Privacy Policy
Last updated: June 16, 2026
Data controller
Viktor Kardell, an individual operating the hobby project vmutmaningen.se.
Contact: vmutmaningen@gmail.com
What we process
- Account: email address, plus name and profile picture if you sign in via Google.
- Training data: kilometers, date and timestamp for each logged activity, and the chosen activity type (running, walking, cycling, etc.).
- Challenge level: which level (Easy, Medium, Hard, or custom) you've selected. Not shared with other users.
- Groups: group name, code, and your stats such as streak and percent of goal. Visible to other members of the same group.
- Strava (optional): if you connect a Strava account we request OAuth scopes
readandactivity:read. See the Strava section below for a full breakdown of endpoints, stored fields, retention and deauthorization.
Strava integration (if you connect)
Connecting Strava is entirely optional. If you choose to connect your Strava account the following applies:
- OAuth scopes:
readandactivity:read. We never receive write access or access to private activities you haven't shared with us. - Endpoints we call:
GET /api/v3/athlete/activitiesto fetch your logged activities,POST /oauth/tokento refresh access tokens, andPOST /oauth/deauthorizewhen you disconnect. We never call segment-, follow-, or friend- related endpoints. - Fields stored per activity: activity ID (for deduplication), start time, distance (km), and sport type. Nothing else — we don't store routes, GPS data, pace, heart rate, names or photos.
- Tokens: access and refresh tokens are stored in Firestore so we can sync in the future without re-prompting you. Tokens are not encrypted beyond Firestore's transport and at-rest encryption.
- Filter: you choose which sport types to sync (run, walk, ride, etc.). Activities of other types are not fetched at all.
- Retention: within 7 days of import we automatically strip Strava-identifying metadata (activity ID, sport type) from your log. What remains is just distance and date — your own challenge log, no longer Strava Data. These entries are kept until you delete them or delete your account.
- Deauthorization: you can disconnect Strava in the app at any time — we call Strava's
/oauth/deauthorizeand delete the tokens from our side. If you instead revoke access directly in Strava's settings, our webhook receives the signal and deletes your tokens automatically within a minute. - Account deletion: deleting your vmutmaningen account also removes all Strava-related fields (tokens and imported activities) as part of the account deletion.
- Strava's use of Usage Data: Strava may collect usage data about our integration (call counts, response times and similar) for its own business purposes — operations, quality improvements and compliance monitoring. This is not data about you as a user; it's our API traffic.
Children under 13
The service is not directed at children under 13 and we don't knowingly collect personal data from children under that age. If you're a guardian and believe your child has shared data with us, email vmutmaningen@gmail.com and we'll delete it.
Why we process the data
To make the app work — show your stats, sync across devices, let you take part in groups. The legal basis is the performance of the agreement that arises when you create an account.
Third parties
- Google / Firebase: handles authentication and database. Data is stored in the EU (region
europe-west). - Strava: only if you connect your account yourself. We use only the access you explicitly granted.
- Vercel: hosts the site.
- football-data.org: provides match data. Receives none of your personal data.
We don't sell your data and we don't share it with others.
Retention
We retain your data for as long as your account exists. If you want to delete your account, email vmutmaningen@gmail.com and we'll remove all data within 30 days.
Your rights
- Download your data: click Ladda ner min data in the footer when signed in, or email us.
- Correct incorrect data: edit in the app, or email us.
- Delete your account: email vmutmaningen@gmail.com.
- Complain: you have the right to file a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe we process data incorrectly.
Cookies and local storage
We use:
- localStorage: stores your selected level and your log in the browser when you're not signed in. We also store a random anonymous browser ID (UUID) so we can count unique visitors per day without knowing who you are.
- Firebase Authentication: keeps you signed in between visits.
- Vercel Web Analytics: counts aggregated page views and unique visitors so we can understand how the site is used. No cookies, no personal data or identifiers are stored. Read more at Vercel's privacy policy.
We don't use ads and we don't do personal tracking. That's why no cookie banner is required.
Contact
Questions, data requests, or complaints: vmutmaningen@gmail.com