← Stride

Privacy Policy

Last updated 14 August 2026

Stride reads your calendar to work out when you are actually free, then plans tasks for your side project around what is already there. This page explains exactly what that involves. It is written to be read, not to be survived.

What Stride stores

When you sign in with Google, Stride stores:

  • Your name, email address, and profile picture, from your Google account.
  • Access and refresh tokens for Google Calendar. These let Stride keep reading your calendar after you close the tab. They are stored in Stride's database and never shown to anyone, including you.
  • What you tell Stride during onboarding: a description of your project, what stage it is at, how many hours a week you want to spend on it, your time zone, your sleep and wake times, and any recurring commitments you add by hand.
  • The tasks Stride suggests, whether you completed them, and any notes you write in a check-in.
  • Whether you want reminder emails, and the time the last one was sent — so that you get at most one a day.
  • Messages you send in Stride's chat, and its replies.
  • Anything you write in a Brainstorm session, its replies, and the map of concepts it builds from the conversation — including which ideas were backed up by evidence and which were ruled out.

What Stride does with your calendar

Stride asks for two Google Calendar permissions, and they are not the same:

  • Read your calendars. Stride reads the title, start time, and end time of your events for the next 14 days, so it knows when you are busy and can spot days it should leave alone, like an exam. It does not read guests, locations, attachments, descriptions, or anything further ahead than 14 days.
  • Manage calendars Stride created. Stride makes its own separate calendar and writes suggested tasks there. This permission gives Stride no access to any other calendar. It cannot edit, move, or delete your school timetable, your existing events, or anything it did not create itself.

Stride never writes to your primary calendar, and it never deletes an event it did not create.

Who else sees your data

Stride sends some of your information to Anthropic, whose Claude model generates your plan. Specifically: your project description and stage, your available hours and time zone, and the titles and times of your calendar events for the planning window, plus your check-in notes, your chat messages, and your Brainstorm conversations. Anthropic processes this to produce a response and does not train its models on it.

If you would rather your event titles not leave your device, Stride is not the right tool for you — reading them is how it knows that “Biology exam” is a day to keep clear.

If you have reminder emails switched on, your email address and the title of the task being asked about are sent to Resend, which delivers the message. Nothing else goes with it, and turning reminders off stops this entirely.

Stride is hosted on Railway, which stores the database. Beyond these three, your data is not sold, rented, or shared with anyone. There is no advertising, no analytics tracking you across other sites, and no third-party trackers.

How Stride protects your data

Your calendar is sensitive information, and your Google access tokens are more sensitive still — anyone holding them could read your calendar without you. These are the specific measures that protect them.

  • Encrypted in transit. Every connection is HTTPS, using TLS. That covers your browser talking to Stride, and Stride talking to Google, Anthropic, and Resend. Stride sends nothing over an unencrypted connection.
  • Encrypted at rest. Everything Stride stores lives in a managed PostgreSQL database hosted by Railway, which encrypts stored data at rest.
  • Your Google tokens never leave the server. They are never sent to your browser, never included in anything sent to Anthropic or Resend, never written into a log, and never displayed to you or to anyone else. They exist only in the database, and are used only by Stride's server to call Google Calendar on your behalf.
  • The least access that works. Stride requests two Calendar scopes and no others. One is read-only. The other can only touch the calendar Stride created itself, so even a total compromise of Stride could not delete or alter your existing events.
  • Separated by account. Every read from the database is filtered by the signed-in user's ID, so one account cannot reach another's data. Sign-in is through Google only — Stride never handles, stores, or sees a password.
  • Sessions kept server-side. Your session lives in Stride's database. The browser holds only an opaque identifier, in a cookie that is HTTP-only (unreadable by JavaScript), Secure (sent only over HTTPS), and SameSite-restricted (not sent by other sites). Signing out invalidates the session on the server, not just in your browser.
  • Restricted human access. Only Stride's developer can reach the production database and hosting account, through accounts secured with two-factor authentication, and only to diagnose a fault or where the law requires it. Nobody reads your calendar, chats, or Brainstorm sessions as a matter of routine. Database credentials and API keys are held in the hosting provider's encrypted environment settings — never in the source code, which is in a private repository.
  • Kept only as long as needed. Your calendar events are read fresh each time a plan is generated and are not retained afterwards beyond the plan itself. Deleting your account erases your Google tokens and everything else immediately, as described below.

No system is perfectly secure, and Stride will not pretend otherwise. If data obtained from Google were ever exposed in a breach, everyone affected would be told by email, without undue delay, along with what was exposed and what to do about it.

Emails Stride sends

Stride can send at most one reminder a day, in the evening, and only when there is something to say: a task whose day has passed that you have not answered for, or a Sunday with nothing planned for the week ahead. There are no newsletters, product announcements, or marketing emails of any kind.

Every message carries a one-click unsubscribe that works without signing in. You can also turn them off at any time in Settings.

Google API Services User Data Policy

Stride's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms: Stride uses your Google Calendar data only to provide the scheduling features you can see in the app. It is not used for advertising, it is not sold, and it is not read by any human at Stride except where required for security or to comply with the law.

Deleting your data

Go to Settings and choose Delete account. This deletes your account and everything attached to it — your profile, your Google tokens, your tasks, check-ins, and chat history — immediately and permanently. There is no soft delete and no recovery period, so do it deliberately.

The calendar Stride created stays in your Google account, because it is yours. You can delete it from Google Calendar whenever you like. You can also revoke Stride's access at any time from your Google account permissions, with or without deleting your Stride account.

How long things are kept

For as long as your account exists. Stride does not archive deleted accounts. Calendar events are read fresh each time a plan is generated and are not stored beyond what is needed to build that plan.

Children

Stride is built for students, including people under 18. It asks for no more information than the app needs to function, and it shows no advertising. If you are under 13, please use Stride with a parent or guardian's permission.

Changes

If this policy changes in a way that affects what happens to your data, the date at the top will change and you will be told in the app before it takes effect.

Terms of service

The rules for using Stride — what it promises, what it doesn't, and what happens if it gets your week wrong — are in the terms of service.

Contact

Questions, or want your data removed manually? Email imd28@gsiscommunity.kr.