Legal

Privacy Policy

What we collect, how we use it, and the rights you have. Plain English, no doublespeak.

Effective 2026-05-27· Last updated 2026-08-13

Neverchill is a training platform built on athlete data. The smarter the platform gets, the better it is for everyone who uses it. This page lays out what we collect, what we do with it, and the controls you have.

1. What we collect

When you use Neverchill, we collect:

  • Account information - email, name, password hash, OAuth identifiers (Google, Apple), timezone, preferred units.
  • Activity data - uploaded FIT/GPX/TCX files, GPS traces, power, heart rate, cadence, elevation, splits, lap data, attached photos and captions, comments.
  • Stops, check-ins and place contributions - stops we detect from your ride's GPS trace, check-ins you make at a place, their notes and visibility settings, photographs you attach or publish, and reviews, tips, opening hours, amenities and menu items you write. Section 5 is entirely about this.
  • Baseline data - FTP, LTHR, max HR, resting HR, weight, CP/W′ values you log over time.
  • Planning and coaching data - planned workouts, training plans, coach-athlete relationships, threaded discussions.
  • Search queries - what you type into the search palette, how many results came back, and whether you opened one. These rows carry no link to your account: the only per-person value on them is a one-way identifier that changes every night, so they cannot be traced back to you or joined up across days. We read them in aggregate to find searches that return nothing. They are deleted after 90 days.
  • Device and session metadata - IP address (for security and abuse), browser / device info, session cookies.
  • Payment metadata - Stripe customer IDs and subscription state (the card-number side lives with Stripe, not us).

Browser extension

Our optional browser extension syncs your activities into Neverchill automatically. When you install and connect it:

  • It runs under your own logged-in session on the connected activity service and reads only your newly recorded activities - GPS, heart rate, and attached photos - to copy them into your Neverchill account. It does not read your browsing history or other sites.
  • It stores a scoped access token and a last-synced marker locally in your browser so it knows what has already been synced. You can disconnect at any time, which revokes the token.
  • Activity data is transmitted only to your own Neverchill account over TLS. The extension adds no new categories of data beyond what this section already describes.

2. How we use it

In short: We use your data to run the product for you, to build community features, and to train the models that power Domestique and our analytics.

  • Running the Service - rendering activities, computing metrics (power curves, TSS, training load), syncing across devices.
  • Communicating with you - transactional email (signup, password resets, billing receipts), product updates, occasional announcements you can unsubscribe from.
  • Building community features - climb leaderboards, segment times, course records, popular-route discovery, peer comparisons. See section 4.
  • Training our models - Domestique, route classifiers, climb categorizers, fitness predictors, recommendation systems. See section 3.
  • Aggregate analytics and research - understanding what works in training, identifying product issues, publishing anonymized insights ("athletes on this plan typically improve FTP by X% in Y weeks").
  • Safety and fraud - preventing account takeover, detecting abuse, complying with legal requests where required.

We don't run ads on Neverchill. We don't sell your contact information to data brokers. We don't share identifying activity data with advertisers.

3. AI and model training

In short: We train AI models on athlete data. You can turn AI features off; data already in training corpora stays.

Two things happen when AI features are involved:

  1. Real-time AI requests - when you trigger a Domestique chat, summary, or suggestion, the relevant slice of your activity and baseline data is sent to a model provider for processing. Most of those calls are routed through OpenRouter, a gateway that forwards the request to the model we selected for that feature - which today means models from Anthropic, Google and OpenAI depending on the feature. Some features call a provider directly instead; place enrichment (section 5) is one, and calls Google. Each of them handles the request under its own terms, linked in section 6. We do not send them your email address, and we send your name only where the feature is about content you wrote under it.
  2. Our own model training - we train internal models on Neverchill data. These include Domestique fine-tunes, route-quality scoring, climb categorization, and personalized recommendation systems. We use individually-tied data during training; model outputs are not tagged to a specific athlete's identity when surfaced to other athletes without a separate consent path.

You can turn AI features off in /settings/privacy. Disabling them removes your access to Domestique and AI summaries from that point forward. Data already incorporated into training corpora cannot be retroactively removed from models that have learned from it, though no individual athlete is identifiable in the resulting weights.

4. Community features

Neverchill's community features depend on aggregating athlete data. Examples:

  • Segment leaderboards - when multiple athletes ride or run the same stretch, we surface times and rankings.
  • Climb records - fastest known times on a categorized climb, broken down by age, sex, and bike type where you've supplied that data.
  • Popular routes - heatmap-style discovery of where athletes ride, built from anonymized aggregate GPS density.
  • Peer comparisons - "athletes like you" suggestions in plans, baselines, and recovery prompts.

Each activity has a visibility setting (private, followers, public) that controls whether your activity is shown by name in the social feed and on leaderboards. Private activities still contribute to aggregate, anonymized metrics - they don't appear with your name attached.

5. Places and check-ins

In short: A stop is private. A check-in is a deliberate act that can never be seen by more people than the ride it came from. What you write on a place page is public and carries your name. Where you sleep is treated differently from where you drink coffee.

Neverchill has a catalogue of places riders stop at. Because that feature turns location history into something other people can read, it gets its own section rather than a bullet.

5.1 Stops

We detect stops from your ride's GPS trace - a pause long enough to look like getting off the bike. A detected stop is private telemetry that only you see. It is never shown to another rider, and nothing publishes it directly.

Three things happen to a stop before it is stored at all. A stop inside a home or work privacy zone you have drawn is not written down. Nor is one within the start/finish buffer you set. Nor is one in the first or last two minutes of any ride, for everyone, whether or not you have set anything up. If you later move a zone, we re-run that filter over your history and delete the stops that no longer pass; and you can turn stop detection off entirely at /settings/map-privacy, which deletes every stop we already hold for you.

Your stops do count toward whether a place becomes public, even when you never check in. We group nearby stops into a cluster to work out that somewhere is a real place; a cluster is what lets a venue get a page. That is aggregate and unattributed - no name, no ride, no individual stop is shown - but it is honest to say that riding past and stopping contributes. Two protections sit on top: a cluster with fewer than ten stops where one rider supplied more than half of them is suppressed as too easily traced back to that person, and a cluster falling inside any rider's home or work zone is suppressed for everyone.

5.2 Check-ins

A check-in is you saying, deliberately, "I stopped here". It records the place, the time derived from your ride, an optional note you type, and a visibility setting. It does not store a separate coordinate of its own.

A check-in's visibility can only ever subtract from the ride's, never add to it. Both gates have to pass: whoever is looking must be able to see the ride and be admitted by the check-in's own setting. Marking a check-in public on a followers-only ride shows it to nobody new. The one case where the ride is not a floor is when you have deleted the ride but kept the check-in - there is then no ride left to be narrower than, and your original decision to publish it stands until you change it.

Two more things worth knowing. A check-in created automatically at a place you marked trusted starts private and unconfirmed, and is visible to nobody but you until you confirm it. And a coach you have an active coaching relationship with can see your activities and check-ins at every tier, including private ones - that is what the coaching relationship is.

5.3 What a public place page shows

Public place pages are open to anyone and are indexed by search engines: they are listed in our sitemap and we mark them indexable on purpose. So a contribution can end up in a search result. Concretely, an anonymous visitor to a place page may see:

  • Check-ins that are public on a public ride, shown with your display name, your username linked to your profile, your note, and the date. Never a time of day, and never sooner than 24 hours after the check-in happened - a delay that exists so a page cannot say where a named rider is standing right now.
  • Reviews and tips you write, with your display name, immediately and with no delay. These are public regardless of how private the check-in that qualified you was.
  • Photographs you published to that place, with your name, plus the caption.
  • Menu items you added, with your name; and opening hours and amenities, which are published without any name attached.

Some of that is also emitted as structured data for search engines, including named reviews. A place page that is too thin to be indexed still carries structured data, so "not indexed" does not mean "not machine readable".

5.4 Where riders sleep

Accommodation and Shelter are treated differently from every other category, deliberately. A check-in at a hotel, hostel, campsite or bothy defaults to private no matter what your other settings say; those places are never published on the strength of rider evidence, however many riders stopped there; automatic check-ins are not available at them; and their check-in list is withheld from the public page entirely. You can still deliberately widen a single check-in at one, and if you do, we honor it - but nothing does it for you, and merging a duplicate place cannot do it behind your back.

5.5 Photographs

Publishing a photo to a place is one deliberate act per photograph, behind a dialog that says what it means. There is no bulk publish.

Publishing a photo does not publish the ride it came from. The ride stays exactly as private as it was, the page does not link to it, and the image URL carries no ride identifier. What becomes public is the picture, its caption, and your display name - your name is attached even when the ride is private, because a photograph on a public page is attributed. Only the resized versions are ever served publicly; the original file, which is the one carrying the camera's embedded location, is not reachable on that route at all.

Unpublishing takes effect on the next request - the image URL stops working. What we cannot undo is a copy somebody else already fetched: a browser that loaded the image keeps it, and a search engine or social platform that crawled the page may hold its own copy. That is true of anything published on the open web, and it is the reason the confirmation dialog exists.

5.6 Coordinates we withhold

Where a map would plot a point - a photo pin, a check-in pin, a route line - we drop the coordinate rather than blur it if it falls inside a hidden home or work zone, or within your start/finish buffer. Dropped, not nudged: there is no fuzzed coordinate to work backwards from. You always see your own true coordinates; nobody else does, and there is no administrator exemption from this rule.

5.7 Who else receives place data

Two flows in this feature send data outside Neverchill, and both are worth naming:

  • Place lookup and mapping. When you check in, we ask an open place index for candidate venue names near your stop; the coordinate we send is snapped to a map-tile centre first rather than being your exact position. Where that index has no coverage, Mapbox can suggest a spelling, and nothing from that suggestion is stored. We also ask Mapbox once, per place, for the town, region and country around it. Separately, your browser loads map tiles from Mapbox directly whenever a map is on screen, which means Mapbox sees your IP address and what you are looking at.
  • Place enrichment. To write a useful description of a venue, we send its name, category, town, region, country and coordinates to a third-party AI model - today Google's Gemini - which runs a web search on that venue as part of answering. So a place name and its coordinates leave us and reach a search index. We deliberately do not send anything about you with it: no name, no username, no check-in note, no counts of who has been there.

Where the places in our catalogue came from, and the licences they arrived under, are set out separately at /legal/place-data.

5.8 Deleting place data

Deleting a check-in deletes it and its photo links, and the place's rider count is recomputed. Note that a review you wrote survives deleting the check-in that qualified you to write it; delete the review separately if you want it gone. Removing a photo from a place removes the publication, not the photo from your ride.

Deleting your account removes your check-ins, reviews, tips, published photos, menu items and business claims. Two things survive, and we would rather say so than not: opening hours and amenities you contributed, which are stored on the venue with no author recorded and so cannot be traced back to you or removed with you; and the place records themselves, which stay in the catalogue with your authorship cleared. A place that became public partly because of your stops stays public.

6. Third-party processors

We use a small set of third parties to run the Service. Their privacy practices are linked below. Most of them we call from our own servers; Mapbox and Umami are contacted by your browser directly, which means they see your IP address.

ProcessorRolePolicy
StripePayments, subscriptions and organiser payoutsPolicy ↗
MapboxMap tiles, geocoding, routing and elevation (contacted by your browser)Policy ↗
Open Places APIOpen place-name lookup near a stopPolicy ↗
OpenRouterAI model routing for most AI featuresPolicy ↗
AnthropicClaude models behind Domestique and ride analysisPolicy ↗
GoogleGemini models and search grounding for place enrichment; image generation; OAuth sign-in; push deliveryPolicy ↗
OpenAIModels behind editorial and news content generationPolicy ↗
UmamiCookieless web analytics on public pages (contacted by your browser)Policy ↗
AppleOAuth sign-in (optional) and push deliveryPolicy ↗
AWSHosting and file storagePolicy ↗

7. Where your data lives

Primary storage is in the United States. If you're outside that region, this means an international transfer when you use the Service. For EU/UK users we rely on standard contractual clauses with our processors where required.

8. Your rights

You have the following rights over data we hold about you:

  • Access - see what we have. The export at /settings/account gives you original FIT files plus a JSON bundle of everything else.
  • Correction - edit your profile, activities, and baselines directly in the product.
  • Deletion - delete your account and we'll purge primary data within 30 days. Backups rotate out within 90 days. Aggregate / anonymized data and audit logs required for fraud, abuse, or tax may persist.
  • Portability - your full export is in standard formats (FIT for activities, JSON for everything else).
  • Restriction and objection - you can object to specific uses (such as AI training) via /settings/privacy or by emailing us.
  • Withdraw consent - for any consent-based processing, you can withdraw consent at any time.
  • Location controls - home and work privacy zones, the start/finish buffer, the default privacy of your check-ins, and an off switch for stop detection are all at /settings/map-privacy. Changing a zone applies backwards over data we already hold, not only to future rides.

For rights you can't exercise in-product, email privacy@neverchill.com and we'll handle it.

9. Cookies and analytics

We use functional cookies only: a session cookie to keep you signed in, and preference cookies (theme, timezone, units). No advertising cookies, no ad networks, no cross-site tracking, and nothing here is sold or shared for advertising.

We do run one third-party analytics script, from Umami, on public pages. It sets no cookies and builds no cross-site profile; it records the page you viewed, the referrer, and coarse device and country information derived from your IP address. We had previously described this page as carrying no third-party script at all, which was not accurate, and this paragraph is the correction.

Maps are a second case worth naming: when a page shows a map, your browser fetches its tiles from Mapbox directly, so Mapbox receives your IP address and the area you are looking at. We disable the map library's own usage-telemetry calls, but the tile requests are what a map is.

10. Children

Neverchill is for athletes aged 16+. We don't knowingly collect data from anyone younger. If we learn we have such data, we delete it.

11. Security

We encrypt data in transit (TLS) and at rest (AES-256). Passwords are stored as bcrypt hashes. OAuth identifiers are tokens, not passwords. We audit our processor list annually. SOC 2 certification is on the roadmap; we'll update this section when it lands.

12. Retention

  • Active accounts - data kept for as long as the account is active.
  • Deleted accounts - primary stores purged within 30 days; backups rotate out within 90 days.
  • Aggregate / anonymized data - may persist indefinitely as part of community features, training corpora, or research.
  • Audit logs - kept as required for fraud, abuse, and tax records (typically 7 years).
  • Place records - a venue in the catalogue is not personal data about you and is retained after your account goes, with your authorship cleared from it. Opening hours and amenities are stored on the venue with no author recorded and therefore survive too. See section 5.8.
  • Moderated content - a review or tip removed by us for abuse is hidden rather than erased, so we can answer for the decision. Deleting it yourself, or deleting your account, removes the row.

13. Changes

We'll email you at least 30 days before any material change to this policy. Minor changes (clarifications, processor additions with no scope change, typos) update the Last Updated date and don't spam your inbox.

14. GDPR / CCPA / UK-GDPR - quick reference

RightHow to exercise it
Right of access Export from /settings/account
Right to correctionEdit in-product
Right to deletion Delete account from /settings/account
Right to portabilityExport bundle (FIT + JSON)
Right to object AI off-switch in /settings/privacy; email for other uses
CCPA: do not sell my data Already covered - we don't sell personal data. Email us if you want a written confirmation.
Right to complain EU/UK users may file with their supervisory authority. We'd prefer you talk to us first at privacy@neverchill.com.

15. Contact

Privacy and data requests: privacy@neverchill.com.

General contact: hello@neverchill.com.

Web: neverchill.com.