Superride Privacy Policy
Effective date: 4 October 2026
Superride is a route weather app for cyclists. We built it to need as little of your data as possible: there is no account, no advertising and no tracking, and your routes stay on your iPhone. This policy explains exactly what does leave your device, why, and for how long anything is kept.
The short version
- No account. You don't give us your name, email address or phone number to use Superride.
- Your routes stay on your iPhone. Route files, forecasts, settings and cached data are stored on your device only. We can't see them — unless you choose to share a ride as a link (section 3.11).
- Weather requests don't contain your route. To get a forecast, the app sends our server only the centres of the weather-model grid cells your route passes through. Our server fetches the weather from Open-Meteo (or Apple WeatherKit as a backup) and does not record who asked.
- No advertising, no analytics SDKs, no tracking. Our server keeps only anonymous daily totals (for example, how many forecasts were served) with no identifiers. The only third-party code in the app is Adapty, which shows the introduction screens and will handle in-app purchases, under a random, anonymous ID (see section 3.10).
- Strava and Ride with GPS are optional. If you connect them, your sign-in tokens stay in your iPhone's Keychain. Strava data is kept on your device for at most 7 days, is shown to nobody but you, and is never used to train or prompt any AI.
- We don't sell or share your personal information.
- You can delete everything at any time: Settings → About & legal → Delete all my data.
1. Who we are
Superride is provided by Aleksey Goncharov, an individual developer based in the United Kingdom ("we", "us", "our"). We are the controller of the personal data described in this policy.
- Contact for privacy questions and requests: 1061040@gmail.com
This policy covers the Superride iOS app and the Superride server (a Cloudflare Worker that the app uses for weather and for Strava and Ride with GPS sign-in). It does not cover Strava, Ride with GPS, Apple or any other service you reach through the app; they have their own privacy policies.
2. What stays on your iPhone
The following is stored only on your device. It is never sent to us, and we have no way to access it:
- Your route library: route files you import (GPX, TCX, FIT) and the built-in demo route.
- Recent forecasts: the last forecast of up to 20 recently opened routes, so they can be shown offline.
- Route thumbnails and the names of stops along your routes (for example, the café where you stop).
- Your settings: units, rider and bike mass, riding position, your usual speed on the flat, climbing effort, comfort temperature, how warm you usually feel, food and drink preferences — including the answers you give in the introduction screens, which are applied on your iPhone and not sent anywhere.
- Ride feedback: the last ride you looked at and your answer to "How was your kit?", used to fine-tune clothing advice.
- Recently opened routes, so the Home screen can suggest them.
- Strava and Ride with GPS data, if you connect them (see section 4).
- Sign-in tokens for Strava and Ride with GPS, in the iOS Keychain (see section 4).
Superride does not use Location Services: it never asks for or reads your iPhone's location. It does not use the advertising identifier (IDFA), never shows the App Tracking Transparency prompt, and does not access your contacts, photos or health data.
Your route library and settings are included in your iPhone backups (iCloud or computer) according to your own backup settings. Caches (forecasts, thumbnails, stop names, Strava and Ride with GPS data) are not backed up, and your sign-in tokens are stored "this device only", so they are not included in backups either.
3. What leaves your iPhone, and why
3.1 Weather forecasts
To forecast the weather along a route, the app splits the route into the grid cells of a weather model (for example, 2 km squares for the Met Office UK model, or about 9 km for the global ECMWF model) and asks our server for the forecast at the centre of each cell. The request contains those cell centres, the model name, the weather variables and the number of days. It does not contain your route, your start time, your name, any account or device identifier, or any Strava or Ride with GPS data.
Our server passes the request on to Open-Meteo, our main weather provider, or to Apple WeatherKit as a backup when Open-Meteo is unavailable or its daily limit is reached. Those requests come from Cloudflare's network, not from your device, so Open-Meteo and Apple do not receive your IP address.
To stay within Open-Meteo's usage limits, our server keeps each weather answer in a shared cache keyed by grid cell, until the weather model's next run (at most 12 hours). The cache contains weather data per grid cell, is shared by all users and is not linked to anyone. We do not log or store which cells any person requested.
A set of grid cells can reveal the general area of a route. We treat it with care for that reason: it is used only to answer your request, and it is never stored against you or combined with anything else.
The app also asks our server for information about weather models (such as when a model last ran). Those requests contain no location.
3.2 Map and stop names (Apple)
The map is Apple Maps (MapKit). Your iPhone loads map tiles for the area on screen directly from Apple.
When the app finds a stop on a recorded ride (for example, a café stop), it asks Apple MapKit for the name of the closest café, shop or park, using only the coordinate of that stop. Nothing else is sent with it, and no Strava or Ride with GPS data is ever sent to Apple or anyone else. The name is cached on your iPhone for 90 days.
Apple handles these requests under the Apple Privacy Policy.
3.3 Connecting Strava or Ride with GPS (optional)
If you choose to connect Strava or Ride with GPS:
- Sign-in happens on their website. The app opens Strava's or Ride with GPS's own sign-in page in a secure Apple sign-in sheet. We never see your password.
- Our server completes the sign-in. It exchanges the one-time code from Strava or Ride with GPS for your access tokens (this needs a secret that only our server holds) and hands the tokens to the app through a one-time link. That hand-off is deleted as soon as the app collects it, and in any case after 120 seconds.
- Your tokens are then stored only in your iPhone's Keychain. When a token needs renewing, or when you disconnect, the app sends it through our server to Strava or Ride with GPS; our server passes it on and does not keep it.
3.4 Your Strava and Ride with GPS data
With your permission, the app reads from Strava or Ride with GPS, directly from your iPhone: your saved routes, a list of your rides from about the last 100 days, and the recorded track (position, time, elevation, distance and moving/stopped) of a few rides. It does not request heart rate, power or other health data.
We use this data only to:
- show your routes so you can forecast them;
- time a forecast by replaying a ride you have already done on the same route; and
- estimate your usual speed on the flat and how hard you climb, to predict your pace.
This data is:
- stored only on your iPhone, never on our server;
- shown to nobody but you, unless you share a ride yourself: sharing an image or a ride link (section 3.11) is your own choice, and the image and the ride's page then say where the route came from ("Route from Strava");
- deleted automatically — Strava data after at most 7 days, Ride with GPS data after at most 30 days — and immediately when you disconnect;
- never sold, never shared, and never used to train or prompt any AI or machine-learning system.
3.5 Strava update notifications
Strava sends our server a short notice when an athlete who has connected Superride creates, updates or deletes an activity, or disconnects Superride. A notice contains the Strava athlete ID, the activity ID, the type of change, the time, and changed fields such as the activity title, type or privacy. We keep these notices for at most 7 days, so the app can refresh the right routes, and would return them only to that athlete, after Strava confirms who is asking. When you disconnect Superride from Strava, Strava tells our server and we delete everything we hold for your athlete ID at once. To confirm who is asking, our server may keep a one-way fingerprint (SHA-256 hash) of an access token linked to the athlete ID for at most 1 hour.
3.6 Anonymous usage counters
Our server counts things like the number of forecast requests and cache hits per day. These are daily totals only: no IP addresses, no locations, no device or account identifiers. We keep them for about 13 months to plan capacity.
3.7 Hosting and network data (Cloudflare)
Our server runs on Cloudflare. Like any internet service, Cloudflare necessarily processes your device's IP address and basic request details (such as the time and the address requested) to deliver each request and to protect the service from abuse. We have not switched on persistent request logging for our server, and we do not store IP addresses. Cloudflare may keep aggregated statistics and security data under its own policies.
3.8 If you contact us
If you email us, we receive your email address and whatever you write, and use them only to reply. We keep support emails for up to 24 months after the conversation ends, unless we need them longer to deal with a legal claim.
3.9 The App Store
Apple distributes the app. Apple may give us aggregated statistics (such as downloads) and, only if you chose to share them with app developers, crash reports. These do not identify you to us.
3.10 Introduction screens and in-app purchases (Adapty)
The introduction you see on first launch, and the Superride Pro subscription page (Superride Pro is needed to use the app), are provided by Adapty, our processor for in-app purchases. On first launch the app creates a random, anonymous Adapty profile ID — it is not linked to your name, email address, Apple Account or any Superride account (there is none).
The app sends Adapty:
- the anonymous profile ID, a random installation ID and the app's identifier for vendors (a device identifier Apple gives each app developer, which can't be used by other companies);
- technical details: device model, iOS version, app version, language, region, time zone and App Store country;
- whether the app was installed from an Apple Ads campaign (an attribution token from Apple, without any advertising identifier);
- which introduction and subscription screens were shown, so we can see how they perform in aggregate; and
- if you buy or restore Superride Pro: your App Store purchase and subscription records (product, price, dates, transaction IDs), so the purchase can be verified and your subscription recognised on your devices.
We have switched off Adapty's collection of the advertising identifier (IDFA) and of your IP address (Adapty's servers still see it in transit to answer the request, but do not store it). The app does not send Adapty your answers in the introduction, your name or email address, your routes, your location or any Strava or Ride with GPS data. Adapty does not use this data to track you across other companies' apps or websites.
Adapty processes this data on our behalf, under a data processing agreement, only to show these screens, to process and verify purchases, and to give us aggregated statistics about them. Card details are handled by Apple, never by us or Adapty.
3.11 Shared ride links (only if you share one)
When you tap Share on a forecast, the app creates a link to that ride (for example https://superrideapp.com/r/Ab3dE5fG7h) and puts it in the message next to the image. To make the link work, the app sends our server and we store:
- the ride: its name, where the route came from (your file, the demo route, Strava or Ride with GPS), the route's line and elevation (simplified to points a few dozen metres apart), the planned start time and time zone, and the planned timing along the route, including stops;
- what the forecast said when you shared it (Ride Score, the date line and the one-sentence verdict), for the link preview; and
- the shared image, smaller, for the link preview in messaging apps.
Nothing in it identifies you: no name, account, device identifier or IP address is stored with the ride, and we never know who shared it or who opened it. Anyone who has the link can see the ride — its route and planned timing — on the link's web page and in Superride, free of charge. A route is a sensitive thing (it may start at your home), so share links only with people you trust; you can remove a link at any time.
- Retention: a shared ride is deleted automatically after 90 days.
- Stop sharing: the app keeps a secret delete key for each link it created, on your iPhone only. Share → Stop sharing removes the ride from our server at once (link pages may stay in caches for up to 5 minutes), and Settings → About & legal → Delete all my data stops sharing every link you created.
- Abuse protection: to limit how many links can be created, our server counts creations per network for each hour under a one-way, hourly-changing fingerprint (SHA-256 hash) of the IP address, deleted after at most 2 hours. The IP address itself is not stored.
- Opening a link: the app asks our server for the ride by its link; nothing about you is sent or stored. The forecast is then made like any other (section 3.1).
4. What we don't do
- We don't have user accounts, and we don't ask for your name, email or phone number to use the app.
- We don't use analytics or advertising SDKs (Adapty, described in section 3.10, only counts the introduction and subscription screens and records purchases), and we don't track you across other companies' apps or websites.
- We don't sell or share personal information, including for targeted advertising.
- We don't use your data to make decisions that have legal or similarly significant effects on you.
- We don't pass Strava data, or any other personal data, to any AI or large-language-model service.
5. Our lawful bases (UK GDPR and EU GDPR)
| Processing | Lawful basis |
|---|---|
| Weather requests, stop names and map tiles — providing the forecast you ask for | Performance of a contract: providing the app's features to you (Art. 6(1)(b)) |
| Connecting Strava or Ride with GPS, reading your routes and rides | Performance of a contract, at your request; you can stop at any time by disconnecting (Art. 6(1)(b)) |
| Strava update notifications | Our legitimate interest in keeping your Strava routes current in the app and in deleting your data promptly when you disconnect (Art. 6(1)(f)) |
| Shared ride links: storing the ride you chose to share and showing it to whoever has the link | Performance of a contract: providing the sharing feature you use (Art. 6(1)(b)) |
| Network data for delivering and securing our server | Our legitimate interest in running a secure, reliable service (Art. 6(1)(f)) |
| Introduction screens, and processing, verifying and restoring purchases through Adapty | Performance of a contract: providing the app and the subscription you buy (Art. 6(1)(b)) |
| Aggregated statistics about the introduction and subscription screens and about purchases (Adapty), including whether an install came from an Apple Ads campaign | Our legitimate interest in understanding, in aggregate, how the app is found and how the subscription performs (Art. 6(1)(f)) |
| Replying to your emails | Our legitimate interest in answering you (Art. 6(1)(f)) |
| Keeping records when the law requires it | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced them against your rights: the data involved is minimal, short-lived and never used for anything else. You can object at any time (see section 9).
We don't process special category data (such as health data).
6. Who processes data for us, and other services
| Organisation | Role | What for | Data involved | Location |
|---|---|---|---|---|
| Cloudflare, Inc. | Our processor (hosting) | Runs our server, its short-lived storage and weather cache | IP address and request details (in transit); weather grid-cell coordinates; sign-in hand-offs (up to 120 s); Strava notices (up to 7 days); shared rides you create (up to 90 days) | Global network; United States |
| OpenMeteo GmbH (Open-Meteo) | Weather data provider | Weather forecasts | Grid-cell coordinates only, sent from our server (never your IP address) | Switzerland |
| Apple Inc. / Apple Distribution International | Independent provider | WeatherKit backup forecasts (via our server: grid-cell coordinates only); Apple Maps tiles and place names (directly from your iPhone); App Store | Grid-cell coordinates; map area; stop coordinates | United States; Ireland |
| Adapty Tech Inc. (Adapty) | Our processor (in-app purchases) | Introduction and subscription screens; processing, verifying and restoring App Store purchases; aggregated statistics | Anonymous Adapty profile ID, installation ID, identifier for vendors, device model, iOS and app version, language, region, time zone, App Store country, Apple Ads attribution token, screens shown; App Store purchase records if you buy | United States |
| Strava, Inc. | Independent controller, only if you connect | Your Strava routes and rides; sign-in | Your Strava account, as described in section 3 | United States |
| Ride with GPS | Independent controller, only if you connect | Your Ride with GPS routes and trips; sign-in | Your Ride with GPS account, as described in section 3 | United States |
Strava and Ride with GPS handle your data under their own privacy policies: Strava Privacy Policy, Ride with GPS Privacy Policy.
We will update this policy before we add any new processor.
7. International transfers
Cloudflare processes requests in the data centre closest to you and may store data in the United States. Where personal data is transferred from the UK or the European Economic Area to a country without an adequacy decision, we rely on Cloudflare's data processing addendum, which includes the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and on Cloudflare's certification under the EU-U.S. Data Privacy Framework and its UK Extension. Transfers to Adapty in the United States rely on Adapty's data processing agreement with the Standard Contractual Clauses and the UK International Data Transfer Addendum. Switzerland, where Open-Meteo is based, has an adequacy decision from both the UK and the EU. Apple, Strava and Ride with GPS use their own transfer safeguards, described in their privacy policies.
8. How long data is kept
| Data | Where | How long |
|---|---|---|
| Your route library and settings | Your iPhone | Until you delete them, use Delete all my data, or delete the app |
| Recent forecasts | Your iPhone | Up to 20 routes (oldest removed first); forecasts that include Strava data at most 7 days; iOS may clear them sooner |
| Route thumbnails | Your iPhone | Strava routes 7 days, Ride with GPS routes 30 days, your own files 60 days (then redrawn) |
| Stop names | Your iPhone | 90 days |
| Strava data | Your iPhone | At most 7 days; immediately on disconnect |
| Ride with GPS data | Your iPhone | At most 30 days; immediately on disconnect |
| Sign-in tokens | Your iPhone's Keychain | Until you disconnect or use Delete all my data (see the note below) |
| Sign-in hand-off | Our server | Deleted on first use, and after at most 120 seconds |
| Token fingerprint linked to Strava athlete ID | Our server | At most 1 hour |
| Strava update notices | Our server | At most 7 days; immediately when you disconnect Superride from Strava |
| Shared ride links you create (ride, preview image) | Our server | 90 days, or until you stop sharing |
| Delete keys of the links you created | Your iPhone | Until the link expires, you stop sharing, or Delete all my data |
| Hourly rate-limit fingerprints of IP addresses | Our server | At most 2 hours |
| Weather cache (per grid cell, not linked to anyone) | Our server | Until the model's next run, at most 12 hours |
| Anonymous daily counters | Our server | About 13 months |
| Support emails | Our mailbox | Up to 24 months after the conversation ends |
| Network and security data | Cloudflare | Under Cloudflare's own policies |
| Anonymous Adapty profile, technical details and screens shown | Adapty (our processor) | While Superride uses Adapty, then deleted under our agreement with Adapty; sooner on request (section 9) |
| App Store purchase records, if you buy Superride Pro | Adapty (our processor) | As long as your subscription needs them, then as long as the law requires us to keep accounting records (up to 6 years after the purchase) |
Note on sign-in tokens: iOS can keep Keychain items after an app is deleted. To be sure your Strava or Ride with GPS access is revoked, disconnect them (or use Delete all my data) before deleting the app. You can also revoke access at any time on Strava (Settings → My Apps) or on Ride with GPS (account settings).
9. Your rights
Under UK and EU data protection law you have the right to:
- access the personal data we hold about you;
- have it corrected if it is wrong;
- have it deleted;
- restrict or object to how we use it;
- receive it in a portable format (data portability);
- withdraw consent where we rely on it; and
- complain to the UK Information Commissioner's Office (ico.org.uk, 0303 123 1113) or, in the EU, to your local data protection authority.
Because almost everything stays on your iPhone, you can exercise most of these rights yourself, straight away:
- Delete all your data: Settings → About & legal → Delete all my data. This disconnects and revokes Strava and Ride with GPS, deletes your sign-in tokens, your imported routes (the built-in demo route stays), forecasts, thumbnails, stop names and all cached provider data, stops sharing every ride link you created, and resets your settings.
- Disconnect Strava or Ride with GPS in Connections at any time. Disconnecting revokes access and deletes that provider's data from your iPhone; for Strava it also makes our server delete the update notices it holds for you.
- Adapty: Delete all my data works on your iPhone and doesn't reach Adapty. To have your anonymous Adapty profile deleted, email us; if you bought Superride Pro, include the order ID from your Apple receipt so we can find it (without it, the profile can't be linked to you).
For anything else, email 1061040@gmail.com. We hold so little that we usually can't identify you; if your request is about Strava update notices, please include your Strava athlete ID. We'll reply within one month.
California residents (CCPA / CPRA)
In the past 12 months, the only personal information we have handled is: identifiers (your IP address, processed by Cloudflare and Adapty in transit; your Strava athlete ID, if you connected Strava; the anonymous Adapty profile ID and the app's identifier for vendors), commercial information (your App Store purchase records, if you buy Superride Pro) and approximate location in the form of weather grid-cell coordinates that are not linked to you. We used it only to provide the app, as described above. We do not sell or share personal information, including for cross-context behavioural advertising, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information. You have the right to know, to delete and to correct your personal information, and not to be discriminated against for exercising these rights. To make a request, email 1061040@gmail.com.
10. Children
Superride is not directed at children under 16, and we do not knowingly process personal data of children under 16. If you believe a child has given us personal data, contact us and we will delete it.
11. Security
All connections use HTTPS. Sign-in tokens are kept in the iOS Keychain, and the secrets needed to talk to Strava and Ride with GPS exist only on our server, never in the app. Data on your iPhone uses iOS data protection. Our server keeps as little as possible, for as short a time as possible.
12. Changes to this policy
If we change this policy, we will publish the new version at the same address with a new effective date, and tell you in the app about any significant change before it takes effect.
13. Contact
Aleksey Goncharov, United Kingdom
Email: 1061040@gmail.com