Privacy

What we keep, and what we do not.

Last updated 18 September 2026

Indore is an indoor cycling companion app operated by Superawesome (sprawsm.com). This policy explains what data we collect, why, and how it’s handled.

Account data

When you sign in with Google, we receive and store your email address and a Google account identifier. That’s it — no name, no profile photo, no phone number.

We also store OAuth tokens for Google and (if you connect it) Strava. These tokens allow Indore to access your YouTube playlist and upload rides to Strava on your behalf. They can be revoked at any time through your Google or Strava account settings.

Ride data

When you complete a ride, we store a summary of it: duration, average and max power, heart rate, cadence, and a couple of derived metrics. We also store the full ride recording as a FIT file — this contains second-by-second power, heart rate, cadence, and speed data.

Ride recordings are stored on Cloudflare’s infrastructure (R2 object storage). They’re tied to your account and are not shared with other users.

Profile data

You may optionally provide your FTP (Functional Threshold Power) and body weight. These are used to calculate power zones and display watts-per-kilogram. You can update or remove them at any time in Settings.

Payments

Ride credits and the monthly plan are sold through a checkout run by Paddle. We never see your card number. Paddle collects it, holds it, and takes the payment.

Paddle is our Merchant of Record. The Paddle entity named on your receipt is the seller, not Indore. Paddle handles sales tax and VAT wherever you are, and issues the receipt.

What Paddle passes back to us: your email address, your country, what you bought, when you bought it, how much you paid, whether a subscription is active, and the card brand and last four digits — enough to match a payment to a support request, and no more.

What we store against your account: a record of what you bought and when, your credit balance and the history behind it, and whether your subscription is active. That is what makes the balance and the plan work.

The checkout is Paddle’s own, so whatever it stores in your browser during a purchase is covered by Paddle’s privacy policy rather than this one. For the payment data Paddle collects, Paddle acts as an independent controller under data-protection law, and its own policy governs how that data is handled.

AI processing

Indore uses AI to power a few features. All of them run on Google’s Gemini API, and none of the data we send is ever used to train AI models.

  • Ride summaries — After a ride, your ride metrics (power, heart rate, cadence, duration) are sent to generate a short description. The raw FIT file is not sent — only aggregate numbers.
  • Session generation — When you create a session from a text description, that text along with your FTP and zone definitions are sent to generate the interval structure.
  • Daily picks — Indore builds a few suggested sessions each day using the same interval-building service.
  • Ride suggestions — When you ask Indore to fit a ride to how you’re feeling, we send derived numbers about your recent riding (ride counts, durations, and intensity summaries) along with your own check-in answers. We never send activity names, GPS or location data, or anything that identifies you. If you’ve connected Strava, those activities are reduced to plain numbers on our own servers first — the raw Strava activities are never sent to any AI provider, and are never stored.
  • Voice commands — Voice input is transcribed on your device using Apple’s speech recognition. Only the resulting text transcript is sent to our server for parsing — audio never leaves your phone.

YouTube

Indore requests YouTube access to do two things: create a private playlist called “Indore” on your account, and read that playlist to show your videos during a ride.

Indore does not access your watch history, subscriptions, recommendations, or any other YouTube data.

Strava

If you connect Strava, Indore uploads your completed ride as a FIT file with a title and description. If you import one of your Strava routes to ride indoors, Indore fetches that route — and only that route — when you ask it to.

If you also grant read access, Indore reads summaries of your recent activities — dates, durations, distance, and power numbers — solely to fit ride suggestions to your recent riding. It never reads or stores GPS tracks, maps, or activity names from your ride history, and how those numbers are handled is described under AI processing above. The read permission is optional: decline it and uploads work as before.

Trainer telemetry

Indore can collect data about how your smart trainer responds to power targets — things like ERG response time, power stability, and connection reliability. This is device behavioral data, not personal health data, and is used to improve compatibility across different trainers.

Telemetry is linked to your account (so we can follow up on specific device issues) but is only used internally in aggregate. You can opt out in the app under Preferences.

What we don’t collect

  • Location data
  • Device identifiers (IDFA, IDFV, etc.)
  • Browsing history
  • Card numbers — Paddle takes the payment, so we never see them
  • Contacts or calendar data
  • Your real name — unless it’s part of your Google email address, we don’t have it

Where data is stored

All data is stored on Cloudflare’s infrastructure — Workers for the API, D1 for the database, R2 for file storage, and KV for sessions. Cloudflare operates data centers globally. For more on their practices, see Cloudflare’s privacy policy.

Payment data is the exception: it sits with Paddle, not on our infrastructure. Paddle operates internationally.

Data retention

Your account and ride data are kept for as long as you have an account. If you want them deleted, email [email protected] and we’ll remove what’s associated with your account.

Records of purchases and refunds are the one thing a deletion request can’t reach. Tax and accounting law requires us to keep them for a number of years, and that obligation outlives the account. Paddle keeps its own copy as seller of record. We can’t delete either, and we won’t pretend otherwise.

Third parties

We share data with the following services:

  • Google — OAuth authentication, YouTube playlist access, and the Gemini API for all AI features (ride summaries, session generation, daily picks, ride suggestions, and voice parsing)
  • Strava — ride uploads (only if you connect your account)
  • Cloudflare — infrastructure and hosting
  • Paddle — payments, tax and receipts

We do not sell your data. We do not run ads. We do not share your information with anyone else.

Changes

If this policy changes in a meaningful way, we’ll note it here with an updated date. We won’t notify you by email for every minor wording tweak, but anything that affects what data we collect or how we use it will be clearly communicated.

Contact

Questions about your data? Email [email protected].