Authentication provider for passwordless email-code, Apple and Google sign-in and email verification.
Privacy
How Sunset Cycle handles crew data.
Sunset Cycle is a private ride-planning app. Verified members can create a crew or join by invitation. This notice explains what data the app uses, why it uses it and what does not belong in the service.
Controller and contact
Neuronet Ltd is the controller of personal data handled through Sunset Cycle and this website. “Sunset Cycle”, “we” and “us” refer to that controller. Contact support@sunsetcycle.co.uk.
What we collect
- Native Clerk passwordless email-code, Apple and Google identity and existing web Supabase/Google identity, including the account identifier, email, verification status and profile name returned during authentication.
- Crew membership records, organiser status, invite redemption and starter-link creation.
- Approved spots, pending spot suggestions, ride plans, ride votes, meeting-point text and home check-in timestamps.
- Ride participation and completion records, ride and sunset-day counts, optional bike category, and private one-to-five sunset ratings. These are self-reported activity records, not GPS distance or medical measurements.
- First Plan views and authenticated returns, recorded with your account identifier, optional crew identifier, London date and event timestamp. These first-party usage events are linked to your account; they are not anonymous.
- Private messages and ride-vote content. The native and web apps can also store photos, captions and reactions shared inside a crew.
- Reports, member blocks and account-deletion actions created through the mobile app.
- Expo EAS Observe collects an anonymous identifier unique to each app installation, session identifiers, startup timings, and device and network performance information to monitor reliability. These performance metrics are separate from our account-linked pilot usage events.
- Authentication and hosting providers process network and service information, such as IP addresses, session information and request/error logs, to secure and operate the service. These may be associated with your account or session.
What we do not collect
- No public profile or public discovery directory.
- No live tracking or route history.
- No home addresses in planning.
- No advertising SDKs or data-selling behavior in the current app codebase.
- No background location tracking, motion-activity collection, HealthKit or Google Fit integration in the current native app.
Optional location and saved meeting places
When you choose Use my location, the native app requests foreground location permission and rounds phone coordinates to two decimal places before sending a nearby-place request. iOS may provide a more precise position on the device, but the app rounds it before transmission. You can decline permission and enter a public spot manually. Rounded lookup coordinates are not saved in crew records; provider request logs may still contain network or lookup information. We do not claim end-to-end zero retention.
Saved public spots, map links, meeting times and ride participation are retained separately. They associate your account with a planned or completed ride at a public meeting place. They are not a live location feed.
How shared photos are handled
Native photo selection does not request EXIF metadata. Photos selected in the native or web app are prepared on the device and re-encoded on the server before storage, removing embedded camera metadata such as GPS data. Photos are kept in private crew storage. Authenticated crew members receive signed viewing links that expire after five minutes (300 seconds). If you choose the native Share action, the recipient or app you select receives that temporary photo link and can view it until it expires. A recipient may save a copy while the link is valid; expiry does not remove copies they have saved.
Why we use the data
- To authenticate members and keep each crew separate.
- To operate private messaging, spot approvals, ride voting and ride planning.
- To show weather, sunset context and AI-assisted ride summaries.
- To show your ride history, personal ratings and statistics, and keep pending home check-ins available.
- To understand use of the pilot and improve it, using first-party usage events and counts derived from ride records. We do not use these records for targeted advertising.
- To answer support, privacy and deletion requests.
AI-assisted summaries
The Ride tab may generate a short AI-assisted headline or summary from the selected day, forecast context and approved-spot context. The assistant does not need your password, invite token, full private chat history or photo library to create that summary. Requests contain public spot context, date, weather and a spot reference; they do not contain your account identifier or crew messages. These summaries are generated planning aids, not guarantees. Configured providers process requests under their service terms; a request for restricted retention or training is not a promise that every provider retains no data.
UK lawful bases
- Contract, to provide the account, private crew and requested app features.
- Legitimate interests, to secure the service, prevent cross-crew access, handle abuse and keep it reliable.
- Legitimate interests, to measure pilot uptake and improve the service using limited account-linked usage events and activity counts. You can contact us to object to this processing.
- Consent, when you choose optional device location permissions.
- Legal obligation and legitimate interests, to handle privacy, support and deletion requests.
Who processes the data
Authentication, database, realtime updates and private storage.
EAS Observe processes app-installation, session, startup, device and network performance metrics.
Hosting and serverless endpoints.
Map links, broad place lookup and public-place suggestions.
Sunset and forecast data.
Routes approved spot names, broad areas, forecast evidence and a spot reference to the configured model provider. It does not receive your account identifier, crew messages, photos or password in that request.
International transfers and security
Some providers may process information outside the UK. Where UK transfer rules apply, we rely on the safeguards in the relevant provider agreement, such as adequacy regulations or approved contractual clauses. We also use encrypted connections, crew-scoped database rules, private photo storage, short-lived photo links and server-side image validation. No online service can guarantee absolute security.
Retention and deletion
- Invite and starter links expire automatically after seven days if unused.
- Crew content stays available until it is deleted, the account is removed or the crew records are cleared.
- Photos remain until their uploader removes them, related crew data is cleared or the account is deleted.
- First-party pilot usage events have a 180-day retention rule and a daily deletion schedule. This rule does not apply to shared ride records, support records or provider backups.
- Expo retains EAS Observe metric data for at least 60 days, under its separate metrics data-handling policy. This is separate from the 180-day account-linked pilot-event retention rule.
- Start account deletion in MY SC → Delete account, or use the account-deletion page if app access is unavailable. Deletion removes personal membership, authored messages and polls, votes, ratings and usage events, then removes the authentication accounts. It can remain pending if one service fails; contact support if it does not finish.
- Shared rides and public spots can remain with account attribution removed. A quoted excerpt copied into another member's message may remain. Local onboarding preferences may also remain on the device; deleting the app removes its local app data.
- Limited provider logs and backups may remain for their normal security and recovery cycles before being overwritten.
Website storage and cookies
This public site has no advertising, analytics, tracking pixels, social embeds or non-essential cookies. The app stores its authentication session and essential app state on your device. Both the native and web apps link to this notice from their account surfaces. The account-linked pilot measurement described above happens in the app and service, not through marketing-site cookies or third-party advertising pixels.
Teens and children
Sunset Cycle is intended for teens and adults aged 13 and over, not children under 13. If you are under 13, do not create an account or send personal data through the app. Contact support@sunsetcycle.co.uk if you believe an under-13 child has created an account so we can investigate and arrange removal of their personal data. Users under the age of majority should review this notice with a parent or guardian. Any consent required by applicable local law must be obtained before the relevant processing.
Your rights
You may have rights to access, correct, erase, restrict or object to processing, receive a portable copy of certain data and withdraw consent for optional processing. These rights can have lawful limits and we may verify your identity. Email support@sunsetcycle.co.uk. We normally respond within one month. If you are in the UK and remain unhappy, you can complain to the Information Commissioner’s Office.
Last updated 8 September 2026