Privacy, in plain language.
Due has no Due account, advertising, analytics SDK, or social feed. Your plans and derived training summaries live on your iPhone and, when available, in your private iCloud database.
Last updated August 14, 2026
Who operates Due
Due is operated by Red Ducks Studio LLC in Albany, New York, USA. Questions can be sent to hello@due.run.
What Due keeps
Due stores the information needed to show your plan and training record:
- training plans, scheduled workouts, plan dates, and your changes to them;
- derived activity summaries such as an activity name, date, duration, distance, summary route, heart-rate summary, quality-mile result, and weekly totals;
- app preferences, sync state, and optional week receipts already posted to Strava;
- Strava access credentials in the iPhone Keychain.
Raw Strava streams—such as point-by-point time, distance, pace, elevation, and heart rate—are fetched for on-device calculations and discarded. They are not stored in Due’s training database.
Where it lives
Due’s app data is stored on your device using Apple’s data frameworks. It is also mirrored through CloudKit to your private iCloud database when iCloud is available. Private CloudKit data is controlled through your Apple account; Red Ducks Studio cannot browse that database.
If iCloud is unavailable, Due falls back to local storage so the app remains usable.
How Strava is used
Connecting Strava is optional. At connection, Due asks for permission to read your activities. Due uses Strava to:
- retrieve completed runs and match them to your plan;
- read activity details, streams, and laps needed to calculate derived training summaries;
- detect when a previously synced Strava activity has been removed.
An optional setting can post a compact Due week receipt to an activity description. It is off by default and requests Strava write permission separately. Due reads the existing description immediately before writing so your own text can be preserved.
Strava processes information under Strava’s privacy policy.
The authentication service
Due uses a small stateless service at auth.due.run to exchange and refresh Strava OAuth tokens because Strava’s client secret cannot be included in an iPhone app. The service relays the authorization exchange and returns the tokens to your device. It does not store your training plan or Strava activity data.
The marketing website
The website at due.run is a static site. It does not include advertising or analytics code and does not set a Due account cookie. If you email us, your email provider and ours process the message so we can reply.
Sharing and sale
Red Ducks Studio does not sell your personal information. Due shares data only as needed for the services you choose: Apple for private iCloud sync, Strava for activity access and optional write-back, and the authentication service for the Strava token exchange.
Your choices and deletion
- You can disconnect Strava in Due. Due asks Strava to revoke the grant and removes the stored tokens.
- You can remove an individual plan in the plans library. Removing a plan does not remove completed runs.
- You can turn optional Strava description write-back off at any time.
- You can delete Due from your devices and manage its iCloud data through your Apple account settings.
For a privacy request or help locating these controls, email hello@due.run.
Security and retention
Due uses iOS Keychain for Strava credentials and Apple’s private CloudKit storage for sync. Derived activity summaries remain until you remove the relevant data or the app removes them after Strava reports a deauthorization or deletion. Raw streams are discarded after the calculation that requested them.
No method of storage or transmission is perfectly secure. If we learn of an incident that affects information we control, we will respond as required by applicable law.
Children and changes
Due is not directed to children under 13. We may update this policy as the app changes. The current version and its effective date will remain posted here.