Privacy Policy
Last updated: 15 July 2026
This policy explains what data cai.bike collects, why, and what happens to it. The short version: we store your email and your Strava cycling data to provide the service, we share activity data with an AI provider to generate coach responses, and we don't sell anything to anyone.
1. Data we collect
- Account data: your email address, used for login links and essential service messages, plus an optional athlete profile (sex and year of birth) used to personalise coach advice.
- Strava data: when you connect Strava we sync your activities (rides, routes, power, heart rate, and similar metrics) and your athlete ID. We store an OAuth token so syncing keeps working; we never see your Strava password.
- Data you enter: FTP and weight records, goals, race and planned ride entries, daily feel logs and messages you send to the AI coach.
- Support and signup messages: if you contact support or join the waitlist, we keep your email and message so we can reply.
2. What we use it for
- Showing you your own dashboard, analytics, calendar and goals.
- Computing training metrics (training load, CTL/ATL/form) from your activities.
- Generating AI coach responses grounded in your training data.
- Sending login links and replying to support requests.
We do not sell your data or use it for advertising.
3. AI processing
When you chat with the coach, relevant parts of your training data (recent activities, fitness metrics, goals, your messages) are sent to a third-party AI provider (Anthropic and/or OpenAI) to generate the response. This data is sent via their APIs, which are contractually not used to train their models. Don't put anything in the chat you wouldn't want processed by these providers.
4. Cookies
cai.bike uses a single signed session cookie to keep you logged in; it expires after 30 days. There are no advertising or analytics cookies and no third-party trackers. The login, signup and support forms are protected by Cloudflare Turnstile (bot protection), which may set its own functional cookie. These cookies are strictly necessary for the service to work, so no cookie consent banner is shown.
5. Third-party services
- Strava: activity data source (you authorise this via Strava OAuth and can revoke it there or in settings).
- Anthropic / OpenAI: AI coach responses.
- Paystack: subscription and credit top-up payments. Your card details are entered on Paystack's payment pages and never touch our servers.
- Content delivery networks: the app loads a few open-source interface libraries from public CDNs (jsDelivr, unpkg, cdn.tailwindcss.com), which receive your IP address when a page loads, as any web request does.
- Other third-party providers: used for email delivery and for security, such as bot protection on public forms.
6. Storage and retention
Your data is stored in the service's own database and is kept while your account is active so that long-term training history and trends work. Login links are single-use and short-lived.
7. Your rights and choices
- Disconnect Strava at any time from the settings page; this stops all syncing.
- Delete your account and data at any time from the account menu in the app; this removes your account, activities and chat history.
- Access or correct your data: most of it is visible in the app, and you can ask us about anything that isn't.
8. Security
The service runs over HTTPS, sessions are signed, login is via one-time email links (no passwords to leak), and each user's data is scoped to their own account. No system is perfectly secure, but we keep the attack surface deliberately small.
9. Changes to this policy
If this policy changes materially we'll announce it in the app or by email. The "last updated" date at the top always reflects the current version.
10. Contact
Privacy questions or requests: use the support page.