It cannot follow a person. It stores no account identifier, it ties steps together within one page load only, and it records the site a visitor came from, never the full address.

Who else handles your data

These companies help run ourpr. Each has its own policy.

  • Supabase — accounts, database, and photo storage. Policy.
  • Vercel — hosts the website. Policy.
  • Render — hosts the API that reads and writes your data. Policy.
  • Cloudflare — serves the map tiles through R2. Policy.
  • Sentry — reports faults. It receives an account identifier so that we can reach the affected person. It receives no IP address, no request headers, and no request bodies. Policy.
  • Resend — sends email. Policy.
  • OpenStreetMap (Nominatim) — turns coordinates into place names. This service receives coordinates from your runs and photos. It receives no name and no account identifier. Policy.
  • Strava — for existing connections only. Policy.

We also disclose data when the law requires it, or to protect someone's safety.

Getting your data out, and deleting it

Both are buttons. You do not have to ask us.

  • Export. Open your history and export everything. You get one file with your activities, records, and photos. Keep it, or take it elsewhere.
  • Delete. Open Settings and delete your account. This is immediate and permanent. It removes your photos and every row we hold. We do not keep a copy.

Two limits. Sentry holds fault reports with your account identifier until they age out. Cached place names stay, with no link to you.

How long we keep it

We keep your data until you delete it. Notifications retire after 60 days. If you stop using ourpr, your history stays, so it is there when you come back.

Security

The database enforces access row by row, so a request reaches only the rows it owns. Photo links expire. Strava tokens are encrypted. No system is perfect. We will tell you if something happens to your data.

Your rights

  • See, correct, or delete your data
  • Export everything, at any time, without asking
  • Delete your account yourself, at any time
  • Disconnect Strava at any time
  • Turn off notifications at any time
  • Stop non-essential email

If your country or state gives you further rights, write to us and we will honor them.

Children

ourpr is not for children under 13. Write to us if you believe a child gave us data, and we will delete it.

Changes to this policy

We may update this policy. We will post it here and change the date. If a change is material, we will tell you.

Contact us

Write to us with any question about your data:

privacy@cordonate.io

Cordonate Labs LLC · Fort Worth, Texas