Strava’s CEO just did something almost nobody in Silicon Valley has the nerve to do: he named the company scraping his platform, explained exactly how they tried to hide it, and then locked the front door on every AI lab in the industry. The timing — weeks before Strava’s IPO — is not a coincidence. It’s a calculated signal to Wall Street that this company treats its 130 million users’ fitness data like an asset worth protecting, not a commodity to be siphoned.

The target? Perplexity, the AI search startup that Strava CEO Michael Martin says routed its scraping through aggregator services to disguise its identity after being explicitly turned away. This isn’t a new accusation — Perplexity has been caught doing the same thing to other sites — but hearing a CEO preparing for a public listing single out a well-funded AI company by name in a TechCrunch interview is a different level of escalation entirely.

The Public Internet Has a Scraping Problem — and Strava Just Quantified It

Here’s what most people miss about the AI scraping wars: it’s not just about training data anymore. Martin told TechCrunch that AI scraping has caused actual performance degradation on Strava’s servers — multiple incidents in recent months where the site slowed down or went partially offline because bots were hammering public-facing pages. That’s not a philosophical data rights debate. That’s a denial-of-service attack wearing a hoodie.

Strava’s response is comprehensive. Previously, anyone could see public profiles and fitness club listings without an account. All of that now goes behind authentication. If you’re not logged in, you see nothing. It’s the digital equivalent of pulling the blinds shut because someone parked a surveillance van outside your house.

The company also flagged a secondary headache: poorly built “vibe-coded” apps whose API calls are so inefficiently structured that they generate outsized server load. When your developer ecosystem grows from 185,000 to 241,000 members in a year and half of the newcomers are building with ChatGPT-generated code that makes redundant API calls, the infrastructure costs add up fast.

The $11.99 Fee Is Smarter Than Reddit’s Approach — But Developers Won’t See It That Way

The inevitable comparison is to Reddit’s 2024 API crackdown, which priced access by the number of calls and effectively killed every beloved third-party Reddit client overnight. Strava clearly studied that playbook and decided to take a different path: a flat $11.99 per month for all developers, regardless of usage volume.

On paper, this is far more developer-friendly. A flat fee doesn’t punish high-volume apps the way per-call pricing does. But there’s a catch. Strava is also sunsetting specific API endpoints — the ones that let outside apps pull club details and certain user data. For apps built entirely around those endpoints, no subscription fee in the world fixes the fact that your data source is being turned off.

Strava is giving developers a 90-day grace period, which is more generous than Reddit’s timeline. But the direction is clear: the era of free, open API access to consumer data platforms is over. Every company with user data valuable enough for AI training is now running the same calculation — lock it down, charge for it, or watch it get scraped into someone else’s model.

The MCP Play Is the Smartest Part Nobody’s Talking About

Buried in Strava’s announcement is a detail that matters more than the fee structure: the company plans to add support for Model Context Protocol (MCP), the emerging standard (originally developed by Anthropic) that lets AI assistants access external data in a structured, permission-based way.

This is the opposite of scraping. Instead of bots blindly crawling public pages and grabbing whatever they find, MCP gives Strava granular control over exactly what data gets shared, with whom, and under what conditions. It’s the difference between leaving your front door unlocked and installing a smart lock that logs every visitor.

If Strava executes this well, it becomes a template for how consumer platforms can participate in the AI economy without surrendering their data assets. You don’t block AI entirely — you create a controlled pipeline that lets AI apps integrate with your data on your terms. The companies that figure this out first will have a meaningful competitive advantage in the IPO market, because investors increasingly want to see data governance as a core competency, not an afterthought.

Follow the Money: This Is IPO Prep Disguised as Privacy Policy

Strava confidentially filed for an IPO earlier this year with Goldman Sachs leading the offering. The company’s valuation is estimated around $3 billion, built on a subscription model that converted 130 million registered users into a meaningful (though undisclosed) number of paying subscribers.

Publicly cracking down on scrapers before going public accomplishes three things simultaneously. First, it tells institutional investors that Strava’s user data — arguably its most valuable asset — is being actively protected. Second, the developer fee creates a new revenue line, however small, that shows the company can monetize its API ecosystem. Third, calling out Perplexity by name generates press coverage (like this article) that reinforces the narrative of a company that doesn’t roll over for Big AI.

Martin is acutely aware of the optics. “We want the users to feel that they own their data and feel comfortable with how we are controlling and securing it,” he told TechCrunch. “But we want the developers to continue to flourish and grow.” It’s a line designed to reassure both sides of the marketplace — and prospective shareholders.

The Verdict: Strava Is Building the Playbook Every Data Company Will Copy

The broader pattern here is unmistakable. Reddit locked its API. Twitter charged $42,000 a month for enterprise access. LinkedIn sued AI scrapers in federal court. Mastodon updated its terms to explicitly ban AI training. Now Strava joins the list — but with a more nuanced approach that combines authentication gates, flat-fee developer access, endpoint retirement, and MCP integration into a single, coherent strategy.

The lesson for every company with a consumer data platform: if you haven’t already locked down your public-facing data, you’re already being scraped. The AI labs aren’t going to politely ask permission. Perplexity proved that when it routed around Strava’s explicit refusal. The only defense is architecture — putting data behind authentication, charging for structured access, and building the technical infrastructure to control exactly who sees what.

Martin called unchecked AI scraping “the death knell of the public internet.” He’s not wrong. The open web as we’ve known it for 30 years is being consumed, token by token, by companies that never asked and never paid. Strava’s move won’t reverse that trend. But it might just be the template that keeps the next generation of web companies from being eaten alive.