Last updated: September 8, 2026
Derny (“the app”, “we”) is an indoor cycling training app that connects to a Bluetooth smart trainer and heart-rate monitor and drives adaptive workouts based on your live metrics. This policy explains what data the app handles and why.
The short version: The app works fully without an account, but while Derny is in beta the rides you record are shared with us to improve the app even if you never create one — see “Beta data sharing” below. If you sign in, your account email is stored too, and your workouts and ride history sync across your devices. The app has no ads or advertising trackers. The website counts visits without cookies, and uses limited conversion measurement for our Reddit ads.
While Derny is in beta, the app signs your device in automatically with a random, anonymous identifier the first time you open it. The rides you record — their metrics, the warm-up measurements the app uses to model your fitness, and basic usage events such as which screens you reach — are uploaded to our cloud under that identifier. This happens with no account, and during the beta it is not optional: it is how we find bugs and confirm that adaptive workouts behave correctly on real trainers and treadmills. The identifier is not your name, your email, or any advertising identifier, and we do not use this data for advertising. If you later create an account, that same identifier becomes your account, so the rides you already recorded stay yours. Deleting a ride in the app marks it deleted on our servers and removes its recorded samples; the remaining summary record is erased when the account it belongs to is deleted. While you have no account that is the only deletion route we can act on: an anonymous identifier carries no email address, so we have no way to match an emailed request to your install. If you want us to handle deletion by email, create an account first — it claims the rides that install already recorded — and then write to us at the address below.
The app does not collect your location, contacts, photos, or advertising identifiers, and contains no advertising or cross-app tracking SDKs. We use Sentry for crash reporting, as described above, and count our own usage events in our own backend.
Data is used solely to provide and improve the app’s features: to store and sync your workouts and ride history, show your training metrics, (optionally) mirror finished rides to Apple Health, and keep the app working reliably across different smart trainers. We use the website events described above only to measure our own Reddit ads, and the visit counts only to see how many people reach our pages and how many of them go on to sign up. We do not use your email, account data, or ride data for advertising.
When you are signed in, your account and ride data are stored using Supabase, our cloud backend provider, which processes this data on our behalf. During the beta your rides are stored there whether or not you have an account; outside the beta, when you are signed out your data stays only on your device. Our website is served by Cloudflare, which also provides the cookieless visit counting described above and processes it on our behalf. The crash reports and performance diagnostics described above are processed on our behalf by Sentry, in their United States data region.
We do not sell your personal data. We share account and ride data only with the service providers above, strictly to operate the app, and where required by law. We share the limited website events described above with Reddit to measure our ads, but not your email address or app data.
You can use the app without an account, though during the beta your rides are still shared with us as described above. Without an account, deletion is in the app: delete a ride there and it is marked deleted on our servers and its recorded samples are removed; the remaining summary record is erased when the account it belongs to is deleted. We cannot act on an emailed request for such an install, because an anonymous install has no email address on record and we have no way to match your request to it. The other route is to create an account — it claims the rides that install already recorded — after which you can request deletion of your account and all of its cloud data by emailing us at the address below; we will delete it within a reasonable period. Workouts saved to Apple Health are controlled by you in the Apple Health app.
Data in transit is protected with standard encryption (HTTPS/TLS), and cloud data is protected by access controls so each account can only reach its own records.
Derny is not directed to children under 13, and we do not knowingly collect personal information from them.
We may update this policy as the app evolves. Material changes will be reflected here with a new “last updated” date.
Questions or requests: [email protected].