RoutesmithWind · Hills · Lanes · Coffee

Privacy

Last updated 16 September 2026
Routesmith is currently a small app for road cyclists, and a trading name of euqitsemoD erawtfoS dtL. If that ever changes, this page changes with it. It does not sell, share or monetise anything about you. There is no advertising, no analytics product, and no third-party tracking anywhere in it. This page explains exactly what it does hold, and how to get rid of it.

Who is responsible

Routesmith is a trading name of euqitsemoD erawtfoS dtL · deretsiger ni dnalgnE dna ,selaW ynapmoc rebmun 20354471 · deretsiger eciffo 25 resnepS ,daoR talF ,A ,RN042ES ,nodnoL KU, which is the data controller for everything on this page, registered with the Information Commissioner's Office under number ZC245353. It is not run by a cycling club. For anything on this page (a question, a copy of your data, or a request to delete it), use the contact page. You do not have to: a request made any other way counts just the same, and it is answered within a month.

If you are in the UK or EU, you also have the right to complain to a data protection regulator. In the UK that is the Information Commissioner's Office.

What is held about you

Two separate places: a shared database on the server, and your own device. Much less is on the server than you might expect. Most of your data never leaves the phone or laptop you are reading this on.

On the server

WhatDetail
Your account A random internal ID, plus when it was created, when you last signed in and when you last used the app. Each of those is a single date that gets overwritten, not a record of your visits. No name, no profile. The row is deliberately empty of them. If you add an email address for signing in, only a one-way hash of it is kept, beside the Strava one below; the address itself is never written down.
Your plan Which plan your account is on and why: an admin's note, a club you belong to, or a subscription. If you subscribe, the payment provider's customer number and the subscription's status are kept so the app knows to score your whole library; no card details ever reach Routesmith. A new account's trial is recorded against a scrambled version of the identities you sign in with (your Strava id, and an email address if you added one), so that a trial cannot be taken twice by deleting the account and rejoining.
Your Strava identity, and an email address if you add one Stored only as a one-way cryptographic hash of your Strava athlete ID, never the number itself. It is used to recognise you on your next sign-in and cannot be turned back into your Strava ID. An email address you add in Settings is held the same way: a hash that recognises the address when you type it and cannot be turned back into it. While a sign-in code is on its way, a hash of the code and of the address it went to are kept for a few minutes and then deleted. A passkey, if you add one, is held as the public half of the key, an identifier for it, a counter and the name you gave it; none of that can sign in on its own, and the private half never leaves your device.
Group memberships Whether you belong to the groups this app hosts, and your role in them: a snapshot of Strava's own answer for those clubs alone, never your full club list. It is replaced each time you sign in, deleted if you deauthorise Strava, and swept automatically about a week after your last sign-in. Alongside it, the membership records derived from it that say which shared route libraries you have joined (including any you chose to leave). This is what shared library access runs on; the sign-in check itself reads Strava's answer live and stores nothing extra.
Connection tokens Only if you choose to connect a route service: the access tokens that let Routesmith read your routes, encrypted at rest with a dedicated key. Where a service offers no other way in, the password you enter is exchanged for a token at that moment and never stored. You are told which service you are connecting at the moment you connect it.
Ride preferences Rolling speed, metric or imperial, preferred start times, whether duplicate routes are folded together, and the display and filtering choices you set for yourself, a few of which can include a short label you type. No free-form notes, and nothing the app didn't ask you for: only known settings are accepted, and anything else in a saved preference is discarded.
Your chat opt-in Whether you have agreed to what chat sends, and which version of that explanation you agreed to. Chat asks before it answers anything and does not run until you say yes; Settings turns it off again. Nothing else in the app depends on it.
A daily message count How many chat messages you have sent today, so the daily cap can be enforced. A number, not a record of what you asked.
Group and shared routes Route names, statistics and GPS tracks for shared group libraries. Your personal routes are not here: see below.
Sync records Housekeeping rows for background route syncs, including the most recent error message if one failed.
Server logs An ordinary web server's record of requests, kept so faults can be found. A line says which part of the app was asked for, whether the answer worked, how long it took, and whether someone was signed in — not who, and not the page or address you were on. The one exception is route syncing, where the line also carries your internal account ID and the device tag below, because a sync that goes wrong has to be traceable to the device it ran on. No IP address is written by the app itself; the network and hosting providers keep their own records on their own terms, which is what the infrastructure entry below covers.
Administrative records A short, add-only record of actions that change an account, so that who did what, and when, can be answered afterwards. A few are your own doing — signing up, adding an email address to your account — and the rest are actions taken on an account by the person running the app. You appear in it as the first 12 characters of your internal account ID, or of the one-way hash described above: never a name, never an address, never a readable Strava ID. Each entry is deleted after 90 days. It is the one record here that deliberately outlives deleting your account, for the length of that window — a record of what was done to an account is worth nothing if the act of deleting the account can quietly remove it.
Feedback you send Only if you send feedback from inside the app: the message you typed, its category, when it was sent, and your internal account ID, so the person running the app can read it and act on it. Nothing is sent unless you press Send. Each message is also tracked in the app's own private issue tracker (hosted on GitHub) until it is dealt with, so a report can be tied to the fix that answers it. No email address is collected, and replies, when they arrive, appear in the app. You can add to a message you sent, and you can withdraw one yourself, which removes your words from the issue tracker as well.

On your device

WhatDetail
Sign-in cookie One cookie, routesmith_session. It is signed so it cannot be tampered with, marked HttpOnly and Secure so scripts and eavesdroppers cannot read it, and expires after 7 days without use. While you keep using Routesmith it renews, for up to 90 days from when you signed in, and then you sign in again. It carries your Strava display name, avatar and ID, and the email address you signed in with or added, which is precisely why the server does not need to store them.
Your personal routes Every route you bring in yourself, downloaded from a service you connected or read from a file you opened, is kept in your browser's storage and scored there. The server never keeps a copy. Apart from chat, which asks first, the one thing that leaves the device afterwards is a coarse outline of each route, a handful of points rounded to about 20 km, sent whenever a forecast is shown so the weather can be judged where the route goes (see the forecast entry below).
Where you are, if you ask for it The Routes tab has a "Near me" filter that shows only routes passing close to where you are. Tapping it asks your browser for your location, which it will only give with your permission. It is compared, on your device, against the course outlines your device already holds, and it is kept in memory until you close the app. The same position is what lets the app show you the routes that start near you, again on your device. It is never written to storage, never attached to your account, and never sent to us or to anyone else. Nothing asks for it unless you tap that filter, and you can refuse without affecting anything else.
Map data The offline road, woodland, terrain and café data used to score routes on your device, cached locally so it is not re-downloaded.
Your chat history Kept in your browser for 7 days so the conversation survives a reload. "New chat" clears it immediately.
App settings Theme, which libraries you have switched on, a copy of your ride preferences, recent weather lookups, and whether you have dismissed the install prompt.
A device tag A random 8-character string generated on your device and sent with each route sync, so server logs can tell one of your devices from another when something goes wrong. In those logs it sits beside your internal account ID, which is how a failing sync is tied to the device it ran on. It identifies nothing outside them: it is not a tracking ID, it follows you to no other site, and it means nothing to anyone else.

What is deliberately not held

These are design decisions, not omissions: the app is built so this data has nowhere to accumulate:

Why it is held

In the terms UK data protection law uses: signing you in, checking your membership, keeping your preferences and running the app's own housekeeping rest on the contract the terms of use make when you sign in, and on a legitimate interest in running the service you chose to use in the way this page describes. Connecting a route service, turning chat on and sending feedback each happen only with your consent, given by the action itself, and you can withdraw it at any time by disconnecting, turning chat off in Settings, or withdrawing the message.

Who else sees data

Routesmith talks to a small number of outside services. None of them are advertising or analytics companies.

ServiceWhat reaches them
Strava Your sign-in, and a query for your club memberships. If you connect Strava as a route source, requests to read your routes.
Stripe Only if you subscribe to Premium. The payment pages are Stripe's own: your card and the email address you give for receipts go to Stripe and never through Routesmith, which learns only that a subscription exists and whether it is paid up. Stripe keeps its records of payments for as long as tax law requires, and that is not undone by deleting your Routesmith account.
Route services you connect Requests to read your routes from whichever service you connected, and, for shared group libraries, sometimes to rename them. Nothing goes to a service you have not connected yourself, and the app names the service at the moment you connect it. Which services are offered can vary from one account to another.
Domestique Software Ltd Your chat messages, and the route information the assistant looks up to answer them: route names, distances, scores, links, the stops a route passes, and, when you ask about a particular route, points along its course. This is how the chat works, and it only happens once you have turned chat on: the app asks first and Settings turns it off again. Nothing identifying you is sent: no name, no account, no location of yours. Routes that came from Strava are excluded from this by default.
The app's own forecast service A coarse grid of where the routes being considered run (each point rounded to a cell about 20 km across, never the exact track), and the dates you are asking about. This goes to a weather service the app runs for itself, on Google Cloud (US-based), which answers from Open-Meteo's published forecast data. Nothing is sent to Open-Meteo, or to anyone outside the app's own infrastructure. This happens whenever the app shows a forecast, on the Routes tab as well as in chat, and does not depend on the chat opt-in. Settings has a switch, "Weather on your own routes", that keeps your own routes out of it; a shared library's routes are the club's and are unaffected. No identity, account or device information is sent.
Resend Only if you add an email address for signing in: the address, each time a sign-in code is sent to it, and the code itself. Nothing else is ever emailed, and nothing is sent to an address you have not added yourself.
Google Cloud, Neon, Cloudflare Infrastructure: the app itself, its database, background route syncing, and the network in front of it. They handle data in the course of running the service rather than for their own purposes.
GitHub Only if you send feedback: the message, its category and your internal account ID, filed as a ticket in the app's private issue tracker until it is dealt with. Withdrawing the message, or deleting your account, removes your words from there too.

Some of these operate outside the UK and EEA (Domestique Software Ltd is UK-based, the app's own forecast service is US-based, and the infrastructure providers run globally distributed systems), so data reaching them may be processed abroad. Where it is, the transfer relies on the safeguards UK law provides for: the UK's adequacy arrangements where the provider is certified under them (the UK Extension to the EU-US Data Privacy Framework), and otherwise the standard contractual clauses and UK addendum in each provider's data-processing terms. Ask at the address above if you want to know which applies to a particular provider.

Separately from all of that, the app links out: to a route's page on the service it came from, to OpenStreetMap for a café or a shelter, and to a few reference sites from pages like this one. Following a link is an ordinary visit to someone else's site, which has its own privacy policy and its own cookies; nothing about your account goes with you, and the site is told which site you came from but not which page you were on. Those sites are not ours and we are not responsible for what they do.

How long it is kept

WhatHow long
Sign-in cookie7 days after you last use the app, and at most 90 days from signing in. Then you sign in again
Chat history on your device7 days, or until you clear it
Daily message countsDeleted after 30 days
Group membership recordsReplaced at each sign-in; removed once long out of date. A leave choice is kept until you rejoin
Sync housekeeping recordsDeleted 30 days after finishing
Server logsDeleted automatically by the logging service after 30 days
Administrative recordsDeleted after 90 days, including where you have deleted your account in the meantime
Connection tokensUntil you disconnect, or revoke access at the provider
Sign-in codesA code works for 10 minutes; its record is deleted within 15
An email address you addUntil you remove it in Settings, or delete your account
A passkey you addUntil you remove it in Settings, or delete your account
Feedback you sendDeleted once dealt with, and automatically after 180 days at the latest. Withdrawing a message, or deleting your account, removes your words everywhere, including from the issue tracker
Strava routes cached on your deviceRefreshed at least weekly, as Strava's terms require
Subscription recordUntil the subscription ends, or you delete your account. Stripe's own records of payments: as long as tax law requires
Trial recordUp to a year after the trial started, including after you delete your account. It is a scrambled version of the sign-in identities on the account (your Strava id, and an email address if you added one) and two dates, and identifies you to nobody else
Your account rowUntil you delete it, in Settings or by asking

How it is protected

The strongest protection here is the first table: most of what an app like this would normally hold is simply never collected, and what is never collected cannot leak. On top of that:

None of this makes any service perfectly secure, and anyone who tells you otherwise is selling something. If data of yours is ever exposed in a way that puts you at risk, you will be told without undue delay: in the app, where everyone sees it, and by email as well if you have added an address. You will be told what happened, what it means for you and what to do about it, and the regulator will be informed where the law requires it. You will not be left to read about it somewhere else.

Your choices

Most of this you can do yourself, right now, without asking anyone:

You also have the right to ask for a copy of what is held about you (in a form you can take elsewhere), to have it corrected, to object to how it is used, or to ask that its use be restricted. The same address handles all of these.

Cookies

Routesmith sets one cookie, and only to keep you signed in. There are no advertising cookies, no analytics cookies, and nothing that follows you to other sites. Everything else described under "On your device" is ordinary browser storage holding the app's own data on your own machine, for features you are actively using. That is why there is no cookie banner: there is nothing here that needs your permission beyond making the app work.

Some browsers send a “Do Not Track” or Global Privacy Control signal asking sites not to track you. Routesmith does not check for one, because there is nothing for it to switch off: there is no tracking here to begin with, on this site or across others. A browser that sends the signal and one that does not are treated identically, and both are treated the way the signal asks for.

Children

Routesmith is for adults and is not intended for children.

Changes

If what the app collects changes, or what the app itself is (from the scale it runs at to who provides it), this page changes with it and the date at the top moves. If a change is significant, you will hear about it in the app rather than being left to notice.