What the Strava heatmap actually is

Strava's Global Heatmap is a single map built from billions of activities uploaded by Strava users. The more often people run or ride over a path, the brighter it glows. It's aggregated and stripped of names, so you can't click a glowing line and instantly see who made it.

That sounds anonymous, and at the level of one runner it mostly is. The privacy problems come from two places: what the aggregate quietly reveals, and the separate issue of individual profiles and activities that are public by default or by accident.

What the heatmap has exposed

This isn't hypothetical. The heatmap and Strava's public activity data have caused real, documented security incidents.

2018 - secret military bases

Analyst Nathan Ruser noticed paths glowing in otherwise empty desert in Syria, Iraq, and Afghanistan. They traced the perimeters, patrol routes, and supply runs of military personnel who were wearing fitness trackers. The heatmap had effectively mapped secret bases and the daily movement patterns inside them. Strava responded by restricting data visibility and simplifying the heatmap opt-out. (Engadget)

2024 - the security details of world leaders

A Le Monde investigation found that bodyguards for several heads of state were regular Strava users, and their public activities gave away sensitive movements. Journalists identified members of the US Secret Service, the French presidential security group, and Russia's Federal Protection Service, then used their runs to place leaders at specific locations - including a private weekend trip by the French president. Security expert Bruce Schneier wrote up the findings. (Schneier on Security)

2025 - a prime minister's home address

Later reporting found that bodyguards for the Swedish prime minister had leaked sensitive locations, including a private residence, through the start and end points of routes shared on Strava. (road.cc)

The pattern: in every case the leak came from where activities start and end, and from routes being public - not from someone's name on the map. A heatmap of repeated routes is a map of habits, and habits are exactly what a security team wants to hide.

The real problem is defaults, not the map alone

It's worth being fair to Strava here. Its privacy controls are actually quite good and easy to find. In every incident above, the issue was that the people involved hadn't used them. Activities were public, start points sat on a front door, and the heatmap simply reflected real behaviour.

That's the catch with any social, cloud-based fitness platform. Your data is uploaded, it's public or aggregated by default unless you intervene, and a single forgotten setting can reveal where you live or train. The safest data is the data that never leaves your phone in the first place.

How to lock down your Strava privacy

If you use Strava, take five minutes and work through this list. These settings genuinely work - they're just not switched on for you.

  • Set default activity visibility to Followers or Only You, under Settings, Privacy Controls, Activities.
  • Opt out of the aggregated heatmap under Privacy Controls, Aggregated Data Usage. Turning this off removes your activities from the global heatmap.
  • Add privacy zones (hidden areas) around your home and workplace so the start and end of routes are obscured.
  • Hide your start and end points by default, so a single public activity can't pin your front door.
  • Review Flyby and your public profile so other users can't trace routes back to you.

One caveat: setting names move around as Strava updates its apps, so the exact labels may differ slightly from what you see today.

A heatmap that never leaves your phone

If what you actually want is to see your own routes glowing on a map - your personal heatmap, your training patterns, your coverage - you don't need to upload anything to anyone.

MoveMap builds your heatmap and your lifetime map on your iPhone, from the workouts already in Apple Health. There's no account, no server, and no global map your runs feed into. Nothing is uploaded, so there's nothing to leak, accidentally make public, or forget to lock down. See how MoveMap compares to the Strava heatmap.

One honest detail, because privacy claims should be precise: MoveMap's street-coverage feature fetches the public street map for your city from OpenStreetMap, which means sending a bounding box for that area - never your routes or coordinates. Your workouts themselves never leave the device. The full privacy policy spells this out.

MoveMap
Your heatmap, on your phone.
MoveMap reads Apple Health locally. No account, no upload, no global map.
Download Free

Frequently asked questions

Does opting out of the heatmap make my Strava private?

It removes your activities from the aggregated global heatmap, but your individual activities can still be public. Set your default activity visibility and add privacy zones separately - those are the settings that protect your home address.

Is the heatmap really a risk for an ordinary runner?

For most people the bigger risk isn't the aggregate heatmap but public activities that start and end at a home address. Fix that first with privacy zones and activity visibility set to Followers or Only You.

Can I see a heatmap without Strava at all?

Yes. MoveMap generates a personal heatmap on your iPhone from Apple Health, with no account and no upload. Here's how to see your running heatmap for free.

Does MoveMap contribute to any heatmap?

No. There's no global map and no server. Your routes are read from Apple Health and stay on your device.