Privacy

Last updated: 6 October 2026

1. Overview

This privacy policy applies to the oudena website and to the Oudena app (iPhone and iPad). It explains which personal data we process, for what purpose, on which legal basis, who receives it and how long we keep it.

In short: the website sets no cookies and uses no analytics or advertising services. The app stores your account, routes and rides in a database in Frankfurt so they are available on your devices. Heart-rate data never leaves your iPhone. We do not sell data and do not track you.

2. Controller

The controller responsible for data processing is:

Kristof Van Ende Lachmannstr. 10 38102 Braunschweig Germany Email: datenschutz@oudena.app

No data protection officer has been appointed because there is no legal obligation to do so. Please send privacy questions to the email address above.

3. Website: delivery and server logs

The website is delivered via Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). To display a page, Cloudflare processes technically necessary connection data:

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and reliable delivery of the website and protection against attacks. We have not set up persistent access logging. Cloudflare acts as our processor; for transfers to the USA see section 14.

  • IP address
  • date and time of access
  • page or file requested
  • browser and operating system information
  • HTTP status code and amount of data transferred

4. Website: cookies, local storage, audience measurement

The website sets no cookies, stores nothing in local or session storage, loads no fonts or scripts from third parties and uses no analytics or advertising services. That is why there is no consent banner.

5. Website: beta requests

When you request a beta invitation, we process your email address and – where provided – your name, smart trainer model, iPhone model, iOS version, training habits, the app you currently use, your testing interest, beta experience and message. We use this to select beta participants, send invitations and manage the beta. A person makes the selection; there is no automated scoring.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a suitable, compatible beta group). Requests are stored with Supabase in Frankfurt and deleted no later than three months after the end of the beta.

6. Website: contact and support

If you email us (support@oudena.app, kontakt@oudena.app or datenschutz@oudena.app), we process your details to answer your request. The legal basis is Art. 6(1)(b) GDPR where your request concerns use of the app, otherwise Art. 6(1)(f) GDPR. We delete correspondence twelve months after the request is closed unless statutory retention obligations apply.

7. Website: shared trainings

When someone shares a training in the app, a link to a training page on this website is created. Anyone with the link can view the shared performance figures and preview image for 30 days. The page contains no name, profile picture, training date or heart rate. It shows key figures and the course of power, speed and cadence and – if shared – the ghost gap over distance or time, without any location. For routes and workouts from the Oudena catalog, the elevation profile or intervals from the catalog are added. Private routes, their GPS coordinates and their elevation profile are not published.

A training link is created when you share a training in the app, and automatically when a ride is uploaded to Strava; the link is then placed in the Strava activity description and is visible to everyone who can see that activity. Internally, the link remains associated with your account so that you can revoke it; the share is therefore not fully anonymous.

You can revoke the link in the app at any time. After 30 days, after revocation or when you delete the ride or your account, we block access and delete the stored content. A link in a Strava description then no longer resolves; Oudena does not change the description on Strava itself. We cannot recall images or previews already downloaded by WhatsApp or other recipients.

For evaluation we record only daily totals of page views and clicks per sharing channel (e.g. WhatsApp, Strava), without cookies, user profiles or stored IP addresses. The legal basis for sharing is Art. 6(1)(b) GDPR (you request the feature); for the totals it is Art. 6(1)(f) GDPR (improving the feature).

8. App: account and sign-in

You sign in with a link sent to your email address, with “Sign in with Apple” or with a Google account; pre-provisioned test accounts can sign in with a password. Sign-in runs through Supabase Auth (Supabase Inc., Frankfurt data centre). We store your email address, an account identifier, the sign-in method and your username. When you use Apple, Apple learns that you sign in to Oudena; we receive your email address (optionally a relay address) and an identifier. For Google Sign-In, see section 9.

The legal basis is Art. 6(1)(b) GDPR. The data is kept as long as your account exists.

9. App: Google Sign-In

Google Sign-In is optional. If you choose it, Oudena requests only the basic scopes for signing in (openid, email, profile). Oudena does not request access to Gmail, Google Drive, Google Calendar, your contacts or any other Google service. Google learns that you sign in to Oudena and provides us with your Google account identifier, your email address and whether it is verified, your name and the address of your profile picture. Supabase Auth stores this information with your account record in the Frankfurt data centre.

We use this information solely to authenticate you, to associate your sign-in with your Oudena profile and to provide the Oudena service. The app works with your email address and account identifier; it does not display or otherwise use your Google name or profile picture.

Oudena does not use Google user data for advertising, AI model training, generation of AI content, or the creation of non-consensual intimate imagery. Google user data is not sold and is not passed on to third parties, apart from Supabase as our processor for sign-in. It is never included in requests to the AI Ride Builder (section 11).

The data is kept as long as your account exists. When you delete your account in the app (section 13), your account record is deleted together with the information received from Google. You can additionally remove Oudena's access in your Google account at any time at https://myaccount.google.com/connections; this does not delete your Oudena account.

Oudena's use of information received from Google APIs complies with the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy). The legal basis is Art. 6(1)(b) GDPR.

10. App: profile, routes and rides

Profile: username and – voluntarily – weight, height and FTP. If you leave them empty, the app uses default values. The values are used solely to calculate speed, resistance and training zones.

Routes: routes you import (e.g. GPX files), that the AI Ride Builder creates for you or that you choose from the catalog, including coordinates and elevation data. Rides: start time, duration, distance, power, cadence, speed, elevation, position on the route, ghost comparisons and technical diagnostic data on ride physics.

This data is stored with Supabase in Frankfurt so that it is available on all your devices and ghost comparisons are possible. The legal basis is Art. 6(1)(b) GDPR. It is kept until you delete it in the app or delete your account.

Heart rate: readings from a chest strap are stored encrypted on your device only. They are transferred neither to us nor to Strava and are not included in device backups. They are deleted with the ride, the account or the app.

11. App: third-party services

Maps, place search, routing and elevation – Mapbox (Mapbox, Inc., 740 15th Street NW, Washington, DC 20005, USA). The app requests map tiles, place search, cycling routes, elevation data and the map image for shared story images directly from your device. Mapbox receives your device's IP address and the places or coordinates concerned. The legal basis is Art. 6(1)(b) GDPR. Telemetry collection by the Mapbox software (anonymous map usage data) is switched off by default; you can switch it on under “Mapbox telemetry” in Settings (Art. 6(1)(a) GDPR) and off again at any time.

Route images – Wikimedia (Wikimedia Foundation, Inc., San Francisco, USA). For route pictures, the app looks up freely licensed photos near the route on Wikipedia and Wikimedia Commons. Your device's IP address and a route location rounded to about ten kilometres are transmitted. The legal basis is Art. 6(1)(f) GDPR (an appealing presentation of routes).

AI Ride Builder – Mistral AI (Mistral AI SAS, 15 rue des Halles, 75001 Paris, France). When you describe a ride, your text goes via our server to Mistral AI. Your text and language are transmitted, not your account identifier or IP address. Only the structured result is stored, not your wording. The legal basis is Art. 6(1)(b) GDPR.

Push notifications – Google Firebase Cloud Messaging (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) and the Apple Push Notification service. If you allow notifications, we store a device token for notifications; the title and text of the message are delivered. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw in iOS at any time; individual categories can be switched off in the app.

Strava (optional; Strava, Inc., USA). If you connect your Strava account, we store an access token, a refresh token and your Strava athlete ID on our servers. When uploading, we transfer the ride data (start time, duration, distance, elevation, power, cadence, route, title) and the training link in the description (see section 7). Heart rate is not transferred. We do not read any data from your Strava account. Uploads happen on your action or – if you switch it on in Settings – automatically at the end of a ride. When you disconnect or delete your account, we revoke the authorisation at Strava and delete the tokens; activities already uploaded remain in your Strava account. The legal basis is Art. 6(1)(b) GDPR. Strava's privacy policy applies to your Strava account: https://www.strava.com/legal/privacy

Apple Health (optional). At your request, the app saves a completed ride as a workout in Apple Health on your device. The app does not read any data from Apple Health. The data remains on your device and in your iCloud, for which Apple is responsible.

12. App: operations, costs and abuse prevention

So that we can control the costs of external services (e.g. maps and AI) and detect abuse, the app periodically transmits counters of how often such features were used, together with platform and app version. These are associated with your account. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is economically viable, abuse-free operation. If you delete your account, these records are anonymised or deleted.

13. App: deleting your account

You can permanently delete your account in the app under Settings, confirming your identity again. We first revoke any Strava authorisation, then delete your stored files and then your account with profile, routes, rides, training links and settings. Operational data under section 12 is anonymised. The data on your device is removed as well. Data already transferred to Strava or Apple Health remains there and can only be deleted there.

14. Recipients and transfers to third countries

We use the following service providers as processors under Art. 28 GDPR: Supabase (database, sign-in, file storage; Frankfurt data centre), Cloudflare (website delivery), Mistral AI (language model; France) and Google Firebase (push notifications). Mapbox, Wikimedia and Strava receive data so that the respective feature works for you; Strava and Apple process data in your own accounts under their own responsibility.

Supabase, Cloudflare, Mapbox, Google, Strava and the Wikimedia Foundation are based in the USA or may process data there; with Supabase, the data nevertheless resides in the Frankfurt data centre. Transfers to the USA are based on the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) or – for Wikimedia – on the transfer being necessary for the feature you use (Art. 49(1)(b) GDPR). You can obtain a copy of the safeguards by writing to datenschutz@oudena.app.

15. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). You can withdraw consent at any time with effect for the future. Please write to datenschutz@oudena.app.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany, https://www.lfd.niedersachsen.de

16. Obligation to provide data, automated decisions

You do not have to provide any data to use the website. The app requires an account; all other information (body values, Strava, Apple Health, notifications, sharing) is voluntary. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

17. Changes

We update this privacy policy when the app, the website or the law changes. The version published here applies.