Your runs are a map of your life.

Where you live, where you work, when you are out. Most apps upload all of it to a server. Here is what that has cost people, and why Steady Pace is built so it can't.

Naval ships traced from the fitness tracks of their crews
Strava's 2017 global heatmap drew about one billion runs and rides, some three trillion GPS points. In January 2018 an analyst noticed the bright tracks in empty deserts traced the perimeters and jogging routes of secret military bases. The same tracks map a warship at sea, drawn by nothing but the crew's laps of the deck. Nobody put these on a map. The runs did.

A leak like this needs no hack. It needs an app that uploads where you go and a setting you never changed. The same public traces that outlined a base in Syria can outline a stranger's street, their gym, and the hours they are away from home. Researchers have shown that four location points are enough to pick one person out of a million.

The numbers are worse than the map.

Once your movements become data, they have a price. It is cheap, and there is a buyer.

12ยข

the price one broker charged for a U.S. soldier's location record. CNN ↗

61 million

phones whose week of movements one broker sold at once. FTC ↗

11,000+

things one data broker tracks about each of 2.5 billion people. Acxiom ↗

87%

of people are identifiable from just ZIP code, birthday, and gender. EFF ↗

It keeps happening.

A short and incomplete history of location and health data getting out, sold, or handed over. Every item below is a real, reported incident.

87 real, cited incidents since 2006, and this is only a selection. Scroll the wall.
2026

Troops were still exposing CENTCOM base routines in the Middle East through public Strava posts.

Stars and Stripes ↗
2026

A sailor's logged run on Strava revealed the position of an aircraft carrier at sea.

Bitdefender ↗
2026

Samsung Health told users to share medications and menstrual data with its AI or lose synced data.

Notebookcheck ↗
2026

The FBI director testified the FBI had resumed buying Americans' location data from brokers.

TechCrunch ↗
2025

1,400 Strava activities from seven bodyguards exposed the Swedish prime minister's home and movements.

Euronews ↗
2025

Broker Gravy Analytics was hacked, leaking about 17 terabytes of precise location data on millions.

NBC News ↗
2025

A jury found Meta liable for using period-app data to target ads.

The Register ↗
2025

Le Monde found French nuclear-submarine crews leaking patrol dates through their Strava runs.

Euronews ↗
2025

Ransomware leaked about 72 million Under Armour customer records, including names and locations.

Malwarebytes ↗
2025

Oura's deal with a defense contractor raised fears over access to health and reproductive data.

Slate ↗
2025

A lawsuit alleged Whoop shared users' health data with a third-party tracker without consent.

Milberg ↗
2025

The FTC banned brokers Gravy Analytics and Venntel from selling sensitive location data.

FTC ↗
2025

Reporting found ICE moving to buy a tool tracking hundreds of millions of phones every day.

404 Media ↗
2025

The FTC acted against a carmaker for selling drivers' precise location without consent.

FTC ↗
2024

Le Monde tracked the bodyguards of Biden, Trump, Macron, and Putin through their Strava posts.

Semafor ↗
2024

Researchers pinned Bumble, Hinge, and Grindr users to within about two metres.

TechCrunch ↗
2024

A regulator banned a broker from selling sensitive location data, the first ban of its kind.

FTC ↗
2024

Strava's new terms banned third parties from using its data to train AI, after an API crackdown.

TechRepublic ↗
2024

A broker's tool tracked a phone to an abortion clinic with no warrant needed.

404 Media ↗
2024

A broker sold the location data of visitors to 600 reproductive-health clinics.

The Record ↗
2024

Senate documents confirmed the NSA buys Americans' internet browsing records from data brokers.

US Senate ↗
2024

A stalkerware breach exposed data from 2.4 million customers of a covert phone-surveillance app.

TechCrunch ↗
2024

Automakers were found secretly sharing driving data with insurers through a data broker.

The New York Times ↗
2024

A Senate probe found carmakers selling driver data for as little as 26 cents per car.

US Senate ↗
2023

A study de-anonymized Strava heatmap users and found their home addresses.

BleepingComputer ↗
2023

A regulator found GoodRx shared prescription and health data with Facebook and Google.

FTC ↗
2023

BetterHelp was found to have shared mental-health data with Facebook and Snapchat.

FTC ↗
2023

The 23andMe breach exposed genetic and ancestry data on about 6.9 million users.

HIPAA Journal ↗
2023

A regulator found a fertility app shared data with Google and overseas analytics firms.

TechCrunch ↗
2023

A man used Strava to monitor a jogger's routes; a court granted a stalking order against him.

The Sun ↗
2023

A privacy review called cars the worst product category it had ever reviewed for privacy.

Mozilla Foundation ↗
2023

Reuters found workers at a carmaker privately sharing intimate videos from customers' car cameras.

Reuters ↗
2023

Researchers bought about 5,000 US servicemembers' records for as little as 12 cents each, sortable by base.

CNN ↗
2022

SafeGraph sold a week of location data on abortion-clinic visitors for about 160 dollars.

Vice ↗
2022

Records showed a US agency buying vast quantities of cellphone location data without warrants.

ACLU ↗
2022

Two US agencies contracted a broker selling location data harvested from dating apps.

The Intercept ↗
2022

A regulator sued a broker for selling data that traced visits to abortion clinics.

CNN ↗
2022

A company was found selling app-sourced location data cheaply to local police.

EFF ↗
2022

Gay and bisexual dating apps and prayer apps sold users' location data to a broker.

The Markup ↗
2022

A woman was tracked on Strava and murdered by a rival who followed her routes to find her.

Fox News ↗
2022

Fake Strava segments were used to surveil about 100 personnel at six secret Israeli military bases.

Bitdefender ↗
2022

Researchers defeated Strava's privacy zones and located users' homes with up to 85% success.

Dark Reading ↗
2022

A firm demonstrated tracking the phones of CIA and NSA staff using ordinary app location data.

The Intercept ↗
2022

Google paid $391.5 million to 40 US states over misleading location-tracking practices.

NJ Attorney General ↗
2022

A woman used an AirTag to find her boyfriend, then ran him over and killed him.

The Register ↗
2022

A sex trafficker used a family-tracking app as an electronic leash on a teenage victim.

Forbes ↗
2022

A broker sold timestamped location data from 61 million unique devices in a single week.

FTC ↗
2021

Life360 sold precise location data on tens of millions of people, including children.

The Markup ↗
2021

A Catholic priest was outed after a publication bought his Grindr location data.

Washington Post ↗
2021

A regulator found the Flo app shared fertility and pregnancy data with Facebook, Google, and others.

FTC ↗
2021

A prayer app sold user location data through a broker.

Vice ↗
2021

The US Treasury bought a location-data app to investigate people.

The Intercept ↗
2021

An unsecured third-party database exposed 61 million Fitbit and Apple Health records.

AppleInsider ↗
2021

Peloton's unauthenticated API let anyone pull riders' private profile and workout data.

TechCrunch ↗
2021

Researchers found Nike Run Club, Runkeeper, and MapMyRun lacked two-factor login and allowed weak passwords.

TechCrunch ↗
2021

A US intelligence agency admitted buying Americans' phone location data without warrants.

The Hill ↗
2021

One broker advertised 11,000-plus data attributes on 2.5 billion people.

Acxiom ↗
2020

The Untappd beer check-in app was used to track military and intelligence staff at the Pentagon and Camp Peary.

Bellingcat ↗
2020

The Muslim Pro app, with 98M+ downloads, sent location data to a broker that reached the US military.

Vice ↗
2020

Venntel sold app location data to ICE, CBP, and the FBI, who tracked phones worldwide.

Vice ↗
2020

Garmin's fitness services were knocked offline for days by a ransomware attack.

BleepingComputer ↗
2020

Strava turned its Flyby feature off for everyone after it exposed nearby strangers and enabled stalking.

BleepingComputer ↗
2020

US special operations bought location data drawn from Muslim prayer-app users.

Vice ↗
2020

The Secret Service bought a phone-tracking tool built on app location data.

Vice ↗
2020

An antivirus company was found selling users' browsing data through a subsidiary.

Vice ↗
2019

The New York Times tracked named Secret Service and Pentagon staff from a leaked 12-million-phone dataset.

The New York Times ↗
2019

The Flo period app sent menstruation and pregnancy data to Facebook.

CNBC ↗
2019

A pregnancy app sold aggregated employee pregnancy data to their employers.

Washington Post ↗
2019

Los Angeles sued a weather app for covertly selling users' location data.

NBC News ↗
2019

A study found 99.98% of Americans could be re-identified from almost any dataset.

Nature Communications ↗
2019

Google's location store was found feeding police geofence warrants that snared innocent people.

The New York Times ↗
2018

Strava's global heatmap exposed the perimeters and patrol routes of secret military bases.

CNN ↗
2018

Polar Flow exposed names and home addresses of 6,500+ personnel at 200+ military and intelligence sites.

Bellingcat ↗
2018

The US military said it was refining wearable-device rules after the Strava heatmap exposed base activity.

The Register ↗
2018

Grindr shared users' HIV status and location with two third-party firms.

BuzzFeed News ↗
2018

Under Armour's MyFitnessPal breach compromised about 150 million accounts.

CNBC ↗
2018

Analysts traced Russian soldiers' movements inside bases, including in Crimea, through Strava.

Atlantic Council DFRLab ↗
2018

Google was found storing location data even when users turned Location History off.

Associated Press ↗
2016

Researchers found flaws in a fertility app that let attackers reach users' sensitive data.

TechCrunch ↗
2015

Four points re-identified 90% of people in a set of credit-card records on 1.1 million people.

Science ↗
2015

Runtastic left live workout maps unsecured by default, letting attackers track runners in real time.

Pen Test Partners ↗
2014

Tinder's API leaked distances, letting anyone triangulate a user's exact location.

Include Security ↗
2014

Strava began selling athletes' data to transport agencies; one paid $20,000 for cyclists' movements.

Gizmodo ↗
2013

Four location points were enough to uniquely identify 95% of 1.5 million people in phone data.

Scientific Reports ↗
2008

Anonymized Netflix ratings were de-anonymized using a little outside knowledge.

Narayanan and Shmatikov ↗
2006

The New York Times re-identified an anonymous searcher from a released AOL dataset.

The New York Times ↗
2000

A researcher showed 87% of Americans are identifiable from ZIP, birth date, and gender alone.

EFF ↗

Here is every Steady Pace run on a map.

A single dot alone in the empty ocean, where Steady Pace anonymizes every run
Steady Pace shifts every route to a single point in the open ocean, on your phone, then throws the offset away. There is nothing to see, because there is nothing to upload.

Steady Pace has no account and no server, and it makes no network connections at all. Your runs are written to your phone and stay there. Each one is anonymized on the device: the whole route is shifted by an offset that is worked out locally and then discarded, so the coordinates saved on your phone do not match the ground you ran, and the shift cannot be reversed. Put the phone in airplane mode and every feature still works.

No account. No server. No network connections. Nothing to leak. The strongest privacy promise is not a policy you have to trust. It is an app that cannot spill what it never collects.

This is not a reason to stop running.

Tracking a run is useful. The risk comes from apps that send your location somewhere it can be stored, sold, or spilled. Pick a tool that keeps your runs on your phone and asks for nothing else.

Download on the App Store No data. No leaks. One purchase.
Does Steady Pace ever send my location anywhere?

No. The app makes no network connections at all. There is no account and no server, so your runs have nowhere to go. They are written to your phone and stay there, and deleting the app deletes them.

What does "anonymized" mean here?

Each run's whole route is shifted by an offset that your phone works out and then discards. The coordinates saved on your phone no longer match where you ran, and because the offset is gone, the shift cannot be reversed by us or by anyone reading the file.

Can a run I share reveal where I live?

The shape of the route is kept, because that is the map, while its true location is discarded. A shared run shows the shape of your loop sitting in the open ocean, far from the streets around your home.

Is "no data" just a marketing line?

You can test it. Put your phone in airplane mode and go for a run. Everything still works, because nothing was ever being sent. A promise you can check beats a privacy policy you have to trust.

Hold your pace by ear

Set a target pace. A tone rises when you slow and falls when you speed up, so you hold it without looking at your phone. No ads, no account, no subscription.

Download on the App Store