Privacy policy

This describes the BikeScout mobile app and the website at bikescout.app. It was written by reading what the software actually does — which fields a live-tracking point carries, which sweep deletes it and when, which hosts get contacted — rather than from a template. Where a limit is stated as a number, that number is the one in the code.

Version 1.0 · last updated 2 August 2026 · applies to the pre-release app and to this site

The short version

  • There is no analytics and no crash reporting. No Google Analytics, no Firebase, no Sentry, no advertising or attribution SDK — neither in the app nor on this website. Nothing here counts you.
  • Most of the app needs no account at all. Route planning, route push, ride download, rules and alerts all work signed out. An account exists only for live tracking, ride-notification e-mails and the Strava link.
  • Your routes, your ride files and your voice stay on the phone. Speech recognition runs on-device; there is deliberately no cloud speech tier.
  • Live tracking is the one feature that publishes your position, to anyone holding the link, for the length of the ride. Heart rate and power are off by default. Position points are deleted 24 hours after the ride ends; the session itself 7 days after that.
  • One thing the app does without asking: it checks for a code patch on launch, through Shorebird, and that check cannot be turned off. It carries no identity we give it — but it does reach a server. §10.1 explains exactly what we know and what we don't.
  • Nothing is sold, rented or shared for advertising. Ever.