LEGAL
Privacy Policy
Slipstream is local-first. The app works completely without an account, and what leaves your phone only does so because you signed in and asked it to.
This policy explains what Slipstream does with your personal data, and the rights you have over it under the General Data Protection Regulation (GDPR) and Slovenian data protection law.
1. Who we are
[LEGAL ENTITY NAME] ("we", "us") is the data controller for the personal data described here.
| Entity | [LEGAL ENTITY NAME] |
| Registered address | [REGISTERED ADDRESS] |
| Registration number | [COMPANY REGISTRATION NUMBER] |
| VAT number | [VAT NUMBER] |
| Privacy contact | privacy@slipstream.app |
| General contact | support@slipstream.app |
If you have a question about your data, write to the privacy address. We answer within one month, as GDPR requires.
2. The short version
Slipstream runs on your phone. Every ride, workout, FTP value and setting is stored on the device, and the app is fully usable with no account and no network connection. That is a design constraint, not a fallback.
Signing in adds one thing: sync across your devices. Nothing is uploaded before you create an account.
We do not sell your data. We do not share it with advertisers. There is no analytics SDK and no crash-reporting SDK in the app — we do not track how you use it, because we do not collect anything that would let us. This website counts page views with a cookieless tool that cannot identify you; Section 12 says exactly what it does.
3. What stays on your device
Until you sign in, all of it:
- Completed rides, including the second-by-second power, heart-rate and cadence samples
- Your FTP and its history
- Workouts, plans and progress
- App settings and preferences
Deleting the app removes all of this. If you never sign in, we never receive any of it, and we have no record that you exist.
4. What we store when you sign in
Creating an account stores the following, and nothing else:
| Category | Fields |
|---|---|
| Account | Email address. If you use Sign in with Apple and choose to hide your address, we receive only Apple's relay address. |
| Profile | Display name, body weight, height, sex, year of birth, FTP, and the date FTP was last tested. |
| Rides | Start time, workout name, duration, and the recorded sample series — power, heart rate and cadence over the ride. |
| Training | Plans you have enrolled in, and any workouts you have built yourself. |
| Settings | Your app preferences, including whether you opted in to marketing email. |
| Strava (only if you connect it) | Your Strava athlete ID and display name, the access and refresh tokens that let us upload on your behalf, and a record of each upload — which ride, when, whether it succeeded, and the resulting Strava activity ID. See Section 8a. |
There is no location tracking, no contacts access, no advertising identifier and no behavioural profile. We do not know what other apps you use, and we do not build a picture of you beyond the training data above.
5. Health data
Some of what Section 4 describes is capable of revealing information about your health — heart rate in particular, and body weight, sex and year of birth when combined to calculate training load and zones.
We treat this as special category data concerning health under Article 9 of the GDPR, and process it only with your explicit consent, given when you create an account and accept this policy.
What that means for you in practice:
- You can withdraw that consent at any time by deleting your account (Section 10). Withdrawal does not affect processing carried out before it.
- The app works without it. Heart rate is optional — Slipstream will pair with a trainer and record power and cadence with no heart-rate sensor connected, and the body metrics exist to make training targets meaningful, not because we require them.
- We do not disclose this data to anyone. It is never used for advertising, never sold, and never shared with insurers, employers or health providers.
6. Why we are allowed to process it
| Purpose | Legal basis |
|---|---|
| Creating your account and syncing your rides between your devices | Performance of a contract — Art. 6(1)(b) |
| Storing heart rate and body metrics to calculate zones and training load | Your explicit consent — Art. 9(2)(a) |
| Sending you training tips and occasional offers by email | Your consent — Art. 6(1)(a), withdrawable at any time |
| Uploading your rides to Strava, if you connect it | Your consent — Art. 6(1)(a), withdrawn by disconnecting |
| Keeping the service secure and preventing abuse | Our legitimate interests — Art. 6(1)(f) |
| Responding to a support request you send us | Performance of a contract, and our legitimate interest in answering you |
We do not use your data for automated decision-making that produces legal effects, and we do not profile you.
7. How long we keep it
- Your rides and profile are kept for as long as your account exists. This is deliberate: training history is only useful over seasons.
- When you delete your account, deletion begins a 14-day grace period. Nothing is destroyed during it, and signing back in cancels the deletion entirely. After 14 days a scheduled job permanently removes your account, every row belonging to it, and any export files still in storage. That step is not recoverable.
- Data exports are deleted as soon as you request a new one, and the download link expires after one hour.
- Strava tokens, if you connect it, are kept until you disconnect or delete your account, and are removed immediately in either case. The record of which rides were uploaded is kept with the rest of your account data.
- Support email is kept as long as needed to deal with your request and to keep a record of it.
8. Who else processes it
We keep this list short on purpose. Each of these is a processor acting on our instructions under a data processing agreement.
| Processor | What they do | Where |
|---|---|---|
| Supabase | Hosts the database, authentication and file storage behind sync | European Union |
| Cloudflare | Serves this website, counts page views (cookieless — see Section 12), and runs the small authentication worker behind our content editor | Global edge network |
| Apple | Distributes the app, provides Sign in with Apple, and processes subscription payments | Ireland / United States |
| Strava | Receives the rides you choose to upload, only if you connect your account | United States |
Apple is a separate controller for the payment itself. We never see your card details — subscriptions are bought and billed inside the App Store, and what reaches us is the fact that you have an active subscription.
We do not use any advertising network, data broker or customer-tracking tool. The only measurement anywhere is the cookieless page-view counting on this website described in Section 12 — it is not connected to your account and does not apply to the app at all.
8a. Connecting Strava
Strava is entirely optional and off unless you turn it on. If you never connect it, nothing in this section happens and no data reaches Strava.
What we send. When a ride finishes we upload a standard .tcx file
containing the ride's second-by-second record: timestamps, elapsed distance,
speed, cadence, heart rate and power, plus the workout's name and a note that
it was recorded with Slipstream. No location data is included — these are
indoor rides and the file contains no GPS coordinates at all.
Strava is a separate controller, not a processor acting for us. Once a ride
is in your Strava account it is governed by Strava's own privacy policy and
your Strava privacy settings, including who can see it. We cannot see your
Strava activities, feed, followers or anything else: the access we request is
write-only (activity:write). We can add rides; we cannot read them back.
Where the tokens live. Connecting Strava stores an access and refresh token so uploads can continue without asking you again. Those tokens never reach the app on your phone — the exchange happens server-side, because it needs a secret that cannot safely ship in an app bundle. In the database they sit in a table with row-level security enabled and no policies at all, meaning no signed-in user — including you — can read it; only our server-side functions can.
Why your data export leaves them out. The export in Section 10 includes the full record of your uploads but deliberately excludes the tokens. Writing live credentials into a file you download would turn a privacy feature into a way to leak them. Everything about your uploads is there; the keys are not.
Disconnecting. Turn Strava off in the app at any time. We ask Strava to revoke the authorisation and then delete our copy of the tokens regardless of whether Strava answers — so a disconnect always removes our access even if Strava is unreachable. Rides already uploaded stay in your Strava account, because they are yours; delete them there if you want them gone.
Transfers. Strava is based in the United States, so choosing to connect it means the rides you upload are transferred outside the EEA. That transfer happens because you asked for it, and it relies on your explicit consent for that specific purpose.
9. Where it is stored
Your account data lives in a Supabase project hosted in the European Union, so it does not leave the EEA in the ordinary course of using Slipstream.
Three exceptions worth naming honestly:
- Cloudflare serves this website from a global edge network, so a request for a page may be answered by a server outside the EEA. Those requests carry no account data.
- Apple operates internationally; where Apple transfers data outside the EEA it does so under its own safeguards, described in Apple's privacy policy.
- Strava, if you connect it, is in the United States — so the rides you upload go there. This one is entirely your choice and does not happen unless you switch it on. See Section 8a.
10. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectify data that is wrong or incomplete
- Erase your data ("right to be forgotten")
- Restrict processing in certain circumstances
- Port your data — receive it in a machine-readable format and take it elsewhere
- Object to processing based on our legitimate interests
- Withdraw consent at any time, where consent is the basis
- Complain to a supervisory authority
Most of these you can exercise yourself, immediately, without asking us:
- Access and portability — Settings → Account → Export my data. This produces a complete machine-readable dump of your profile, settings, plans, custom workouts and every ride. The download link is valid for one hour.
- Rectification — edit your profile in the app.
- Erasure and withdrawal of consent — Settings → Account → Delete account, which starts the 14-day process in Section 7.
- Marketing consent — turn email off in the app's notification settings, or use the unsubscribe link in any message we send.
- Strava consent — disconnect Strava in the app, which revokes our access and deletes the tokens (Section 8a). You can also revoke it from Strava's own settings.
For anything else, write to privacy@slipstream.app.
If you think we have handled your data wrongly, you can complain to the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia) — https://www.ip-rs.si — or to the supervisory authority where you live. We would rather you told us first, so we can put it right.
11. Children
Slipstream is not intended for children. You must be at least 16 years old to create an account. We do not knowingly collect personal data from children below that age; if you believe a child has given us data, contact us and we will delete it.
12. This website
This site sets no cookies of its own and does not track you between visits or across other websites. There is no consent banner because nothing here stores or reads anything on your device.
Three things involve a third party:
- Visitor statistics. We use Cloudflare Web Analytics to see which pages people read and roughly where they come from. It is deliberately chosen because it is cookieless: it stores nothing on your device, uses no fingerprinting, assigns you no identifier, and cannot follow you to another site. It reports aggregate counts — page, referring site, country, browser and page-speed measurements. Your IP address is processed to derive the country and is not stored by us. We cannot identify you from any of it, and there is nothing here for you to opt out of because there is nothing tied to you. Legal basis: our legitimate interest in knowing whether the site works (Art. 6(1)(f)).
- Typefaces are loaded from Google Fonts, which means Google receives the request for those font files, including your IP address. The Slipstream app itself bundles its fonts and does not do this.
- Cloudflare serves the site and processes request logs, including IP addresses, to deliver pages and protect against attack.
The editor at /admin/ is for our own use, requires a GitHub sign-in, and is
excluded from search engines.
13. Security
- Every database table enforces owner-only row-level security, so the database itself refuses to return another person's rows. This is the real boundary, not something the app politely chooses to respect.
- On iOS, authentication tokens are stored in the system Keychain, not in ordinary app preferences.
- All traffic is encrypted in transit.
- Data exports are delivered over short-lived signed links rather than public URLs.
No system is perfectly secure. If you find a vulnerability, please tell us at privacy@slipstream.app before disclosing it publicly.
14. Changes to this policy
If this policy changes materially we will update the date at the top of this page, and where the change affects you meaningfully we will tell you in the app or by email before it takes effect. The full revision history of this page is public.