Rimba — Privacy Policy
Last updated: June 2026
Rimba is a private, single-player companion experience built on top of Strava that turns your running consistency into a living, private world diorama and a personal collection of memories. We design with a philosophy of strict data isolation and minimization: there are no public activity feeds, no competitive telemetry leaderboards, and no cross-athlete performance comparisons. Your athletic data is handled securely to power your private game state.
1. Information We Collect
When you authenticate Rimba using Strava OAuth, our system collects and processes only the bare minimum data payloads required to drive your private world:
- Identity Provider Profile: Your Strava athlete ID, display name, and profile image URL.
- Timezone:Your IANA timezone identifier (e.g. Asia/Kuala_Lumpur) is collected from your Strava profile at login. For users whose Strava profile does not include a timezone, it is inferred once from your browser's timezone settings on first use and immediately stored. This is used exclusively to determine the sunrise to sunset animation and the correct local calendar day boundary for your daily check-ins and continuity tracking, so a run at 11pm in your timezone counts for that day, not the next.
- Activity Data (Via Secure Webhooks): Activity type, distance in meters, moving time, elapsed time, and start date.
- Activity Legitimacy Signals:
- Presence of device-recorded GPS data (used for Run/Walk/Hike eligibility verification).
- Presence of device-recorded Heart Rate data (used for Run/Walk eligibility when GPS is absent, and for treadmill verification).
- Strava metadata flags identifying if an activity was manually entered or completed on an indoor trainer.
- Geospatial Boundaries: Rimba processes activities categorized as a Run, Walk, or Hike. We do not store, cache, or process route polylines or GPS coordinates beyond the instant validation required to confirm activity legitimacy. Map geometry is completely discarded and is never rendered anywhere within the platform.
- Consent Timestamp: The timestamp of your first acceptance of this Privacy Policy is recorded when you first access your world. This is retained as part of your account record to demonstrate consent compliance under GDPR and applicable data protection law. The consent timestamp persists for the duration of your account and is permanently deleted as part of the full account purge described in Section 5.
- Push Notification Subscriptions:If you enable notifications, we store your device's push endpoint and encryption keys to deliver them. Deleting your account removes these, and turning notifications off removes them from that device.
2. How Your Data Is Processed & Used
Rimba uses your activity data exclusively through automated script operations to power your personal world progression loop:
- Eligibility Evaluation: To protect ecosystem integrity, our scoring engine checks activities against strict gates. Eligible activities (Runs, Walks, Hikes) must be at least 0.5 km and be GPS-tracked, or recorded with device heart-rate data (Runs and Walks qualify with HR when GPS is absent). Manually entered activities are completely excluded. Activities that fall outside expected parameters are marked ineligible and contribute zero Growth XP. Raw telemetry for these activities is retained for the standard 7-day window then deleted.
- Growth XP Calibration: Eligible activities calculate a non-linear Growth XP reward based on distance covered.
- Visual Asset Generation: XP updates your incremental evolution stage database field, unlocking static ecosystem assets (e.g., progressing from Forest Seed toward Ancient Rainforest) in your private world view.
- World Event Generation: Significant milestones emit Journey events (e.g., stage progression, consistency achievements), which are displayed in your Journey timeline. Each Journey event records the milestone narrative, your activity category (Run, Walk, or Hike), the local calendar date, the Leaves earned, and a Strava activity reference identifier (used solely to group and de-duplicate your Journey entries). Journey events are permanently retained as game state and are not subject to the 7-day raw telemetry deletion described in Section 5.
Rimba does not sell, license, rent, or market your data to any third party. We do not use your data for advertising, marketing, or any purpose beyond powering your personal world layout.
- Product Usage Analytics:Rimba collects anonymized product usage analytics — such as which screens you open and which features you interact with within the Rimba interface — to understand how the experience is used and to improve it. These analytics record only your interactions within the Rimba application (e.g., opening a companion profile, viewing your journey timeline, tapping a world asset) and do not analyze, aggregate, or derive insights from your Strava activity data for analytics purposes. Usage analytics are stored in our database using your Strava athlete identifier, are never shared with third parties, and are never used for advertising or marketing purposes.
- Personalized Encouragement: To let your companion respond to your running, Rimba maintains a single rolling average of your own run pace and distance (a derived figure, not your individual runs). It is used solely to tailor encouragement shown only to you within your world, is never shared, sold, or disclosed to any third party, and is never used for advertising, marketing, cross-athlete comparison, or AI/LLM processing.
3. Privacy Isolation & Opt-In Social Layer
Rimba is designed as a private experience. All of your data — world state, progression, and companion state — is visible only to you when securely authenticated. There are no public profiles, leaderboards, activity feeds, or surfaces that expose your data to other users without your explicit action.
- No Public Surfaces:Your world, progression history, and companion state are never publicly indexed or searchable. Visiting another user's world requires a confirmed, mutually accepted friend connection — there is no way to browse or discover users.
- Opt-In Friends & World Visits: Rimba includes an optional, fully opt-in social layer. You may generate a personal link code (a “Friend Hash”) and share it with people you choose. A confirmed friend who visits your world can see: your world growth stage (a game progression level, not a reflection of any specific run distance or count), your companion name, and the cosmetic items you have purchased in the in-game shop. They cannot see your Leaves balance, any numerical XP figures, your Strava activities, your run history, distances, paces, or any raw telemetry. The same boundary applies in both directions. You can remove a friend connection at any time through your profile, immediately revoking their access to your world.
- Visit Notifications: When a confirmed friend visits your world, you receive a notification. No record of the visit is retained after you have been notified.
4. Technical Constraints & Non-Goals
In absolute adherence to Strava’s Developer Program Policies, Rimba enforces strict operational limitations:
- We do not display raw activity logs, split times, or routes to other users.
- We do not query, store, or call any Strava public social-graph, club, or follower endpoints.
- We do not use any third-party AI systems, large language models (LLMs), or data aggregators to process or analyze your activity payload.
5. Data Retention, Minimization, & Deletion
We do not permanently store your raw activity telemetry.
- 7-Day Automatic Data Deletion:Raw activity telemetry metadata ingested from webhooks (distance, moving time, start date) is retained in our transactional ledger for a maximum window of 7 days to ensure accurate read-time continuity evaluation and auditing. A daily background cron job permanently removes activity ledger records older than 7 days. Only your transformed game attributes persist past this window: Growth XP, evolution stage, Journey events, and a single rolling average of your run pace and distance used to personalize your companion's encouragement. Journey events include the milestone text, the activity category (run, walk, or hike), the local calendar date, the Leaves awarded, and a Strava activity reference identifier used solely to group and de-duplicate Journey entries. We do not retain your individual runs' distances, durations, paces, or routes beyond 7 days; the only derived figure that persists is the single rolling average described above.
- Revoking Access: You can cut off Rimba’s access at any time through your Strava Profile Settings panel under "My Apps," which triggers an automated
oauth/revokeconnection pipeline. - Permanent Account Purge:You can trigger a complete, irreversible account purge at any time directly within your world (Settings → Delete My Account & Data). Upon execution, our database performs a cascading delete that instantly and permanently erases your User profile, StravaAthlete records, historical game states, companion milestones, remaining ledger items, and OAuth secure tokens. Your historical activities on Strava remain completely unaffected.
6. Security Measures
We apply appropriate technical and organisational security measures to protect your data, in accordance with the Strava API Agreement and applicable data protection law:
- Encrypted Transit: All data exchanged between your browser, our servers, and the Strava API is encrypted during transmission. No data is sent over unencrypted connections.
- Activity Validation: Activity events from Strava are validated for authenticity before processing. Duplicate activities are prevented through automated idempotency checks.
- Secure Token Storage: Your Strava OAuth tokens are stored securely in our managed database, which encrypts stored data at rest at the storage layer. They are never logged, exposed in API responses, or shared with other systems.
- Principle of Least Privilege: We request only the minimum OAuth scopes required to operate Rimba (
read,activity:read_all,profile:read_all). No write, club, segment, or social-graph scopes are requested. - Data Breach Notification: We will notify Strava within 24 hours of discovering any security breach as required by the Strava API Agreement, and will notify affected users and the relevant authorities without undue delay in accordance with applicable law.
- Subprocessors: Rimba relies on the following infrastructure subprocessors to deliver the service: Vercel, Inc. (hosting and serverless compute), Supabase (managed PostgreSQL database), and Vercel Analytics and Speed Insights (platform performance monitoring). Vercel Analytics and Speed Insights collect anonymized metrics only — page load performance, Core Web Vitals, and device type — and receive no personally identifiable information. All subprocessors are bound by data protection obligations equivalent to those described in this policy. A current list of subprocessors is available on request.
7. Governing Law & Jurisdiction
This Privacy Policy is governed by the laws of Malaysia, including the Personal Data Protection Act 2010 (PDPA). By using Rimba, you agree that any disputes relating to data privacy will be subject to Malaysian jurisdiction.
For users in the European Economic Area (EEA) or United Kingdom, data processing is conducted in accordance with the General Data Protection Regulation (GDPR) and UK GDPR where applicable. You may have additional rights under those frameworks, including the right to access, rectify, or erase your personal data. To exercise any such right, contact us at the address below.
8. Contact & Support
For explicit inquiries regarding your data security, systemic privacy boundaries, or account deletion support, contact Moriya Works (Registration No. 202603164785 (CT0165913-P)) at:
Disclaimer
Rimba is an independent application and is not affiliated with, endorsed by, or sponsored by Strava, Inc.
Rimba is operated by Moriya Works (Registration No. 202603164785 (CT0165913-P)), a sole proprietorship registered in Malaysia.