Privacy Policy
Effective date: September 16, 2026 · Last updated: September 16, 2026 · Version 1.0
Who this is from: Soltra LLC, a California limited liability company (“Soltra”, “we”, “us”)
Soltra is an iPhone app that turns the places you have run, ridden, walked and hiked into a personal map: glowing routes and lit-up tiles of territory that only you can see. To do that, it works with some of the most personal data a phone holds: where you go, how your body performs, and photographs you took along the way. This policy explains, in plain words, what Soltra collects, why, where it goes, how long it stays, and what you can do about it. Nothing here is hidden in a definition; where a word carries a legal meaning we say so. Throughout, “only you” means no other Soltra user: Soltra and the companies that run its infrastructure (Section 9) handle your data only as needed to run the service, under the controls Section 11 describes. Soltra is available only in the United States.
If you live in Washington, Nevada, or Connecticut our separate Consumer Health Data Privacy Policy also applies to you. It repeats the health-data parts of this policy in the form those states require.
Your data in one minute
| What | Why Soltra has it | Where it lives | Who can see it | How long |
|---|---|---|---|---|
| Your account (Apple sign-in identifier, email address) | To identify your account data | Soltra's servers | You, and our staff only when you ask for help | Until you delete your account |
| Your profile (display name, profile photo, preferences) | To personalize your map | Soltra's servers | Only you | Name and photo: until you delete your data or your account |
| Workouts from Apple Health and activities you record in Soltra: GPS routes, heart rate, calories, cadence, power, steps, elevation, duration, the device that recorded them | To draw your routes, light your tiles, and compute your statistics | Soltra's servers | Only you, plus Strava for the route, distance, altitude, times and title of activities you record in Soltra, if you connect it (Section 8) | Until you delete the activity, your data, or your account |
| Your body weight (from Apple Health or typed in Settings) | To estimate calories for activities you record | Soltra's servers | Only you | Until you delete your data or your account |
| Files you import (GPX, TCX, FIT, and Strava export ZIPs) | To bring in your history | Soltra's servers while they are processed | Only you | Up to 30 days, then deleted |
| Photos you choose to attach, each with a precise location and time | To place your photos on your map | Soltra's servers | Only you | Until you delete the photo, its activity, your data, or your account |
| Which features you use and crash reports | To find bugs and see what is worth improving | PostHog and Google Firebase, on our behalf | Our team | Deleted with your account; otherwise up to 7 years (usage), 90 days (crashes) |
| Subscription status | To turn on Premium | RevenueCat and Apple, on our behalf | Our team | Until you delete your account |
| A push-notification token for your phone | To send the notifications you turned on | Soltra's servers, Google Firebase | Our team | Until you sign out or delete your account |
| Server logs (IP address, time, request) | To keep the service running and secure | Supabase | Our team | 7 days |
| Emails you send to [email protected] | To answer your request and show it was honoured | Our mailbox | Our team | 2 years after the request is closed |
Two things belong at the top rather than buried further down:
- Everything Soltra shows you is private to you. There are no friends, followers, feeds, leaderboards, public profiles or shared heatmaps. No other Soltra user can see your routes, tiles, statistics, or photos and no one else's data is shown to you.
- A stored calorie figure can reveal your body weight. Calories for an activity are computed from your weight, so anyone able to read that number and the model could estimate your weight to within a few kilograms. Only you and Soltra can read it, but we would rather say this plainly than let you assume the weight stays on your phone.
What we never do
- We never sell or rent your personal data and never have.
- We never show you advertising and never let anyone use your data to advertise to you.
- We never use data from Apple Health or from your photo library for marketing, advertising, or any kind of data mining and we never allow anyone else to.
- We never train artificial-intelligence models on your data or supply your data for anyone else to.
- We never publish heatmaps, “popular routes”, or any other derivative of users' routes and we never build de-identified or aggregated datasets from your routes, photos or health data. The only aggregate we keep is the feature-usage counting described in Section 3.11.
- We never let another Soltra user see your data.
- We never store your health data in iCloud, never sync anything through iCloud, and keep the app's local copy of your activities out of your iPhone backups.
- We never let advertising companies or anyone else track your Soltra activity over time and across other apps or websites.
- We never read your Strava activities. If you connect Strava, data flows one way: from Soltra to your Strava account.
- We never look in your Hidden album when suggesting photos and we never change or delete anything in your photo library.
1. Who we are
The company responsible for your data is:
Soltra LLC
440 N Barranca Ave #5017
Covina, CA 91723
United States
For anything to do with privacy, or with this policy, write to [email protected]. We have not appointed a data protection officer; the privacy address reaches the people who run Soltra.
Soltra is offered only through the United States App Store and is supported only in the United States. This policy is written for US law; if we ever offer Soltra elsewhere, we will update it first (Section 13).
2. What the words in this policy mean
- Health data means anything about your body or its performance: heart rate, calories burned, cadence, power, step counts, your weight, and the workouts those numbers describe. Washington, Nevada and Connecticut call this “consumer health data” and require your consent before it is collected or shared.
- Precise location means the GPS coordinates that make up a route, the coordinates attached to a photo, and any other position accurate to within a few metres.
- Your account means the Soltra account created when you sign in with Apple and everything stored against it on our servers.
- Our servers means the database, file storage, and server code we run on Supabase (Section 9). Soltra has no servers of its own; “Soltra's servers” throughout this policy means that hosted service, operating under our instructions.
3. What we collect, and where it comes from
Soltra collects only what the map needs and only from sources you turn on. Each source below names the exact data involved.
3.1 Your account and profile
When you tap Sign in with Apple, Apple gives us a stable identifier for your Apple Account, an email address, and (the first time only) the name on your Apple Account. If you chose Apple's Hide My Email, the address we receive is a private relay address that forwards to you; it is the only email address we hold and you can stop it forwarding at any time in your Apple Account settings. We use the name Apple supplies as your starting display name, which you can change.
Your profile also holds what you set in the app: your display name, a profile photo if you add one, your preferred units, your time zone, your theme and map preferences, whether you have finished onboarding, and your body weight, if you granted Apple Health permission to read it or typed it into Settings. The weight is used for the calorie estimate described in Section 3.5.
There is no email-and-password sign-in and no guest mode. Soltra never asks for your date of birth, sex, or gender.
3.2 Apple Health
Soltra reads from Apple Health only after you grant permission in the system prompt, and you choose which of these types to allow. Soltra asks to read:
- Workouts (type, start and end time, duration, distance, and the app or device that recorded them)
- Workout routes (the GPS track Apple Watch or another device recorded)
- Heart rate
- Active energy burned
- Cycling cadence
- Cycling distance
- Cycling power
- Running power
- Step count
- Walking and running distance
- Body mass (your weight). Soltra reads your most recent weight each time you open the app, until you type a weight of your own in Settings; from then on Apple Health is not read for it again. Soltra never writes weight to Apple Health
Soltra asks to write the activities you record inside Soltra back to Apple Health so your rings, history, and other Health-connected apps stay complete. It writes only:
- Workouts
- Workout routes
- Active energy burned
- Walking and running distance
- Cycling distance
With permission granted, Soltra asks iOS to wake it in the background when a new workout or route lands in Apple Health, so your map is up to date without you opening the app.
Apple Health data does not stay on your phone. Soltra reads each workout on the device, builds a structured activity record from it (the route as a list of timed coordinates, the heart rate, cadence, power and altitude at points along it, and the totals), and sends that record to our servers, where it is stored with your account. Section 3.5 lists exactly what the record contains. iOS does not tell an app whether a read permission was granted or refused, so if you refuse, Soltra finds no workouts.
You can change any of these permissions at any time in the Health app › your profile › Apps (under Privacy) › Soltra. Health permissions are not shown under iOS Settings › Soltra.
3.3 Recording an activity on your iPhone
When you record an activity in Soltra itself, the app uses:
- Location. Soltra asks for location access while using the app and asks for precise accuracy for the duration of the recording. During a recording, and only then, Soltra keeps receiving your location with the phone locked and iOS shows its blue location indicator while that is happening. Soltra never asks for “always” location access and never tracks your location outside a recording.
- Motion & Fitness. Soltra asks for this permission when a recording starts to count your steps. It also uses the phone's raw motion sensors, which need no permission, to pause and resume the recording automatically when you stop and start. If you refuse, the activity carries no step count.
- Audio. Soltra can speak progress cues during a recording. It only plays audio; it never listens. Soltra has no microphone permission.
The recording is kept in a private database on your phone until it is saved and uploaded, then handled exactly like a workout from Apple Health (Section 3.5).
3.4 Files you import
You can import GPX, TCX, and FIT files and ZIP archives such as a Strava or Garmin data export. The file picker is the consent: nothing is read until you choose files.
- What leaves your phone. From a ZIP archive, Soltra extracts only the route files (GPX, TCX, FIT, and their compressed variants) and the activities list. Photos, comments, kudos, messages and every other file in the archive are discarded on your phone and never uploaded.
- What those files contain. Route files hold health data: GPS coordinates, heart rate, cadence, power, temperature, and altitude. They are parsed on our servers, not on your phone, and the resulting activity record is stored with your account (Section 3.5).
- How long the files themselves stay. Each extracted route file is deleted from our servers as soon as it has been processed. The archive you uploaded, and anything a failed import leaves behind, is deleted by a scheduled sweep no later than 30 days after the import finishes or fails (30 days after upload if the import never ran). Deleting your data or your account deletes these files at once.
- What we keep about the import. Your import history records each file's original name and whether it succeeded, so you can see what was brought in.
Soltra keeps no connection to the app the files came from.
3.5 What an activity record contains once it is on our servers
Whether an activity arrived from Apple Health, a Soltra recording, or an imported file the record we store holds:
- The full-resolution route: every coordinate and its timestamp. A simplified copy is also kept for fast drawing at low zoom.
- A sample track along the route, thinned to at most 1,500 points, with the heart rate, cadence, power, temperature, and altitude at each point.
- Totals and summary values: distance, elapsed, moving and active time, elevation gain and loss, highest point, average and maximum heart rate, cadence, power and speed, average temperature, step count, and calories.
- The calorie figure, which for activities Soltra records is computed from your body weight. As said above, that number can be used to estimate your weight.
- The activity's title and description if you gave it one, whether you marked it a race, and its type (run, ride, walk, hike, and so on).
- The device and app that recorded it, as reported by Apple Health or the file: for example the name, model and manufacturer of a watch, or the name of the app that exported the file.
- Derived facts Soltra computes from the route: the tiles it lit, the city, region and country it passed through, whether it was your longest or your biggest climb, and whether it was your first in a city or country.
Soltra does not offer “privacy zones” or start-and-end trimming because no one but you can see your routes. Everything in this section is visible only to you.
3.6 Territory and places
Your lit tiles are computed on our servers from your routes using a fixed hexagonal grid and stored as a list of tile identifiers against your account. The city, region, and country attributed to an activity are worked out entirely inside our database by comparing your route against public map data (boundaries from Overture Maps, Natural Earth, OpenStreetMap and GeoNames, which we load and keep ourselves). Your coordinates are never sent to a geocoding service or any other third party for this.
3.7 Photos
Soltra can attach photos from your library to your activities. This works as follows:
- Matching happens on your phone. With your permission, Soltra looks for photos taken during the time of an activity and shows them to you. You may also grant access to a limited selection rather than your whole library; Soltra works fully in that mode.
- Nothing uploads until you confirm. Every suggested photo is shown to you first, and you choose which to add. Soltra never uploads a photo in the background.
- Hidden and shared photos. Soltra never looks in your Hidden album when it suggests photos and it never suggests photos from iCloud Shared Albums. You can still hand-pick a photo from a shared album if you want to. A photo you have already confirmed and then hide in Photos afterwards is still uploaded: past your confirmation it is your decision, not Soltra's suggestion.
- What is uploaded. A downsized display copy (about 1,600 pixels on the long edge) and a thumbnail. The original file is never uploaded. Soltra reads the photo's embedded metadata (its capture time and, if present, its GPS position) to place it, then strips that metadata from the copies it stores.
- The location we store. Each attached photo is stored with a precise location and its capture time. That location comes from the photo's own GPS position when it has one and it lies on or near your route. When it does not, Soltra estimates a position from the photo's timestamp along the route; when even that is not possible, or the photo's GPS is far off the route, the activity's starting point is used. You can remove photos from the activity. Because this is a precise location linked to your account, it is treated as location data throughout this policy.
- Profile photo. A profile photo you choose is uploaded as a small display copy through the system picker, which needs no library permission.
Soltra has no camera permission and never takes photos.
3.8 Sharing cards and replay videos
When you share an activity card or export a replay video, it is rendered entirely on your iPhone and handed to the iOS share sheet. Nothing is uploaded to Soltra. The temporary video file is written to the app's own storage, excluded from device backups, and deleted once the share sheet closes. What leaves your phone is the image or video you chose to share and only to the app or person you chose.
3.9 Purchases
Premium is sold by Apple through the App Store. Soltra never sees your card or bank details. To know whether your account has Premium, we use RevenueCat (Section 9), which receives the App Store transaction identifiers for your purchase and links them to your Soltra account identifier. Our servers keep your subscription status, product, trial and renewal dates, and the notifications Apple sends about your subscription (renewals, refunds, disputes).
3.10 Notifications
If you allow notifications, iOS gives Soltra a push token for your phone, which we store against your account so our servers can send you the summaries and milestones you have turned on. The text of a notification can name a place you have lit up, a rounded distance or tile count, or the kind of activity; it never contains coordinates, a route, heart rate, calories, an imported file's name, or any text you typed. That text is delivered through Apple's and Google's push services (Section 9). Every kind of notification can be switched off in Soltra's Settings and the token is deleted when you sign out.
3.11 Usage analytics and crash reports
Soltra records which features you use and whether they worked, so we can fix what breaks and improve what matters. Specifically:
- Usage events go to PostHog (Section 9). Each event names the feature and an outcome plus your app version, device model, iOS version, and subscription status (free or Premium). Events never carry a count of your activities, photos, imported files, or any other figure derived from your workouts. Events are keyed to your Soltra account identifier, so they are pseudonymous rather than anonymous. They never carry GPS coordinates, route geometry, heart rate, calories, or any other health value; never a count of your activities or photos; and never free text you typed. Automated tests in our code enforce this; it is not left to policy alone. PostHog also sees the network address your phone connects from; we do not use it. Screen recording and session replay are switched off.
- Crash reports go to Google Firebase Crashlytics (Section 9). They contain the state of the app at the moment it crashed and your device model and iOS version; they are not linked to your account identifier.
Both are on by default and can be turned off at any time with the Share usage analytics switch in Soltra's Settings › Privacy. Turning it off deletes the crash reports already waiting on your phone and anything collected during the session you switch it off in is deleted the next time you open Soltra. Nothing collected after you turn the switch off is ever sent off of your device.
3.12 The map itself
The map is drawn by software from Mapbox that runs inside Soltra. To draw the map around you, Soltra requests map tiles from Mapbox's servers. Like any internet request, those carry your IP address, the map content requested, and technical details of the app and software version under Mapbox's own privacy policy (mapbox.com/legal/privacy), which states how long Mapbox keeps them. Soltra can also send Mapbox de-identified location and usage telemetry (coordinates, altitude, accuracy, timestamp, app, and software versions). Soltra switches that telemetry off by default. The map's ⓘ (attribution) menu shows the toggle to turn telemetry on or off; if you turn it on there, Soltra respects your choice and Mapbox's statements about that data apply.
3.13 Age check at sign-in
Where the law requires it, Apple may show its own age-range prompt before you sign in. Apple tells Soltra only an age range, never a birthday and Soltra keeps nothing from it: the answer is used once to decide whether sign-in can continue, then discarded. It is not stored and it is not sent to our analytics. Outside those jurisdictions, no prompt appears.
3.14 Server logs and IP addresses
Every request the app makes to our servers is logged by our hosting provider, Supabase, with the IP address it came from, the time, the request path, and the outcome. We use these logs only to keep the service running and secure and to investigate faults; they are kept for 7 days. Mapbox (Section 3.12), PostHog (Section 3.11), and Google's push service also see your IP address as part of serving their requests, under their own policies.
3.15 The joinsoltra.com website
This policy is published on joinsoltra.com. The site sets no cookies and runs no analytics. If you join the launch waitlist, your email address and the time you signed up are stored with Cloudflare (Workers KV) until Soltra has launched or you ask to be removed and are used only to tell you about Soltra's availability. The waitlist form is protected by Cloudflare Turnstile, which examines technical signals from your browser to tell people from bots under Cloudflare's privacy policy. Cloudflare keeps ordinary access logs (IP address, time, page) for a short period as the site's host.
3.16 What Soltra does not collect
Soltra has no permission for, and never accesses: your contacts, calendar, camera, microphone, Bluetooth devices, clipboard, or the advertising identifier. It does not ask for App Tracking Transparency because it does not track you across other companies' apps or websites. It does not use iCloud. There is no Apple Watch app; watch workouts reach Soltra only through Apple Health.
4. Why we use your data and the legal basis for each use
| What we do | The data involved | Why we are allowed to (the legal basis) |
|---|---|---|
| Create and secure your account and show you your own map, tiles, statistics, and photos | Account and profile; activities, routes, tracks, tiles, places; photos | Performing our contract with you (the Terms of Service), which for health data and precise location means processing only to the extent needed to provide the features you asked for. You turn each source on yourself, and give your explicit consent to it, on Soltra's own screens (the Apple Health page, the import page, and the photo confirmation), which say what is collected, that it is stored with your account, and link to this policy; the iOS permission prompts that follow are how the phone lets Soltra read the source, and Section 12 is how you stop |
| Estimate calories | Body weight | Your explicit consent, given when you allow the Body Mass read or type a weight in |
| Save activities you record back to Apple Health | Workouts, routes, energy, distance | Your consent, given in the Apple Health write permission |
| Send your recordings to Strava | The activity data listed in Section 8 | Your consent, given when you connect Strava; withdrawn by disconnecting |
| Provide Premium | Subscription status, transaction identifiers | Performing our contract with you. Apple is the seller and keeps the payment records the law requires; we keep only the subscription records described in Section 3.9 |
| Send you notifications | Push token, notification preferences, the summary text | Your consent, given in the iOS notification prompt and Soltra's notification settings |
| Find bugs and improve the app | Usage events, crash reports | Our legitimate interest in running a reliable app, balanced by the fact that these contain no location or health data and can be switched off. Where the law requires consent first, we ask first |
| Draw the map | Map area | Performing our contract (drawing the map). Mapbox's telemetry is switched off by Soltra; turning it on in the map's ⓘ menu is your consent |
| Check age where the law requires | An age range from Apple, discarded immediately | Legal obligation |
| Keep Soltra secure, prevent abuse, and meet legal duties | Account identifiers, server logs, import and deletion records | Our legitimate interest in security and integrity; legal obligation |
You can withdraw consent at any time: change a permission in iOS or the Health app, disconnect Strava, turn off analytics, or delete your data. Withdrawing consent does not undo processing that already happened, but it stops it going forward and deleting your data removes what was collected.
What you must provide. Signing in with Apple is required to create an account; without it there is no account. Everything else is optional, but Soltra can only draw a map from activities, so with no Apple Health permission, no recordings, and no imports the map stays empty.
No automated decisions. Soltra makes no decision about you by automated means that has a legal or similarly significant effect. The only things computed automatically are your own statistics, tiles, place attributions, and achievements, shown to you alone.
5. Our commitments for Apple Health data
Because Soltra uses Apple's HealthKit framework, we make the following commitments, which also reflect Apple's requirements for such apps:
- We use Apple Health data only to provide Soltra's features to you: drawing routes, lighting tiles, computing statistics, and estimating calories.
- We never use it for advertising or marketing, never use it for data mining, and never disclose it to any third party for those purposes.
- We never sell it to advertising platforms, data brokers, or information resellers.
- We share it with a third party only at your instruction and only with a service that provides health or fitness features to you; today that means Strava, and only if you connect it.
- We never store it in iCloud.
- You can revoke Soltra's access in the Health app at any time, and you can delete everything Soltra derived from it in Settings.
Deleting your data (Section 10) pauses Apple Health sync until you turn it back on in Soltra's Settings, so deleted workouts are not immediately re-imported.
6. Location, routes and territory
Soltra is a record of where you have been, kept for you alone. In practice:
- Your location is collected only while you are recording an activity, or when you import or sync a route that already contains one. Soltra does not use geofencing of any kind, around healthcare facilities or anywhere else.
- The blue location indicator in iOS shows whenever Soltra is receiving your location in the background, which happens only during a recording.
- Routes are stored at full resolution, with the points where you started and stopped. Soltra does not offer privacy zones or trimming, because routes are never shown to anyone but you. If that ever changed, this policy would change first, and any sharing would be opt-in.
- Tiles and place attributions are derived on our servers from your routes, as Section 3.6 describes, without your coordinates leaving our database.
7. Photos
Section 3.7 describes photos in full. The short version: matching happens on your phone, nothing uploads until you confirm it, only a downsized copy and a thumbnail are stored, the copies carry no embedded metadata, and each photo is stored with a precise location (sometimes estimated) and a time. Photos and their locations are visible only to you, and you can delete every attached photo at once from Settings.
8. Connecting Strava
Connecting Strava is optional. If you do, Soltra sends each activity you record in Soltra that has a real GPS route to your Strava account, automatically, until you disconnect. Recordings you made before connecting are not sent unless you start the one-off catch-up offered in Settings. Activities that came from Apple Health or an import are never sent, because they already exist elsewhere. Once on Strava, your Strava settings decide who can see an activity there.
- What Strava receives. A standard workout (FIT) file built from the stored sample track: the title you gave the activity, its type and start time, timestamps and GPS coordinates, cumulative distance, altitude, elapsed and active time, and elevation gain. A recording made on an iPhone has no heart rate, cadence, power or temperature, so none is sent, and Soltra never sends your step count or calories to Strava. It is the thinned track described in Section 3.5, not the full-resolution route.
- What we ask you for. The connect screen in Soltra tells you what each upload contains and that disconnecting stops it; connecting is your consent to that sharing, separate from any other permission you have given.
- What we ask Strava for. Permission to upload activities, and Strava's basic read permission, which our connection requests alongside it. Soltra never calls Strava to read your activities, statistics, or profile. Data flows one way.
- What we store. Your Strava athlete identifier and the access credentials Strava issues, kept on our servers where only our server code can read them, never on your phone. Soltra never shares them with anyone.
- Disconnecting. You can disconnect in Soltra's Settings at any time. Disconnecting stops further uploads, revokes Soltra's access on Strava's side, and deletes the credentials from our servers. Deleting your account does the same, and also discards any upload still queued. Strava's interface for apps gives us no way to delete, or even flag, activities already in your Strava account, so deleting your Soltra data does not remove them; delete them in Strava if you wish. Where the law requires us to notify Strava of your deletion request, we will do so.
Once an activity reaches Strava, Strava is responsible for it under its own privacy policy. Soltra's use of the Strava API follows Strava's API Agreement.
9. Who processes your data on our behalf, and who else receives it
We do not sell, rent, or trade your personal data and we do not share it for anyone else's advertising. Two kinds of company appear below. Processors (Supabase, Google Firebase, PostHog, RevenueCat) handle data only on our instructions, under contracts that require them to protect it at least as strongly as this policy states and to use it only to provide their service to us. Independent recipients (Apple for sign-in, purchases and push delivery; Mapbox for the map requests it serves; Strava, only if you connect it) receive data under their own privacy policies, which govern what they do with it. We name each one because you have a right to know where your data is.
| Company | What it does for Soltra | What it receives | Where |
|---|---|---|---|
| Supabase, Inc. | Runs our database, file storage, sign-in service, and server code. Everything described as “our servers” in this policy | All the data in Section 3 that is stored on our servers | Hosted in the United States (Ohio) |
| Apple Inc. | Sign in with Apple; Apple Health on your device; App Store purchases; push notification delivery | Your Apple Account identifier; the text of notifications; purchase records Apple already holds as seller | Apple's own systems |
| Google LLC (Firebase) | Crash reporting (Crashlytics) and push-notification delivery (Cloud Messaging) | Crash reports without your account identifier; your push token and the text of each notification | United States |
| PostHog, Inc. | Usage analytics | The events described in Section 3.11, keyed to your account identifier; your network address | United States (PostHog US Cloud) |
| RevenueCat, Inc. | Subscription status | Your Soltra account identifier; App Store transaction identifiers; subscription status; device type | United States |
| Mapbox, Inc. | Draws the map | Tile requests: your IP address, the map content requested, app and software details; telemetry only if you turn it on yourself (Section 3.12) | United States |
| Strava, Inc. | Receives your recorded activities, only if you connect Strava | The data in Section 8 | United States |
| Cloudflare, Inc. | Hosts the joinsoltra.com website and its waitlist (Section 3.15) | Waitlist email address and sign-up time; the site's access logs; Turnstile's bot-check signals | United States |
The public map data used to name cities and countries (Overture Maps, Natural Earth, OpenStreetMap contributors under the Open Database License, GeoNames) is downloaded and stored by us; those projects receive nothing from us or from you.
Location is never collected for analytics. Soltra's own analytics never receive your location, your routes, or any health value and the Mapbox telemetry that could have sent location to Mapbox is switched off (Section 3.12). Soltra's App Store privacy label lists location and your account identifier as collected for the app's own features only.
The few cases where we would disclose data to anyone else.
- If the law requires it: a subpoena, court order, or lawful request from a public authority. We will tell you unless the law forbids it and we will disclose only what the request lawfully covers.
- To protect someone's safety, or to investigate fraud or abuse of Soltra.
- If Soltra is sold or merged, your data may transfer to the new owner under this same policy. We would tell you first and your deletion rights would continue to apply.
10. How long we keep your data, and how to delete it
10.1 Retention
| Data | Kept until |
|---|---|
| Account, sign-in identity, email address | You delete your account |
| Display name, profile photo, body weight | You delete your data or your account (all three are cleared at once) |
| Activities, routes, sample tracks, tiles, place attributions, statistics | You delete the activity, your data or your account |
| Duplicate activities Soltra detected | Hidden from you; deleted with your data or your account |
| Uploaded import archives | Deleted no later than 30 days after the import finishes or fails; extracted route files are deleted as soon as they are processed |
| Import history (file names and results) | You delete your data or your account |
| Photos (display copies and thumbnails) and their locations | You delete the photo, all photos, its activity, your data or your account. The stored files are removed by a deletion ledger within minutes; the ledger entry itself is kept for 90 days as proof and then removed |
| Subscription status and Apple's subscription notifications | You delete your account. The full text of each Apple notification is reduced to a summary after 180 days; notifications no longer tied to any account are deleted after 30 days |
| Strava connection and credentials | You disconnect Strava or delete your account |
| Push token, notification settings, notification history | Sign-out or account deletion clears the token; data deletion clears the history; account deletion clears everything |
| A record that you asked for deletion (your account identifier, which kind, when, and the file paths it covered) | Kept after “Delete your data” so the request can be proven and completed; removed with your account on “Delete your account” |
| Usage events (PostHog) | Deleted, together with the analytics profile keyed to your account, when you delete your data or your account. Otherwise kept up to 7 years, the retention our PostHog plan sets and does not let us shorten. Signing out only unlinks the device's session from your account for later events |
| Crash reports (Crashlytics) | 90 days |
| Server logs (Supabase) | 7 days |
| Waitlist email (joinsoltra.com) | Until Soltra has launched or you ask to be removed |
| Emails to [email protected] | 2 years after the request is closed |
| Encrypted platform backups | Up to 7 days after the data was deleted (some state laws allow up to six months; we do not use it). Backups exist only to restore the service after a failure and are never used to restore data you deleted |
| Data on your phone (local copies of your activities, cached photos, the recording buffer, preferences) | Until the next signed-in session refreshes it, or you delete the app; excluded from device backups |
10.2 Three ways to delete, all in Soltra's Settings
Delete all photos. Removes every photo attached to your activities: the associations, the stored copies and their locations. Your activities, routes, territory, statistics, profile and account are untouched. This happens at once.
Delete your data. Permanently removes all your activity data from our servers: routes, sample tracks, tiles, territory, place attributions, statistics, achievements, import history and files, photos, notification history, and any queued Strava uploads. It also clears your display name, profile photo, and stored body weight and stops Soltra reading your weight from Apple Health again until you enter one yourself. What it deliberately leaves, so that you can keep using the app: your sign-in identity, your subscription and its records, your notification settings and push token, and your Strava connection if you made one. You stay signed in and can start again with an empty map. Apple Health sync is paused until you turn it back on in Settings, so deleted workouts are not immediately re-imported.
Delete your account. Everything above, plus your sign-in identity, your subscription records, your notification settings and push token, and your Strava connection (which is also revoked on Strava's side). We ask Apple to revoke the Sign in with Apple grant and ask RevenueCat to delete your subscriber record. You are signed out on every device. Deleting your account does not cancel an App Store subscription; cancel that in your App Store settings, as the app reminds you.
Each request is accepted immediately and your data becomes inaccessible at once; the physical removal from our database and file storage runs in the background, usually within minutes, and a scheduled process retries anything that fails until it is done. Copies in our hosting provider's backups expire within 7 days, well inside the six-month limit some state laws set. We also instruct the processors in Section 9 that hold data for us to delete it and we delete the analytics profile and events PostHog holds under your account identifier. A request made by email is completed within 30 days of our verifying it and never more than 45 days after we receive it. Both are irreversible. If an import is still running you will be asked to wait for it to finish first.
If you cannot use the app, email [email protected] and we will delete for you after verifying the request (Section 12).
11. How we protect your data
- All traffic between your phone and our servers, and between our servers and the companies in Section 9, is encrypted in transit.
- Your data is stored in a database where every table holding personal data is restricted to its owner: the server refuses any query for another person's rows and there is no feature that reads across users.
- Photos and import files are stored in private buckets that no public URL reaches; the app fetches them with short-lived links that expire after one hour.
- Strava credentials and other secrets are kept in a part of the database that only our server code can read and are never logged.
- On your phone, import staging files, pending uploads, cached photos, and Health sync markers are excluded from device backups and protected by iOS file encryption until you first enter your passcode after a restart. Soltra's local copy of your activities and the live recording buffer are excluded from device backups as well, so an iCloud or computer backup of your iPhone does not carry your health data out of the app; Soltra rebuilds that local copy from our servers when you sign in on a restored phone.
- Our server code never writes coordinates, email addresses, or health values into logs.
- The app holds no key that can read another person's data. The only keys it ships are the public ones Mapbox and RevenueCat issue for use inside an app; everything else it does, it does as you.
- Soltra itself never writes to iCloud and never syncs through it.
No system is perfect. If we learn that your health or location data has been acquired or disclosed without authorisation, we will notify you without unreasonable delay and no later than 60 calendar days after discovery, as the Federal Trade Commission's Health Breach Notification Rule requires, and notify the FTC, the media where 500 or more residents of a state are affected, and any other regulator the law requires. We will tell you what happened, what data was involved, and what we are doing about it.
12. Your choices and your rights
12.1 Controls inside the app and iOS
| To | Do this |
|---|---|
| Stop or change what Soltra reads from or writes to Apple Health | Health app › your profile › Apps (under Privacy) › Soltra |
| Change location, motion, photo or notification access | iOS Settings › Soltra |
| Stop usage analytics and crash reporting | Soltra Settings › Privacy › Share usage analytics |
| Check Mapbox telemetry (off unless you turned it on) | The ⓘ button on the map › telemetry setting |
| Stop uploading to Strava and revoke access | Soltra Settings › Strava › Disconnect |
| Turn individual notifications off | Soltra Settings › Notifications |
| Correct your name, photo, weight or an activity's details | Edit them in the app |
| Delete photos, your data, or your account | Soltra Settings (Section 10.2) |
12.2 Rights you can exercise by writing to us
Wherever you live, you can ask us to:
- Tell you whether we hold personal data about you and give you a copy of it (access).
- Correct anything inaccurate.
- Delete your data or your account (also available in the app).
- Give you a copy in a usable format so you can take it elsewhere (portability). Soltra does not yet have a one-tap export; until it does we prepare the export by hand and send it within the deadlines below.
- Stop or limit a particular use, or object to processing based on our legitimate interests.
- Withdraw consent you gave earlier.
- Appeal if we decline a request; we will explain why and how to escalate.
Write to [email protected]. We answer within 45 days (extendable once by 45 days if we tell you why), and complete a deletion within 30 days of verifying it and never more than 45 days after receiving it. We keep the correspondence for 2 years after your request is closed, so we can show it was honoured. We never charge for a request unless it is clearly repetitive or unfounded and we never treat you differently for exercising a right.
How we verify it is you. The only contact detail we hold is the email address Apple gave us, which may be a private relay address that forwards to you rather than your own. To act on an emailed request we reply to that address and act only on a confirmation that comes back from it; you can see which address it is under iOS Settings › your name › Sign in with Apple › Soltra. Making the change from inside the app, where being signed in is the proof, is always the faster route. If you have turned off Sign in with Apple for Soltra in your Apple Account, the relay address no longer forwards to you and we may be unable to verify an emailed request; signing in again restores it. An authorised agent can act for you with your written permission and the same verification.
13. Outside the United States
Soltra is offered only through the United States App Store and is not supported anywhere else. This policy therefore describes United States law and your rights under it. If we ever offer Soltra in another country, including the European Economic Area, the United Kingdom or Switzerland, we will update this policy before doing so with the rights, legal bases and safeguards that country's law requires, and we will tell you in the app.
14. If you are in the United States
California. The California Consumer Privacy Act applies only to businesses above certain size thresholds, which Soltra does not meet today; we make the commitments below anyway, and they will bind us if it comes to apply. We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months. We collect the categories listed in Section 3 (identifiers, health and fitness information, precise geolocation, photographs, commercial information about your subscription, and internet-activity information about how you use the app), for the purposes in Section 4, from you, your devices and the companies in Section 9. Precise geolocation and health information are sensitive personal information; we use them only to provide the features you asked for, and never to infer characteristics about you, so there is nothing to limit under the “Limit the Use of My Sensitive Personal Information” right, although you may still write to us. You have the rights in Section 12, including the right to know, delete, correct, and not be discriminated against. Because we do not sell or share personal information, a Global Privacy Control signal from your browser changes nothing, and we do not respond to “Do Not Track” signals because we do not track you across other sites or apps. We do not permit advertising companies or other third parties to track your Soltra activity over time and across unrelated apps or websites. Under California's “Shine the Light” law (which applies to businesses with 20 or more employees) you may ask what personal information we disclosed to third parties for their direct marketing: the answer is none.
Virginia, Colorado, Connecticut, Texas, Oregon, Maryland and the other states with their own privacy laws. Your health data and precise location are sensitive data under those laws, and we process them only with your consent, given through the permissions and choices described in Section 3. We do not sell personal data, do not sell precise geolocation, and do not process personal data for targeted advertising or profiling. You have the rights in Section 12, and if we decline a request you may appeal by replying to our answer; if the appeal is declined you may contact your state attorney general.
Washington, Nevada and Connecticut consumer health data. Our separate Consumer Health Data Privacy Policy states, in the form those laws require, what consumer health data we collect, why, with whom we share it, and how to exercise your rights over it.
15. Consumer health data laws
The document at joinsoltra.com/consumer-health-privacy is our Consumer Health Data Privacy Policy under Washington's My Health My Data Act, Nevada's consumer health data law and Connecticut's consumer health data provisions. It is a standalone document; if it and this policy ever appear to differ, it governs for those states' consumer health data.
16. Children and age
Soltra is not directed at children. You must be at least 13 to use it. If we ever offer Soltra in the European Economic Area, the United Kingdom or Switzerland, we will require users there to be at least 16, our own floor for an app that processes health and location data.
Apple's age-range check may run before sign-in where the law requires it (Section 3.13); Soltra keeps nothing from it. If we learn that someone under the minimum age has created an account, we will delete the account and its data. If you believe that has happened, write to [email protected].
If you are under 18, ask a parent or guardian to agree to our Terms of Service on your behalf. Because nothing in Soltra is shared with other users, a teenager's routes are never exposed to anyone.
17. Changes to this policy
When we change this policy we will change the date at the top and keep earlier versions available on request. For a change that affects how we use data we already hold about you, or that reduces your rights, we will tell you in the app at least 30 days before it takes effect and, where the law requires, ask for your consent again. Continuing to use Soltra after a change that needs no consent means the new policy applies.
18. Contact
Privacy questions and requests: [email protected]
Post: Soltra LLC, 440 N Barranca Ave #5017, Covina, CA 91723, United States