Ridegain ("the App") is an indoor cycling training app provided by its developer, Ridegain ("we", "us"). This policy explains how the App handles your information.
If you do not sign in, the App stores your data only on your device.
If you choose to sign in to an account, we store some of your data on servers we operate (Cloudflare Workers / D1) in order to provide Strava integration and synchronization across your devices. Section 3 lists exactly what is stored.
The App displays no advertising and uses no third-party analytics or tracking SDKs whatsoever.
The following is stored on your device. If you are not signed in, none of it is sent to our servers.
| Type | Details | Location |
|---|---|---|
| Workout records | The content, results, and history of your training sessions | On-device storage |
| Sensor readings | Exercise data such as heart rate, power, and cadence obtained from Bluetooth-connected sensors or smart trainers, including the raw one-second-interval waveform | On-device storage |
| App settings | Display language, units, FTP, body weight, and other preferences | On-device storage |
| Sign-in session | If you sign in: a session token, and a random device identifier generated by the App | Encrypted on-device storage (Secure Store) |
| Diagnostic log | Error records used for troubleshooting | On-device storage (never sent automatically) |
| Type | Details | Purpose | Retention |
|---|---|---|---|
| Account identifier | The identifier (sub) of the Google account used to sign in, and a user ID we issue | Recognizing you across devices | Until account deletion |
| Device information | A device ID generated by the App, platform type (android / ios), push token, last access time | Multi-device sync, uninstall detection | Until account deletion |
| Strava connection | Your Strava athlete ID, access and refresh tokens (stored encrypted with AES-GCM), granted scopes | Automatic sync with Strava | Until you disconnect or delete your account |
| Settings & metrics backup | FTP and body-weight history, custom workouts, notifications, unit and language preferences | Restoring on a new or additional device | Until account deletion |
| Rides awaiting upload | Indoor rides that do not yet exist on Strava, including the raw waveform | Relaying the ride to Strava | Automatically deleted once the ride is confirmed on Strava (temporary custody) |
| Incoming Strava events | Activity IDs and event types (create / update / delete) notified by Strava | Ensuring no update is missed | Cleared when the sync is processed |
We do not store your name or email address on our servers. From the ID token issued by Google at sign-in, we read only the identifier (sub) that uniquely designates you; we neither store nor use any other claim, including your email address.
Apart from the temporary custody of rides awaiting upload, we do not permanently store raw one-second-interval waveform data on our servers.
Only if you choose to enable Strava integration:
You can disconnect Strava at any time within the App. Disconnecting deletes the tokens from our servers and revokes the authorization on Strava's side.
When you sign in, your device's push token (on Android, Firebase Cloud Messaging) is registered with our servers.
We use it primarily to detect that you have uninstalled the App. When an uninstall is detected, we deactivate that device's registration and automatically revoke the Strava authorization, so that no abandoned token is left behind without you having to do anything.
| Party | Role | Information involved |
|---|---|---|
| Strava | Sync destination, if you connect it | Your workout data |
| Google (Sign-In) | Verifying your identity at sign-in | Verification only; we pass no user data to Google |
| Cloudflare | Hosting and storage for our servers (processor) | The data in Section 3 |
| Google (Firebase Cloud Messaging) | Push delivery infrastructure (processor) | Push tokens |
We do not sell your personal information.
You can delete your data at any time. See Account Deletion for step-by-step instructions.
The App is not directed to children under 13 (or the minimum age set by your country). We do not knowingly collect personal information from children.
We may revise this policy as needed. If we make significant changes, we will announce them on this page.