Legal
Privacy Policy
Last updated: October 7, 2026
This Privacy Policy explains how Covian LLC (“Covian”, “we”, “us”), the operator of MyBikes (the “Service”), collects, uses, discloses, retains, and deletes personal data. Covian is the controller of personal data it processes for MyBikes. This policy does not modify, conflict with, or supersede the Strava Privacy Policy, which governs Strava’s processing and controls in the event of a conflict.
1. Strava account and activity data we collect
Only after you expressly authorize MyBikes through Strava OAuth, MyBikes may receive the following data from Strava, depending on the read-only scopes displayed and granted and your Strava privacy settings:
- OAuth credentials and permissions: access token, refresh token, token expiration, granted scopes, authorization state, and Strava athlete ID. Tokens allow server-to-server API access and are treated as confidential credentials.
- Athlete profile: first and last name, username, display name, profile image, city, and country.
- Bikes and gear: Strava gear ID, bike name, primary-bike status, total distance, brand, model, description, and frame type.
- Cycling activities, including private activities: activity ID, name, description, activity and sport type, date and time, assigned gear ID, distance, moving time, elevation gain, average speed, commute and trainer status, and a link to the original activity.
- Ride photos: available primary ride-photo URLs, images you select for private display in your account, and the related activity ID, activity name, and date.
- Device and sensor information: recording-device name, external activity/device identifier, power-data presence, device watts, average and weighted-average power, average and maximum heart rate, average cadence, trainer status, available raw device/sensor fields, and MyBikes’ device-match or sensor-presence results.
MyBikes requests only read, profile:read_all, and activity:read_all. It does not request permission to write to Strava. The activity:read_all scope can make your private activities available to MyBikes. MyBikes does not request route or raw GPS-stream data for the described maintenance features.
2. How Strava data is collected and used
MyBikes collects Strava data through the OAuth authorization and token-exchange process and through authenticated Strava API calls during initial setup and user-requested or scheduled synchronization. MyBikes may refresh an expiring access token using the refresh token. MyBikes does not scrape Strava or write to Strava.
We use authorized Strava data only to authenticate you; show your own profile, bikes, rides, and selected photos privately to you; calculate bike and component usage; prepare maintenance status and reminders; identify device or sensor signals available on a ride; associate rides with your bike; and link you back to the original activity. Strava data belonging to one athlete is displayed only to that authenticated athlete. We do not display it to another user or make it public. Community features, public Strava-data sharing, and access to Strava data through MCP, an agent, a proxy, or another intermediary are unavailable.
Authorized Strava synchronization, private display, maintenance calculations, and maintenance reminders are free and do not depend on a trial, paid plan, or payment. We do not sell, rent, license, syndicate, or use Strava data for targeted advertising. We do not use Strava data—whether raw, derived, aggregated, anonymized, or de-identified—for general analytics, customer insights, product improvement, benchmarking, or the development or operation of an AI system. Strava data, Strava photo URLs, and account context derived from Strava are not sent to an AI model or AI service provider and are not placed in an embedding, vector, retrieval, or other persistent index.
Email sign-in and workshop ownership
You can request workshop ownership without connecting Strava. We store your name, email, ownership explanation, review decision, and account association. After approval, we email a one-time sign-in link. We store only a hash of the link token, its expiry, and redemption status. Ordinary sign-in links expire after 30 minutes and invitations after 24 hours. We use short-lived, pseudonymous request counters to prevent abuse. Control of the mailbox is verified when you redeem a link. Email sign-in does not authorize access to Strava.
3. Other information we collect
- Data you provide directly to MyBikes: bike setup, components, service records, reminders, tools, spare parts, devices, compatibility information, lending details, email address and communication preferences, and other profile settings.
- Mechanic directory, bookings, reviews, and location: you may save a city selected from an OpenStreetMap-powered search, including its city, region, country, OpenStreetMap identifier, and coordinates, so MyBikes can show the correct local mechanic area by default. If you separately choose to find nearby mechanics, your browser may provide current precise coordinates for that request; we use them to calculate distance and do not add them to your public profile. Mechanics applying to the directory provide their name, workshop and contact details, city, country, address or coordinates, offered services, description, and photos. When you request a visit, we store and share with that workshop your name, contact email, selected bike, requested services, preferred or proposed time, booking status, and comments needed to arrange the visit. Riders may also publish a visit date, star rating, selected services, review text, an abbreviated display name, and replies; the listed workshop may reply using its public workshop name. Approved workshop details, published reviews, and their reply threads are public and may be hidden by authorized administrators for moderation. Booking information and workshop contact details are available only to the relevant signed-in rider, selected workshop, and authorized staff.
- User-provided photos and messages: non-Strava images you upload for recognition or highlighting, bike gallery images, mechanic-chat messages, customer-support conversations, and mechanic-directory application photos. When an optional AI feature is enabled, the provider receives only the specific eligible text and non-Strava file that you submit directly to that feature. It does not receive other account context, Strava data, data derived from Strava, or Strava photo URLs.
- Billing data: our payment provider collects payment details for optional first-party features independent of Strava, such as expanded workshop-inventory capacity, private user-upload storage, and advanced organization tools. MyBikes stores a billing/customer identifier, subscription status, billing interval, and relevant transaction timestamps. We do not store full payment-card details, and payment is not required for Strava synchronization, private display, maintenance calculations, or maintenance reminders.
- First-party campaign attribution and funnel measurement: campaign parameters supplied in the page URL, ad click identifiers, the MyBikes sign-in button used, landing path, referring URL, a pseudonymous visitor identifier, and timestamps for website visits, sign-in starts, account creation, checkout starts, and successful subscriptions. The landing page also records whether it loaded in a browser, which named sections entered view, which sign-in button was used, and whether the access explanation was opened, accepted, or dismissed. These events do not include typed content, bike or ride details, or Strava activity data, and are not combined with Strava activity data for analytics.
- Technical and security data: IP address, browser or device information, first-party cookie and session identifiers, request timestamps, and diagnostic, security, and error logs.
4. Consent, authorization, and withdrawal
Before MyBikes accesses Strava data, we identify the types of data requested, explain that collection occurs through OAuth and Strava API synchronization, and ask you to expressly continue to Strava’s authorization screen. Strava then presents the granular scopes for your approval. You may decline any authorization and may withdraw it at any time.
You can withdraw authorization by selecting Disconnect Strava or Delete account in MyBikes, revoking MyBikes in your Strava account settings, or emailing serega@budyakov.com. Disconnecting or revoking Strava removes OAuth tokens, cached Strava data, and data derived from Strava. Accounts with email sign-in keep their workshop access and separately provided MyBikes content. Accounts without email sign-in are deleted so they are not left inaccessible. Delete account always removes the entire MyBikes profile. Withdrawal stops future collection and triggers the deletion process in Section 8. It does not affect processing that was lawful before withdrawal. If we propose collecting a materially different type of Strava data or expanding the scope, we will notify you and obtain any new consent and Strava authorization required before the change takes effect.
5. Purposes and legal bases
- Performance of a contract: create and operate your account; provide the features you request; synchronize authorized Strava data; maintain your bikes, inventory, and service history; provide support; and administer an optional subscription for independent first-party features.
- Consent: connect your Strava account and access the scopes you approve; enable optional communications; and process optional content where consent is required. You may withdraw consent as described above.
- Legitimate interests: secure MyBikes, prevent abuse, diagnose failures, answer support requests, and understand first-party campaign effectiveness without using Strava activity data. We balance these interests against your rights and expectations.
- Legal obligations: comply with tax, accounting, consumer-protection, privacy, security, and lawful-request requirements and establish or defend legal claims.
Where applicable law requires a different legal basis, we will use that basis and provide any required notice.
6. Disclosures, service providers, and processing locations
We disclose only the minimum information needed for the purposes described here. Covian maintains a current provider list and will provide Strava, or a user where required by law, the provider’s name, role, and processing location on request. Provider categories and typical processing locations are:
- Infrastructure, hosting, database, backup, and security providers—primarily the United States and, where a regional service is selected, the EEA. These providers may process account data, encrypted credentials, the permitted transient Strava cache, uploaded files, and technical logs on Covian’s instructions.
- Strava—the United States, Ireland, and other locations described in the Strava Privacy Policy. OAuth, API requests, and related Usage Data are processed by Strava as an independent controller.
- OpenStreetMap Nominatim city search—a city-search request you explicitly submit is sent to the configured Nominatim provider. MyBikes caches normalized search results to reduce repeat requests and stores only the city you select in your profile. OpenStreetMap attribution and provider policies apply.
- Payment processing—the United States and EEA. The payment provider processes payment and billing identifiers and may act as an independent controller for legally required payment processing. It does not receive Strava ride, bike, photo, or sensor data.
- Email delivery through the production SMTP provider, if enabled—the United States or EEA region selected for the Service. It processes the destination email address and the message the user requested, subject to contractual confidentiality and data-protection obligations.
- AI-assisted image or text processing, if enabled—the United States and other provider locations covered by the applicable transfer safeguards. It receives only the specific eligible text or non-Strava file submitted directly by the user for that request; it does not receive other account context, Strava data, data derived from Strava, or Strava photo URLs.
Providers acting as our processors are contractually required to process data only on our documented instructions, protect it with obligations no less protective than those applicable to Covian, and delete or return it as required. We may also disclose information when required by valid law or necessary to protect users, the Service, or legal rights. We do not disclose Strava data to advertisers, data brokers, model developers, or other users.
7. Strava Usage Data and independent controllers
Strava may monitor and collect Usage Data relating to MyBikes’ access to and use of the Strava API and may use that Usage Data for any business purpose, internal or external, including enhancing the Strava API materials or Strava Platform, providing developer or user support, ensuring compliance with Strava’s agreements, or otherwise. API requests necessarily disclose request metadata and the credentials needed for Strava to authenticate the request. Strava processes that information under the Strava Privacy Policy.
Covian and Strava are separate and independent controllers of personal data each receives or discloses; they are not joint controllers. Each independently determines its processing purposes and means and is responsible for its own compliance. If you ask Covian to exercise rights over data controlled by Strava, we will direct you to Strava, and vice versa where appropriate.
8. Retention, disconnection, and deletion
- Strava cache: Strava data and data derived from it are kept only in a transient operational cache and never for more than seven days. Expiry is enforced when cached data is read as well as by scheduled cleanup, so an expired item is not served while waiting for a cleanup run. If a resource is no longer available from Strava, we remove it immediately after determining that it is unavailable.
- Items deleted on Strava: webhook events and synchronization identify source deletions. We stop displaying and delete Strava data that you delete on Strava expeditiously and in all cases within 48 hours.
- Disconnect, revocation, or deletion: if you request deletion, disconnect Strava, revoke MyBikes in Strava, or delete your Strava account, we promptly revoke or invalidate access where possible and permanently delete your OAuth tokens, Strava data, and personal data derived from Strava from live systems under our control. The in-app confirmation is returned only after deletion from the live account store completes.
- MyBikes account deletion: Delete account removes the complete MyBikes account and separately provided content. Disconnecting or revoking Strava deletes the whole profile only when it has no email sign-in; email-enabled profiles keep workshop access and independently supplied content. Narrow records that applicable tax, accounting, security, or other law requires us to retain may be isolated and retained only for the required purpose and period.
- Backups: deleted data is unavailable for ordinary processing and removed from backups within 30 days. It is not restored except where necessary for disaster recovery, in which case the deletion request is re-applied before ordinary processing resumes.
When deletion is complete, we provide written confirmation in the interface or through the contact channel associated with the request. If Covian ceases using the Strava API or its access ends, Covian will permanently delete all affected Strava data and derived personal data as required.
9. Your choices and privacy rights
You can disconnect Strava, change email preferences, and request access to, correction of, portability or export of, restriction of, objection to, or deletion of personal data. You may withdraw consent at any time. Strava also provides a free bulk export of your Strava data through Strava; MyBikes does not limit that right. Depending on your location, you may also have rights to know the categories and sources of personal data, opt out of sale or targeted advertising, and not be discriminated against for exercising a right. We do not sell personal data or use it for targeted advertising.
For EEA, UK, and Swiss users, you may object to processing based on legitimate interests, request restriction, withdraw consent, and lodge a complaint with your local data-protection authority. To exercise a right, email serega@budyakov.com. We may verify your identity and will respond within the period required by law. An authorized agent may submit a request where local law permits.
10. Cookies
MyBikes uses first-party cookies to complete Strava authorization, keep you signed in, protect OAuth and login state, temporarily preserve campaign attribution during sign-in, and measure the acquisition funnel and landing-page engagement. The temporary attribution cookie expires after 10 minutes. The pseudonymous marketing visitor cookie expires after 180 days, while a website visit is counted at most once per 30-minute session. Landing-page interactions are counted once per browser and page version. Session and security cookies expire according to their stated settings or when invalidated. We do not add third-party advertising or analytics pixels.
11. Security and incident response
We use HTTPS, access controls, limited production access, credential protection, and administrative and operational safeguards designed to protect personal data. No system can guarantee absolute security. If we identify a breach requiring notice, we will notify affected users and regulators as required by law and will notify Strava of a breach involving Strava data within the period required by our agreement with Strava.
12. International transfers
Covian LLC is based in the United States, and personal data may be processed in the United States and the provider locations listed above. When personal data is transferred from the EEA, United Kingdom, or Switzerland to a country without an applicable adequacy decision, we use an appropriate safeguard, such as the European Commission Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, or an analogous Swiss or other legally recognized mechanism, together with supplementary measures where required. You may request information about the applicable safeguard by contacting us.
13. Children
MyBikes is not directed to children under 16, and we do not knowingly collect their personal data. Contact us if you believe a child has provided information. Where a different age threshold or verifiable parental consent is required by applicable law, we follow that requirement.
14. Changes and contact
We may update this policy as the Service evolves. Material changes will be announced in the App or by email before they take effect where required. A change that expands the types or scope of Strava data collected will be presented before collection and will require any new consent and Strava authorization that applies.
For privacy questions, provider-list requests, or data-rights and deletion requests, email serega@budyakov.com. The Service and this policy are operated by Covian LLC in the United States.
15. Telegram Mini App and bot
When you open or connect the Telegram Mini App, MyBikes receives the Telegram user and chat identifiers, display name, username, language code, optional profile-photo URL, authorization timestamp, and messaging preference supplied by Telegram. We use these fields only to authenticate the Mini App, link it to the Strava-authenticated MyBikes account you choose, and deliver requested maintenance notifications. Telegram processes bot messages and Mini App authorization data under its own terms and privacy policy. MyBikes does not send your Strava OAuth credentials to Telegram. The Telegram link is deleted when the MyBikes account is deleted.