An exposure page, not a locate method

Finding Someone Through a Fitness App: The Exposure Runs the Other Way

A training app does not publish a route. It publishes a routine — the same streets, the same hour, the same three mornings a week, month after month, ending at the door the person sleeps behind. So this page is written for the person on the map, not for anyone looking at it. It contains no technique for locating a third party through their fitness data, and we do not accept files whose deliverable is a picture of where someone goes and when. What it does contain is a plain account of what these accounts broadcast by default, and a control-by-control review you can run in your own settings in about twenty minutes.

No movement profiles, no pattern-of-life work, ever Every setting below read at the vendor’s own documentation Records research since 2004, under a purpose the law permits
EveryoneThe audience a brand-new Strava profile, its activities and its group activities default to
200 mHidden at each end of a Strava activity map by default — on future uploads only
85%Share of privacy zones whose protected location a peer-reviewed 2022 study recovered
0Past activities made private when you change your default visibility setting

The Short Version

Yes, these platforms publish location patterns, and yes, that is a genuine safety problem. A new Strava account starts with its profile, its activities and its group activities visible to everyone, and its activity pages readable by people who are not logged in at all. No, this page will not show anyone how to point that at another person. Publicly visible is not the same thing as lawfully usable, and assembling a person’s movements from data they published about themselves is surveillance by a nicer name. We decline that work at intake, including when the requester is family. What is worth twenty minutes of your evening is the opposite exercise. The controls that govern all of this sit in three different screens, they behave three different ways on activities you have already posted, and the one most people reach for first does the least. That is the part of the story nobody writes down, so it is most of this page.

What Your Weekly Route Map Says About Your Week

A short walk through the difference between one activity and a season of them.

Watch first

What the App Publishes on the Day You Sign Up

Not what it could publish if you configured it badly. What it publishes when you configure nothing at all.

Product settings move, and a page that recites them from memory ages into something actively misleading. So everything in this section was read at the vendor’s own help center in 2026 rather than recalled, and it describes Strava specifically, because Strava documents its defaults in one place and is the platform the security research has concentrated on. Other services differ. Check yours at its own support pages rather than assuming the shape below transfers.

Strava’s article “Your Privacy Defaults When You Create a Strava Account” lists what a new account starts with. Profile: everyone. Activities: everyone. Group activities: everyone. Mentions: everyone. A handful of controls start closed — Flyby is set to no one, the training log is private, and messaging is limited to accounts you follow — and a handful start open in ways that are easy to miss, including product improvements enabled, public photos on routes enabled, and personal information sharing opted in. The company notes that these defaults do not apply to accounts belonging to people under eighteen.

Some of your profile is visible to every member no matter what you set. Strava states that your first and last name, your badge if you have one, your bio, and your follower and following counts “will always be visible to all Strava members, regardless of your privacy settings.” That is a floor, not a control. If your legal name is the exposure, the only lever is what name the account carries.

The part that reaches people with no account at all

With a profile set to everyone, Strava says a logged-out version of the profile page is available to non-members, and that “the information on your profile page may be indexed by search engines and consequently appear in search results.” Setting the profile to followers is what stops search engines from seeing it — and the company adds the detail that matters for anyone acting urgently: the public version “may be displayed in search engine results until the search engine refreshes its cache.” Closing the door does not empty the hallway on the same day.

For an activity left at everyone, the company describes what a logged-out visitor sees: the activity, distance, elevation, moving time, calories, photos, map, elevation profile, kudos, comments and an achievement count. It adds that “anyone on the internet may be able to see your placement on leaderboards.” To a signed-in member, the activity details page carries more still — Strava lists date and time, statistics, biometrics, analysis charts, map, segment matches, achievements, times and elevation profile.

The social surface is a second map

People audit the route and forget the ring of accounts around it. Kudos, comments, group-activity tagging, club membership and the follower list are all population data about a person’s real-world life: who trains with them, at what pace, in what area. Group activities default to everyone, which means other athletes can see that you were part of a group. None of this needs a map to be informative, and none of it is fixed by hiding one.

The same logic runs through every account a person holds, which is why a footprint review that stops at one app is not a review. If your concern is the address itself rather than the route, our walkthrough of how to get a home address off the public internet covers the record-side work, and the aggregation side is set out in what the data-broker industry already holds on you.

Ninety Runs Is a Schedule, Not a Route

One activity is a line on a map. A season of them is a description of somebody’s life, and the second thing is not the first thing repeated.

A single published run tells a stranger almost nothing. It shows a person moved through some streets on some morning. The exposure only appears when the activities stack up, because repetition converts a location into a prediction. Ninety runs over a season answer questions no individual run does: which days, which hour, which direction out of the door, how long before they come back, which stretch is quiet and unlit, and therefore when a person is reliably alone outdoors and where. That is not a home address. It is a timetable, and it is worth more to somebody with bad intentions than an address is.

This was demonstrated at scale before most people had heard of the problem. In January 2018, Strava’s published global activity heatmap was found to trace the perimeters and internal paths of military installations in conflict zones, because personnel stationed there had been recording ordinary workouts on ordinary devices. The episode is documented in Alex Hern’s report “Fitness tracking app Strava gives away location of secret US army bases”, published in The Guardian on January 28, 2018, and it is cited in the peer-reviewed security literature discussed in the next section. Nobody in that story published a secret. Each individual run was unremarkable. The facility appeared out of the aggregate.

The same arithmetic runs at household scale. Nobody publishes their address; enough people publish enough loops that begin and end in the same place, and the place stops being private. A person who trains from home has, without ever typing it anywhere, described that home’s location, the hours it is empty, and the hours it is occupied by one person.

Two things follow, and they point in opposite directions. For the person on the map, the practical target is the pattern rather than any single post — which is why the retroactivity question further down this page turns out to be the whole game. For anyone tempted to read this in the other direction, the fact that a pattern is technically visible does not make assembling one a legitimate thing to do, and the section on why we decline that work says so without hedging.

The Zone Around Your House Was Studied, and It Leaked

The privacy zone is the feature everybody recommends. It is also the feature that has been tested hardest, and it did not hold.

Most of these platforms offer some version of a protected area — the security literature calls it an endpoint privacy zone — that hides the portion of a track near a sensitive address so other users see a route that appears to begin and end somewhere down the street. It is a sensible idea and it is better than nothing. It is not a wall, and the strongest evidence for that comes from people who tested it properly and then told the vendors first.

In “A Run a Day Won’t Keep the Hacker Away: Inference Attacks on Endpoint Privacy Zones in Fitness Tracking Social Networks”, presented at the ACM Conference on Computer and Communications Security in Los Angeles in November 2022, Karel Dhondt, Victor Le Pochat, Alexios Voulimeneas, Wouter Joosen and Stijn Volckaert of KU Leuven reported that these zones “remain vulnerable to inference attacks that significantly reduce the effective anonymity provided by the EPZ, and even reveal the protected location.” Evaluating against 1.4 million Strava activities, they found their method recovered the protected location for up to 85 percent of the zones examined. The paper proposes six countermeasures, notes that each carries a usability cost, and records that the findings were responsibly disclosed to the major networks before publication.

Two earlier results sit alongside it and are described in the same paper’s review of related work. Hassan, Hussain and Bates, at the USENIX Security Symposium in 2018, identified protected locations for 84 percent of 432,022 athletes across 2.3 million zone-enabled Strava activities using a different technique. Mink and co-authors, in 2022, found that ordinary people shown activity endpoints on a map could visually pinpoint up to 68 percent of protected locations without any tooling at all. This page deliberately does not describe how any of those methods work, and no part of it is a recipe. The finding is what matters to a reader deciding what to trust.

Why a bigger radius is not the fix people assume

The obvious response is to enlarge the zone, and the paper confirms a larger radius does degrade the attack. But it also notes the cost: a large zone can swallow a short activity entirely, which is why users gravitate to small ones. More importantly, the authors conclude that measures aimed at making the zone harder to identify “cannot fully thwart our attack”, because the reported distances survive regardless. The countermeasures that worked best were the ones that blur the numbers, and those are exactly the ones that break the comparison and achievement features people use these products for. There is a real trade-off here and no setting resolves it.

The vendor says as much itself, in plainer words than most coverage of this topic manages. Strava’s “Map Visibility” help article states that “applying Map Visibility settings to your activity does not mean it would be impossible for someone to deduce a hidden location using additional information”, and directs anyone who wants the map genuinely unavailable to hide it completely rather than partially. That sentence deserves more attention than it gets. The company is not promising the zone works against a determined effort, and neither should anyone else.

What the same survey found across other apps

The KU Leuven paper also tabulated the zone features of nine popular services as they stood when the authors surveyed them in September 2021. Three offered no endpoint privacy zone at all: Adidas Runtastic, Map My Run and Nike Run Club. Of the six that did, Strava used circular zones from 200 up to 1,600 meters in 200-meter steps; Garmin Connect from 100 up to 1,000 meters in 100-meter steps; Relive from 200 to 1,000 meters; Ride With GPS at 150, 300, 600 or 1,200 meters; Map My Tracks at 500, 1,000 or 1,500 meters, with an automatic detection tool enabled by default that creates a zone once it notices a recurring start point; and Komoot used a randomly shaped polygon rather than a circle, specifically to make the boundary harder to infer. That table is five years old and is offered as history, not as current product truth — several of those apps have changed since. Its lasting value is the demonstration that “my app has privacy settings” and “my app has a location-hiding feature” were never the same claim.

Which Controls Fix the Past, and Which Only Go Forward

This is the distinction that decides whether you actually closed anything. The controls sit next to each other and behave nothing alike.

ControlWhat it hidesWhat it still leaves visibleApplies to activities you already posted?
Activity visibility set to FollowersThe activity from non-followers, and from anyone not logged in, who are sent to a sign-in page insteadFull details to approved followers, including start time, photos and gearNo — the default preference governs new uploads only
Activity visibility set to Only YouThe activity from every other personChallenge progress may still update for others where the activity counts toward oneNo — again, new uploads only
Map visibility, hide near an entered addressThe portion of a track that starts or ends near that address, at up to a one-mile radiusThe rest of the route, the distance, the duration and the time of dayReaches backYes — past and present, except activities you have already edited individually
Map visibility, hide the start and end of all activitiesThe first and last portion of every map wherever it beginsThe middle of every route, and everything that is not the mapNo — future activities only
Map visibility, hide the entire mapThe whole route lineDistance, duration, pace, time of day, kudos and commentsNo — future activities only
Product improvements checkboxYour contribution to the global heatmap and to the aggregated data productNothing on your own activity page changes at allSeparate control — not part of map visibility

Every row above is drawn from Strava’s own help center articles “Activity Privacy Controls” and “Map Visibility”. The row that surprises people is the first. In the company’s words, updating your default activity privacy preference “does not retroactively change the privacy controls on past activities.” Somebody who changes that one setting, sees the confirmation, and closes the app has protected next week and nothing before it. Every run already posted stays exactly as public as it was.

The address-based map control is the one that reaches backward. Strava describes it as applying “to all past and present activities, excluding any activities whose Map Visibility settings you have edited individually” — while the two broader options, hiding the start and end of everything and hiding maps entirely, “will only apply to future activities.” So the narrow-looking control does the retrospective work and the sweeping-looking ones do not, which is close to the opposite of what the labels suggest. Where an address zone and a general start-and-end setting overlap, the company says the larger selection wins.

Two further wrinkles are worth carrying with you. Editing map visibility on one activity permanently detaches it from your account defaults, so a change you make later will skip it. And the heatmap is governed somewhere else entirely: Strava says an activity set to everyone “will contribute to Strava Metro and the Global Heatmap by default”, with the opt-out sitting under product improvements rather than under any map setting. Hiding your maps does not remove you from the aggregate. As the company puts it, “map visibility does not replace your activity privacy control.”

If You Are Leaving, Start With These Settings

Of everything on this page, this section is the reason it exists. A published training routine is exactly the information that makes a person findable at a predictable moment, alone, outdoors.

Stalking is common and it is frequently technological. The Bureau of Justice Statistics reported in Stalking Victimization, 2019 that about 1.3 percent of people aged sixteen or older — some 3.4 million people — were stalked in that year, that fewer than a third of victims reported it to police, and that an estimated 67 percent of those who experienced both traditional stalking and stalking involving technology feared being killed or physically harmed. Those are not edge-case numbers, and a person leaving a controlling relationship is not being paranoid when they treat an exercise app as part of the problem.

Do the settings review early, and do it before the pattern changes rather than after. The reasoning is uncomfortable but it is the reasoning that matters. If a new address is going to appear in the data, the controls need to be closed before the first activity is recorded from it, because the address-based map zone is the only control that reaches backward and it has to be pointed at somewhere for it to help. A week of open activity from a new neighborhood cannot be un-posted by a setting change afterward; it can only be deleted activity by activity.

The account may not be the only exposure, and it may not be under your sole control. Check whether a watch or ring is still paired to a shared phone or a family plan. Check whether the account credentials were ever known to the other person, and change them from a device they have never handled. Check whether the app is authorized to push activities into a second platform that has its own separate audience setting. And check whether someone else’s account tags you into group activities, because your own settings do not govern what appears on their page.

Where the legal protections are

An Address Confidentiality Program issues a substitute address that agencies accept in place of a real one when records are created. New York’s is administered by its Department of State, which describes the substitute mailing address it provides for use in place of a home, school or work address, with free mail forwarding and acceptance of legal notices on a participant’s behalf, for victims of domestic violence and their household members who have moved somewhere their abuser does not know. New York’s is the one we read at the source for this page. Other states run comparable programs through different offices, under different names, with different eligibility rules, and we have not surveyed them — so ask whether your state operates one rather than taking a count from anybody’s website, this one included.

If you need the human help rather than the paperwork, the Department of Justice Office on Violence Against Women publishes a page of resources for victims and survivors that routes to national hotlines and to the state and tribal coalitions which connect people with providers where they live, and an advocate is generally better placed than any website to sequence a safety plan. For the device and app permissions layer underneath all of this, the Federal Trade Commission’s explainer on how websites and apps collect and use your information is short, current and worth the five minutes: it sets out that an app may ask for access to information on your device including your location, tells you to open the phone’s privacy settings to see what each app can reach, and advises turning off the permissions an app does not need. And if what you are actually trying to work out is whether someone is already doing this to you, our guide to recognizing the signs that you are being tracked is written for that reader.

A request that reaches us framed around a person who left gets more scrutiny at intake, not less. We would rather state that here than bury it in terms of service. Somebody who is hard to find is often hard to find deliberately, at real cost to themselves, and we treat that as information about the request rather than an obstacle in it. We do not work around an address confidentiality program, a protective order or a no-contact order, and we do not accept a file whose purpose is to reach a person who has arranged not to be reachable.

Six People Who Should Open Settings Tonight

Not hypotheticals. These are the situations where a published training pattern does concrete harm, and they are more ordinary than the security framing suggests.

Anyone who has just moved

A new home is at its most exposed in the first two weeks, before any zone exists around it. The address-based control has to be set to the new address, not merely left on from the old one, and until it is, every loop from the front door draws the same conclusion.

A participant in an address confidentiality program

A substitute address protects what agencies write down. It does nothing about a route the participant published themselves, from the real address, on a platform no state office controls. The two protections have to be maintained separately.

A teenager with a paired watch

Strava says its standard defaults do not apply to accounts held by people under eighteen, but it does not follow that the account in front of you is safe: a watch handed down from a parent can carry the parent’s settings and the parent’s history. School, practice and the walk between them form a schedule as regular as any adult’s, usually more so.

Someone whose employer is the reason

Protective details, clinicians who have been threatened, court staff, shelter workers. The pattern that exposes them is often not their own home but a workplace they arrive at on foot at a predictable hour, which no home-address zone touches.

Anyone who trains with a group

Group activity settings default to everyone, so membership is visible even where individual routes are not. A club roster plus a recurring meeting point plus a start time is a location and a schedule for every person on the list, not only the one who posted.

The person who fixed this two years ago

Settings survive product redesigns unevenly, new features arrive switched on, and a phone restored from a backup can reinstate an old preference. This is worth twenty minutes annually rather than once, and the review below is the same each time.

The Settings Review, In This Sequence

The order is not arbitrary. Doing these in the wrong sequence leaves the largest hole open longest.

1

Close the audience before touching the map

Set the profile and the activity default away from everyone first. This is the control that governs whether a logged-out stranger can read anything at all, and every later refinement is narrower than it.

2

Set the address-based zone, at a generous radius

This is the only control that reaches back over what you have already posted. Point it at every sensitive address you actually start or finish at, not just the home one, and set it wider than feels necessary.

3

Deal with the history the settings cannot reach

Anything the address zone does not cover has to be handled activity by activity, or deleted. This is the slow part and it is the part that actually removes the pattern rather than capping it.

4

Then the aggregate and the social ring

Turn off the contribution to community heatmaps, review followers and remove accounts you cannot place, and check what the app is authorized to push into other services that hold their own separate settings.

Step one, in detail: the audience

Open privacy controls and deal with three separate items: the profile page, the activity default, and group activities. Setting the profile to followers is the switch that stops search engines indexing it, and setting activities to followers is what sends logged-out visitors to a sign-in page instead of your route. Only you is stricter again. Both of the tighter options remove the activity from public segment leaderboards, which is the real reason many people never move off everyone — the competitive features are the product, and closing the audience costs you some of them. That is a legitimate trade to weigh, not a mistake, and it is worth weighing consciously rather than by default.

Step two, in detail: the map

Map visibility is a different screen from activity privacy and does a different job; the vendor is explicit that one does not replace the other. Enter each address you regularly begin or end at — home, and also a workplace, a partner’s home, a child’s school, a gym you walk to. Take the radius seriously. The security research is consistent that larger zones degrade inference attacks and small ones barely slow them, and the cost of a large zone is only that short activities get swallowed by it. If a route is sensitive enough that you would not want it deduced, the honest answer is the one Strava itself gives: hide that map completely rather than partially.

Step three, in detail: the back catalog

This is where most reviews quietly fail. The address zone covers past activities, but not any activity whose map visibility you have edited by hand, and not the ones that started somewhere you did not list. Work backward through the history and check what a stranger would see. Anything that still describes a place you care about has to be edited individually or deleted, and there is no setting that does this for you. It is tedious. It is also the only step that changes what is already published, which is the only thing an adversary can already have looked at.

Step four, in detail: everything downstream

Uncheck the community data contribution if you do not want to feed the aggregate. Prune the follower list, and treat an account you cannot identify as a reason to remove it rather than a puzzle to solve. Check the app authorizations screen for other services receiving your activities, because those services enforce their own visibility rules and inherit none of yours. Then look at the phone underneath all of it: the Federal Trade Commission’s guidance covers reviewing which apps hold location permission at the operating-system level, and revoking one there is more durable than any in-app toggle.

Why We Will Not Run This Search for You

A page that spends this long describing an exposure owes the reader a straight account of what the firm writing it does with the same information.

Publicly visible is not the same thing as lawfully usable, and it never has been. The fact that a person can be seen does not create a right to watch them, and the fact that they published something about themselves does not transfer it to anyone who wants it for a different purpose. Assembling a subject’s movements from their own fitness data would produce a record of where a named individual goes, when, and how predictably. That is a pattern of life. Building one is surveillance whatever the source material was, and it is not work we do.

So we decline it, and the decline is not situational. We do not accept a file whose deliverable is a person’s routine, schedule, or ongoing whereabouts. We do not accept a file framed as checking on a partner, a former partner, an adult child or a family member who moved away. Monitoring is not a service here, surveillance is not a service here, we neither place nor read location devices, and we cannot report where somebody is standing right now. A provider who says otherwise is selling something else, under a regulatory regime we do not operate in.

We are not licensed private investigators. Nobody here holds an investigator’s license in any state and we do not present ourselves as holding one. We are a skip-tracing and public-records research firm, which is a narrower thing, and where a matter genuinely needs a licensed investigator the right answer is to retain one rather than have us approximate the work. The scope we actually operate in is described in our overview of what locate research covers and where it stops.

No pretexting, and none of the versions of it that have better manners. We do not create an account under a false identity, we do not send a follow request as somebody we are not, we do not join a club or a group to see activity that has been restricted to its members, and we do not talk a third party into disclosing something by misrepresenting who we are or why we are asking. A restricted setting is a decision the account holder made. Engineering around it by deception is the thing the setting exists to stop.

Every file needs a purpose permitted by law, stated before we take a name. Curiosity is not one of them, and neither is wanting to know where someone lives now. The purpose determines which sources are open to us at all, and for several categories of record it determines whether the request is lawful in the first place.

Nothing this firm produces is a consumer report, because this firm is not a consumer reporting agency. No file of ours may be turned into a credit decision, a hiring decision, an insurance rate, a tenancy decision, or anything else the Fair Credit Reporting Act reaches at 15 U.S.C. 1681b. Those decisions require a consumer reporting agency and a consented, compliant process, and a research file is not a substitute for one. Private financial account contents are outside our reach as well — no balances, no statements, no card transactions, no returns.

The reading of this subject that is legitimate

There is a real professional use for everything above, and it is the mirror image of the misuse. It is advising someone about their own exposure. Counsel preparing a client for a contested separation, a corporate security team briefing a principal, an advocate building a safety plan, a person who has just been granted a protective order — all of them need to understand that a subject may have self-published a schedule, and that the schedule needs closing. Understanding the mechanism is what makes that advice specific enough to act on. It is also why we tell anyone who has left a dangerous situation to audit these settings early rather than eventually. That is a different job from locating a third party, and the difference is who asked and about whom.

Where a locate is legitimate, it rests on records and lawful data sources, not on a subject’s social feed. Recorded property interests, court filings, and licensed data accessed under a covered use are checkable, dateable and defensible in front of a judge, which a reconstructed running route is not. If harassment is the actual problem you are dealing with, our guide to documenting stalking and harassment covers the evidentiary side and the routes that lead to a court rather than to a confrontation.

None of this is legal advice. It is general information about how these products and these statutes work. What your own situation requires — whether an order applies, what a program in your state covers, what a platform owes you — is a question for counsel or an advocate who knows the facts we do not.

Who Brings Us This Question

Almost nobody who raises this with us is trying to find a stranger. They are trying to work out how much of somebody’s life is already showing, usually their own or their client’s.

People who have just left

Closing a routine, not opening one

Advocates building safety plans

The app layer of a wider plan

Counsel advising on exposure

Before a contested separation

Corporate security teams

Briefing a principal who travels

Parents of paired-device teenagers

Different defaults, same schedule

Confidentiality program participants

The gap a substitute address leaves

What We Will and Will Not Put in a File

Everything we hand over is traceable to a record or a lawful data source you can name back to us, and we say plainly when a question could not be answered instead of filling the gap with something that merely looks like an answer. Most files come back within 24 hours. What will never be in one is a person’s routine, their schedule, or anything reconstructed from what they published about their own movements — and if that is the file you need, you will hear so on the first call rather than after an invoice.

People Locator Skip Tracing Investigation Team has run public-records locate work since 2004 and wrote this page for the reader on the map rather than the one reading it. Every product setting described above was read at the vendor’s published help documentation during 2026, and the research findings are quoted from the papers themselves; where a figure could not be confirmed at its source, it is not printed here.

Questions About What Your App Shows

Can someone find my home address from a fitness app?

Where activities are public and start or finish at home, that is the documented risk, and it has been studied rather than merely speculated about. A 2022 paper presented at the ACM Conference on Computer and Communications Security, evaluating 1.4 million Strava activities, recovered the protected location for up to 85 percent of the endpoint privacy zones it examined. An earlier study presented at USENIX Security in 2018 reached 84 percent of 432,022 athletes by a different route. The exposure is strongest for people whose activities repeatedly begin at the same place, and weakest for those who do not publish maps at all.

Does a privacy zone actually hide my house?

It helps, and it is better than leaving the route bare, but it is not a guarantee and the vendor does not claim it is. Strava’s own Map Visibility documentation states that applying those settings “does not mean it would be impossible for someone to deduce a hidden location using additional information”, and points anyone who wants the map genuinely unavailable at hiding it completely instead. A larger radius measurably degrades the published inference techniques; a small one barely slows them.

What are the default privacy settings on a new account?

Strava publishes its own list. A new account starts with profile, activities, group activities and mentions all set to everyone; the training log private; Flyby set to no one; messaging limited to accounts you follow; product improvements enabled; public photos on routes enabled; personal information sharing opted in; and the first and last 200 meters of future activity maps hidden by default. The company notes these defaults do not apply to accounts held by people under eighteen. Other platforms set their own defaults, so read theirs rather than assuming.

If I change the setting now, does it fix my old activities?

Mostly no, and this is the single most misunderstood point on the subject. In Strava’s words, updating your default activity privacy preference “does not retroactively change the privacy controls on past activities.” Of the map controls, only the address-based zone reaches backward, applying to all past and present activities except any whose map visibility you previously edited by hand; hiding the start and end of all activities, or hiding maps entirely, applies to future activities only. Everything the address zone does not cover has to be edited or deleted one activity at a time.

Can people see my runs if they do not follow me or are not logged in?

With activities set to everyone and a public profile, yes. Strava says a logged-out visitor sees the activity, distance, elevation, moving time, calories, photos, map, elevation profile, kudos, comments and an achievement count, and that anyone on the internet may see your placement on leaderboards. Set to followers, a logged-out visitor is redirected to a sign-in page instead. Separately, your first and last name, badge, bio and follower counts stay visible to all members whatever you choose.

Does hiding my map take me off the heatmap?

No, because that is a different control in a different place. Strava states that an activity set to everyone “will contribute to Strava Metro and the Global Heatmap by default”, with the opt-out sitting under product improvements on the privacy controls page rather than under any map setting. An activity set to followers still contributes to the aggregated data product by default. If leaving the heatmap matters to you, that checkbox is the one to find, and hiding your maps will not do it for you.

I am leaving an unsafe situation. What should I change first?

Close the audience before anything else, because that governs whether strangers can read the account at all, then set an address-based zone at a generous radius pointed at the addresses you actually use, then work backward through the history the zone does not reach. Do it before recording anything from a new address rather than after. Check whether devices remain paired to a shared phone or plan and whether credentials were ever known to the other person. Then contact a local advocate and ask about your state’s address confidentiality program; an advocate can sequence the rest of a safety plan far better than a settings list can.

Will you find someone for me using their fitness app?

No. We decline that at intake and we do not make exceptions for family relationships or sympathetic explanations. Reconstructing where a named person goes and when, from data they published about themselves, produces a pattern of life, and building one is surveillance regardless of how the underlying information became visible. We also do not create accounts under false identities or join groups to see restricted activity, which would be pretexting. Where a locate is legitimate, it rests on records and lawful data sources under a purpose the law permits, and the file has to show its working.

Ask About Your Own Exposure, Not Somebody Else’s

If you are working out how much of a life is already visible — yours, or a client’s you are advising — describe the situation and we will tell you honestly what records research can and cannot answer, and where an advocate or counsel is the better call. If what you want is someone’s whereabouts, we will say no, and we will say it on the first call at no cost. Put the question to our team either way.

Start a conversation about exposure