Strava Restricts Data Access to Thwart AI Scrapers

Strava is implementing a series of stringent security measures to block automated data harvesting by artificial intelligence companies. The fitness platform is restricting website access and introducing new developer fees, marking a significant shift in how the company manages its vast repository of user and activity data.
CEO Michael Martin warned that the unchecked practice of AI entities scraping public websites threatens the stability of the internet. According to the company, aggressive extraction attempts have frequently degraded site performance, forcing Strava to prioritize platform integrity over open access.
Tightening Security and API Access
Under the new policy, Strava is moving away from its previous model where public profiles and club listings were visible to anyone without a login. Going forward, the company will require authentication for users to view these details, effectively placing a wall between its data and unauthorized scrapers.
The company is also restructuring its developer ecosystem. While it previously offered a tiered, free access program for building apps, it is transitioning to a flat fee structure:
- New Pricing: A flat fee of $11.99 per month for developers, with potential regional variations.
- Grace Period: Developers have a 90-day window to adjust before the changes take full effect.
- API Retirement: Several specific API endpoints will be decommissioned to prevent the unauthorized pull of granular data, such as club details.
The AI Data Battle
Martin revealed that Strava has proactively rejected data licensing requests from prominent AI labs. He specifically identified the AI search startup Perplexity, alleging that the company attempted to bypass blocks by routing traffic through aggregator services to disguise the origin of its scraping bots.
Beyond malicious scraping, Strava is struggling with server strain caused by inefficient, “vibe-coded” applications that generate excessive and poorly structured API calls. By moving toward the Model Context Protocol (MCP), Strava aims to regain control over how external apps and AI assistants interact with its data in a structured, permissible environment.
Strategy Ahead of IPO
These defensive moves come as Strava prepares for a public offering, having confidentially filed for an IPO earlier this year. The crackdown on data usage serves as a signal to potential investors that the company maintains strict discipline over its most valuable asset.
While the developer community has expanded to 241,000 members this year, the company maintains that these changes are necessary to protect user privacy. Unlike other platforms that utilize usage-based billing, Martin emphasized that the flat fee model is designed to sustain the developer ecosystem rather than dismantle it, provided those developers adhere to the new, stricter API agreement.