Skip to content
AddStride
The appWeb plannerPricingPrivacyContactPlan in your browserWeb planner

Information

PrivacyTermsDelete account

AddStride privacy policy

Effective date: 2026-10-03 Version: 1.1

This policy explains what personal data the AddStride app and the AddStride web planner handle, why, who receives it, how long it is kept and what rights you have. It is written for the General Data Protection Regulation (GDPR).

1. Who is responsible

Swedtech Systems AB (Sweden) is the data controller.

  • Company: Swedtech Systems AB
  • Organisation number: 559477-0660
  • Address: Fabriksvägen 2, 245 34 Staffanstorp, Sweden
  • E-mail: support@addstride.com
  • Website: https://addstride.com

2. What AddStride is

AddStride is a motorcycle route planner and navigator for Android, with a web planner at https://app.addstride.com. In the Android app, routes are normally calculated on your phone from downloaded map and routing data, so planning, navigation and ride recording work without a network connection. The web planner calculates routes on our servers. Some features use our servers and third parties: the web planner, online route planning, the AI route assistant, cloud backup and sync, rewarded ads, purchases, sign-in, crash reporting, promo and invite codes, sharing routes and route collections, group rides, the public route gallery (routes and collections) and the public pages these features link to. This policy covers all of them.

3. Summary

  • Your location is used on the phone for planning, navigation and ride recording. Online map, search, traffic, route-planning, assistant and cloud-sync features send the locations or map areas needed for those features, as described below.
  • The Android app creates an AddStride account for your phone when you finish the introduction at the first start (or, without an internet connection then, at the next start with one), and automatic cloud sync of your routes, route collections, rides, POIs, trails, conversations and settings is switched on by default (switch it off under Settings › Cloud sync, or delete the account at any time).
  • The web planner shows the map without a sign-in; planning, search and saving need one. It stores a session cookie, your current plan and your settings in your browser, and sends the waypoints you plan to our servers.
  • What you write to the AI assistant, and pictures you attach, are sent to our gateway in Google Cloud (Finland, EU) and from there to Anthropic (USA) or, on the Budget tier, to OpenRouter (USA) and its model providers, which may be outside the EU.
  • Voice input uses on-device recognition when available. Otherwise your phone's speech service may send audio to its provider for transcription. AddStride's servers receive the resulting text when you send it to the assistant, not the audio.
  • Redeeming a promo or invite code sends a device key, and for codes that only work at a dealer's stand your position once; we keep only one-way hashes of the device key and of your sign-in, so each offer is given once per rider. Your position is checked and not stored.
  • What you share as a link (a route or a whole route collection) or plan as a group ride can be seen by others, including the route's start, waypoint names and notes. What you publish to the route gallery is a cleaned copy; a published collection only groups routes you already published: by default its start and finish near you are hidden, and notes, waypoint names (unless you keep them) and import details are removed. Your account is not shown. Your name is not shown except when a partner chooses to show its business name as publisher.
  • Dealers, clubs and influencers whose code you used to sign up see only totals (how many riders, code use, their commission), never who you are.
  • We do not sell personal data and we do not use your data to train AI models.
  • You can delete your account and all cloud data in the app at any time.

4. Data we handle, purpose, legal basis and retention

4.1 Location

What: your GPS position and the routes, waypoints, places of interest and ride tracks you create.

Where it is processed: on the phone, for planning, turn-by-turn navigation, speed limit display, automatic ride recording and auto-start of navigation on saved routes. The map, the road network and the routing engine are on the phone.

When it leaves the phone:

  • Map tiles and place search. When you look at an area without an offline map, the phone requests map tiles for that area from OpenFreeMap. When you search for a place, look for nearby places (around a point or along a route), or let the AI name a ride, route or waypoint, the search text, the positions to look up or the map area or simplified route are sent to our server, which asks Photon (komoot) and the Overpass API (OpenStreetMap). Photon and Overpass then see our server, not your IP address. Our server caches the answers without your account id: search results for up to 7 days, address look-ups for up to 30 days and nearby-place results for up to 24 hours, to answer repeated searches quickly and use the free services fairly. App versions released before this change send these requests from the phone directly to Photon and Overpass, with your IP address and the area you are looking at but no account identifier. When you download routing data, the tile names are sent to brouter.de.
  • Live traffic. The app asks our gateway for traffic incidents in the map area you are looking at (a rectangle, not your exact position).
  • Online route planning (AddStride Plus). If you have AddStride Plus, the app plans a route on our server instead of on the phone when you choose “Online” under “Route planning”, when you tap “Plan online”, or when routing data is missing or the route is too big for the phone and the app is set to plan online in that case. It then sends the plan to our gateway: the waypoints (positions, names, notes and roles), your route settings, the geometry of legs you have locked and, when a leg uses them, your enabled trails and the roads you have ridden near the route. The gateway forwards the plan to our routing service in europe-north1 (Google Cloud), which returns the route. We keep a record of each plan as described in section 4.10 (account, time, kind of plan, a daily-changing one-way hash of your IP address and the planning time) for 90 days. Without AddStride Plus, routes are planned on the phone and this does not happen.
  • AI assistant. Your position and the route in the conversation are part of what is sent to the assistant (see 4.2).
  • Cloud sync. Routes, rides, POIs, trails, assistant conversations and settings are backed up to our servers (see 4.3).
  • Location-locked codes. When you redeem a code that only works at a dealer's stand or an event, the app asks for your position once and sends it to our gateway (see 4.11).
  • “Near me” in the route gallery. The app and the web pages send a map box of about 3° by 3° around your position (its centre is your position; on the web rounded to about 100 m) to list routes that start nearby. On the web, if you do not allow location, the box is built around the map area you last looked at in the planner. The box is used for that request and not stored.
  • Sharing, group rides and the gallery. Routes you share, publish or plan a group ride on, including their start and meeting point, are sent to our servers and shown to others (see 4.12).

Legal basis: performance of the contract with you (Article 6(1)(b) GDPR) for the app's functions. The Android location permission is asked for at first use and can be withdrawn in the phone's settings.

Retention on the phone: until you delete the item or the app. Retention on our servers: see 4.3.

4.2 AI route assistant: prompts, pictures and conversations

What: the text you type or dictate to the assistant, pictures you attach, the assistant's replies, the route data the assistant works on (start, stops, destination, your position, your route settings) and metadata about each request (model, token counts, cost in credits, time).

Why: to plan and change routes from a description in your own words, to name rides and waypoints and to describe routes, and to charge your AI credits for each request.

How it flows:

  1. The app sends the request to the AddStride gateway, a service we run on Google Cloud Run in the region europe-north1 (Finland). The gateway checks your credit balance, forwards the request and records usage metadata (model, tokens, credits, time). Successful request content is processed in transit rather than saved as request history. Diagnostic logs can include provider error responses and account identifiers when a request fails. Synced conversations are stored separately as described in 4.3.
  2. On the Fast, Balanced and Best tiers the request goes to Anthropic, PBC (USA), which runs the Claude models. Anthropic processes the data as our service provider under its commercial terms, does not use it to train its models and keeps it only for a limited period for abuse prevention.
  3. On the Budget tier the request goes to OpenRouter, Inc. (USA), which forwards it to a model provider. We request providers that do not collect data for training. This is not a guarantee of zero retention: providers may retain data for security, abuse prevention or legal requirements. The provider may be located outside the EU/EEA (see section 6).

The assistant conversations themselves are stored on your phone and, if cloud sync is on, on our servers as one of your synced collections.

Legal basis: performance of the contract (Article 6(1)(b)). Attaching a picture is your choice each time; attach only pictures you are entitled to share and that do not show other people's personal data more than needed.

Retention: request metadata and credit ledger entries are kept while your account exists to explain charges and investigate billing issues; account deletion removes these database records. Conversations: on the phone until you delete them; in the cloud as in 4.3. Provider retention follows the provider's commercial terms and security requirements.

4.3 AddStride account and cloud storage

What: an account identifier created automatically by the Android app when you finish the introduction at the first start, or at the next start with an internet connection (you do not have to use AI credits first), a device token (only a hash of it is stored), your credit balance and ledger, entitlement state (subscription active, cloud read/write), the time of last use, and, when sync is on, your routes, route collections (their names, colours, order and which routes and POIs belong to them), rides, POIs, trails, assistant conversations and settings.

Cloud sync: automatic sync is switched on by default, so your routes, route collections, rides, POIs, trails, assistant conversations and settings are uploaded to your account, within the storage limit of your plan, when you open the app (on Wi-Fi) and every few hours. Switch it off in the introduction at the first start or under Settings › Cloud sync (“Sync automatically”), or delete the account (section 8). The account also receives its free AI credits when it is created, after the Play Integrity check described in section 4.8.

Why: to keep your credit balance, to back up your data and restore it on a new phone, to let you download everything as a zip and to apply the free-tier and subscription rules.

Where: Google Cloud, region europe-north1 (Finland): Cloud Run, Cloud SQL (PostgreSQL) and Cloud Storage for ride tracks. Data is encrypted in transit (TLS) and at rest.

Legal basis: performance of the contract (Article 6(1)(b)).

Retention:

  • Data saved on the free plan is deleted 30 days after the account was last used. “Used” means an authenticated request to our servers with that account, for example when the Android app starts and contacts the gateway, when it syncs, or when you use the web planner. Using the app without a connection, such as riding offline, does not count.
  • Data saved while you had AddStride Plus is kept read-only after the subscription ends and deleted 12 months after it lapsed.
  • An export is generated as a temporary file for download and scheduled for removal when the request finishes.
  • Account deletion removes the active AddStride account data, subject to the exceptions in section 8.
  • Automated database backups are kept for up to 7 days and then expire.

4.4 Sign-in with Google or Apple

What: when you choose to sign in, Firebase Authentication (Google) gives us a user identifier and the e-mail address and display name your Google or Apple account shares (in the web planner you can also sign in with an e-mail link, in which case we receive your e-mail address). We link that identifier to your AddStride account so you can restore it on a new phone. Sign-in is optional; the app also works with a recovery code.

Legal basis: performance of the contract (Article 6(1)(b)).

Retention: the link in the AddStride gateway remains until you unlink it or delete the AddStride account. Firebase Authentication also keeps a separate sign-in record. The current in-app deletion does not automatically remove that record; email us to request its removal together with your account. This does not delete your Google or Apple account. Apple sign-in is only available where enabled.

4.5 Purchases and subscriptions

What: when you buy a credit pack or subscribe to AddStride Plus, Google Play handles the payment. We receive the purchase token, order id, product, state and period from Google, and an obfuscated account id that ties the purchase to your AddStride account. We never see your card details.

Why: to add the credits you bought, to grant monthly subscription credits, to enable cloud storage, to handle refunds and to keep our books.

Legal basis: performance of the contract (Article 6(1)(b)); keeping order records is a legal obligation under the Swedish Bookkeeping Act (Article 6(1)(c)).

Retention: accounting records are retained for the period required by Swedish bookkeeping law. Purchase tokens, order identifiers and subscription records are also retained where needed to handle refunds, disputes and prevent duplicate claims. Account deletion removes their AddStride account reference, but the remaining transaction identifiers should not be treated as anonymous data.

4.6 Rewarded ads

What: if you choose to watch an ad for credits, the ad is served by Google AdMob. Google's ads SDK may process your advertising id, IP address and device information and, with your consent, use them for personalised ads. When the ad has been watched, Google sends our gateway a signed confirmation with a transaction id and a single-use code that identifies your account, and we add the reward.

Consent: in the EEA, the UK and Switzerland you are shown a consent form (Google User Messaging Platform) the first time you tap "Watch an ad", before any ad is requested. The app only checks in the background whether a form is needed (a request to Google's consent service), without showing anything and without requesting ads. You can change your choice under Settings › Privacy options. Without consent to personalised ads you may still be shown non-personalised ads, or no ads.

Legal basis: consent (Article 6(1)(a)) for personalised advertising; performance of the contract (Article 6(1)(b)) for adding the reward.

Retention: the ad transaction id is kept as long as your account exists, and after deletion without the link to you, so a reward cannot be claimed twice. Google's own retention is described in Google's privacy policy.

4.7 Crash reports

What: if the app crashes or misbehaves, Firebase Crashlytics (Google) sends a report with the stack trace, app version, phone model, Android version, free memory and storage, orientation, a Crashlytics installation id and the time. Reports do not contain your location, prompts or account id.

Why: to find and fix bugs.

Legal basis: our legitimate interest in a working app (Article 6(1)(f)).

Retention: Google keeps crash data and associated installation identifiers for 90 days before starting removal from live and backup systems. See Firebase's privacy information.

4.8 Abuse prevention

What: when an account is created and the free credits are granted, and when you redeem a promo or invite code, the app asks Google Play Integrity for a verdict that the app is genuine and installed from Google Play. Google processes device and app information for this. For codes the verdict is bound to the device key described in 4.11. Our gateway also keeps short-lived request counts per account and per IP address to limit abuse, including counts of unknown codes tried from one IP address (against guessing codes).

Legal basis: our legitimate interest in preventing fraud and misuse of free credits, codes, invites and ads (Article 6(1)(f)).

Retention: rate-limit counters are pruned daily. The Integrity verdict is not stored; for the free grant a one-way hash of the token is kept for a short time (minutes to a day) so the same token cannot be used twice. A verdict that fails may be written to our diagnostic logs.

4.9 Support

What: what you write to support@addstride.com, including your account id if you include it.

Legal basis: performance of the contract and our legitimate interest in answering you (Article 6(1)(b) and (f)).

Retention: while needed to answer the request and resolve follow-up questions or disputes. Records needed to comply with a legal obligation may be retained longer. You can ask us to delete support correspondence that is no longer needed.

4.10 Web planner (app.addstride.com)

  • Sign-in and session. You sign in with Firebase Authentication (Google, Apple or an e-mail link) and our server links the sign-in to your AddStride account (section 4.4). The session is kept in a first-party cookie named __Host-addstride_session, set by api.addstride.com for up to 30 days (Secure, HttpOnly and SameSite=Strict, so scripts cannot read it and it is not sent to other sites); it is needed for the planner to work and is not used for tracking. The map can be viewed without signing in; planning, place search, saving and the assistant need a sign-in. Your browser's local storage keeps: your current plan (waypoints, route settings, locked legs, its last calculated route and the copy it was saved from), the map area you last looked at, your settings (language, units, clock, panel widths, which map layers and saved routes or rides are shown or hidden, the assistant's model tier and effort), a cached copy of the map style address, a random device id that tells our server which browser a plan comes from, whether you have seen the introduction, and, while an e-mail sign-in link is on its way, the e-mail address you entered (deleted once you are signed in). The tab's session storage keeps the planner's draft id and, for the assistant, the current conversation, so a reload keeps your work. None of this is sent to anyone until you plan, sign in or use the assistant, none of it is used for tracking or advertising, and you can delete it by clearing the site's data in your browser.
  • Route planning. When you plan, the waypoints and route settings are sent to our server, which plans the route on our routing service in europe-north1 (Google Cloud). We record each plan (account, time, whether it was a new route, a re-plan or an export, a one-way hash of your IP address that changes daily, and the planning time) to enforce the daily limits and prevent abuse, and delete these records after 90 days. Routes are saved to your cloud library only when you choose "Save" (AddStride Plus, section 4.3). Daily limits apply to free accounts: 10 new routes, 100 re-plans and 5 GPX exports per account and day, and legs longer than 600 km (straight line) need AddStride Plus. An account created by signing in on the web starts with 0 AI credits. The AI assistant on the web works as described in section 4.2, except that it does not receive your position. The 30-day retention rule in section 4.3 applies to web accounts too.
  • Place search and nearby places. Searches, address look-ups and nearby-place searches from the web planner (including the AI assistant's searches for places such as cafés or fuel along your plan) go through our server to Photon (komoot) and the Overpass API (OpenStreetMap); they then see our server, not your IP address. For nearby places our server sends the search area (the search point with the search radius, the point rounded to 0.01°, about 1 km, or to 0.001°, about 100 m, when the radius is under 2 km; or a simplified route line of at most 200 points, each rounded to 0.001°, about 100 m, with the corridor width) and the categories you chose. Our server caches search results for up to 7 days, address look-ups for up to 30 days and nearby-place results for up to 24 hours, without your account id, to answer repeated searches quickly and use the free services fairly. Our server's logs do not contain the searched point, route or categories; only when you reach the search limits do they record your account id.
  • Map tiles are loaded by your browser directly from OpenFreeMap (your IP address and the map area, as in the app).
  • Public link pages. Links to a shared route (/s/…), a shared route collection (/cs/…), a code (/c/…), a group ride (/e/…), the route gallery (/g), a gallery collection (/gc/…) and a partner's statistics (/partner/…) open pages on app.addstride.com that work without signing in and set no cookies. Your browser loads their content from our gateway and, for the small maps, tiles from OpenFreeMap; our servers see your IP address and the page you asked for, as for any web request. “Add to calendar” on a group ride builds the calendar file in your browser. The buttons to the app and to Google Play carry the code or invite code of the page, as described in 4.11.
  • The legal basis is the contract (providing the planner you use) and our legitimate interest in preventing abuse.

4.11 Promo codes, invites and partners

Promo codes. Dealers, clubs, events and influencers hand out codes that give AI credits. When you redeem one (“Redeem a code” in the app), the app sends the code, a device key and a Google Play Integrity token (4.8) to our gateway. The device key is your phone's Android ID for this app (it stays the same if you reinstall the app and changes with a factory reset). Our gateway stores only a one-way hash (SHA-256) of the device key and, if your account is linked to a sign-in, a one-way hash of that sign-in, together with the campaign, the code, your account id, the credits and the time. We use them to give each offer (campaign) only once per account, phone and sign-in.

Location-locked codes. Some codes only work within a set distance of a dealer's stand or an event. For those the app asks for location access, reads your position once and sends it with the accuracy of the fix and whether it came from a mock-location app. Our gateway compares it with the code's place and does not store or log it. The app does not send your position for other codes.

Invites. Your account has an invite code, made the first time you open “Invite friends” and bound to a hash of your device key. When a new account redeems it, both accounts get credits. We store the inviting and the invited account, hashes of the invited phone's device key and sign-in, the credits and the time, to apply the limits (a phone or sign-in is rewarded as an invited friend once, not on the inviter's own phone or sign-in, a limited number of invites per inviter). The inviter sees that an invite was rewarded, not who redeemed it. When you share a route as a link (4.12), its public page includes your invite code in the Google Play button, so a friend who installs the app from it is invited by you.

Install referrer. Links to Google Play from our pages and posters add the code (referrer=code=…). After a new install, the app asks Google Play once for this referrer (Play Install Referrer API) and, if it contains a code, opens “Redeem a code” with the code filled in. Nothing else from the referrer is used, and nothing is sent to us until you redeem.

Partners. A promo code can belong to a partner (a dealer, a club or an influencer). If your account is at most 7 days old when you redeem a partner's code, we record that the account (and a hash of its device key) signed up through that partner, for 12 months. During those months our internal partner report lists the account id with the order ids, products and dates of its Google Play purchases, so we can pay the partner a share of what Google paid us for them (from Google Play's earnings report). The partner does not get this report. On its own statistics page the partner sees only totals: how many riders signed up per month, how often each of its codes was redeemed, and its monthly net revenue, commission and number of orders. It never sees your account id, name, e-mail, position or individual purchases, although a partner with very few sign-ups could guess that a rider it met bought something. We also keep the partner's own business contact details (name, kind, contact e-mail, commission rate, notes and payouts) to run the partner agreement.

Legal basis: performance of the contract for granting credits (Article 6(1)(b)); our legitimate interest in preventing abuse of codes and invites and in paying partners correctly (Article 6(1)(f)); bookkeeping law for payout records (Article 6(1)(c)).

Retention: redemption, invite and partner records stay while your account exists. When the account is deleted, the account id is removed from them, but the campaign, code, time and the hashes of the device key and sign-in are kept, so that deleting the account and starting again does not unlock the same offer or invite reward. These hashes are pseudonymous: anyone who knows the phone's Android ID for this app could match them. Payout records are kept as long as Swedish bookkeeping law requires. Your invite code is deleted with your account.

4.12 Shared routes and collections, group rides and the route gallery

Shared routes (AddStride Plus). “Share as QR code” on a library route uploads the route file to our servers and gives a link and QR code (app.addstride.com/s/…) that works for 30 days. The link is random and cannot be guessed, but anyone who has it can see the route's public page without an account (name, description, distance, time, climb, gravel share and the route line on a map) and anyone with the AddStride app can save a full copy. The full copy is the route file as in your library: the line, the waypoints with their names and notes, the route settings and the time it was made. Your name and account are not shown; the page includes your invite code (4.11). The share is deleted by a daily job after the 30 days, or when you delete your account. Copies others have saved are theirs.

Shared route collections (AddStride Plus). Sharing a route collection (for example a trip of several days) uploads the collection (its name, colour, order and day setting), the full route files of its routes (up to 20) and the POIs you added to it (name, position, category and note) to our servers and gives a link and QR code (app.addstride.com/cs/…) that works for 30 days. As for a single route, the link is random, anyone who has it can see the public page without an account (the collection's name and, for each route, its name, description, figures and line on a map), and anyone with the AddStride app can save a full copy of the collection, its routes and POIs. Your name and account are not shown; the page includes your invite code (4.11). Route and collection shares count together towards the daily share limit. The share is deleted by a daily job after the 30 days, or when you delete your account.

Group rides. A Plus rider (or we, on behalf of a dealer or club) can plan a group ride: a title, details, a meeting point (the start of the route), a date and time and the route. Anyone with the link or QR code (app.addstride.com/e/…) sees these and the number of riders who joined, without an account; joining in the app saves the route file to your library. Riders do not see who else joined, and the organiser is not named, except that rides we plan for a partner show the partner's name. We store the ride, the organiser's account id, and the account ids of the riders who joined with the time they joined. Choose the meeting point and the text with this in mind: it can be passed on to anyone. A group ride can also be planned for a whole route collection: the ride then stores the collection's name, its routes (up to 20 full route files) and its POIs, everyone with the link sees the collection's name and each route's name, figures and line, and joining saves the collection with its routes and POIs to your library (an older app saves the first route). Group rides, with their routes and collections, are deleted 30 days after their start time; a cancelled ride is kept until then. Rides you organised and your participation are deleted with your account.

Route gallery (“Discover”, app.addstride.com/g). “Publish to gallery” sends the route file and an optional description to our server, which uses it only to make a publication copy; your own file is not stored with the gallery. Before you confirm, the app shows exactly what the copy contains (“What everyone will see”: the line on a map, the name and the figures). The copy:

  • hides where you start and finish, unless you switch off “Hide where I start and finish” (for example when the route starts at a café). A one-way route is cut where it leaves a circle of about 500 to 750 metres around its start and where it enters one around its end (the size varies by route so the centre cannot be worked out), and waypoints inside those circles are left out. A round trip is not cut: it is published whole, but its start and finish are moved to the far side of the loop, so the place you set off from is just a point on the line;
  • leaves out the notes of waypoints, waypoint names (unless you switch on “Show waypoint names”), the original track and file name of an imported GPX, planning details, your own rating of the route, its id in your library and when you made it; the copy shows only the day it was published.

Everyone, also without an account on the web, can see the copy's name, description, distance, climb, gravel share, start point, line, average rating, number of ratings and saves, and the publication day; any AddStride account can save the copy. Your name and account are not shown. We store your account id and your route's id in your library with the copy, so you can update or remove it, and the version of the gallery rules you accepted and when, the first time you publish.

Ridden before publishing. You can publish only a route you have ridden. The app looks among the rides recorded on your phone for one that follows most of the route and sends a simplified copy of that ride's track (at most 2,000 points: positions only, no times or speeds) and the day it started together with the route. Our server uses it only to check that the ride covers the route; the track is not stored and never published. With the route we store, and show publicly, only that it was ridden by its publisher and the month of that ride. Riders with a publisher role (below) can publish without a ride.

Publisher roles. We can give an account a publisher role: partner (a dealer, club or brand we work with), pro or dealer. Routes published by such an account show the role as a badge to everyone. A partner can choose, route by route, to show the partner's name as the publisher; otherwise, and for everyone else, the publisher stays anonymous. We store the role, the partner it belongs to and who of us set it (in our audit log).

Ridden by others. When you save a gallery route (“Save to library”), we store that your account saved it and when. If you later record a ride that follows most of that saved route, the app tells our server once and sends a simplified copy of the ride's track and its start day in the same way as above, again checked and not stored. We store that your account rode that gallery route, the month, a one-way hash of your IP address that changes every day (one count per connection and day) and the time, and the route shows the number of different riders who rode it (‘Ridden by 3 riders’), never who they are. The number of such reports per account and per IP address is limited.

Ratings (1 to 5 stars) are stored with the account id of the rider who gave them. Reports of a route or of a publisher (“Report publisher”) are stored with the reporter's account id, the reason written, the time, a one-way hash of the reporter's IP address that changes every day, and whether the reporter counted as trusted (an account at least 14 days old with a purchase, a subscription, a linked sign-in or a passed Play Integrity check). Every report puts the route on our review list; a route is hidden before we have looked at it only when trusted riders on different connections reported it. The number of reports per account and per IP address is limited. If you block a publisher (“Block publisher”), we store that you blocked them and leave their routes out of your “Discover”; they are not told. We review reports and may hide or delete routes and stop a publisher from publishing (4.13).

Gallery collections (app.addstride.com/gc/…). You can publish a route collection to the gallery as a grouping of routes you have already published there, in your order. Each of its routes is the published copy described above, so the same privacy zone, ridden rule and gallery rules apply; nothing else from your library is sent. We store the collection's name, description, day setting, the order of its routes, your account id and the collection's id in your library (so you can update or remove it), and the time it was published. Everyone can see the name, description, day setting, the routes in it, the totals of distance and climb, the average rating, the number of ratings and saves, and the publication day; any AddStride account can save a copy of the collection with its routes. Your name and account are not shown; a publisher role shows as described above. A route you remove from the gallery, or that we hide, disappears from your collections. Collections are rated, reported (with the same data and limits as route reports, counted together) and moderated like routes; if you block a publisher, their collections are left out of your “Discover” too.

Retention: a published route stays until you choose “Remove from gallery”, we remove it, or you delete your account. A published collection stays until you remove it, we remove it, or you delete your account; removing a collection does not remove its routes. Ratings, reports, blocks, saves and rides of a gallery route (and ratings and reports of a gallery collection) are deleted with the route (or collection) or with the account of the rider who gave them (the count of riders who rode a route stays as a number); reports are also deleted when we close them. The record of your acceptance of the gallery rules and a publisher role are kept until you delete your account or we remove the role.

Ride cards. “Share ride card” draws a picture of a ride (the line and your figures, no map) on the phone and hands it to the app you choose in Android's share menu. It is not uploaded to us.

QR codes. “Scan QR code” uses the Google code scanner in Google Play services, which runs on the phone with its own camera screen; AddStride gets only the scanned link and does not need camera permission. Google may collect usage information about the scanner under its own terms.

Legal basis: performance of the contract (Article 6(1)(b)) for the features you choose to use; our legitimate interest in keeping the gallery free of illegal or harmful content (Article 6(1)(f)) for reports and moderation.

4.13 Administration and the admin site

A few people at Swedtech Systems AB operate the service through an internal admin site (admin.addstride.com) and scripts. The admin site is not for riders. Its users sign in with their Google account through Firebase Authentication; only verified e-mail addresses on our list get access. Through it they can look up an account by its id or by part of a linked sign-in e-mail, see its creation and last-use time, credit balance and ledger, plan, linked sign-ins, invite code, partner and redeemed offers, grant credits or Plus, make a recovery code at your request, manage codes, partners and payouts, cancel group rides, hide or delete gallery routes and gallery collections and suspend a gallery publisher (hide all their routes and collections and stop new ones). For moderation they see which account published a gallery route or collection and the reports about it. Every change is written to an audit log with the administrator's e-mail address, the action, its target (for example an account id or a gallery route) and details such as the amount granted and a note.

Legal basis: our legitimate interest in running, supporting and securing the service and in being able to show who changed what (Article 6(1)(f)).

Retention: audit log entries are kept as long as they are needed to account for changes to credits, entitlements and content and to investigate security incidents; they are not removed when an account is deleted, but then refer only to an account id that no longer exists.

4.14 What we do not do

  • The microphone is used during a dictation session that you start by tapping the microphone button. Tap again to stop; recognition also ends when you finish speaking. On-device recognition is preferred, but the phone's speech service may use its provider's servers when on-device recognition or the required language is unavailable. That provider's privacy terms govern its processing and retention of audio. AddStride's servers do not receive audio.
  • We do not read your contacts, calendar, messages or files other than the GPX files you open with the app and the pictures you choose to attach.
  • AddStride does not operate its own cross-app tracking system. Google's advertising processing is described in section 4.6 and depends on your choices.
  • We do not request background location. Navigation and ride recording run as a visible foreground service with a notification, only while you have started them.
  • We do not sell personal data, and we do not use your data to train AI models.

5. Recipients

We use these processors and independent parties:

Recipient Role What Where
Google Cloud EMEA Ltd / Google LLC Processor: hosting (Cloud Run, Cloud SQL, Cloud Storage, Secret Manager, Pub/Sub) Account, ledger, synced data, request metadata europe-north1 (Finland)
Google LLC (Firebase Authentication) Processor Sign-in identifier, e-mail, name; for our administrators, their Google sign-in to the admin site EU/USA
Google LLC (Firebase Crashlytics) Processor Crash reports USA
Google LLC (Google Play, Play Billing, Play Integrity, Play Install Referrer) Independent controller for Google Play; processor for purchase verification Purchase tokens, order ids, device integrity, the referrer of a new install EU/USA
Google LLC (Google code scanner in Google Play services) Independent controller for its usage information Scanning a QR code on the phone; AddStride receives only the link On the phone; usage information EU/USA
Google LLC (AdMob) Independent controller for advertising, with your consent Advertising id, device data, ad events EU/USA
Anthropic, PBC Processor: AI models (Fast, Balanced, Best tiers) Assistant prompts, pictures, route data, replies USA
OpenRouter, Inc. and the model provider it selects Processor and sub-processors: AI model (Budget tier) Assistant prompts, pictures, route data, replies USA and possibly other third countries
OpenFreeMap Independent service Map tile requests (IP address, map area) EU
Photon (komoot) and Overpass API Independent services Search text, positions looked up, map area or simplified route. Searches from the web planner and from current app versions go through our server, so these services see our server instead of your IP address; older app versions send them from the phone with your IP address EU
brouter.de Independent service Routing-data tile downloads (IP address) EU
Other people: anyone with a link, other riders and the public Recipients of what you choose to share Shared routes and route collections and group rides (to whoever has the link) and gallery routes and collections (to everyone), without your account; a partner may choose to show its business name (section 4.12) Worldwide
Partners (dealers, clubs, influencers) Independent controllers of what they receive Totals only: sign-ups per month, code redemptions, net revenue, commission and orders per month; no data about individual riders (section 4.11) Mainly Sweden and the EU

We do not disclose personal data to anyone else unless the law requires it. Partners receive the totals described in section 4.11 under their partner agreement, without individual rider records. Small totals may still allow a partner to infer information about a rider it knows.

6. Transfers outside the EU/EEA

Anthropic, OpenRouter and its providers, and parts of Google's services process data in the United States or other countries outside the EU/EEA. Our providers' applicable data-processing terms set out their international-transfer safeguards, including European Commission standard contractual clauses where required. See Anthropic's data-processing addendum, OpenRouter's commercial terms and incorporated data-processing agreement and Firebase's privacy and transfer information. Contact support@addstride.com for information about safeguards applicable to your data.

You can avoid the transfer to OpenRouter by not using the Budget tier, and the transfer to Anthropic by not using the assistant at all.

7. Your rights

Under the GDPR you can:

  • Access your data. Settings › Account › Download all data provides an export of the cloud data available under your plan and the credit ledger. For a complete personal-data access request, including data not available through that export, email us; a paid subscription is not required to exercise this right.
  • Correct data. Routes, rides and names can be edited in the app. Publish a gallery route again to update it, or remove it with “Remove from gallery”; a gallery collection is updated by publishing it again and can be removed the same way.
  • Erase your data. Settings › Account › Delete account and cloud data, or see https://addstride.com/delete-account.
  • Restrict or object to processing based on legitimate interest (crash reports, abuse prevention, partner attribution, moderation).
  • Data portability. The zip export and GPX export are machine-readable.
  • Withdraw consent for personalised ads at any time under Settings › Privacy options; this does not affect processing before the withdrawal.
  • Complain to a supervisory authority. In Sweden this is Integritetsskyddsmyndigheten (IMY), https://www.imy.se. You may also complain to the authority in your own country.

Write to support@addstride.com. We answer within one month. To find your data we need the AddStride account id shown under Settings › Account, or the e-mail address you signed in with.

8. Account deletion

Deleting the account removes the active AddStride account, its device tokens and gateway sign-in links, credit balance and ledger, synced routes, route collections, rides, POIs, trails, conversations and settings, ride track files and request metadata, your invite code, your shared route and collection links, your gallery routes and gallery collections with their ratings and reports, the ratings and reports you gave, the group rides you organised and your participation in group rides. Copies of shared, published or group-ride routes and collections that other riders saved stay in their libraries. Promo-code, invite and partner records stay without the account id, with the hashed device key and sign-in, as described in section 4.11; admin audit log entries stay as described in section 4.13. Order, subscription and ad transaction records remain for the purposes described above with the AddStride account reference removed. Database backups expire under the seven-day retention schedule. Diagnostic logs and Firebase sign-in records have separate retention; email us to include these in a deletion request, subject to necessary security and legal exceptions. Data on your phone is not touched. A running AddStride Plus subscription is not cancelled by deleting the account; cancel it in Google Play.

Website visits

This website uses Firebase Hosting. Google processes visitors' IP addresses and request information to serve the pages and prevent abuse, and retains Hosting IP data for a few months under its published privacy information. Our legal pages do not add advertising, analytics or tracking cookies. The legal basis is our legitimate interest in providing a secure, accessible website.

9. Children

AddStride is made for motorcyclists and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, write to support@addstride.com and we will delete it.

10. Security

Traffic between the app and our servers and third parties is encrypted with TLS; the app refuses unencrypted connections. Stored data at Google Cloud is encrypted at rest. Device tokens are stored only as hashes, and device keys and sign-ins used for codes and invites only as one-way hashes. Links to shared routes and collections, group rides and partner statistics are long random values that cannot be guessed. Secrets are kept in Google Secret Manager. Access to production data is limited to the people who operate the service; the admin site lets in only listed, verified Google accounts, is kept out of search engines, and every change made through it is logged (section 4.13).

11. Changes

We will post changes on this page with a new effective date and, for material changes, tell you in the app before they apply.

12. Contact

Swedtech Systems AB, support@addstride.com.

© 2026 Swedtech Systems AB, Staffanstorp, Sweden
Plan in your browserPrivacyTermsDelete accountsupport@addstride.com