Strava Privacy & Security Guide 2026
Strava reveals home addresses, daily routines, and travel patterns through its activity heatmap and segment leaderboards. Multiple high-profile doxxing incidents have used Strava data alone.
Set up Activity Privacy Zones around your home and your office first, at the 1km minimum radius. A private profile does not hide the point every run starts and finishes at, and that point is a doorstep. Then turn on Private profile, enable Hide from public maps and segments, and disable Beacon and Flyby, which broadcast a live position and everyone you passed on the way.
Key steps to lock down Strava in 2026
- Settings → Privacy Controls.
- Turn on Private profile.
- Enable Hide from public maps and segments.
- Set activity visibility to You only or Followers.
- Use Activity Privacy Zones to obscure your home and office addresses (1km minimum radius).
- Disable Beacon and Flyby features.
- Turn off Show on leaderboards.
- Enable two-factor authentication.
Quick checklist
- Profile visibility: Private or friends-only
- Search engine indexing: Off
- Location sharing: Off
- Two-factor authentication: Enabled (authenticator app, not SMS)
- Data partner sharing / personalized ads: Off
- Linked apps + sessions: Audited and revoked where unfamiliar
Why these settings still aren't enough
Even with every Strava setting locked down, your data still leaks through three channels these settings can't reach: historical exposures already in breach corpora, third-party scrapers that mirrored your old public data, and people-search aggregators that re-list your details every time you remove them. That's where continuous external monitoring becomes essential.
How Warden extends your Strava privacy
Warden by GalaxyWarden scans Strava data that leaks into people-search sites and OSINT aggregators. Strava-derived home-address discovery has been documented in multiple executive doxxing campaigns.
Run a free Warden scan to see exactly what is exposed about you across every platform — not just Strava.
