Privacy
Your ride is yours first.
Cycled records locally, makes account sync optional, and publishes a ride, route, club action, or live location only after a deliberate rider action.
Last updated August 2, 2026
The short version
Cycled does not sell personal data, run advertising, or track you across other companies’ apps and websites. Core ride recording works without a Cycled account. Signing in adds cloud sync and community features.
What this policy covers
This policy covers the Cycled iPhone and Apple Watch apps, Cycled rider web, public Cycled share pages, and the related Cycled cloud service. A connected third party such as Apple, Strava, Clerk, RevenueCat, Expo, Convex, or Vercel also applies its own policy to the part of the service it operates.
Data Cycled may collect
“Collect” here means data sent off your device so Cycled or a service provider can retain or access it. The exact categories depend on what you use.
Account and profile
Your sign-in identifier, email address, chosen rider name or username, profile image if you add one, role, and rider settings. Clerk processes private authentication details; Cycled uses a stable account ID for cloud sync.
Ride, fitness, and training
Ride summaries and samples such as time, distance, speed, power, cadence, heart rate, elevation, laps, pauses, training load, workout completion, recovery check-ins, private goal and challenge choices, and rider-entered training facts such as FTP, age, height, and weight.
Precise location
Outdoor GPS points used to record a ride, draw its route, provide route guidance, and support an exact-location live safety link when you explicitly start one. If you separately enable ride-time weather, Cycled derives a ride-midpoint coordinate rounded to roughly one kilometre for that lookup.
Content and community activity
Ride notes, posts, captions, routes, sectors, club memberships, events, RSVPs, announcements, waiver acceptances, reactions, follows, blocks, reports, and the bounded in-app activity notifications those actions create.
Connected equipment and services
Private bike or trainer records, optional rider-entered weight, drivetrain, and starting odometer, explicit ride assignments, remembered sensor details, connection status, Strava connection and upload status, Apple Health export status, and other integration state needed to deliver the feature you requested.
Purchases
If Club Pro becomes available, Cycled receives product, entitlement, store, renewal, and expiration status from Apple and RevenueCat. Cycled never receives your payment-card number.
Operations and diagnostics
App version, build, sync and upload status, bounded account actions, security events, service request metadata, and—during a compatible ride—iPhone thermal state, battery level, and Low Power Mode for private failure diagnosis. Anonymous performance monitoring is off unless a release says otherwise inside Account › Your data.
Data that stays on your devices
Cycled keeps a local ride database, dense sensor samples, saved routes and workouts, training plans, remembered sensors, app settings, and a bounded diagnostic log on your iPhone. Authentication and integration credentials use protected device storage where available.
With your permission, Cycled can read Apple Health recovery, sleep, workout, weight, body-composition, and recorded nutrition context on the iPhone and can write a completed cycling workout to Apple Health. Coaching-context categories are requested separately, and missing or declined Health data is never treated as zero. Data read from HealthKit is used on device and is not uploaded to the Cycled cloud or an AI service. A completed ride that originated in Cycled may separately sync from Cycled’s own local ride record when you are signed in.
You can export or erase local Cycled data from Account › Your data. Workouts already saved to Apple Health remain under your control in Apple Health.
How Cycled uses data
- Record, recover, display, analyze, and sync rides and workouts.
- Attach a bike or trainer to a private ride and total only its assigned recorded distance plus any starting odometer you enter.
- Personalize training guidance from the facts and history you provide.
- Connect sensors, control a compatible trainer, prepare Apple Watch workouts, and export authorized workouts.
- Provide routes, segments, clubs, events, community safety tools, and rider-requested sharing.
- Authenticate accounts, prevent abuse, answer support requests, secure the service, and diagnose failures.
- Verify Club Pro access and process store events if purchases are enabled.
Historical activity-file imports
When you choose one or several FIT or TCX files—including a GZIP-wrapped activity or a ZIP export containing them—in Rider web, Cycled parses the bounded selection in your browser and queues its cycling activities for individual review. ZIP paths, GZIP-embedded names, filenames, notes, creator and device identity, and the original archive, wrapper, binary, or XML file are not uploaded. Cycled shows you each cycling activity first and sends only its normalized samples and ride facts after you separately confirm that private import. You may enter FTP, max heart rate, or weight that was true on each ride date; Cycled does not substitute your current values into historical analysis. Exact retries are duplicate-safe within your account.
Cycled does not use health, fitness, or precise-location data for advertising, and does not provide it to data brokers.
Sharing you control
Community and public pages
Community content is private unless you select a club or public audience. Public routes, segments, clubs, events, and completed-ride recaps contain bounded display data rather than private source records. Completed-ride maps hide the configured start and finish privacy zones by default.
The signed-in Rider-web activity inbox stores bounded references to follows, reactions, and comments so you can find activity on your posts. It does not copy comment text, GPS, sensor samples, or private ride records. Undoing an action, blocking a rider, or removing its source removes the related inbox item.
Live safety links
Starting a live safety share is an explicit action. Anyone with the unlisted link can see your current exact location, including inside your normal map privacy zone. A live link expires after four hours and can be revoked sooner.
Strava
If you connect Strava, Cycled requests only activity-upload access. After a complete private Cycled ride has synced, Cycled sends it only when you choose Upload to Strava or when it is covered by an auto-upload setting you explicitly enable. Historical FIT and TCX imports never trigger that automatic upload; you can still choose a manual upload after checking that the activity is not already in Strava. The upload can contain the ride title, date and time, recorded GPS route, elevation, distance, speed, power, cadence, and heart rate. Cycled does not import your Strava activity history or use Strava data for coaching, analytics, or any AI feature.
Strava authorization tokens are encrypted on the server. You can withdraw consent at any time by disconnecting Strava in Settings. Disconnecting revokes authorization when Strava is reachable and removes Cycled’s tokens, Strava athlete identifier, and Strava-returned upload records; Cycled also handles a revocation initiated from Strava. The confirmation appears in Settings. Activities already sent to Strava remain in your Strava account and can be managed there.
Ride-time weather
Ride-time weather is off by default. If you enable it in Settings, Cycled may send the ride time and a ride-midpoint coordinate rounded to roughly one kilometre to the U.S. National Weather Service for compatible outdoor rides in the United States. Cycled stores the nearest available station observation together with its source, observation time, and station distance. It remains private, is excluded from public ride recaps and Strava uploads, and is not sent to an AI service.
You can withdraw this permission in Settings. Turning it off stops future lookups immediately and starts removing stored weather observations from your Cycled ride records in bounded background steps. Your underlying ride and GPS record remain until you delete them separately.
Service providers
Cycled uses providers only to operate requested features: Clerk for authentication; Convex for cloud data and server functions; Vercel for the web service; Apple for distribution, StoreKit, Sign in with Apple, HealthKit, and platform services; RevenueCat for subscription status if Club Pro is enabled; OpenAI for the separately consented owner-only coaching comparison described below; Strava when you connect it; the U.S. National Weather Service when you enable ride-time weather; and Expo for app updates and, only when clearly enabled in a release, privacy-bounded performance monitoring.
Providers receive only the data needed for their role and must protect it under their agreements and applicable law. Cycled does not permit providers to use ride, health, or location data for their own advertising. Strava may monitor and collect usage data about Cycled’s access to the Strava API under its API terms.
AI coaching pilot
An owner-only AI coaching comparison is available to exactly one approved tester. After separate consent, Cycled sends the same minimized context to OpenAI’s GPT-5.6 Luna at High reasoning and GPT-5.6 Terra at Medium reasoning concurrently so the tester can compare their recommendations and measured latency. The server and iPhone validate each answer independently, withhold an answer that fails the coaching contract, and never let either model edit the training calendar automatically. No other rider account is eligible.
The minimized boundary includes ride-calculation facts such as FTP and training zones, up to 42 days of summarized training and load, planned workouts, and numeric recovery check-ins. It excludes name, email, username, authentication identifiers, GPS, routes and locations, raw sensor samples, device identifiers, all free-text notes, Apple Health data and source names, weather, Strava, and other external-integration data.
Cycled requests OpenAI responses with storage disabled and does not save model answers in its database; a comparison remains only in the current app session. OpenAI states that API inputs and outputs are not used to train its models unless the customer opts in. Under OpenAI’s default abuse-monitoring controls, request and response content may nevertheless be retained in logs for up to 30 days. Settings links to the current provider source and identifies the exact models and disclosure before consent.
A material configuration change invalidates the older permission. Consent can be revoked at any time, and the server enforces an owner allowlist plus per-rider and service-wide call and cost limits before sending a request. This self-testing authorization is not independent qualified cycling-coach review; that review remains required before Cycled can offer AI coaching to additional riders. Coaching is advisory and is not medical diagnosis, treatment, or a substitute for qualified professional judgment.
Retention and deletion
Local data remains until you erase it, delete the app, or use a feature that removes it. Cloud account data remains while the account is active or until you delete the applicable item. Revoked or expired shares stop being available through their public links.
Account export includes AI coaching consent history and personal quota-usage records. Account deletion starts immediately from Account › Your data and removes active Cycled account records, coaching consent and personal usage records, synced ride data, shared content, connected-service credentials, and the sign-in identity in resumable steps. To prevent a delayed device from recreating the deleted account, Cycled retains a one-way, purpose-specific hash of the former sign-in identity for 30 days, then automatically purges it. Limited transaction, legal-compliance records, and provider backups may remain for the period required to operate securely or comply with law, then expire under the applicable retention schedule. Deleting Cycled does not delete data already sent to Apple Health or Strava and does not cancel an Apple subscription.
If anonymous Expo performance monitoring is enabled in a future release, Account › Your data will say so. That feed excludes account identity, routes, rides, workouts, GPS, sensors, names, and profile facts; Expo retains it for at least 60 days.
Your choices
- Ride without signing in and keep the core record local.
- Grant or deny Bluetooth, location, notification, and individual Apple Health categories in system settings.
- Change community visibility and map privacy-zone defaults.
- Create, replace, revoke, or allow an unlisted share to expire.
- Connect or disconnect Strava and turn automatic uploads off.
- Enable or disable private ride-time weather enrichment and remove stored observations.
- Review an exact AI coaching configuration before consenting and revoke that consent at any time.
- Export Cycled data, erase local data, or delete the account inside the app.
Security, children, and changes
Cycled uses access controls, purpose-specific share tokens, protected credential storage, encryption in transit, and bounded public snapshots. No system can guarantee absolute security, so do not publish information you do not want others to see.
Cycled is not directed to children under 13. If Cycled learns that a child supplied personal data without any consent required by law, Cycled will delete it.
Material policy changes will be dated here and, when appropriate, explained in the app before the new use begins.
Contact
Cycled is currently a private TestFlight beta. Open TestFlight, choose Cycled, then choose Send Beta Feedback to reach the developer about privacy or data requests. A direct support address will be published here before public App Store release.