Who we are
Drais provides software for managing bikes, components, maintenance, ride history, gear and community features. For personal data processed within Drais, Drais acts as the data controller unless a feature states otherwise.
Data controller: Lukasz Klemens, trading as Drais (sole trader, Netherlands). Dutch Chamber of Commerce (KVK) number 64745239. Contact: info@drais.app. Our postal address is available on request by email.
Contact point under the Digital Services Act (Regulation (EU) 2022/2065). info@drais.app is our single point of contact both for users of the service (Article 12) and for Member State authorities, the European Commission and the European Board for Digital Services (Article 11). We can be contacted in Dutch or English, and messages are read by a person.
What data we collect
- Account data. Email address, display name, authentication identifiers, language, settings and support messages. If you sign in with Apple or Google, we receive the identifier and email address that service returns to us — we never receive your password.
- Device permissions. Depending on your device and settings, Drais may use: location (ride recording, live group-ride location, SOS, nearby group rides), camera and photo library (bikes, parts, receipts), microphone (voice messages and voice dictation), speech recognition (converting dictated notes into text), Bluetooth (cycling sensors), biometrics (unlocking the app with Face ID or a fingerprint) and notifications. You can manage every one of these in your device settings, and the related feature simply stops working if you decline.
- Bike and component data. Bike names, photos, serial numbers (if you add them), component details, installation dates, costs, weight, wear estimates and service intervals.
- Maintenance data. Service logs, reminders, notes, receipts (if you upload them) and cost records for DIY or workshop work.
- Ride data, including GPS routes. Distance, duration, date, elevation, speed, linked bike, imported ride metadata and manually entered rides. When you record a ride, the app uses your device's GPS — including while the screen is off or the app is in the background, so the route is not lost mid-ride. The recorded route is stored on your device and synchronised to your account on our servers, so your rides are available across your devices and survive losing your phone. Routes are never shown to other users unless you choose to share or publish a ride, and are never used for advertising. If you set privacy zones, the parts of a route inside them are removed before the route is stored — they are not reconstructed anywhere. Deleting a ride deletes its route from your device and from our servers.
- Health and fitness data. Ride distance, duration, elevation, speed and pace. If you pair Bluetooth cycling sensors, we also record heart rate, power, cadence and speed, and store per-ride summaries (such as average and maximum heart rate, average power and cadence) in your account. If you connect Strava, imported activity detail can contain the same categories. We use this only to show you your own rides and to keep bike and component mileage accurate. We do not share health or fitness data with other users, do not use it for advertising, and do not use it to train machine-learning models.
- Live location during group rides. If you join a group ride and enable live tracking, the app shares your current GPS position in real time with the other participants. Live tracking is opt-in and off by default, is active only during the group ride, and stops as soon as you leave it. Raw position updates are deleted from our servers after 90 days. A reduced-resolution track of the ride (roughly one point every five minutes) is kept so participants can review the route afterwards, and is also deleted after 90 days. Live location data is never used for advertising and never sold.
- SOS and emergency contacts. If you set up SOS, we store the emergency contacts you choose. When you trigger SOS, each contact receives a message identifying you by display name together with a link showing your current location, for as long as the alert is active. SOS is not an emergency service — see our Terms of Service. If an emergency contact is not a Drais user and we cannot notify them directly, this policy serves as the information required by Article 14 GDPR; they can ask us to delete their details at info@drais.app. Please only add someone who has agreed to be your emergency contact.
- Photos, video and voice messages. Photos and videos you add to bikes, parts, maintenance logs, posts or listings. If you send a voice message in chat, the app uses your microphone; recordings are stored only if you send them and are deleted when you or the recipient deletes the message. If you dictate a maintenance note, your device's own speech-recognition service converts the audio to text — on some devices and settings that processing happens on Apple's or Google's servers under their privacy policies, and the resulting text is what Drais stores.
- Integration data. Access tokens and imported activity data from services you choose to connect, such as Strava, Wahoo or Garmin. See section 05.
- Community data. Profile data, forum posts, chat messages, marketplace listings, group rides, club activity, reports you submit and moderation records.
- Technical data. Device type, app version, logs, crash diagnostics, security alerts, sync metadata and — if you enable notifications — a push notification token issued by Apple or Google.
- Website analytics. When you visit drais.app, Google Analytics (GA4) collects page views, an approximate location derived from IP, browser/device type, referring URL and session duration — only after you accept the cookie notice.
- Session replays and heatmaps. Only after you accept the cookie notice, Microsoft Clarity records a pseudonymised replay of your visit: mouse movement, clicks, scrolling, the page URLs you visit, referring URL, browser and device type, and an approximate location derived from your IP address. Text you type into form fields (such as your email address) is masked by Clarity in every masking mode and is not sent to Microsoft. Clarity is not loaded on pages whose URL can contain a sign-in or recovery code.
Product analytics in the mobile app. The mobile app includes Google Analytics for Firebase (GA4), provided by Google, which we use only for aggregate product-usage analytics — which screens and features are opened, and whether a flow such as onboarding was completed. It is off by default: nothing is collected until you explicitly opt in, and you can turn it off again at any time in Settings → Privacy. While it is off, the app sends no analytics events at all. These events carry no names, no e-mail addresses, no tokens and no free-text content you have written.
Advertising identifiers. Drais contains no advertising SDKs and shows no ads, and our own code never reads the advertising identifier of your device. Because the Android app includes Google Analytics for Firebase, Google's analytics library adds the com.google.android.gms.permission.AD_ID permission to the Android app, and while product analytics is switched on Google Analytics for Firebase can access the Google Advertising ID. Product analytics is off by default, and while it is off nothing is collected — including the advertising ID. We never use the advertising ID for advertising profiling, for building audience segments, for sharing with ad partners, or to track you across other apps or websites. You can reset or delete your Google Advertising ID at any time in your Android settings. On iOS, Drais does not use the Apple Identifier for Advertising (IDFA): the app never requests tracking permission and no IDFA is collected. Microsoft Clarity runs only on the drais.app website and is never loaded in the mobile app.
We do not sell personal data. We do not use bike, ride, maintenance, health or device data for advertising profiling, for creating audience segments, or for sharing with ad partners.
Why we use data
- To create and secure your account.
- To store, sync and display your bikes, parts, rides, gear, maintenance and costs.
- To calculate component mileage, wear estimates, service reminders and ownership insights.
- To provide community, chat, marketplace, club and group ride features when you use them.
- To deliver notifications you have asked for.
- To connect optional integrations you authorize.
- To respond to support, security and privacy requests.
- To moderate content, keep the community safe and act on reports of illegal content.
- To improve reliability, prevent abuse and meet legal obligations.
GDPR legal bases
- Contract. To deliver the Drais app and account features you request.
- Consent. For optional integrations, live location sharing, SOS, certain communications, in-app product analytics (Google Analytics for Firebase), and website analytics (Google Analytics and Microsoft Clarity) when you accept the cookie notice. You can withdraw consent at any time via Cookie settings on the website, or Settings → Privacy in the app.
- Legitimate interests. To secure the service, prevent fraud and abuse, moderate community content, and monitor crash rates and sync reliability so we can fix defects. Where we rely on this basis, you can object at any time — see section 10.
- Legal obligation. When we must retain or share limited information to comply with applicable law, including our obligations under the Digital Services Act.
Health-related data. Heart rate and comparable physiological metrics from Bluetooth sensors or imported activities may constitute data concerning health under Article 9 GDPR. Where they do, we process them only on the basis of your explicit consent under Article 9(2)(a), given when you pair a sensor or connect an activity platform, and only to show you your own rides and calculate your maintenance schedules. You can withdraw that consent at any time by unpairing the sensor or disconnecting the integration.
Automated decision-making. We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. We use a limited set of automated signals to flag suspected spam, fraudulent listings, duplicate accounts and abusive content for review, but a person at Drais makes the final decision to remove content or restrict an account, and you can ask for that decision to be reviewed — see our Terms of Service.
Do you have to give us this data? An email address and a display name are required to create an account: without them we cannot provide the service or enter into the contract with you. Everything else — bike and component records, photos, rides, GPS recording, Bluetooth sensors, microphone access, live group-ride location, SOS contacts, integrations and website analytics — is optional. If you do not provide it, the related feature will not work, but the rest of Drais will.
Integrations
If you connect a third-party service (such as an activity platform or a bike computer), Drais only imports the data necessary for the feature you authorize — distance, date, duration and linked gear where available, plus activity detail where the platform provides it. Drais uses this data to update ride history, bike mileage, component wear and maintenance reminders. Drais does not write activities back to activity platforms and does not sell or share integration data for advertising.
Alongside Strava, Drais can connect to Wahoo and Garmin where those integrations are available to you. Each is optional, each is authorised through that provider's own consent screen, and each can be disconnected in the app at any time. Your use of those services remains subject to their own terms and privacy policies. When you disconnect, we delete the stored access tokens and stop importing new data.
Strava. When you connect Strava, Drais requests the following OAuth scopes with your explicit consent on Strava's authorisation screen:
profile:read_all— your Strava athlete profile (name, profile photo, and bikes/gear registered on your Strava account).activity:read— your activity list and summaries (distance, date, duration, gear used). This is the default.activity:read_all— requested only if you opt in to importing your private activities. If you do not opt in, Drais usesactivity:readonly and cannot see activities you have marked private on Strava.
When you open an imported ride, Drais fetches that activity's detail from Strava. That detail can include heart rate, power, cadence, energy, suffer score, achievement and PR counts, the GPS route (map polyline), and the recording device. This is your own Strava data, shown only to you, and cached transiently — raw Strava records are purged automatically after no more than 7 days.
Drais uses your Strava data solely to (1) maintain your bike mileage automatically when a Strava activity logs mileage against a linked bike, and (2) populate your Drais ride timeline and inform maintenance schedules. We do not use your Strava data, or any data derived from it, for artificial-intelligence or machine-learning training, evaluation, grounding, embeddings, retrieval, or operation; for analytics, customer-insight generation, product improvement, benchmarking, advertising, or resale; or for disclosure to any person other than you. Strava may monitor and collect usage data related to Drais's use of the Strava API — see the Strava API Policy.
Strava-derived mileage. The component-wear mileage Drais calculates from your Strava activities is kept only while your Strava connection is active. When you disconnect or revoke access, this derived mileage is deleted or recalculated from your non-Strava data within 48 hours. Strava access and refresh tokens are stored securely server-side (not on your device and never in app builds) and are deleted when you disconnect or revoke access.
Disconnect and deletion. You can withdraw consent and remove all Strava data at any time via Profile → Connected Apps → Disconnect. This revokes Drais's access at Strava, deletes your tokens, removes rides imported from Strava, and deletes or recomputes any Strava-derived mileage. You can also revoke access directly in Strava's app settings — Drais receives an automatic deauthorisation notification and deletes your Strava data within 48 hours. To confirm deletion, contact us at info@drais.app.
Strava and the Strava marks are trademarks of Strava, Inc. Drais uses these marks under the Strava API Agreement and Strava Brand Guidelines solely to identify Strava as the source of imported activity data. Drais is not affiliated with, endorsed by, or sponsored by Strava, Inc.
You can disconnect integrations in the app at any time. If you revoke access through an external provider, Drais stops using that connection and deletes tokens in accordance with the provider's deauthorization flow and our retention periods.
Storage, processors and transfers
Drais stores core data locally on your device and syncs it with cloud infrastructure so that your account works across multiple devices. We use the following service providers:
- Supabase — authentication, database and file storage.
- PowerSync — offline-first synchronisation between your device and your account.
- Render — hosting for the Drais application and website, in the Frankfurt (EU) region.
- Sentry — crash reporting and performance monitoring.
- Resend — transactional email delivery.
- Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service) — delivery of push notifications for chat messages, group-ride invitations, reminders and SOS alerts. They receive a device push token and the notification content; they do not receive your account data.
- Google Ireland Limited (Google Analytics) and Microsoft (Clarity) — website analytics only, after cookie consent. Microsoft Clarity is not present in the Drais mobile app.
- Google (Google Analytics for Firebase) — aggregate product-usage analytics in the mobile app, and only after you have opted in.
- Apple and Google — if you use Sign in with Apple or Google Sign-In, they broker the credential and tell us that you authenticated.
We have executed Data Processing Agreements (DPAs) with our processors as required under GDPR Article 28. Every third party that processes personal data on our behalf is bound by a written agreement requiring them to protect your data to at least the standard described in this policy, to process it only on our instructions, and to delete or return it when our agreement ends.
Sentry processes crash logs, stack traces and device context (model, OS, app version). Sensitive fields — access tokens, refresh tokens, encrypted payloads, GPS coordinates and chat messages — are stripped before transmission. Crash data is processed on Sentry infrastructure in the EU (Frankfurt) or the US.
Crash reporting is on by default, and you can disable crash reporting at any time in Settings → Privacy. Crash reports are linked to the identifier of the account you are signed in with, which makes them pseudonymous rather than anonymous — that link is what allows us to find your reports and delete them. The app therefore also offers an Erase my crash data action in Settings → Privacy, which asks Sentry to delete the crash reports stored for your account. In any case, crash reports are retained for no more than 90 days.
Microsoft Clarity provides session replays and heatmaps for the drais.app website. For the data Clarity collects, Microsoft acts as an independent data controller and processes that data under the Microsoft Privacy Statement; for the collection and transmission of that data from our website, we and Microsoft act as joint controllers, and you can ask us for the essence of that arrangement at info@drais.app. Clarity is only loaded after you accept the cookie notice, at which point it sets the first-party cookies _clck and _clsk. We send Clarity a consent signal with advertising storage denied, so Microsoft's advertising cookies are not set. Data is processed on Microsoft infrastructure, including outside the EEA.
OpenStreetMap. Map tiles are served by the OpenStreetMap Foundation. When a map is displayed, your device requests tiles directly, which means the tile server receives your IP address and the map area you are looking at. We do not send it your account identifier or your route.
Open-Meteo provides weather forecasts for ride planning features. When the app needs a forecast, we send your approximate latitude and longitude to the public API. No account identifier, device identifier or API key is sent along. Open-Meteo states that it does not log personal data.
Transfers outside the EEA. Some providers process data outside the European Economic Area. Where they do, we rely on the European Commission's adequacy decision for the EU–U.S. Data Privacy Framework for providers certified under it, or on the Standard Contractual Clauses (Commission Decision (EU) 2021/914) together with a transfer impact assessment and additional technical measures such as encryption in transit and at rest. You can obtain a copy of the safeguards we rely on by emailing info@drais.app.
How we protect your data
All data transmitted between the app and our servers is encrypted in transit using TLS, and data stored with our hosting providers is encrypted at rest. Database access is governed by row-level security rules so that one account cannot read another account's data. Photos, videos, voice messages and ride data are stored in access-controlled buckets that require an authenticated, time-limited link. Access to production systems is restricted and protected by multi-factor authentication. Integration tokens are held in the device keychain or server-side secret storage, never in app builds. Crash diagnostics are kept separate from account content, with location coordinates and message content stripped before transmission.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will inform you and the Dutch Data Protection Authority as required by Articles 33 and 34 GDPR.
Retention periods
We retain account and app data for as long as your account is active or as long as needed to provide the service. Community content — forum posts, listings, club posts and chat messages — is retained while your account is active and until you or the other participant deletes it.
Group-ride location. Raw live-location updates and the reduced-resolution ride track are both deleted 90 days after the group ride.
Imported Strava records are purged after no more than 7 days; Strava-derived mileage is deleted or recalculated within 48 hours of disconnection.
Crash logs and diagnostics (Sentry) are retained for up to 90 days and then automatically deleted. If you switch crash reporting off, or use Erase my crash data in Settings → Privacy, we ask Sentry to delete the reports already linked to your account instead of waiting for that period to expire.
Moderation records — what we removed, why and when — are kept for 12 months, so that we can give you a statement of reasons and handle any challenge, as required by Regulation (EU) 2022/2065.
Session replays and heatmaps (Microsoft Clarity) are retained by Microsoft for 30 days. Recordings marked as favourites, a sampled subset of recordings, heatmaps and labels remain available for up to 9 months.
Deleting your account
You can delete your Drais account at any time from Settings → Account → Delete account in the app, or from drais.app/en/delete-account. You do not need to email us or call anyone.
Deleting your account removes your profile, bikes, components, maintenance records, rides and routes, photos and videos, voice messages, gear, costs and marketplace listings. Data on your device is erased at the time of deletion. Server-side records are deleted or irreversibly anonymised within 30 days unless a longer period is required by law, and backup copies expire as backups rotate.
Two things do not disappear automatically: chat messages you sent remain visible to the recipient unless they also delete them, and forum and club posts are either deleted or detached from your identity and shown as a deleted user, because they form part of another person's conversation. You can ask us to remove specific posts at info@drais.app. We may retain a minimal record where the law requires it — for example fraud or abuse records — and we will tell you if that applies to you.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, export or object to processing of your personal data. You may also withdraw consent where processing is based on consent, without affecting the lawfulness of processing before you withdrew it.
You can withdraw consent for optional processing (analytics, crash reporting, integrations, live location) via Settings → Privacy in the Drais app and via Cookie settings on the website, or by emailing info@drais.app.
To exercise any other right, email info@drais.app. We will respond without undue delay and in any event within one month of receiving your request. If your request is complex or you have made several requests, we may extend this by up to two further months; if we do, we will tell you within one month and explain why.
You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in the country where you live.
Children
Drais is not intended for children under 16, and you must be at least 16 to create an account. If you believe a child has provided personal data without appropriate consent, please contact us so we can review and remove it.
Changes
We may update this policy as Drais evolves. We will publish every version on this page with its version number and date. Where a change is significant, we will tell you by email or an in-app notice before it takes effect. Where a change concerns processing based on your consent, we will ask for your consent again rather than rely on this notice.