Legal

Privacy Policy

Last updated April 4, 2026

The short version

Treadly is a tool to help you track the mileage on your running shoes. We collect only what we need to make the product work, we don't sell your data, and we don't run ads. This policy explains what we collect, why, and how you can control it.

Who we are

Treadly is operated by an individual based in Washington State, USA. If you have any questions about this policy or your data, you can reach us at privacy@treadly.run.

What we collect and why

Account information

If you sign up with email, we store your email address and a hashed version of your password (we never store your password in plain text). If you sign up via Strava, we receive your Strava athlete ID, name, and profile photo, and store an access token so we can sync your activities on your behalf.

Shoe and activity data

Everything you add to Treadly — shoe names, brands, mileage limits, ratings, notes — is stored in your account and used solely to provide the service. If you connect Strava, we sync your run activities and their distances to keep your mileage totals up to date. We do not access any Strava data beyond what is needed for mileage tracking.

Transactional emails

If you sign up with email, we send you a verification code when you register and a reset link if you forget your password. We do not send marketing emails.

Apple Health (HealthKit) data

If you grant permission, the Treadly iOS app can read workout data from Apple Health (specifically running workouts and their distances). This data is used solely to track mileage on your shoes within Treadly. We access HealthKit in read-only mode — we never write to or modify your Apple Health data. HealthKit data is processed on your device and synced to your Treadly account; it is not shared with any third party, used for advertising, or sold. You can revoke HealthKit access at any time in your device's Settings > Privacy & Security > Health.

Push notifications

If you enable push notifications, we store a device token issued by Apple's Push Notification service so we can send you alerts (e.g., when a shoe is nearing its mileage limit). We do not use push notifications for marketing. You can disable notifications at any time in your device settings, and your device token will no longer be used.

Shoe photos

You may optionally attach a photo to each shoe. If you do, the image is uploaded to a private storage bucket on Supabase and is accessible only to your account. We do not perform facial recognition, image analysis, or any processing beyond storing and displaying the photo. You can delete a shoe photo at any time from the app.

Analytics events

Treadly collects lightweight, anonymous usage events (such as "screen viewed" or "shoe added") to help us understand how features are used and to improve the app. These events may include your platform (iOS or web) and app version but do not contain personal information like your name or email. Analytics data is stored in our own database and is never shared with third-party analytics providers.

Technical data

Our hosting provider (Vercel) collects standard server logs including IP addresses and request metadata. We use IP addresses temporarily for rate limiting on authentication endpoints (to prevent brute-force attacks) but do not store them in our database long-term.

What we don't do

We do not sell, rent, or share your personal data with third parties for their own marketing or advertising purposes. We do not run ads. We do not build profiles on you beyond what is needed to run Treadly.

Third-party services we use

Running Treadly requires a small number of trusted third-party services. Each handles your data only to the extent necessary to perform their function:

  • SupabaseStores your account, shoe, and activity data in a PostgreSQL database hosted in the United States. supabase.com
  • VercelHosts and serves the Treadly web application. vercel.com
  • StravaIf you connect your Strava account, Strava's OAuth service authenticates you and our integration syncs your run data. strava.com
  • ResendDelivers transactional emails (verification codes, password resets) on our behalf. resend.com
  • Apple Push Notification service (APNs)Delivers push notifications to your iOS device when enabled. apple.com

Data retention

Your data is kept for as long as your account is active. You can permanently delete your account at any time from the dashboard — this removes all of your shoes, activities, and account information from our database. Some information may remain in encrypted backups for up to 30 days before being purged.

Security

Passwords are hashed using scrypt, a memory-hard algorithm designed to resist brute-force attacks. All data is transmitted over HTTPS. Our database enforces row-level security so that one user's data cannot be accessed by another. Authentication endpoints are rate-limited to prevent automated attacks.

No system is perfectly secure. If you discover a security vulnerability, please contact us at privacy@treadly.run before disclosing it publicly.

Your rights

You have the right to access, correct, or delete your personal data at any time. Most of this is available directly in the app. For anything you can't do yourself, email us at privacy@treadly.run and we'll take care of it promptly.

If you are located in the European Economic Area, United Kingdom, or California, you may have additional rights under GDPR or CCPA respectively. We honor those rights regardless of where you are located.

Children

Treadly is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with their information, please contact us and we will delete it.

Changes to this policy

If we make material changes to this policy we will update the date at the top of this page. For significant changes we will notify you by email if we have your address on file.

Contact

Questions, requests, or concerns about your privacy — email us any time at privacy@treadly.run. We aim to respond within 5 business days.