Legal

Privacy Policy

This Privacy Policy explains how Covian LLC (“Covian”, “we”, “us”), the operator of MyBikes (the “Service”), collects, uses, discloses, retains, and deletes personal data. Covian is the controller of personal data it processes for MyBikes. This policy does not modify, conflict with, or supersede the Strava Privacy Policy, which governs Strava’s processing and controls in the event of a conflict.

1. Strava account and activity data we collect

Only after you expressly authorize MyBikes through Strava OAuth, MyBikes may receive the following data from Strava, depending on the read-only scopes displayed and granted and your Strava privacy settings:

MyBikes requests only read, profile:read_all, and activity:read_all. It does not request permission to write to Strava. The activity:read_all scope can make your private activities available to MyBikes. MyBikes does not request route or raw GPS-stream data for the described maintenance features.

2. How Strava data is collected and used

MyBikes collects Strava data through the OAuth authorization and token-exchange process and through authenticated Strava API calls during initial setup and user-requested or scheduled synchronization. MyBikes may refresh an expiring access token using the refresh token. MyBikes does not scrape Strava or write to Strava.

We use authorized Strava data only to authenticate you; show your own profile, bikes, rides, and selected photos privately to you; calculate bike and component usage; prepare maintenance status and reminders; identify device or sensor signals available on a ride; associate rides with your bike; and link you back to the original activity. Strava data belonging to one athlete is displayed only to that authenticated athlete. We do not display it to another user or make it public. Community features, public Strava-data sharing, and access to Strava data through MCP, an agent, a proxy, or another intermediary are unavailable.

Authorized Strava synchronization, private display, maintenance calculations, and maintenance reminders are free and do not depend on a trial, paid plan, or payment. We do not sell, rent, license, syndicate, or use Strava data for targeted advertising. We do not use Strava data—whether raw, derived, aggregated, anonymized, or de-identified—for general analytics, customer insights, product improvement, benchmarking, or the development or operation of an AI system. Strava data, Strava photo URLs, and account context derived from Strava are not sent to an AI model or AI service provider and are not placed in an embedding, vector, retrieval, or other persistent index.

Email sign-in and workshop ownership

You can request workshop ownership without connecting Strava. We store your name, email, ownership explanation, review decision, and account association. After approval, we email a one-time sign-in link. We store only a hash of the link token, its expiry, and redemption status. Ordinary sign-in links expire after 30 minutes and invitations after 24 hours. We use short-lived, pseudonymous request counters to prevent abuse. Control of the mailbox is verified when you redeem a link. Email sign-in does not authorize access to Strava.

3. Other information we collect

4. Consent, authorization, and withdrawal

Before MyBikes accesses Strava data, we identify the types of data requested, explain that collection occurs through OAuth and Strava API synchronization, and ask you to expressly continue to Strava’s authorization screen. Strava then presents the granular scopes for your approval. You may decline any authorization and may withdraw it at any time.

You can withdraw authorization by selecting Disconnect Strava or Delete account in MyBikes, revoking MyBikes in your Strava account settings, or emailing serega@budyakov.com. Disconnecting or revoking Strava removes OAuth tokens, cached Strava data, and data derived from Strava. Accounts with email sign-in keep their workshop access and separately provided MyBikes content. Accounts without email sign-in are deleted so they are not left inaccessible. Delete account always removes the entire MyBikes profile. Withdrawal stops future collection and triggers the deletion process in Section 8. It does not affect processing that was lawful before withdrawal. If we propose collecting a materially different type of Strava data or expanding the scope, we will notify you and obtain any new consent and Strava authorization required before the change takes effect.

5. Purposes and legal bases

Where applicable law requires a different legal basis, we will use that basis and provide any required notice.

6. Disclosures, service providers, and processing locations

We disclose only the minimum information needed for the purposes described here. Covian maintains a current provider list and will provide Strava, or a user where required by law, the provider’s name, role, and processing location on request. Provider categories and typical processing locations are:

Providers acting as our processors are contractually required to process data only on our documented instructions, protect it with obligations no less protective than those applicable to Covian, and delete or return it as required. We may also disclose information when required by valid law or necessary to protect users, the Service, or legal rights. We do not disclose Strava data to advertisers, data brokers, model developers, or other users.

7. Strava Usage Data and independent controllers

Strava may monitor and collect Usage Data relating to MyBikes’ access to and use of the Strava API and may use that Usage Data for any business purpose, internal or external, including enhancing the Strava API materials or Strava Platform, providing developer or user support, ensuring compliance with Strava’s agreements, or otherwise. API requests necessarily disclose request metadata and the credentials needed for Strava to authenticate the request. Strava processes that information under the Strava Privacy Policy.

Covian and Strava are separate and independent controllers of personal data each receives or discloses; they are not joint controllers. Each independently determines its processing purposes and means and is responsible for its own compliance. If you ask Covian to exercise rights over data controlled by Strava, we will direct you to Strava, and vice versa where appropriate.

8. Retention, disconnection, and deletion

When deletion is complete, we provide written confirmation in the interface or through the contact channel associated with the request. If Covian ceases using the Strava API or its access ends, Covian will permanently delete all affected Strava data and derived personal data as required.

9. Your choices and privacy rights

You can disconnect Strava, change email preferences, and request access to, correction of, portability or export of, restriction of, objection to, or deletion of personal data. You may withdraw consent at any time. Strava also provides a free bulk export of your Strava data through Strava; MyBikes does not limit that right. Depending on your location, you may also have rights to know the categories and sources of personal data, opt out of sale or targeted advertising, and not be discriminated against for exercising a right. We do not sell personal data or use it for targeted advertising.

For EEA, UK, and Swiss users, you may object to processing based on legitimate interests, request restriction, withdraw consent, and lodge a complaint with your local data-protection authority. To exercise a right, email serega@budyakov.com. We may verify your identity and will respond within the period required by law. An authorized agent may submit a request where local law permits.

10. Cookies

MyBikes uses first-party cookies to complete Strava authorization, keep you signed in, protect OAuth and login state, temporarily preserve campaign attribution during sign-in, and measure the acquisition funnel and landing-page engagement. The temporary attribution cookie expires after 10 minutes. The pseudonymous marketing visitor cookie expires after 180 days, while a website visit is counted at most once per 30-minute session. Landing-page interactions are counted once per browser and page version. Session and security cookies expire according to their stated settings or when invalidated. We do not add third-party advertising or analytics pixels.

11. Security and incident response

We use HTTPS, access controls, limited production access, credential protection, and administrative and operational safeguards designed to protect personal data. No system can guarantee absolute security. If we identify a breach requiring notice, we will notify affected users and regulators as required by law and will notify Strava of a breach involving Strava data within the period required by our agreement with Strava.

12. International transfers

Covian LLC is based in the United States, and personal data may be processed in the United States and the provider locations listed above. When personal data is transferred from the EEA, United Kingdom, or Switzerland to a country without an applicable adequacy decision, we use an appropriate safeguard, such as the European Commission Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, or an analogous Swiss or other legally recognized mechanism, together with supplementary measures where required. You may request information about the applicable safeguard by contacting us.

13. Children

MyBikes is not directed to children under 16, and we do not knowingly collect their personal data. Contact us if you believe a child has provided information. Where a different age threshold or verifiable parental consent is required by applicable law, we follow that requirement.

14. Changes and contact

We may update this policy as the Service evolves. Material changes will be announced in the App or by email before they take effect where required. A change that expands the types or scope of Strava data collected will be presented before collection and will require any new consent and Strava authorization that applies.

For privacy questions, provider-list requests, or data-rights and deletion requests, email serega@budyakov.com. The Service and this policy are operated by Covian LLC in the United States.

15. Telegram Mini App and bot

When you open or connect the Telegram Mini App, MyBikes receives the Telegram user and chat identifiers, display name, username, language code, optional profile-photo URL, authorization timestamp, and messaging preference supplied by Telegram. We use these fields only to authenticate the Mini App, link it to the Strava-authenticated MyBikes account you choose, and deliver requested maintenance notifications. Telegram processes bot messages and Mini App authorization data under its own terms and privacy policy. MyBikes does not send your Strava OAuth credentials to Telegram. The Telegram link is deleted when the MyBikes account is deleted.