Privacy

What we keep, and what we do not.

Last updated 19 September 2026

Indore is an indoor cycling companion app operated by Super8 DOO, doing business as Superawesome (sprawsm.com). This policy explains what data we collect, why, and how it’s handled.

For the data described here, Super8 DOO is the controller: the one who decides what is collected and answers for it. Super8 DOO, PIB 111928048, registration number 21573078, Miroslava Mike Antića 135, 21299 Rakovac, Serbia. Anything about your data goes to hi@indoreride.com.

Account data

When you sign in with Google or Apple, we receive and store your email address and an account identifier from whichever one you used. That’s it — no name, no profile photo, no phone number.

If you sign in with Apple and choose to hide your email, we get Apple’s relay address instead of yours, and that is the one we keep.

Neither Google nor Apple leaves us holding a key to your account. We ask who you are and your email address, once, at the moment you sign in. What comes back is spent there and then — there’s nothing left over for us to keep, and nothing we could use to go and look at anything else of yours.

Strava is the exception, and only if you connect it. That one does give us a token we store, because the work happens when you’re not there: uploading a finished ride, fetching a route you asked for. Revoke it any time in your Strava settings.

Ride data

When you complete a ride, we store a summary of it: duration, average and max power, heart rate, cadence, and a couple of derived metrics. We also store the full ride recording as a FIT file — this contains second-by-second power, heart rate, cadence, and speed data.

Ride recordings are stored on Cloudflare’s infrastructure (R2 object storage). They’re tied to your account and are not shared with other users.

While you’re riding, the phone also passes the live numbers through our servers — power, cadence, heart rate, and your position along the route if you’re riding one. That’s how the desktop app keeps showing them when it isn’t on the same network as your phone; when it is, the phone still sends a slower copy up, in case the local link drops. Either way that copy is held for five minutes and then it’s gone. What gets kept is the ride itself, once you finish.

Routes

Import a route — from Strava, or a GPX file off your own computer — and we store the shape of it: latitude and longitude, point after point, roughly one every ten metres, at the precision the file arrived with. Elevation with it. That’s what makes the gradient change under you while you ride it. It sits against your account for as long as you keep the route. Delete the route in the app and the coordinates go with it.

So it’s worth saying plainly: those are the coordinates of real roads, and if the route starts at your front door, the file we’re holding starts at your front door. We don’t go looking for where you live, we don’t work it out, and nothing in Indore asks your phone where you are while you ride. But a route is something you hand us, and you should know what’s in it before you do. If that sits badly, import one that starts a few streets from the house.

Some routes cross climbs we’ve marked out. Ride over one and your time on it is recorded against the ride. Nothing in the app shows you that yet; for now it’s written down and that’s all it does.

Profile data

You may optionally provide your FTP (Functional Threshold Power) and body weight. These are used to calculate power zones and display watts-per-kilogram. You can update or remove them at any time in Settings.

If you set a display name, riders you add as friends and people in a group ride with you see it. Without one, they see the part of your email address before the @.

Notifications and weather

If you allow notifications on the iPhone, we store the token Apple gives us for sending them to that phone. That’s all it is: an address for notifications. Switch them off in the app or in iPhone Settings and they stop.

Nudges can mention the weather. The one moment Indore asks your phone where you are is when you switch Nudges on — not at launch, not during a ride, not on a schedule. It asks for a deliberately blunt fix, rounds it to about 11 km before it leaves the phone, and sends only the rounded version. We use it to look up the forecast where you are, and for nothing else. Say no to the location prompt and nudges still arrive, just without the weather.

The rain check list

Leave your email in the rain check form at the foot of these pages and we keep three things: the address, when you left it, and which page you left it on. No account is made. We use it to send news and stories from Indore now and then, and for nothing else. It isn’t sold, and it isn’t shared with anyone but Resend, who sends the emails and, once you confirm, keeps the list for us.

Nothing arrives until you say so. The first email asks you to confirm; ignore it and that’s the only one. Every email after that carries a link that takes you off the list, and one click does it. If you’d rather the address were gone altogether, ask at hi@indoreride.com and we delete it.

Payments

The monthly plan, the season pass and ride credits are sold through a checkout run by Paddle. We never see your card number. Paddle collects it, holds it, and takes the payment.

Paddle is our Merchant of Record. The Paddle entity named on your receipt is the seller, not Indore. Paddle handles sales tax and VAT wherever you are, and issues the receipt.

What Paddle passes back to us: your email address, your country, what you bought, when you bought it, how much you paid, and whether a subscription is active — enough to match a payment to a support request, and no more. Nothing about the card. Not the number, not the brand, not the last four digits: those stay with Paddle.

What we store against your account: a record of what you bought and when, your credit balance and the history behind it, and whether your subscription is active. That is what makes the balance and the plan work.

The checkout is Paddle’s own, so whatever it stores in your browser during a purchase is covered by Paddle’s privacy policy rather than this one. For the payment data Paddle collects, Paddle acts as an independent controller under data-protection law, and its own policy governs how that data is handled.

AI processing

Indore uses AI to power a few features. All of them run on Google’s Gemini API, and none of the data we send is ever used to train AI models.

  • Ride summaries — After a ride, your ride metrics (power, heart rate, cadence, duration) are sent to generate a short description. The raw FIT file is not sent — only aggregate numbers.
  • Session generation — When you create a session from a text description, that text along with your FTP and zone definitions are sent to generate the interval structure.
  • Daily picks — Indore builds a few suggested sessions each day using the same interval-building service.
  • Ride suggestions — When you ask Indore to fit a ride to how you’re feeling, we send derived numbers about your recent riding (ride counts, durations, and intensity summaries) along with your own check-in answers. We never send activity names, GPS or location data, or anything that identifies you. If you’ve connected Strava, those activities are reduced to plain numbers on our own servers first — the raw Strava activities are never sent to any AI provider, and are never stored.
  • Voice commands — Voice input is transcribed on your device using Apple’s speech recognition. Only the resulting text transcript is sent to our server for parsing — audio never leaves your phone.

Strava

If you connect Strava, Indore uploads your completed ride as a FIT file with a title and description. If you import one of your Strava routes to ride indoors, Indore fetches that route — and only that route — when you ask it to.

If you also grant read access, Indore reads summaries of your recent activities — dates, durations, distance, and power numbers — solely to fit ride suggestions to your recent riding. It never reads or stores GPS tracks, maps, or activity names from your ride history, and how those numbers are handled is described under AI processing above. Indore asks Strava for all of it in one request — uploads, routes and read — so Strava’s own consent screen is where you turn the read part down. Decline it and uploads work as before.

Trainer telemetry

Ride with a smart trainer and the app sends us a short report on the trainer when the ride is over. What’s in it: the Bluetooth name the trainer advertises, split into a make and a model; how long it took to reach each power target Indore set; one number for how much its power readings wobbled around a steady effort; how many times it dropped the connection; and how long it stayed connected. The ride’s own record isn’t in there — no power trace, no heart rate, nothing about how it went for you.

It’s linked to your account, so that when a particular trainer misbehaves we can go back to the person it happened to. Beyond that we read it in aggregate: which trainers are slow to respond in ERG, which ones drop out.

It isn’t optional. Every ride on a trainer sends one, and there’s no switch to turn it off.

Diagnostics

Indore has a flight recorder: a running log of what the app, the Bluetooth connections and the ride clock were doing, with your paired devices named the way they name themselves. It’s off. Once per ride the app asks whether it’s been switched on for your account, and if it hasn’t — which is the normal case — nothing leaves the phone.

We switch it on for a single account at a time, when we’re chasing a fault that happens to one person and nobody else. Today that’s the account the app was built on. When it is on, the log lands on our servers during the ride, sits against your account for seven days, and then expires by itself.

What we don’t collect

  • Where you are while you ride — nothing in Indore asks the phone for your position during a ride. The coordinates we hold are the routes you imported (see Routes) and the rounded fix for the weather (see Notifications and weather)
  • Advertising identifiers — no IDFA, no IDFV, nothing that could follow you from one app to the next
  • Browsing history
  • Card numbers — Paddle takes the payment, so we never see them
  • Contacts or calendar data
  • Your real name — we never ask for it. If it’s in your email address, or you typed it in as your display name, that’s the only way we have it

Why we’re allowed to use it

Data-protection law wants a reason for each use. Ours:

  • Because you asked us to run the service (our contract with you) — your account, your rides and their recordings, your credit balance and plan, syncing to your other devices, and the features you use, AI summaries and sessions included
  • Because we have a legitimate interest — keeping the service secure, stopping fraud and abuse of credits and payments, finding and fixing bugs, and making trainers work better through telemetry. The interest is keeping Indore working, safe and fair for the people riding on it. You can object to any of it (see Your rights)
  • Because you said yes (consent) — connecting Strava and giving it read access, notifications, the rounded location for the weather, and the rain check list. Take it back any time by disconnecting Strava or switching those off; that doesn’t undo what was done before
  • Because the law says so (legal obligation) — answering a lawful request from an authority, if one ever comes

Where data is stored

All data is stored on Cloudflare’s infrastructure — Workers for the API, D1 for the database, R2 for file storage, and KV for sessions. Cloudflare operates data centers globally. For more on their practices, see Cloudflare’s privacy policy.

Payment data is the exception: it sits with Paddle, not on our infrastructure. Paddle operates internationally.

We’re in Serbia, and most of the services under Third parties are not. Many are in the United States. So your data is processed outside Serbia and the EEA. Where it goes, it goes under the providers’ standard contractual clauses, or to countries recognised as protecting it adequately.

Everything travels encrypted between the apps, the website and our servers. Access to it is limited to what’s needed to run the service and fix it.

Data retention

Your account and ride data are kept for as long as you have an account. Delete the account — on the account page or in the app — and they go with it there and then: the rides and their recordings, the sessions and routes you made, your credits, your plan. Rides other people rode alongside you stay with them. If you would rather we did it, email hi@indoreride.com.

Paddle sold you the plan, the pass or the pack, so the tax and accounting records of that sale are Paddle’s, kept under Paddle’s own policy. Our books record what Paddle pays us, not who bought what. What we keep is a note of what you bought and what it added to your account, because that’s how your credits and plan work. It goes when the account goes.

Cookies and local storage

This website sets no cookies of its own and runs no analytics or advertising scripts. Nothing here follows you around the internet.

When you sign in on the website, your sign-in is kept in your browser’s local storage so you stay signed in. Signing out removes it. The sign-in page loads Apple’s sign-in, and the account page loads Paddle’s checkout. Those come with their own cookies and their own policies.

Third parties

We share data with the following services:

  • Google — sign-in, and the Gemini API for all AI features (ride summaries, session generation, daily picks, ride suggestions, and voice parsing)
  • Apple — sign-in, and delivering notifications to iPhones
  • Strava — ride uploads, route imports and, if you allow it, reading recent activities for ride suggestions (only if you connect your account)
  • Cloudflare — infrastructure and hosting
  • Paddle — payments, tax and receipts
  • Resend — sends the occasional email from us, and keeps the rain check list; it gets your email address and the message
  • Open-Meteo — the forecast for weather nudges; it gets the rounded location and nothing that identifies you
  • OpenStreetMap (Overpass) — town names for the map when you import a route; it gets the area the route covers and nothing about you

We do not sell your data. We do not run ads. We do not share your information with anyone else.

Your rights

You can ask us to show you the data we hold on you, correct it, delete it, or limit what we do with it. You can ask for a copy in a form you can take elsewhere, object to what we do on legitimate interest, and withdraw consent you’ve given.

Email hi@indoreride.com from the address on your account. We answer within one month.

If you think we’ve got it wrong, you can complain to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection (the Poverenik, poverenik.rs), or, if you live in the EU or the UK, to your own data protection authority.

Changes

If this policy changes in a meaningful way, we’ll note it here with an updated date. We won’t notify you by email for every minor wording tweak, but anything that affects what data we collect or how we use it will be clearly communicated.

Contact

Questions about your data? Email hi@indoreride.com.

Take a rain check.

Subscribe to news and stories from Indore.

We’ll email you a link to confirm. After that you can unsubscribe at any time.