GRUDGE

Privacy Policy

Version 1.0 · Effective July 2026

What we collect

Your account email and display name, your timezone, your commitments and their weekly outcomes, and — if you connect Strava — the activity fields needed to verify a week: type, start time, distance, moving and elapsed time, whether the entry was manual, and whether it carried GPS. We do not store your route polylines, heart rate, or any body-composition data.

Why Strava asks for full activity access

GRUDGE requests activity:read_all so private activities can count toward your week. We read activities only to produce a verdict, and only for the weeks a pact is running.

Who can see what

Your squad-mates see your activity type, whether a week passed or missed, and forfeit outcomes. Turn on Privacy Mode in Settings and your stake amounts are hidden from them — the pass/miss record stays visible, because that's the point of a squad.

Public information

The transparency page publishes aggregate donation totals per recipient organization. It never names individuals.

The evidence ledger

Consent captures, verification verdicts and week finalizations are written to an append-only, hash-chained ledger. It's what makes a disputed charge auditable, so ledger entries are never edited or deleted.

How we use AI

GRUDGE uses an AI model for three things: writing your squad's weekly recap, screening activity metadata for signs of fabrication, and triaging appeals. AI never decides whether a week passed and never moves money — the deterministic verification rules and your squad do that. The one exception is a narrow auto-excuse: when an appeal is a clear late-sync case corroborated by an activity we already recorded, the week is excused without a squad vote, up to twice per season.

What the model sees

For anomaly screening the model receives derived numbers only — distance, duration, pace, upload timing and how they compare to your own history. No GPS traces, no route data, no heart rate, no names. Recap data is squad-local, and if you have Privacy Mode on, your stake amounts and forfeit recipients are withheld from it. Every AI call is logged with its model, prompt version, and an input hash in the ledger, and the derived metrics themselves are purged after 90 days.

Retention

Activity records are kept for the life of the pact plus twelve months, so an appeal or chargeback can be answered. Financial records are kept as long as tax and payment rules require.

Deleting your data

Settings → Close account deletes your profile, Strava tokens, saved card reference, allegiances and squad memberships. Forfeit and ledger records remain as anonymized financial history. Disconnecting Strava alone removes our tokens and stops all further reads.

Payment data

Card details are handled by our payment processor and never touch GRUDGE's servers. We store a processor reference plus the card brand and last four digits.

Contact

For access, correction, or erasure requests, use the contact address on the account settings page.

Powered by Strava · Terms