Privacy Policy

Effective September 14, 2026

RouteSift is a cycling app for iPhone. This policy explains what it collects, why, who processes it for us, and the choices you have. It covers the app and routesift.app.

Who we are

RouteSift is an independent app made by Johnny Fairbank in the United States. Questions and requests about your data go to support@routesift.app.

What we collect

  • Account. Your email address, name, username, a hashed password, your time zone, and the photo, bio, location text, birth date and experience level you choose to add. With Sign in with Apple, Apple gives us your name and email, or a relay address if you hide your email.
  • Rides. When you record a ride we store its GPS track with times, speed and altitude, plus heart rate, power and cadence when a sensor provides them, the bike you chose, and the statistics we compute. Rides you import from a file are stored the same way.
  • Location. Your precise location while you record or navigate a ride, including in the background while a recording is running, if you allow it. The start point of each route you ask for. iOS asks before either happens, and you can change it in Settings at any time.
  • Routes. The requests you make (distance, preferences, start point and anything you type), the routes we build, the ones you save, and any share links you create.
  • Bikes and road reports. Bikes you add. Road reports you file: the location, the kind of problem, your description and a photo if you attach one.
  • Rider profile and health data. Height, weight, FTP, resting, maximum and threshold heart rate, VO2 max and cycling workouts, whether you type them in or, once available, share them from Apple Health. The health data page covers this in detail.
  • Connected services. If you connect Intervals.icu, TrainingPeaks, TrainerRoad, a calendar feed, Wahoo or Garmin, we store the credentials for that connection encrypted, and the workouts or routes that pass through it.
  • Usage. A small set of product events, such as an account being created or a route being built, with the app version and platform, stored in our own database, and ordinary server logs. RouteSift has no third-party analytics or advertising SDKs.
  • Preferences. Units, route defaults, and whether you want product updates by email.

How we use it

  • To build routes, explain them, and navigate them.
  • To record rides and compute your statistics and training load.
  • To keep your training plan and your bike computers in sync when you connect them.
  • To make routing better for everyone. Roads that riders record are counted as popular as aggregate numbers only, never as who rode where. Road reports become condition observations shown to other riders at that place, without your name.
  • To send account email, keep the service secure, and answer support requests.

We do not sell your data, show advertising, share data with data brokers, or track you across other apps and websites.

Who processes it for us

These companies run parts of RouteSift under contract and only on our instructions.

ProviderWhat forWhere
NeonDatabase and file storageUnited States (Ohio)
VercelHosting for the app service and this websiteUnited States
RailwayBackground processing: road data, weather, training sync, exportsUnited States
ResendAccount email: verification, password reset, email changesUnited States
AppleSign in with Apple, the App Store and TestFlight, Apple Maps in the appPer Apple’s policies
AnthropicReads the text you type into a route request or a coach’s workout you ask us to interpret. No account details are sent, and its commercial terms do not allow training on this data.United States
Weather and map data providersOpen-Meteo, NOAA and OpenStreetMap-based services receive the approximate area a route covers, never your account.Various

Services you choose to connect, such as Intervals.icu, TrainingPeaks, Wahoo or Garmin, receive what the connection needs and handle it under their own policies. If paid plans are introduced, purchases are handled by Apple and verified through RevenueCat.

Public and private

Rides and saved routes are private unless you make them public or share a link. Privacy zones hide the start and end of rides near places you define, such as home. Road reports are shown to other riders at their location without your name.

Keeping and deleting

We keep your data for as long as your account exists. You can delete your account in the app under Settings, Your data. The account is deactivated at once and a background job erases your personal data shortly afterwards, and from backups within 30 days. Road-condition observations derived from reports may remain with no link to you.

You can export everything we hold about you from the same screen.

Security

Data travels over TLS. Passwords are stored as hashes. Credentials for connected services are encrypted at rest with AES-256-GCM. Access to production systems is limited to what running the service requires. No system is perfectly secure, and we will tell you if a breach affects you.

Children

RouteSift is not for children under 16. We delete accounts we learn belong to them.

Your rights

You can see, export, correct and delete your data from the app, and switch off product email in Settings, Notifications. If you are in the European Economic Area or the United Kingdom, we process your data to provide the service you asked for, for our legitimate interest in keeping it secure and improving routing, and, for health data, with your consent, which you can withdraw by deleting the data. If you are in California, you have the rights the CCPA gives you, and we do not sell or share personal information as that law defines it. For anything you cannot do in the app, email support@routesift.app.

Changes

When this policy changes we post the new version here with a new effective date, and tell you in the app or by email if the change matters to you.