Privacy Policy

Last updated: 15 July 2026

This policy explains what data cai.bike collects, why, and what happens to it. The short version: we store your email and your Strava cycling data to provide the service, we share activity data with an AI provider to generate coach responses, and we don't sell anything to anyone.

1. Data we collect

2. What we use it for

We do not sell your data or use it for advertising.

3. AI processing

When you chat with the coach, relevant parts of your training data (recent activities, fitness metrics, goals, your messages) are sent to a third-party AI provider (Anthropic and/or OpenAI) to generate the response. This data is sent via their APIs, which are contractually not used to train their models. Don't put anything in the chat you wouldn't want processed by these providers.

4. Cookies

cai.bike uses a single signed session cookie to keep you logged in; it expires after 30 days. There are no advertising or analytics cookies and no third-party trackers. The login, signup and support forms are protected by Cloudflare Turnstile (bot protection), which may set its own functional cookie. These cookies are strictly necessary for the service to work, so no cookie consent banner is shown.

5. Third-party services

6. Storage and retention

Your data is stored in the service's own database and is kept while your account is active so that long-term training history and trends work. Login links are single-use and short-lived.

7. Your rights and choices

8. Security

The service runs over HTTPS, sessions are signed, login is via one-time email links (no passwords to leak), and each user's data is scoped to their own account. No system is perfectly secure, but we keep the attack surface deliberately small.

9. Changes to this policy

If this policy changes materially we'll announce it in the app or by email. The "last updated" date at the top always reflects the current version.

10. Contact

Privacy questions or requests: use the support page.