From https://www.reddit.com/user/d112358
I won't get past your "login to strava" if you don't have something explaining that it's an oauth connection, and that you aren't harvesting my strava credentials. Unfortunately, you have to be very clear to people about what your doing and what information you may or may not be keeping. To be clear, I'm not accusing you of running an "evil website", but it's one thing for me to give an auth permission to a company I have a relationship with (like my bank). It's another to give it to a a random website.