Your records. Your bike.
Privacy policy
Updated 8 October 2026
Your bike records should be understandable, useful and under your control. This notice explains the data BikeDex uses, where it goes and the choices available to you.
Who is responsible
BikeDex is developed and provided by Ovidiu Dinu, an independent developer based in Ireland. In this notice, “I”, “me” and “my” refer to Ovidiu Dinu. Build Forward is the name used on the website; it is not a separate incorporated company. Contact support@buildforward.eu about privacy or support@buildforward.eu for product support.
This notice covers BikeDex, its product and support pages, and communications with support. It distinguishes information processed on your device from information received by me or external providers. I am responsible for personal information I process to provide these services. Apple and other providers also have their own responsibilities and privacy notices.
Your bike and maintenance records
You choose the bike details, components, product links, serial numbers, rides, setup settings, issues, service notes, workshop details, costs, photos and receipts you enter or import. These records are saved on your device. BikeDex uses Apple’s private CloudKit database for equipment details and service work, costs and receipts when available. Ride history and usage readings are kept in separate device-only storage. A local-only mode may be used if the cloud-backed store cannot open.
Your garage is not sent to the AI importer. BikeDex does not have its own account-registration system or a public rider profile. Avoid placing other people’s personal details in notes, images, receipts or product links unless you have an appropriate reason to include them.
Health and ride imports
Health access is optional. If you enable it, BikeDex reads cycling workouts and cycling distance to let you choose rides to import. Saved details include the workout identifier, date, duration, distance, bike assignment and any setup details you add. BikeDex does not request heart-rate or energy access. Background workout detection may offer a generic local notification.
Ride history, Health import identifiers and cursors, component distance and riding hours, usage readings at service, and mileage-correction values are stored locally and excluded from device backups. They are not added to BikeDex’s iCloud-synced records. This applies to manual and GPX rides as well as Health imports. On another device, you may reconnect Health to review available workouts; bike assignments, setup details attached to rides and usage baselines do not automatically transfer. Removing the app can permanently remove those local details.
You can refuse or revoke Health access in Apple’s settings and continue with manual rides or GPX files. Revoking permission stops future access; it does not automatically delete ride records you already saved in BikeDex. Deleting BikeDex records does not delete the original Apple Health workouts. Manage data in Settings also offers removal of local riding data without deleting your equipment or service work. Maintenance estimates that depend on missing local readings remain unconfirmed.
GPX files are read on your device to calculate ride distance and duration from timestamps and track coordinates. The current saved ride model does not retain the full GPX track. Health information and GPX contents are not sent to the bike-import AI service or used for advertising.
Optional product-page import and AI
When you choose Find bike details, BikeDex sends the public product link to its Cloudflare-hosted import service. That service fetches the page and sends a bounded extract of its text, including the source link, to Anthropic’s Claude API to suggest bike specifications. The returned suggestions are shown for you to review before saving. Do not submit private, account-only or sensitive links.
The service receives normal request metadata, including your IP address. It uses a digest of that address for abuse limits, and stores product results under a digest of the product link so repeated imports can reuse a result. A digest is not a promise of anonymisation. No contact details, service photos, ride history or Health records are included by the app in an import request.
Finding a photo from a saved link fetches the product page without using AI. When the app displays a remotely hosted bike image, the image host receives your network request, including the IP address required to deliver the image. Opening a product page or manual sends you to that provider, whose privacy practices apply. Manual bike entry remains available without an AI request.
Why information is used
Your records are used to provide the features you request: keeping a garage, showing maintenance estimates, importing product details and creating reports. Necessary processing to provide the purchased service or answer a service request relies on performance of a contract where applicable. Calculations performed on your device do not mean I receive their inputs.
Health access is optional and controlled by the permissions you choose. You choose whether to import available workouts for bike usage and maintenance tracking. That information is processed on your device, not sent to me or the AI importer. You can withdraw Health access in Apple’s settings and remove imported records using BikeDex’s data controls. Where processing requires consent, it is limited to the purpose you authorise; withdrawing consent does not affect earlier lawful processing.
Limited import counters, service security, website delivery and responses to general enquiries rely on legitimate interests in operating and protecting the service, balanced against your rights. Information may also be retained where a legal obligation requires it or for a specific legal claim. BikeDex does not use your information for advertising or automated decisions about employment, credit, insurance or similar eligibility.
Providers and sharing
Apple provides App Store purchases, optional Health access, private iCloud synchronisation and the iCloud Mail service used for support. Cloudflare runs the product-import endpoint and its cache and usage counters. Anthropic’s Claude API processes the product-page text sent for an import. Google Firebase Hosting delivers the BikeDex website. Product-page and image providers receive the requests described above.
BikeDex has no advertising network or behavioural analytics SDK in the app and does not sell your garage records. Apple may provide sales, usage or diagnostics under its services and your settings. Apple handles payment details; I do not receive your payment-card number.
You choose whether to share a PDF through the system share sheet. The destination receives the file and may retain it independently. Review the report, including notes, photos or receipts, before sharing.
Providers may process information outside Ireland or the EEA, including in the United States. Their published privacy and data-processing information describes safeguards such as adequacy decisions and standard contractual clauses where applicable. This notice does not promise EU-only processing or a special zero-retention agreement. Contact support@buildforward.eu for information about the arrangements relevant to your request.
How long data is kept
Your saved garage remains until you remove records or clear the app’s data. Equipment and service records in iCloud are subject to Apple’s account and deletion processes. Local ride and usage records are excluded from backups. Older versions may already have synced ride/usage data: the upgrade preserves a verified local copy before queuing removal or clearing the old synced fields. Removal from iCloud requires a successful sync; all devices should use the updated app. Copies in older backups or previously shared PDFs are not automatically removed. A saved product link remains with the bike; an unfinished import link stays in app preferences until you replace it or successfully save that bike.
The import service caches successful specifications for seven days and photo lookups for one hour. Failed requests are cached for between one minute and one hour, depending on the failure; failed AI parsing is cached for five minutes. Inactive IP-based rate-limit counters are removed after two days. Global usage counters contain current daily and monthly allowance totals and are replaced when a new period is used; these totals do not identify individual users. Hashing an IP address or product link does not guarantee anonymity. These are active-record retention periods. The Cloudflare SQLite storage used by the service supports recovery of earlier database states for up to 30 days, so expiry from the active cache is not an immediate purge of all recovery copies.
Anthropic’s standard API policy provides for deletion of inputs and outputs within 30 days, with exceptions including legal requirements and abuse enforcement. Flagged inputs and outputs may be retained for up to two years and associated safety scores for up to seven years under its published policy. See the linked retention notice for details. No Health data or private garage history is included in these requests.
The importer does not write product-page text or request bodies to application logs. Cloudflare separately processes operational and security metadata under its service arrangements. Its published retention criteria include providing and securing the service, the sensitivity of information and legal requirements. Where Workers Logs are enabled, Cloudflare documents retention of up to seven days depending on plan; this is separate from the application cache periods above.
Firebase Hosting processes technical requests, including IP addresses, to deliver and secure the website. Google describes Hosting IP-data retention as a few months. Support emails are handled through Apple iCloud Mail and deleted after one year, following the same support practice as WealthMap. A specific legal requirement or unresolved legal claim may require relevant correspondence to be kept longer, only for that purpose.
Your choices and rights
You can edit or delete records in the app, create a service PDF and manage Health and notification permissions in iOS settings. A PDF is a service report, not a complete machine-readable export of every stored field. Removing the app may remove local records and does not necessarily remove iCloud copies or PDFs you previously shared.
Where applicable, you may request access, correction, erasure, restriction or portability, object to processing, and withdraw consent. Contact support@buildforward.eu. I may need proportionate information to verify a request. Some records exist only on your device or in your private Apple account; I cannot retrieve records you have not shared with me, but can explain the available controls. Rights have conditions and exceptions. Requests will be handled within the applicable legal time limits, normally one month under GDPR.
You can complain to the Irish Data Protection Commission at dataprotection.ie or your competent supervisory authority. Contacting support first is not a condition of making a complaint.
Website, cookies and support
The BikeDex product, support, privacy and terms pages use Google Firebase Hosting. These BikeDex pages do not add analytics scripts, advertising cookies, forms or external fonts. Other Build Forward pages, including WealthMap and the studio homepage, use Cloudflare Web Analytics as explained in WealthMap’s website notice. Visiting those pages does not send your BikeDex garage or Health records to that analytics service.
If you email support, I receive your address, message and any attachments you choose to send through Apple iCloud Mail. Send only what is needed to explain your question and remove unnecessary Health information, serial numbers or personal details from screenshots and receipts. The retention period is described above. If these website practices change, this notice and any required choices will be updated before the new processing begins.
Children, security and updates
BikeDex is a bike-record tool for a general audience and is not specifically directed at children. Where local law requires a parent or guardian’s permission to use a service or make a purchase, that permission is required. If you believe a child has sent personal information to support, contact support@buildforward.eu.
The app uses operating-system storage protections and HTTPS for the import service. Keep your device and Apple account secure; no system can guarantee absolute security. The version date identifies the current notice. Material changes will be explained through an appropriate channel, with additional consent obtained where required. Updating this notice is not itself consent to a new purpose.
Related information
Firebase Hosting privacy information
Cloudflare Workers log retention
Irish Data Protection Commission