← PainCave

Privacy Policy

Last updated 24 August 2026

The short version

PainCave has no accounts and no user database. Your rides are recorded in your browser and stay there. When you connect Strava, the connection lives on your device and your rides go straight from your browser to Strava — they never pass through, and are never stored on, a PainCave server.

Who is responsible

PainCave is run by one person, not a company. Christopher Boe Jensen is the data controller for the limited personal data described below. You can reach him at support@paincave.fit for any question about this policy, to exercise any right listed under Your rights, or for support.

What PainCave stores on your device

All of the following is held in your own browser (localStorage and IndexedDB). It is not transmitted to us, and clearing your browser data erases it.

  • Your rides — the per-second sensor recording of each session, and the workouts you create or import.
  • Your settings — FTP and display preferences.
  • Your Strava connection, if you choose to connect one — see below.

Strava

Connecting Strava is entirely optional; PainCave works fully without it. If you do connect, this is the complete picture:

What we collect
Your Strava display name, athlete ID and username, plus the access and refresh tokens that let PainCave upload on your behalf. We never read your Strava activities, routes, segments, or anything belonging to other athletes.
How we collect it
Only through Strava’s official OAuth flow, and only after you approve it on Strava’s own screen. PainCave requests just two permissions: permission to upload activities, and the basic read permission needed to link you to the ride once Strava has processed it.
Where it is kept
In your browser on this device, and nowhere else. PainCave has no accounts and no user database — your tokens never reach a PainCave server. Rides are sent straight from your browser to Strava.
How to withdraw consent
Press Disconnect here at any time. You can also revoke PainCave from Strava directly under Settings → My Apps, which cuts off access immediately regardless of what this device does.
How to delete your data
Disconnecting erases everything PainCave holds about your Strava account from this device, and we confirm on screen once it is gone. Because nothing is stored on a server, there is nothing left for us to hold afterwards.

You can review and revoke PainCave's access at any time from your Strava account settings.

Strava may monitor and collect data relating to our use of the Strava API, and may use that data for its own business purposes, including supporting and improving the Strava platform and verifying our compliance with its developer terms. Your use of Strava itself is governed by Strava's Privacy Policy, which applies to your Strava account independently of this policy and controls in the event of any conflict with it.

Analytics

We use Vercel Analytics for aggregate page-view counts. It does not use cookies, does not track you across sites, and does not build a profile of you. It is never combined with Strava data.

Connection diagnostics

If a trainer or sensor fails to connect, PainCave can offer to send a diagnostic report. This is always opt-in, one press per incident, and never automatic. A report contains only connection-technical information: your browser and operating system, the advertised name of your trainer or heart-rate strap, and a log of Bluetooth events. It contains no account data, no location, and no ride content. You can download the report and read it yourself instead of sending it.

Your rights

Under the GDPR and UK GDPR you have the right to access, correct, export, restrict the processing of, object to the processing of, and delete your personal data, and to withdraw consent at any time.

Because PainCave holds nothing on a server, most of these you can exercise yourself and immediately: your ride data is already in your possession and can be exported as a .FIT or .TCX file at the end of any ride, and disconnecting Strava deletes the connection from your device on the spot, with on-screen confirmation once it is gone. Clearing site data for paincave.fit in your browser erases everything else.

If you would like help exercising any of these rights, or written confirmation of a deletion, email support@paincave.fit. You also have the right to complain to your local data protection authority.

Children

PainCave is not directed to children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes materially we will update the date at the top. Continuing to use PainCave after a change means you accept the updated policy.