We are preparing our submission for app review. Before we do, we would like to make sure our design complies with the API Policy (effective June 1, 2026), because four provisions bear directly on it. We would rather ask now than build on an incorrect reading.
1. Retention (6.2). Section 6.2 states that we "may not retain Strava Data in your cache for longer than seven (7) days". Our app imports an athlete's own workouts, with their explicit consent, and derives a score from them. That score feeds a lasting history and past duels. Does the seven-day limit cover data an athlete has deliberately imported into their own account in our app? If so, may we retain the derived values (points, ranking) beyond seven days, provided we delete the underlying Strava values?
2. Third parties (6.1 and 6.2). Section 6.1 restricts display to the end user's own data "unless your Developer Application has an athlete capacity of 9,999 or less" — our capacity is well below that. Section 6.2 states, with no threshold, that we "may not provide or display Strava Data or any associated service, to any third party other than the Strava user". In a duel, each athlete sees their opponent's distance and duration. Is an opponent who has joined the same challenge a "third party" in the sense of 6.2? And how do the two provisions relate, given that only one carries a threshold?
3. Deletions (6.3). We intend to reflect deletions within forty-eight hours. Is subscribing to the webhook events the expected mechanism, or is periodic polling acceptable?
4. Charges (5.8). Joute offers optional cosmetic items and season passes. They have no connection to Strava data, and the Strava integration is free and will remain so. Could you confirm this is compatible with 5.8?
