Cette documentation n'est disponible qu'en anglais.

Privacy: AI assistants and your FlaMap data

This page covers only the FlaMap MCP server, the connection that lets an AI assistant read your FlaMap data. The FlaMap privacy policy covers everything else.

In short

  • Nothing is shared until you connect. FlaMap sends nothing to any AI assistant on its own. Data leaves FlaMap only after you connect an assistant yourself, and only when that assistant calls a tool, which happens when you ask it something.
  • Read-only. A connected assistant can read your data. It cannot change, delete, upload or share anything in FlaMap. FlaMap refuses writes from connected apps even if one tried.
  • Your data only. Every request is limited to your account, and the limit is enforced in the database, not only in the app. An assistant cannot reach another rider's data.
  • Health data needs your explicit consent. Heart rate, HRV and weight can say something about your health. The consent screen names them, and the website will not approve a connection until you tick a box that says you agree to share them. Every connection is approved through that box: connections made before 26 September 2026 were revoked and must be approved again. See Consent.
  • Your data may leave the EU. Most assistant providers are in the United States. See Transfer outside the EU.
  • You can revoke at any time, in the assistant or on flamap.app. See below.
  • No training, no sale. FlaMap does not use what your assistant reads to train models, and does not sell it.
  • The assistant's provider decides what it keeps. Once your assistant has read your data, the provider (for example Anthropic, OpenAI, Google, Cursor or GitHub) handles it under their own policy: chat history, retention, and whether chats train their models. Check their settings.

What an assistant can read

The exact list is in the README and every tool is in the tool reference. In summary: your rides and their summary metrics, ride streams without GPS positions, your climb efforts and saved climbs, your planned routes without their GPS track or navigation waypoints, and a short profile (thresholds, weight, age, timezone, units).

What FlaMap withholds or trims

FlaMap gives an assistant what coaching and analysis need, and not what could locate your home or identify you beyond that (GDPR data minimisation). The rules on positions and date of birth are the same for every tool, including query:

  • No start or end of a ride. The start point, the end point and the summary map line of a ride are never returned.
  • Nothing within 500 m of where a ride starts or ends. Where a tool returns positions from a ride you recorded, every position within 500 m, in a straight line, of the ride's first or last GPS fix is withheld, wherever along the ride it falls. It is measured from those two points, not along the ride: GPS drift while you wait at the door cannot use up the 500 m, and a loop that passes your home halfway round is blank there too. A ride that never gets more than 500 m from its start and end has no positions at all. The other measurements (power, heart rate, cadence, speed, elevation, time) are kept complete, second by second, so nothing about the effort is lost; only the position is blank there. Planned routes follow the same rule. Today no tool returns ride or route positions at all: ride streams have no GPS channel, and routes and rides come without their geometry. The rule is there so that stays true if one ever does.
  • Age, not date of birth. The profile gives your age in whole years. Your date of birth is never returned.
  • No identity fields. No tool, query included, returns your email address, username, profile photo, home location name, date of birth, or the serial numbers of your devices. query can read your gender and height if you filled them in, your age, and the devices recorded with each ride with their serial numbers removed.
  • Pass-through details are filtered. Extra ride details that FlaMap passes through (laps, pauses, HRV, climb efforts of one ride) are filtered for positions, map lines and serial numbers before they are sent. Data fields added by apps on your device (developer fields) are dropped whole when their name, units or the standard field they stand in for say they record a position (latitude, longitude, GPS, coordinates), since there the position is the value, whatever the field is called.

Kept, because the analysis needs it: the date and time of each ride, and the town and country where it started (for weather, terrain and travel questions). Climb locations come from the public climb catalogue, not from your rides.

What it can never read: your email address, your password, tokens for accounts you linked to FlaMap, your share links, the cover images of your rides and routes (they show the ride's map), your profile picture, and other riders' data.

You connect an assistant by signing in to FlaMap on flamap.app (with Google or an emailed code) and approving its request on the consent screen. Nothing is shared unless you approve.

Before you can approve, the screen tells you:

  • which app is asking, and the address it will send you back to;
  • what it will be able to read: your rides (power, heart rate, heart rate variability, cadence, speed, elevation and temperature over time, ride summaries, and the town and country where each ride started), your efforts on climbs, your saved climbs, your planned routes (with their town and country), and your profile (FTP, weight, height, gender and age, never your date of birth); and that it can run read-only database queries limited to your own data;
  • what is never shared: your GPS tracks, the exact route of any ride, and where your rides start and end;
  • that access is read-only;
  • that nothing is shared until you approve, and after that only when the assistant asks FlaMap for data it needs to answer you;
  • that once the assistant has your data, its provider, not FlaMap, is responsible for it, under the terms and privacy policy you have with that provider, including how long it is kept;
  • that most providers are in the United States, so your data may leave the EU for a country whose laws may not protect it as well as EU law does;
  • that FlaMap does not sell your data or use it to train AI models;
  • how to withdraw: on flamap.app/settings/ai-assistants or in the assistant, and that deleting your FlaMap account removes every connection;
  • a link to the privacy policy, section 4.2.

Then comes a box you tick yourself. It is never ticked for you:

I explicitly consent to Flamap sharing my health-related data (heart rate, heart rate variability and weight) and my detailed activity data (ride metrics such as power, speed and elevation over time) with assistant, including its transfer outside the EU, as described above.

Approve stays greyed out until the box is ticked. Deny always works, ticked or not. The website's server also refuses to pass on an approval without the tick, so the website itself cannot approve without it. The box starts unticked again every time a request is loaded.

As with any OAuth provider, anything that already holds your own FlaMap sign-in (the FlaMap app, or a script you gave your login to) could approve directly at the sign-in provider, without the website and without the box. Keep your sign-in to yourself.

Connections made before 26 September 2026, when the box was added, were revoked, so an assistant connected before then asks you to approve again, with the box, the next time it connects.

Our sign-in provider (Supabase) records the approval: which app, and when. FlaMap stores nothing new about the connection.

Heart rate, heart rate variability (HRV) and weight can reveal information about your health. Under the GDPR they may be "special category" data (Art. 9), which may only be shared on your explicit consent. That is what the box above is: it names these data, and the website does not approve a connection without it. Refusing costs you nothing in FlaMap: every other feature works the same.

An assistant can draw conclusions from these numbers (fatigue, illness, weight change). Those conclusions are the assistant's, made on the provider's side. FlaMap does not make them and does not receive them.

Transfer outside the EU

Most AI assistant providers (Anthropic, OpenAI, Google, Cursor, GitHub) are based in the United States. When your assistant reads your FlaMap data, it is sent to that provider, so it may be transferred outside the European Economic Area, to a country whose laws may not protect it as well as EU law does. The provider is not FlaMap's processor: it receives your data because you asked it to, under its own terms with you.

This transfer relies on your explicit consent, given on the consent screen after being told of it (GDPR Art. 49(1)(a)). FlaMap makes no statement about any provider's certifications; check the provider's own privacy policy.

Revoking access

Do it on either side. Doing both is the surest.

In your assistant. Remove or disconnect FlaMap. The assistant stops calling FlaMap straight away. Each connect page says where the setting is.

On flamap.app. Open flamap.app/settings/ai-assistants. It lists every assistant you have connected and when. Select Revoke next to one. The assistant can no longer renew its sign-in, so its access ends when its current sign-in expires, within one hour at most. To reconnect later, you sign in and approve again.

Deleting your FlaMap account removes every connection with it.

What FlaMap records

For each tool call, FlaMap's MCP server logs: the tool name, a one-way hash of your account id, which app made the call, whether it worked, how long it took and how much data it returned. When the tool's request to the FlaMap API fails, it also logs the error status and the API path, without the query string.

FlaMap's API logs each request from a connected assistant by method and path, without the query string. When a query fails, it logs the database error code and a one-way hash of your account id.

FlaMap does not log what the assistant asked for (tool arguments, search text, filters, ids in the query string, SQL), the answers, database error messages, or your sign-in tokens.

These logs are for security and keeping the service running. They are kept in rolling, size-capped service logs that are overwritten as new logs arrive.

Your rights (GDPR)

FlaMap applies the same rules here as for shared route links: access is controlled in the database by design, only what the feature needs is exposed, and you can withdraw it at any time with effect from that moment.

  • Legal basis. Sending your data to an assistant is based on your consent (Art. 6(1)(a)), your explicit consent for health-related data (Art. 9(2)(a)) and your explicit consent to the transfer outside the EU (Art. 49(1)(a)), all given by ticking the box and approving the connection. Every connection is approved through the box: connections made before 26 September 2026 were revoked and must be approved again. You can withdraw it at any time by revoking access, as above. Withdrawing does not affect what was shared before, and does not delete what the provider already received.

  • Who is responsible. FlaMap is responsible for your data while it is in FlaMap, and for sending it only to the assistant you approved. Once your assistant has received it, its provider is responsible for what happens to it there.

  • Data minimisation. Only the fields listed above are exposed, with the start and end of every track withheld as described in What FlaMap withholds or trims. GPS tracks and navigation waypoints of planned routes, cover images, full-resolution positions, start and end points, map lines, date of birth, linked-account tokens and share links are excluded at the database level.

  • Access and export. Your FlaMap data export works as before. Connections are not part of it: they are records of your approval, not ride data. You can see them on flamap.app/settings/ai-assistants.

  • Erasure. Deleting your FlaMap account deletes your data and your connections. It does not delete what an assistant already read; ask its provider, or delete those chats.

Questions

See Support.