KOMRIDER combines local training with online services. Your app connects to your smart trainer and sensors and controls your ride on your device. KOMRIDER servers process and store account details, subscriptions, training plans, saved activity metrics, and community data. Saving a ride synchronises activity data with your account. Live features transmit your virtual route position and selected rider data, which other riders can see depending on the ride and its visibility rules. A file stored locally does not mean that its contents or derived data stay on your device: route coordinates, for example, can be sent to external map services.
This Privacy Policy explains which personal data we process, why we process it, where it is stored, which third-party services may be involved, and which rights you have under Swiss data protection law and, where applicable, the EU GDPR.
If anything is unclear, contact us at info@komrider.com.
1. Controller
The controller for your personal data is:
KOMRIDER
Inhaber: Klaus Markus Wilhelm
c/o ExpertFid & Audit SA
Rue des Alpes 11
1700 Fribourg
Schweiz
Email: info@komrider.com
2. Scope and applicable law
This Privacy Policy applies to the KOMRIDER website, the desktop and iPad apps, KOMRIDER accounts, subscriptions, support, route and workout features, Strava integrations, and related online services.
KOMRIDER is operated from Switzerland. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP/DSG). If you are located in the European Union or European Economic Area, the EU General Data Protection Regulation (GDPR/DSGVO) may also apply.
3. Local processing and online services
Trainer and sensor connections, workout execution, and live sensor readings are handled on your device. The desktop app also stores imported route and workout files, activity exports, and detailed ride data locally. The iPad app uses local storage for settings, remembered devices, and activities waiting to synchronise. These local functions coexist with server-side processing.
Account profiles, training settings and their histories, personal training plans, and saved activity metrics are stored on KOMRIDER servers. Pending activities can be synchronised later when a connection is available. The desktop activity-summary synchronisation excludes full route coordinates, elevation profiles, and the raw power time series; map processing, live rides, and Strava uploads are separate transmission paths. A GPX import normally uses external map matching to align coordinates with roads, even when the GPX file itself stays on your computer.
KOMRIDER catalogue routes, catalogue workouts, route resources, segment resources, and training plans provided by KOMRIDER are product content. They are not treated as user-owned uploaded content merely because you access or ride them.
4. Data we process
The exact data depends on which features you use. The following overview describes the main categories and storage locations.
| Category | Examples | Main storage | Purpose |
|---|---|---|---|
| Account and login data | Email address, password hash, user ID, profile name, authentication status | KOMRIDER backend | Create and secure your account, authenticate requests, provide paid features |
| Personal profile and training settings | Date of birth, nationality, time zone, FTP, weight, threshold heart rate, training zones, performance profile, and changes over time | KOMRIDER backend; selected settings are also available in the app | Personalise training, calculate training load and performance, and manage your profile |
| Subscription data | Plan, subscription status, renewal status, customer and transaction references | KOMRIDER backend and payment provider | Manage access, invoices, cancellations, and entitlement checks |
| Trial eligibility and abuse-prevention data | Pseudonymised account and device identifiers, claim time, and client platform | KOMRIDER backend | Determine eligibility for free trials and prevent repeated or abusive use. These records are not used to restrict paid subscriptions |
| Payment data | Payment method details, billing events, fraud checks | Payment provider | Process payments. KOMRIDER does not store full card details |
| Rewards and account progress | Current points, reward events, achievement progress linked to your account | KOMRIDER backend | Provide reward features and account progress |
| Local app data | GPX uploads, local routes, route geometry, workout files, local training data, local activity exports | Your device / local app storage | Run training and route simulation, retain detailed files, and support pending activity synchronisation |
| Activities and training metrics | Activity title, distance, duration, speed, power and heart-rate metrics, elevation, timestamps, FTP and weight at the time of the ride, training load, power bests, laps, and segment efforts | KOMRIDER backend for saved activity metrics; local app storage for ride data and pending synchronisation | Display completed activities across devices, calculate progress and training load, and provide rewards and segment results |
| Live rides and community | User ID and name, virtual route coordinates, route and lap progress, speed, cadence, power where transmitted by the app, timestamps, nationality, rider appearance, friendships, event participation, and leaderboard results | KOMRIDER backend; visible ride and community data is also displayed to other users | Show other riders, organise group rides and events, and provide community and ranking features |
| Strava connection and recent training load | Connection status, OAuth tokens, athlete ID, imported routes or activities; with recent training load enabled: activity summaries and available time, movement, power, and heart-rate streams used to derive training-zone summaries | KOMRIDER backend for the connection, synced summaries, and derived training-zone data; local desktop storage for imported route and activity files; Strava for uploaded rides | Import routes, upload saved rides when connected, show recent outdoor activities, calculate training load, adapt plans, and disconnect access |
| Map and route processing | Coordinates, route points, elevation profiles, map-matching requests | Local app storage; route coordinates may be sent to our backend and map providers for processing | Display maps, snap GPX routes to roads, improve route simulation and elevation handling |
| Workout generation and personal training plans | Original and normalised prompts, training goals and constraints, FTP, generated workouts and drafts, model information, plan schedules, assignments, status, and adjustments | KOMRIDER backend linked to your account; prompts and relevant training context are sent to AI providers for AI generation | Generate, preview, save, schedule, and adapt your training; diagnose generation errors when diagnostic logging is enabled |
| Content safety checks | Proposed usernames, route names, and meet-up titles | Sent through OpenRouter to a model provider for checking; approved names and titles are stored with the related account or content | Check user-submitted names and titles for abusive or unsafe content, including during registration |
| Support | Email address, message content, support correspondence | KOMRIDER backend and communication providers | Respond to support requests and handle related follow-up communication |
| Technical data | IP address, device type, browser, operating system, app version, server logs, error logs | KOMRIDER backend, hosting, and infrastructure providers | Operate, secure, debug, and improve KOMRIDER |
Recent training load (optional): if you enable this feature, the KOMRIDER backend periodically retrieves summaries of your recent Strava activities (sport type, title, start time, duration, distance, elevation, and power or heart-rate averages). For suitable activities it also retrieves available time, movement, power, and heart-rate streams to calculate aggregated zone distributions. This training-load sync does not request GPS tracks or route coordinates. The summaries and derived zone data are stored to show recent outdoor activities in the training calendar, estimate your training load, mark matching planned sessions as completed, and adapt training plans. Only a recent activity window is retrieved. You can disable the feature at any time in the app; disabling it or disconnecting Strava deletes the synced activity and zone records. This does not delete rides already uploaded to your Strava account.
Saving with Strava connected: the app also uploads the saved ride to Strava, including activity measurements and, for route rides, the virtual route recorded in the activity file. Disconnect Strava before saving if you do not want that upload. Strava controls the visibility of activities within its service.
Live visibility: the desktop app normally makes active live rides visible to other riders, including through nearby-rider discovery on imported routes. Closed races limit global visibility. The transmitted coordinates describe your position on the virtual route, not necessarily the physical location of your trainer. An imported route can nevertheless reveal a real route you know or use. Community profile-discovery and online-status settings are separate from live-ride visibility. Live presence expires after updates stop; this does not erase stored activity results, event records, or operational logs.
5. Legal bases
Where the GDPR applies, we rely on the following legal bases:
- Contract performance, Article 6(1)(b) GDPR: account access, subscriptions, app functionality, support, Strava connection, and requested route or workout features.
- Legal obligations, Article 6(1)(c) GDPR: accounting, tax, and legally required records.
- Legitimate interests, Article 6(1)(f) GDPR: security, abuse prevention, debugging, service reliability, and product improvement.
- Consent, Article 6(1)(a) GDPR: optional communications, optional integrations, and other features where we explicitly ask for consent. You can withdraw consent at any time with effect for the future.
Training features process heart rate, weight, performance values, and their histories to calculate training zones, workload, and recommendations. These data can reveal information about your health. This processing also occurs through sensor data and training settings, not only through free-text input. Please avoid including diagnoses or other unnecessary sensitive details in prompts or titles. Acknowledging this Privacy Policy is not a separate consent to every processing activity.
6. Recipients and third-party services
We only share personal data where this is necessary for the service, where you ask us to do so, or where we are legally required to do so. We do not sell personal data.
- Railway provides backend hosting, databases, and object storage. Website delivery and network infrastructure providers process requests to deliver the website and app resources.
- Stripe processes card-based subscriptions and payments. Apple processes subscriptions purchased through the App Store.
- Strava receives and provides data when you connect your Strava account and use Strava features.
- Mapbox processes coordinates and map requests for maps, routing, elevation, and map matching.
- OpenRouter routes AI generation and content-safety requests to model providers. Those providers receive the prompt, training context, or name or title needed for the relevant request.
- Resend or our configured SMTP mail provider handles account and service emails. Email and support providers also process correspondence with us.
- Other KOMRIDER users receive rider and community information through live rides, friendships, events, and rankings as described above.
- Authorities or courts may receive data if we are legally obliged to disclose it.
7. International transfers
KOMRIDER is based in Switzerland. The European Commission recognises Switzerland as providing an adequate level of data protection. Some third-party providers may process data in the EU/EEA, Switzerland, the United States, or other countries.
Where data is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as standard contractual clauses, recognised data protection frameworks, or another lawful transfer mechanism.
8. AI features
AI generation sends your request and relevant training context through OpenRouter to the model provider selected for the request. This can include training goals, available time, experience level, FTP, constraints, and target training load. Payment details and account passwords are not part of these generation requests. The training plan generator removes the recent-activity summary before calling the AI provider; an adjusted target training load can still form part of the request.
KOMRIDER stores workout drafts, original and normalised prompts, generation metadata, accepted workouts, and personal plan instances linked to your account. When AI diagnostic logging is enabled, additional requests, responses, errors, and training context are stored for troubleshooting. This is separate from the AI providers' own processing. We do not promise that requests are never stored by those providers.
Content-safety checks also use OpenRouter and a model provider. Proposed usernames, route names, and meet-up titles can therefore be sent to an AI service even when you are not generating a workout or plan.
Do not include personal data, health information, or sensitive information in AI prompts unless it is necessary for the requested result. AI-generated workouts and plans are KOMRIDER product output and may require manual review before use.
9. Retention
- Account data is kept while your account exists and is deleted or anonymised after account deletion unless legal obligations require longer retention.
- Personal training settings, their histories, saved activity metrics, accepted workouts, and personal plan data are kept to provide your training history and planning features. Inactive generated plans can be removed when service cleanup runs.
- Workout drafts have an expiry time and are removed during service cleanup after acceptance, rejection, or expiry and the applicable retention period. Expiry does not immediately erase the draft, and accepting a draft creates a separately stored workout with generation metadata.
- Live presence is temporary and expires when it is no longer refreshed. Activity summaries, event participation, and ranking results have separate lifecycles.
- Where AI diagnostic logging is enabled, diagnostic records are separate from workout drafts. Draft expiry does not delete those logs; account deletion includes their removal.
- Subscription and billing records are kept as long as required for contractual, accounting, tax, and legal purposes.
- After account deletion, pseudonymised trial eligibility records remain detached from the account solely to prevent repeated or abusive use of free trials. They are deleted automatically no later than 24 months after account deletion.
- Short-lived deletion records and access-revocation markers are retained only as long as needed to complete the deletion reliably and invalidate previously issued access tokens.
- Local app data remains on your device until you delete it in the app, remove the local files, or uninstall/delete the app data.
- Server logs are generally kept only as long as needed for security, debugging, and operation, and normally no longer than 12 months.
- Backups may retain deleted backend data for a limited period, normally no longer than 6 months, before they are overwritten or deleted.
- Strava connection data is kept only as long as required to maintain the connection, comply with your request, or revoke access when the connection or entitlement ends.
- Synced Strava activity summaries and derived zone records cover a recent activity window and are deleted when you disable the recent-training-load feature, disconnect Strava, or delete your account.
- Support correspondence is kept as long as needed to process your request, resolve follow-up questions, and comply with legal obligations.
10. Your rights
Depending on your location and the applicable law, you may have the right to:
- Request access to your personal data and receive a copy.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of personal data where the legal requirements are met.
- Request restriction of processing.
- Object to processing based on legitimate interests.
- Receive personal data that you provided to us in a structured, commonly used, machine-readable format where data portability applies.
- Withdraw consent at any time with effect for the future.
- Lodge a complaint with a competent data protection authority.
To exercise your rights, contact info@komrider.com. We may need to verify your identity before responding.
11. Export and deletion
You can delete your account using the self-service controls in the account settings of supported KOMRIDER apps or request deletion by contacting info@komrider.com. Depending on the subscription, you can delete the account immediately or schedule deletion for the confirmed end of the current subscription period. A scheduled deletion can be withdrawn before it is executed.
Account deletion removes or anonymises account-linked profile, training, activity, rewards, friendship, event, and subscription data from KOMRIDER's active systems. It also removes stored connection credentials and requests revocation of the KOMRIDER connection at Strava. If an individual backend component is temporarily unavailable, the account is disabled and the remaining deletion work is retried automatically.
Account deletion and subscription cancellation are separate processes. KOMRIDER stops renewal of eligible Stripe-managed subscriptions as part of an immediate or scheduled deletion. Subscriptions purchased through Apple must be managed separately in the user's Apple subscription settings. Billing and transaction records that must be retained for accounting, tax, contractual, or legal purposes remain stored without the active KOMRIDER account relationship.
You can request access to your personal data and, where applicable, a portable copy by contacting us. This includes the applicable account and subscription data, rewards, activity metrics, training settings and histories, personal plan assignments and adjustments, and account-linked generation inputs and metadata. Generic KOMRIDER catalogue content is distinct from these personal records. A plan or workout being product content does not exclude your associated personal data from the request. Access and data-portability rights can have different scopes; a local activity export is not a complete export of the personal data held in your KOMRIDER account.
The desktop app attempts to remove its KOMRIDER tokens, completed-activity snapshots, and offline queue after a successful self-service deletion or when the backend reports that the account was deleted on another device. Other files stored only on your device, including separately exported files, remain until you remove them or uninstall/delete the app data.
12. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted transport, password hashing, access controls, and restricted operational access. No system is perfectly secure, but we keep the amount of backend data limited and avoid collecting data we do not need.
13. Children
KOMRIDER is not intended for children under 16. We do not knowingly collect personal data from children under 16.
14. Changes
We may update this Privacy Policy from time to time. Significant changes will be announced in the app, on the website, or by email where appropriate. The latest version is always available at https://www.komrider.com/legal/privacy.
15. Contact
If you have questions or want to exercise your rights, contact: info@komrider.com