Privacy Policy
Last updated: January 9, 2026
Shoey ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our iOS app and related services.
1. Information We Collect
Account Data
- User ID (via Clerk authentication)
- Email address (optional, only if you sign in with email)
- Units preference (miles or kilometers)
- Timezone
Shoe Data
- Brand and model
- Color
- State (Up Next, In Rotation, Resting, Retired)
- Activity type (run, trail run, hike, walk, other)
- Mileage threshold
- Purchase price (optional)
Activity Data
- Source (Strava or HealthKit)
- Distance
- Date
- Shoe assignment
NFC Data
- Tag UID (unique identifier)
- Slug (human-readable reference)
- Scan history
2. Third-Party Services
We use the following third-party services:
Clerk (Authentication)
Clerk handles sign-in and stores your authentication credentials securely. See Clerk's Privacy Policy.
Strava (Optional)
If you connect Strava, we sync your activities to automatically log miles. Your Strava data is cached for a maximum of 7 days and your access tokens are stored encrypted. See Strava's Privacy Policy.
Apple Health (Optional)
If you connect Apple Health, we sync your workout activities to automatically log miles. We only access workout data (activity type, distance, duration, date) — not sensitive health metrics like heart rate or medical data. See Apple's Privacy Policy.
PostHog (Analytics)
We use PostHog for product analytics to understand how users interact with the app and improve the experience. PostHog may record session replays, which capture user interactions (taps, scrolls, navigation) and screen content. Session replays do not capture passwords, payment information, or other sensitive data. You can learn more at PostHog's Privacy Policy.
Cloudflare (Infrastructure)
Cloudflare hosts our API and website. See Cloudflare's Privacy Policy.
3. Strava Data Handling
In compliance with the Strava API Agreement:
- Activity data is cached for a maximum of 7 days
- Your Strava data is never shared with other users
- Strava data is not used for analytics or advertising
- Access tokens are stored encrypted (AES-256-GCM)
- Strava may monitor and collect usage data related to your API access
- Disconnecting Strava deletes ALL your Strava data: activity pointers, cached activity details, and encrypted tokens
- You can disconnect Strava at any time in app settings
4. Apple Health Data Handling
In compliance with Apple's HealthKit guidelines:
- We only access workout/activity data (type, distance, duration, date)
- We do not access sensitive health data (heart rate, blood pressure, medical conditions)
- Activity data is cached for a maximum of 7 days
- Your health data is never stored in iCloud
- Health data is not shared with other users or third parties
- Health data is not used for analytics or advertising
- You can disconnect Apple Health at any time in app settings
5. Background Processing & Push Notifications
Background Activity Sync
Shoey uses background processing to sync your workout activities:
- When Apple Health records new workouts, Shoey updates in the background
- Background sync ensures your shoe mileage stays accurate without manual refresh
- You can disable background sync in iOS Settings > Shoey > Background App Refresh
Push Notifications
If you enable notifications, Shoey may send alerts when:
- A new activity is automatically assigned to a shoe
- An activity needs manual shoe assignment
We store a device token to deliver notifications. This token:
- Is not linked to your personal identity
- Is deleted when you sign out or delete your account
- Is not shared with third parties
- Can be revoked in iOS Settings > Shoey > Notifications
6. Data Retention
- Account data: Retained until you delete your account
- Activity cache: Maximum 7 days
- Strava tokens: Until you disconnect Strava
7. Your Rights
Export Your Data
You can download all your data in JSON format via Settings > Account > Export Data.
Delete Your Account
You can permanently delete your account and all associated data via Settings > Account > Delete Account & Data.
Disconnect Strava
You can revoke Strava access at any time via Settings > Account > Disconnect Strava.
8. Security
- All data is transmitted over HTTPS
- Authentication uses industry-standard JWT tokens
- Strava tokens are encrypted at rest
- We follow security best practices for data storage
9. Analytics
- We use PostHog for product analytics to improve the app experience
- We may record session replays that capture user interactions and screen content
- Session replays are used solely to understand app usage and fix issues
- We do not display advertising
- We do not track you across apps or websites for advertising purposes
- We do not sell your data to third parties
10. Contact Us
If you have questions about this Privacy Policy, please contact us at support@shoey.app.