Cicloruta

Privacy at Cicloruta

Cicloruta is designed to know as little about you as possible. This is what it actually does:

Your location

We use it only on your phone, to show you on the map, calculate the route and guide you. The route is calculated in the browser itself: your starting point and destination are not sent to any server.

What you search for

When you type a destination, the text travels to our server to find the address or place, together with a location rounded to about one kilometre (yours or the centre of the map), used only to rank nearby results first. We do not store searches: they are answered and forgotten, and since they travel in the body of the request they are not written to the server logs either. Offline, the search runs on your phone with the saved places.

Your rides

When you record a ride, it is stored in this browser’s storage (IndexedDB). We never receive it. If you clear your browser data or change phones, it is lost. You can export rides as GPX.

Road reports

When you report a pothole, roadworks or a car in the bike lane, we store the type, the point on the map and the time. Reports are visible to anyone using the app and expire on their own, or when other cyclists confirm they are gone.

To prevent duplicates and abuse we also store an encrypted fingerprint (a SHA-1 digest of your IP address, your browser type and a secret key). We do not store the IP. The fingerprint is deleted after 30 days. Since we do not know who you are, we cannot link a report to a person or answer an access request about it.

What there is not

No accounts, no cookies, no analytics, no advertising and no third-party trackers. The map, fonts and street network are served from this same domain.

The browser keeps a few preferences (last map view, hidden layers, route type, voice on or off). They are needed for the app to work the way you left it and never leave your phone.

Contact

Data is processed under Colombia’s Law 1581 of 2012 and, for people using Cicloruta from the European Union, under the General Data Protection Regulation: the report fingerprint is pseudonymous data processed on the basis of legitimate interest (preventing abuse) and deleted after 30 days. For questions, complaints or to exercise your rights over personal data, write to helena.cortes@udea.edu.co.