Upshift Cycling

Privacy Policy

Updated: October 3, 2026
Your rides start private. You can use Upshift Cycling as a guest. Ride history stays on your device unless you choose to export it or explicitly back it up to an optional account. The app includes no advertising or analytics SDKs and does not sell your personal information. Infrastructure requests retain the network information described below.

Which release this describes. Version 1.0.2, build 17 is the current public release as checked on October 2, 2026. Outdoor GPS recording and optional account backup in the mobile app are being prepared for the next release. The optional account website is now available at /account. This does not announce a new public mobile-store release.

Guest use and local history

Upshift Cycling is provided by Vakil Ventures LLC. No account or email address is needed for guest riding. Power, cadence, ride times, summaries, workout settings and, in the planned outdoor release, route points and ride statistics are stored locally. Signing in, signing out or connecting another device does not automatically upload your guest history. Device or operating-system backup services may keep app data according to your settings; they are separate from Upshift's optional cloud backup.

Bluetooth

The app connects to your Bluetooth Low Energy (BLE) power meter only to read live power (watts) and cadence (RPM) using the standard Cycling Power Service. This connection displays and records your ride locally. Upshift never writes to or changes any setting on your meter. Power and cadence records leave Upshift only through an export or an explicit optional backup choice.

Outdoor location and background recording

The planned outdoor recorder explains location use before asking for system permission. After you start a ride and allow precise location, it records latitude, longitude, timestamps and GPS accuracy to draw your route and calculate distance, active duration and average speed. An active ride can continue recording while your screen is locked or you use another app. Background recording uses additional battery and can be interrupted by system limits or unavailable GPS.

Pause or finish stops route collection. A recovered interrupted ride remains paused until you resume it. Upshift does not record a route when you are not recording an outdoor ride. You can decline or revoke location permission and continue using the meter and other guest features. GPS recording works without mobile data; account operations require an internet connection.

Exports are your choice

CSV meter exports and planned GPX outdoor exports open the operating system's share sheet only after you choose to share. A GPX export includes precise route points and timestamps, which may reveal your home, workplace and start or finish location. The app warns you before sharing. Choose destinations you trust; their handling of an exported copy is governed by their own policies.

Optional accounts and explicit backup

Optional registration uses the name you enter, your email address and a password. The service stores a password hash, an account ID and email-verification status. Verification and password-reset messages use Amazon Web Services SES. Email verification is required before signing in or using backup.

Signing in alone does not upload rides. A separate confirmation is required to back up your chosen history, including any precise routes and fitness statistics it contains. Backups are linked to your account. Restoring adds missing rides to local history; it does not replace or erase your guest rides. Cloud connections use HTTPS. These backups are not end-to-end encrypted: Upshift's operator can access server-side data to provide and maintain the service.

Connecting devices and protecting access

The device connection flow uses a device name and a temporary code. A verified account holder must review the named device and confirm that the displayed code matches a device in their possession. Codes expire after ten minutes. Only approve requests you started. You can sign out or revoke a connected device; password reset revokes existing sessions. Accounts are not automatically linked to another sign-in provider.

Authentication uses session records, including IP address and user-agent information, verification or reset records, and short-lived abuse-prevention identifiers. These support access controls and rate limits. They are not used for advertising or analytics. The app keeps native sign-in tokens in the operating system's secure credential storage; browser sessions use secure cookies.

Service providers

The existing website is hosted on Oracle Cloud and served through Cloudflare. Website and update-check requests expose ordinary network information such as an IP address to that infrastructure. The app checks for updates and, when you open account settings, checks whether the account service is available. These requests send no recorded route points or ride statistics.

The existing Oracle web server writes access logs. Its configured fields are the connecting IP address, any forwarded IP addresses supplied in request headers, an HTTP authentication username when supplied, request time, method, URL including query parameters and HTTP version, response status and byte count, and referrer and user-agent headers when present. These infrastructure records are retained beyond the request itself. Cloudflare may keep separate network and security records; its deployment-specific logging settings and retention have not yet been verified.

Optional accounts are hosted on the same infrastructure, with Amazon Web Services SES for verification and password-reset delivery. Account email delivery does not include your ride routes. No advertising networks, marketing email campaigns or rider analytics are part of Upshift.

Delete your data or request account deletion

You control local ride history in the app. Deleting a local ride does not delete a copy already exported or backed up. Cloud controls let you delete individual backups or all cloud history separately. Account deletion requires password confirmation and removes the active account, its cloud ride backups, connected sessions and pending device connection records. It does not erase local guest history or copies you shared elsewhere.

Account deletion is available on the account website and in the upcoming mobile account controls. You can also request account and associated data deletion by emailing [email protected]. Please identify Upshift Cycling and the account email address. We will verify ownership; do not send your password, verification code or a private route.

Retention

Local history remains until you delete it or remove the app, subject to your device's storage and backup settings. Active cloud copies remain until you delete them or your account. Device codes and sign-in sessions have access-expiry limits; expiry does not by itself promise that every recovery copy has been erased.

The existing Oracle web-server log rotation is configured to run daily, compress rotated logs and retain ten rotated archives in addition to the active log. This describes the origin server's configuration, not a verified deletion deadline for every record or copy. Empty logs may skip rotation, and Cloudflare and other infrastructure copies have separate retention arrangements that have not been verified. We do not promise that all network information is deleted within ten days.

Account records, password hashes and account-linked security records remain while your account exists. Deleting the account removes its active database records, ride backups, sessions and device connections. Sessions expire after 30 days, verification links after one hour, and device codes after ten minutes; expired records may remain until subsequent service cleanup or account deletion. Rate-limit identifiers are removed when their window has elapsed and a subsequent rate-limited request runs cleanup; these identifiers are not linked to account deletion.

Routine recovery snapshots containing account data are not currently configured. Existing pre-activation snapshots contain no registered accounts. We will publish retention and deletion arrangements before enabling account-data snapshots. Application logs record email delivery failure status without recipients, verification links or ride locations; Amazon SES processes the recipient and message to deliver transactional email. Provider infrastructure records are subject to the providers' retention arrangements; we do not promise a deletion deadline for those records. Account/API routes have origin access logging disabled; other website routes retain the server logs described above.

Children

Upshift Cycling is a general-audience cycling tool. Guest use does not require a name or email address. If you have a concern about information a child provided to an optional account, contact us so we can investigate and remove it where appropriate.

Changes

Changes will be posted here with an updated date and accurate feature availability. We will update this policy when feature availability or personal-information handling changes.

Contact

Questions? Email [email protected].