VELOSTATS
Privacy
Last updated: 4 October 2026
In brief
VeloStats (called “Velo” on your iPhone) is built to collect as little data as possible: the app computes on your device, and the website works without cookies or tracking. The app has no account, no advertising and no tracking. It reads your activities from Strava or Apple Health, stores them on your iPhone and analyses them there; our server keeps no copy of them. On its own, the app only asks Strava and our server for new rides (if you connected Strava), asks for a newer app version and for replies to your feedback (if you sent any), sends anonymous error reports, reports without any identifier when Strava’s request limit is reached, and saves a backup of your own entries to your iCloud Drive (can be turned off). Everything else happens only when you trigger it: the online AI (add a bike by photo, components, torque values, workout generator, nutrition photo and “Describe”) and the barcode lookup each only after your consent, plus feedback, “Send for review” and the workout export to intervals.icu. What goes where is listed point by point below.
This website (velostats.app)
- No cookies, no trackers, no analytics services. Only your language choice (DE/EN) is stored in a strictly necessary cookie; your browser loads the fonts from Google Fonts (Google sees your IP address in the process, but no cookies).
- The website runs on Cloudflare Workers (Cloudflare, Inc.) as hosting infrastructure. When you access it, Cloudflare processes technically necessary connection data (such as your IP address) to deliver the page and prevent abuse.
- Contact: whatever you send via the form or by email to support@velostats.app (name, email address, message) is used solely to answer your enquiry, is not shared with third parties, and is deleted automatically after 90 days at the latest.
- Spam filter: incoming messages (form and email) are checked for typical spam characteristics by a rule-based filter on our server (Cloudflare Workers) — without AI and without sharing with third parties. Messages recognised as spam are not answered, but they are stored like all others and deleted automatically after 90 days at the latest.
The app
- On-device processing: your activities — rides and, if you turn them on, runs and hikes — and everything computed from them (FTP, form, records, analyses, explorer tiles) are stored by VeloStats on your iPhone, as are your bikes, your own workouts and your fueling log. There is no account, and our server keeps no copy of them.
- Strava (optional): if you connect Strava, VeloStats reads your own activities — including private ones — with their data streams (power, heart rate, speed, cadence, temperature, altitude, GPS route) and, from your profile, your weight, FTP and the names of your bikes and shoes. VeloStats only reads and writes nothing to Strava; the requests go directly from your iPhone to Strava. Sign-in happens at Strava, VeloStats never sees your password. Only two things run via our server (auth.velostats.app): the sign-in exchange — the access keys wait there for at most 10 minutes until the app collects them — and the regular renewal of the access keys, which the server does not store.
- Strava notifications and athlete ID: so that new rides arrive quickly, Strava notifies our server of new and deleted activities and of some changes (such as to the title): activity ID, type and time of the notification and, for changes, only the names of the changed fields — no content. The server keeps these notifications under your Strava athlete ID for 30 days, and the app retrieves them under this ID. Because Strava limits the number of connected accounts, the server also keeps a list of the athlete IDs of connected accounts; when a new account connects, the developer receives a Telegram message without a name and without the ID. If the app hits Strava’s request limit (it applies to all VeloStats users together), it sends our server, without any identifier, when syncing will resume and how many requests are pending, and later that it has finished; the developer receives this via Telegram.
- Disconnecting Strava: if you disconnect in VeloStats, the app deletes the access keys and the data loaded from Strava on your iPhone. The authorisation at Strava itself remains: you revoke it in Strava’s settings under My Apps (strava.com/settings/apps). Our server then also removes your athlete ID from its list; the stored notifications expire on their own after 30 days.
- Apple Health (optional): only after you grant access in iOS, VeloStats reads workouts — rides and, if you turn them on, runs and hikes — with route, distance, speed, power, cadence, heart rate and active energy, plus resting heart rate, body weight, date of birth and biological sex (for energy and heart-rate estimates). You decide in iOS for each value individually. VeloStats only ever writes one value: your FTP, and only if you turn on “Write FTP to Apple Health” (off by default). Analysis happens on the device. Raw data and histories from Apple Health do not go to our server; values computed from them only with the workout generator and when you send an activity “for review” (see there).
- Online AI — only after your consent: before VeloStats sends anything to the online AI for the first time, the app asks; without “Allow” nothing goes out. The app does not remember “Don’t allow” — it asks again the next time you tap. You can withdraw your permission at any time in Settings under “AI” (“Online AI allowed”). The requests go to our server and from there to the AI service Anthropic (Claude) for analysis; what each feature sends is listed in the following points. If “On device only” is turned on there, no AI request goes to our server: VeloStats then builds workouts from its own templates, “Describe” only searches your inventory, and the other AI features are not available.
- Bike by photo, components and torque values: if you add a bike by photo, the app sends up to three photos — downscaled and as a newly rendered image without the original’s metadata (such as the location where it was taken) — plus any name you gave the bike. For components, build variants and torque values it sends make, model and year or your search term; Anthropic researches them on the web. Our server does not store photos or requests; it only keeps the answers for a make, model and search term for up to 60 days as a cache — not linked to you or your device.
- Workout generator and “Recommend something”: the generator sends your wish as text (at most 500 characters), your FTP and your form (fitness, fatigue and form as one number each), for an adjustment the previous workout and your change request, and for run workouts your threshold speed. “Recommend something” additionally sends the app’s weekly advice (target ramp, weekly TSS, days until the next hard session and the reasoning with your values), your minutes per power zone over the last four weeks and your most recent rides with a power meter as short facts (how many days ago, duration, TSS, highest zone). VeloStats computes these values from your Strava or Apple Health activities. No data streams, no route, no name; our server does not store the request.
- Nutrition photo and “Describe”: if you photograph a nutrition label or a product, the app sends the photo (downscaled, without the original’s metadata) and any product name you typed; if you describe something in words (“2 salted pretzels”), it sends your text. Our server passes the request on to the Vita service — a Cloudflare Worker also operated by us — which passes it to Anthropic. No ride or health data travels along. Neither our server nor the Vita service stores the photo or the text.
- Device identifier and daily limit: the online AI requests and “Send for review” carry a device identifier: Apple’s “identifierForVendor” — no Apple ID, no name. It is the same for all apps of this developer on your iPhone and changes when you delete all of these apps; it never goes to Anthropic. Under it our server counts the requests of a day; these counters expire at the latest one day after the last request. For the nutrition photo, the Vita service additionally counts the estimated cost per device (it deletes the daily value at the latest two days and the monthly total at the latest 40 days after the last request) — numbers only, no content.
- Retention at Anthropic: under Anthropic’s rules for the API, Anthropic automatically deletes inputs and outputs (for VeloStats: the photos, texts, names and training figures of the requests and the answers to them) within 30 days of receipt or generation. Exceptions: if Anthropic’s automated review systems flag a request as violating Anthropic’s usage policy, Anthropic keeps inputs and outputs for up to 2 years and the review results for up to 7 years; Anthropic may also retain data as required by law or as necessary to combat usage policy violations. By default, Anthropic does not use inputs and outputs from the API to train its models. Anthropic may process the requests in the US, Europe, Asia or Australia; they are stored in the US. Sources in Anthropic’s Privacy Center (retrieved 1 October 2026): retention, training, server locations.
- Barcode lookup (optional): if you scan a barcode while logging fuel, the app queries the open product database Open Food Facts after your one-time consent. Only the barcode is transferred (for technical reasons Open Food Facts sees your IP address) — no photo, no ride, no name. The answer is cached on your iPhone.
- Data check for review (optional): if you explicitly send an activity that the data check excluded “for review”, the app transfers for each activity its start time, duration, sport, distance, elevation gain, the source as a short code (such as “strava” or “apple-watch”, never a device name) together with other sources of the same activity, the Strava activity ID, attributes such as e-bike or indoor, metrics (power, heart rate, speed, cadence, temperature), the power, speed and heart-rate curves (best values per duration, no data streams), what the check found and the app version to our server; the device identifier only serves the daily limit there and does not end up in the entry. It becomes an entry in a private GitHub repository of the developers that we use to improve the check; the developer receives a Telegram notice without the data. The entry stays stored; we delete it on request (support@velostats.app). No route, no name, no free text.
- intervals.icu (optional): if you connect VeloStats with intervals.icu, you can transfer individual workouts to your calendar there (from where they sync to Garmin, Wahoo or Karoo). Sign-in happens at intervals.icu — VeloStats never sees your password. Only the sign-in exchange (at most 10 minutes until the app collects the keys) and the renewal of the access keys, which the server does not store, run via our server. Only the workout you deliberately export is transferred — directly from your iPhone to intervals.icu.
- Feedback from the app (voluntary): if you send feedback — including a language wish (“Request another language”) —, the app transmits your text, the chosen category, app version, build number and iOS version, plus a random identifier created per installation that groups feedback from the same device and serves the daily limit — no name and no Apple device identifier. Follow-up questions and edits to your feedback are added as text. Screenshots are only included if you deliberately pick them — downscaled and as a newly rendered image without the original’s metadata; a screenshot can only be retrieved via our server and only under its unpublished file name. The feedback, including the identifier, is stored as an entry in a private GitHub repository of the developers so that we can reply; the developer receives a Telegram message with your text. To show you replies, the app asks our server for the status of your own feedback (only its numbers and the app version). To prevent abuse, the server counts a day’s feedback per identifier; these counters expire at the latest two days after the last feedback.
- Update notice: at launch the app asks our server whether a newer version exists that you can install the way you installed the app. Only the app name, the installed version number and whether the app came from the App Store or TestFlight are transmitted — no identifier, no content.
- Error and crash reports: if VeloStats crashes or something fails internally, the app sends an anonymous report to our server so that we can fix the error: the feature in which it occurred, the technical error message, app version, build, iOS version and device model (such as “iPhone17,1”), and for a crash also the technical crash location in the program (iOS delivers crash reports at the next launch) — no activities, no names, no device identifier. The report is stored as an entry in a private GitHub repository of the developers; the server counts repeats of the same error instead of creating new entries. The developer receives a Telegram notice about it.
- Backup to iCloud Drive (on by default): so that your own entries survive a device change, VeloStats writes a backup file to your iPhone whenever it goes to the background and — as long as iCloud Drive is active and you don’t turn off “Back up to iCloud” — to the “Velo” folder of your own iCloud Drive. It contains your bikes and shoes, your own workouts and fueling products, your fueling log, your decisions per activity (such as “Power ignored”) and your settings including values you entered yourself (for example FTP, weight, sex, heart-rate thresholds). No activities, no values from Apple Health, no photos. There is no server of ours in between, and we have no access to this file.
- VeloStats and Vita on the same iPhone: for Vita, an app by the same developer, VeloStats places the time window, energy (work in kJ, estimated kcal including the share from carbohydrates and fat), intensity and the fuel logged during the ride for the rides of the last 35 days in a keychain area on your iPhone that only apps of this developer can read and that is not synced via iCloud Keychain. If Vita is installed, Vita reads it on the device; nothing runs via a server.
- Maps: VeloStats shows routes, the explorer and the replay with Apple Maps (MapKit); for this your iPhone loads map material for the visible area from Apple. The app draws the route itself on the device.
- No advertising, no tracking: VeloStats contains no advertising, tracking or analytics SDKs and does not pass data to third parties beyond the services named here.
- Beta via TestFlight: during the beta, Apple distributes the app via TestFlight. We receive crash reports and TestFlight feedback from Apple only to the extent you allow this in TestFlight; Apple’s TestFlight terms apply.
Services that receive data
- Strava, Inc. (USA) — your activities and your profile, only if you connect Strava; the requests come directly from your iPhone.
- Apple — Apple Health (on the device), iCloud Drive (backup), Maps (MapKit) and TestFlight (during the beta).
- Cloudflare, Inc. — runs our server (auth.velostats.app, app-feedback.dgertis.workers.dev, beta-review-watcher.dgertis.workers.dev) and the Vita service and processes technically necessary connection data such as the IP address; Cloudflare keeps technical logs (such as the requested address, time and error messages) for up to 7 days.
- Anthropic — AI analysis (bike by photo, components, torque values, workout generator, nutrition photo, “Describe”), only with your consent; for retention see above.
- Open Food Facts — barcode lookup, only with your consent.
- intervals.icu — workout export, only if you connect and export.
- GitHub, Inc. (USA) — storage of feedback, activities sent “for review” and anonymous error reports in a private repository.
- Telegram — notification of the developer about new feedback (with your text), error and review reports, new Strava connections and the Strava request limit.
Deleting your data
On the iPhone: delete the app — this removes activities, analyses and your entries from the device; you revoke access to Apple Health in the iOS settings. You delete the backup in iCloud Drive in the Files app (“Velo” folder). Strava: disconnect in VeloStats and revoke the authorisation in Strava’s settings (strava.com/settings/apps) — our server then also removes your athlete ID; the stored notifications expire on their own after 30 days. For questions, information or the deletion of feedback or a review report you sent: support@velostats.app.
Controller
David Gertis
support@velostats.app