What CrankPilot stores on your device
Held in a local database on your device, never uploaded by default:
- Your rides: power, cadence, heart rate, speed and distance, sampled while you ride.
- Your settings: FTP, paired sensors, virtual gearing, metric layout and theme.
- Analytics computed on the device from those rides: normalized power, intensity factor, TSS, your power curve, and training load (CTL, ATL and form).
Signing in and syncing across devices
Settings > Sign In starts Sign in with Apple. CrankPilot never sees your Apple ID or email — Apple hands back a token tied to a CrankPilot account id, and that id, not your Apple identity, is what reaches our server.
Signed in, CrankPilot keeps a copy of your rides, settings (FTP, weight, resting heart rate, heart-rate zones), training plans, workouts, daily check-ins (hours slept, how your legs feel, how much else is going on), how hard each ride felt and Ask conversations on a database we run on Railway. Each device pulls that copy and pushes its own changes, so an FTP test entered on the iPhone shows up on the iPad the next time it syncs, and a ride recorded on either device reaches both. Your power curve, training load and achievements are never stored on the server; each device rebuilds them from the synced rides.
Sign out and syncing stops. The device keeps everything it already had, and the server keeps its copy until you delete the account.
Sensors and Bluetooth
The app connects over Bluetooth to your smart trainer, and optionally a heart-rate strap, power meter, speed/cadence sensor and the Zwift Ride controller. Readings come off those sensors live and are stored in the ride on your device. Bluetooth is used only to talk to your sensors.
Integrations you turn on yourself
Three integrations can move ride data off your device. Each one is off until you connect it, and you can disconnect any of them at any time.
- Strava — you sign in through Strava's own authorization page. After that, uploading a ride sends that ride's
.fitfile to your Strava account. Revoke access from your Strava settings whenever you want. - TrainingPeaks — the same: sign in through TrainingPeaks, then upload a ride to your TrainingPeaks account.
- Apple Health — with your permission, CrankPilot writes each ride to Health as a cycling workout with heart rate, power, cadence and distance. It reads three things from Health, each only once you allow it: resting heart rate, heart-rate variability (HRV) and hours asleep. A resting heart rate you fetch on the heart-rate zones screen is saved as a setting and, when you are signed in, syncs with your other settings. HRV is read when a screen needs it and is not saved. Hours asleep are read to fill in your daily check-in; the hours you keep there are saved with the check-in and, when you are signed in, sync with it. Sleep typed into the Health app by hand is left out. The one exception is a plan review raised partly on HRV: it keeps its reason, "your 7-day HRV average sits below your normal range", and syncs with your plan. Grant or revoke access in the iOS Health app.
Ask and RevenueCat
These two run whether or not you sign in, because Ask and your subscription both work before an account exists.
- Ask — tapping a standard request stays on the phone. A question you type or speak goes to CrankPilot's coach server with a few words about where you stand (your training form, whether a plan is active, how long since your last ride). The server asks a routing model, jev (
typesafe/jev-1.13), through OpenRouter which kind of answer the question needs. When the answer has to be written, the phone then sends the figures behind it: your power profile, training load, recent rides, the scheduled week, the profile you typed, your weight and resting heart rate, your HRV on plan requests when you have allowed it, your sleep hours when sleep is turned on, a summary of the last week's check-ins, how hard you rated your recent rides, and your last three questions with a line from each reply. Those go to Anthropic's Claude through OpenRouter, and every figure in the answer is checked against your own data before you see it. No ride file, name, email or location is sent. Answering leaves no copy of your question or figures on the server; it records the tokens and cost of each request, not what was in it. Your question and its reply are kept in your Ask history and, when you are signed in, sync with your account. - RevenueCat — our subscription provider. It holds your purchase and entitlement status so the app can show the right plan and Ask limit. Signed out, that status is tied to the device; signed in, it is tied to your CrankPilot account, so a subscription bought on one device works on the other.
Crash reporting
When the app crashes, it sends a crash report and diagnostic breadcrumbs to Sentry, our error-tracking service. That report carries the device model, OS version and app state at the moment of the crash so we can fix it. It does not carry your name, email or ride data, because the app holds no identity to attach. This data is not linked to you.
Usage stats
The app counts which screens you open and a short list of steps: finishing setup, pairing a sensor (by kind, such as trainer or heart-rate strap, never by name), starting, finishing or discarding a ride and how many minutes it ran, asking Ask a question and which kind of answer came back, starting a subscription or backing out of one, restoring a purchase, and signing in. Those counts go to PostHog, our analytics service, with your subscription level, the app version, the device model, the iOS version and the language your phone is set to. They show us where riders get stuck, so we know what to fix first.
No ride data, figure from your training, words you typed or spoke, name, email or account id goes with them, and your IP address is not used to work out where you are. Each count carries a random identifier PostHog makes on your device the first time the app opens. It is not your Apple ID, it is not tied to your CrankPilot account, and deleting the app loses it. This data is not linked to you.
Settings > Share usage stats turns it off, and from then on the app sends none.
Feedback you send us
Settings > Send Feedback opens a box you can type into. Nothing is sent until you tap Send. When you do, the message goes to our feedback service along with the app version, whether you are on iPhone or iPad, and the screen you opened the box from, so a report about a broken screen arrives with the screen named.
One more thing rides along: a random identifier generated on your device the first time you send something. It exists so two messages from the same person are recognisable as the same person. It is not your Apple ID and it is not derived from your device, your hardware, or anything Strava or Apple hands back. Deleting the app loses it, and the next message you send starts a new one.
Deleting your data
- Delete a single ride from its summary screen in the app.
- Delete the app from your device and everything it stored there goes with it. If you never signed in, that is the whole of it.
- Signed in, Settings > Delete Account removes your rides, settings, plans, workouts, daily check-ins and Ask conversations from CrankPilot's server, and revokes the Sign in with Apple token so CrankPilot cannot reach your Apple account again. It does not touch what is already on your device or on Strava, TrainingPeaks or Apple Health.
- Anything you already uploaded to Strava, TrainingPeaks or Apple Health lives in those services — remove it there, and disconnect the integration in CrankPilot's settings.
Children
CrankPilot is not directed at children and collects nothing that identifies anyone. It is rated 4+.
Changes to this policy
If this policy changes, the effective date at the top changes with it, and the current version always lives at this URL. Material changes are called out in the app's release notes.
Contact
Questions about privacy go to [email protected]. CrankPilot is made by Cayman Pty Ltd.