RideACycle is a free fitness app for runners and cyclists. This policy explains what we collect, why, and what control you have over it.
1. What we collect
Account information. When you create an account we store your email address, a display name, and an internal user ID. Passwords are handled entirely by Firebase Authentication and are never visible to us. You may also use the app anonymously, in which case no email is stored.
Precise location, including in the background. This is the core of the app. While an activity is being recorded we continuously collect GPS coordinates, timestamps, speed and elevation, and we keep collecting them while the app is in the background or your screen is off. These points are stored as the route of your activity so you can replay it, measure distance, and compare segments. We do not track your location when no activity is running.
Fitness and activity data. Distance, duration, pace, elevation gain/loss, maximum speed, and — where your device supports it — step cadence read from the device's motion sensors.
Emergency contacts. If you use the SOS feature you may save the names and phone numbers of people to contact. These are stored on your account so the feature works across devices. When you trigger an SOS the message is composed in your phone's own SMS app and sent by you — it does not pass through our servers.
Content you post. Text and any photo you attach to a community post, plus your display name, likes and comments.
Purchases. If you buy from the in-app shop, your order (items, amounts, status) is stored on your account. Card and payment details are collected and processed directly by Razorpay and never reach our servers.
Diagnostics and usage analytics. The app includes Firebase Analytics, which automatically collects app opens, screen views, device model, OS version, approximate region, and a resettable app-instance identifier.
Advertising. The app shows ads through Google AdMob, which may access your device's advertising identifier and approximate location to select ads.
2. Why we collect it
| Purpose | Data used |
|---|---|
| Recording and displaying your activities | Location, fitness data |
| Personalised route challenges | Location, activity history |
| Leaderboards, segments and races | Display name, activity results |
| Community feed | Posts, photos, display name |
| SOS | Emergency contacts, current location |
| Orders and payments | Account, order details |
| Keeping the app free | Advertising identifiers |
| Fixing crashes and improving the app | Diagnostics, analytics |
We do not sell your personal data.
3. Who we share it with
- Google Firebase (Authentication, Firestore, Storage, Cloud
Messaging, Analytics) — hosting and infrastructure. Data is stored in the
asia-south1(Mumbai) region. - Google Maps Platform — map display and route generation. Coordinates are sent to Google to render maps and compute routes.
- Google AdMob — advertising.
- Razorpay — payment processing for shop orders.
- Other users — anything you post to the community feed, your display name, and your results on public leaderboards and segments are visible to other users of the app.
4. Retention and deletion
Activity, profile and post data is retained until you delete it or delete your account. Deleting your account removes your profile, activities, posts and emergency contacts. See how to request account deletion, or email connect@akshaykotish.com — we will action requests within 30 days.
5. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to or restrict processing. Contact connect@akshaykotish.com to exercise any of these.
You can withdraw permissions at any time in your device settings — note that revoking location permission stops activity tracking from working.
6. Children
RideACycle is not directed at children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their data.
7. Security
Data in transit is encrypted with TLS. Access to stored data is restricted by Firebase Security Rules so that users can only read and write their own records, except for data that is deliberately public (leaderboards, the community feed, and public segments).
8. Changes
We will update this page and change the effective date above when this policy changes. Material changes will be announced in the app.