Cycloscape

Privacy Policy

Last updated: June 20, 2026

Cycloscape (“Cycloscape”, “we”, “us”) operates the website at cycloscape.com, where you can upload a GPX route and ride it as an immersive 3D world. This policy explains what personal data we process and why. Questions: info@cycloscape.com.

1. Information we collect

  • Account information. When you sign in with Google, we receive your name, email address, and profile picture from your Google account.
  • Routes you create. The GPX files you upload and the analysis we compute from them (distance, elevation, gradients, climbs, and the geographic coordinates of the route), plus any routes you choose to save to your library.
  • Strava data (optional). If you connect Strava, we access your Strava profile and the activities or routes you import, under the permissions you approve (read, activity:read_all). We store Strava access and refresh tokens so the connection keeps working until you disconnect.
  • Technical data. Standard server logs (such as IP address, browser type, and pages accessed) collected by our hosting provider to operate and secure the service.

2. How we use your data

To authenticate you, generate and store your 3D worlds, show your route library, connect to Strava at your request, keep the service secure, and improve how it works. We do not use your data for advertising and we do not sell it.

3. Legal bases

Where the GDPR applies, we process your data to perform our contract with you (to provide the service), on the basis of your consent (for example, connecting Strava), and for our legitimate interests in keeping the service secure and improving it.

4. Service providers

We share data only with providers that help us run Cycloscape:

  • Supabase — database, authentication, and file storage.
  • Vercel — hosting and content delivery.
  • Google — sign-in.
  • Strava — only if you connect it, to import your activities and routes.
  • YouTube (Google) — only if you connect it, to create and start a live broadcast on your own channel. See section 4b.

4b. YouTube — what connecting your channel means

Cycloscape uses YouTube API Services. Connecting your channel is entirely optional; everything else on Cycloscape works without it, including hosting a group ride and sharing the link.

When you connect it, we store, and nothing else:

  • An access token and refresh token for your Google account, so we can start a broadcast on your behalf when you press Go Live.
  • Your channel ID and name, so we can show you which channel you are about to stream to.

We use them for one thing: creating a live broadcast and its stream on your channel when you ask us to, and stopping it when the ride ends. We do not read your videos, your analytics, your subscribers or your comments, and we never post to your channel outside a ride you started.

You can disconnect at any time from Settings, which deletes both tokens from our database and revokes them with Google. You can also revoke Cycloscape’s access independently at Google’s security settings, which works even if you never come back here.

Who else sees it: nobody. We do not sell, rent or transfer your YouTube data to anyone. It is never shared with advertisers, data brokers or analytics providers, and it is never used to train machine-learning models. The only parties that touch it are the infrastructure providers listed in section 4, acting solely on our instructions to run the service — Supabase, which stores it, and Vercel, which hosts the code that reads it.

How it is protected. The tokens live in a database table that is locked to server-side access only: row-level security is enabled on it with no policy granting browser access, so they can never be read from the client, by you or by anyone else. Our servers reach them through a privileged key that never leaves the server. All traffic is encrypted in transit over HTTPS with HSTS.

How long we keep it. Only while your channel is connected. Pressing Disconnect deletes the access and refresh tokens and the channel details from our database immediately, and asks Google to revoke the token as well. Deleting your Cycloscape account removes them too. We keep no backup copy and no archive of your YouTube data.

Cycloscape’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your use of YouTube through Cycloscape is also governed by the YouTube Terms of Service and the Google Privacy Policy.

5. Storage and security

Your data is stored with Supabase and protected by row-level security, so each account can only access its own profile, routes, and Strava connection. The Strava and YouTube tokens go further: their tables have row-level security with no policy at all, so they are unreadable from a browser and reachable only by our server. All traffic is encrypted in transit over HTTPS.

6. Retention

We keep your account and saved routes until you delete them or ask us to close your account. Disconnecting Strava or YouTube deletes the stored tokens for that service immediately, and in YouTube's case also asks Google to revoke them.

7. Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing or withdraw consent. To exercise these rights, email info@cycloscape.com. If you are in the EU/EEA, you may also lodge a complaint with your local data protection authority.

8. Cookies

We use strictly necessary cookies to keep you signed in (your authentication session). We do not use advertising or third-party tracking cookies.

9. Children

Cycloscape is not directed to children under 16, and we do not knowingly collect their personal data.

10. Changes

We may update this policy from time to time. We will post the updated version on this page and revise the date above.

11. Contact

Cycloscape · info@cycloscape.com. See our contact page for our postal address.