Strava's global heatmap could reveal the location of your home, according to researchers
Findings suggest setting your account to private mode does not mean your Strava data is private, although it is easily turned off
Privacy and safety concerns have been raised about Strava’s global heatmap feature, with research suggesting that it could reveal user locations, even on private mode.
Researchers at the North Carolina State University in Raleigh found that they could locate the start and end point of activities, especially in low-populated areas.
A spokesperson for the activity-tracking application said that Strava "does not track users or share data without their permission".
Introduced in 2018 to “improve user experience”, the global heatmap feature enables users to find new hiking, running and cycling routes, popular exercising hotspots in their area, and even find new training partners, should it be used in a certain way.
The feature is based on GPS data and is updated every month. It compiles data from the previous two years, compiling it into one single map, highlighting areas of activity with bright yellow and white lines.
Just one month after introducing it to the popular fitness app, Strava provided an opt-out function for the heatmap after discovering that it could pose a privacy and safety risk to its more than 100 million users.
Furthermore, there were even concerns that it was exposing secret or sensitive information through its global heatmap.
In a paper published last month, researchers said that people could use the heatmap feature to track Strava users to their home addresses.
Get The Leadout Newsletter
The latest race content, interviews, features, reviews and expert buying guides, direct to your inbox!
The study found that all Strava users in a given lesser populated area can be looked up, to the extent that it is allegedly even possible to discover where users exercise routes begin and end.
“Strava users expect their personal information to be protected, and our work shows that this is not always the case,” Anupam Das, one of the authors of the paper, said. “This could be particularly problematic for users concerned about stalkers or have other reasons to desire that their location data be kept from the public.”
“In a densely populated area, with lots of routes and lots of users, there is so much data that it would be difficult to track any specific person,” Das added. “However, in areas where there are few users or few routes, it becomes a simple process of elimination, particularly if the person someone is looking for is a highly active Strava user.”
Das also suggested that making an account private doesn’t guarantee protection against this, although Strava told his researchers that its heatmaps only use aggregate data, making it impossible for anyone to capture private information.
“We did reach out to Strava about this, and the company has said it does not share heatmap data unless several users are active in a given area,” said Kevin Childs, first author of the study paper. “However, we were still able to identify the home addresses of some users in certain areas using the heatmap.”
"The safety and privacy of our community is our highest priority," a spokesperson for Strava said this week. "We've long had a suite of privacy controls (including Map Visibility Controls) that give users control over what they share and who it’s shared with.
"Strava does not track users or share data without their permission. When users share their aggregated, de-identified data with the Heatmap and Strava Metro, they contribute to a one-of-a-kind data set that helps urban planners as they develop better infrastructure for people on foot and bikes, and makes it easy to plan routes with the knowledge of the community.
"The Global Heatmap displays aggregated data from a subset of Strava activities and will not show ‘heat’ unless multiple people have completed an activity in a given area. Any Strava user who does not wish to contribute to the Heatmap can toggle off the Aggregated Data Usage control to exclude all activities or default their Activity Visibility to be only to themselves (`Only You`) for any given activity.
"We are consistently strengthening privacy tools and offering more feature education to give users control over their experience on Strava. This includes simplifying our Privacy Policy with our Privacy Label at the top."
Thank you for reading 20 articles this month* Join now for unlimited access
Enjoy your first month for just £1 / $1 / €1
*Read 5 free articles per month without a subscription
Join now for unlimited access
Try first month for just £1 / $1 / €1
Tom has been writing for Cycling Weekly since 2022 and his news stories, rider interviews and features appear both online and in the magazine.
Since joining the team, he has reported from some of professional cycling's biggest races and events including the Tour de France and the World Championships in Glasgow. He has also covered major races elsewhere across the world. As well as on the ground reporting, Tom writes race reports from the men's and women's WorldTour and focuses on coverage of UK domestic cycling.
-
The Oura ring reviewed: is this wellness tracker helpful to cyclists?
With its focus on recovery and wellness, the Oura ring offers unique insights but is it worth the investment over other wearables?
By Anne-Marije Rook Published
-
Shimano RC703 road shoe review: sleek, stiff and robust
Shimano's second-tier offering combines a rigid carbon sole with handy Boa dials and protective toe caps
By Sam Gupta Published
-
Amateur cyclist in talks with four WorldTour teams after Strava KOM heroics
Jack Burke says there's a 30% chance he'll ride at cycling's top level in 2025
By Tom Davidson Published
-
Amateur cyclist beats Sepp Kuss's time on Alpe d'Huez to take Strava KOM
Jack Burke hopes professional teams will offer him 'a chance to compete against the best'
By Tom Davidson Published
-
Strava blocks other apps from using leaderboard and segment data
Exercise tracking app says move will help maintain user privacy in the long term
By Tom Thewlis Published
-
Amateur cyclist breaks Strava KOMs on Mortirolo and Stelvio, makes plea for pro contract
'Let's hope some kind of opportunity comes from this,' said Canadian Jack Burke, after taking the Mortirolo crown
By Tom Davidson Published
-
Strava says its new AI feature is 'not a novelty' - but I think it's pointless
It promises to help users understand stats more, although it has just left me feeling more confused
By Adam Becket Published
-
Strava introduces new artificial intelligence feature for subscribers
Athlete Intelligence will take workout data and translate it into personalised insights
By Adam Becket Published
-
Strava introduces new feature which brings privacy settings up to speed
Quick Edit option allows users to hide specific workout data the moment they open the app
By Tom Thewlis Published
-
'It was a nice break' - Cycling sensation 'on holiday' breaks Zoncolan, Stelvio and Giau Strava records
Hill climber Illi Gardner added more iconic climbs to her trophy cabinet
By Tom Davidson Published