Privacy policy
Last updated 6 October 2026.
Selekoh is a ride recording, group ride and garage app for motorcyclists, built and run in Malaysia by Selekoh, the data user under Malaysia's Personal Data Protection Act 2010 and the data controller under the GDPR and UK GDPR for riders in Europe. This page says what the app collects, where it goes, who can see it, and how to remove it. It is written to be read, not skimmed past; if anything here is unclear, write to support@selekoh.app.
The short version
- Your rides are recorded on your phone. They only reach our servers if you sign in and keep cloud sync on, and then only you can read them.
- What you share (a route link, a share card, a family link) is what leaves the phone. Privacy zones and the share range cut out the parts near home before anything is shared.
- During a group ride, your live position is visible to the members of that ride and to anyone holding a family link for it, for the ride only.
- We count how the app is used (which features, how long rides are), under a code that cannot be turned back into you. No location in those counts. You can switch this off.
- No advertising, no data brokers, no selling or renting anything, no tracking across apps or sites.
- You can delete your account inside the app. That removes everything we hold about you.
What is collected, and where it is kept
| Data | When | Where | Who can see it |
|---|---|---|---|
| GPS track of a ride (positions, speed, altitude, time) | While you record | Your phone. If signed in with cloud sync on: an encoded copy in Cloudflare R2 so a new phone can restore it | You only |
| Ride summary (name, notes, bike name, times, distance, speeds, climb, bounding box) | When a ride is saved, if signed in with cloud sync on | Supabase (Singapore) | You only |
| Account: the identifier, email address and name Apple or Google gives us when you sign in with them (with Apple's Hide My Email, the relay address Apple makes for you) | When you sign in | Supabase (Singapore) | Us, to run your account |
| Display name and avatar picture | When you set them | Supabase; the avatar in Cloudflare R2 | Members of your events, riders who open your published routes, and anyone holding a family link for a ride you are in |
| Phone number (optional) | When you add it | Supabase (Singapore) | Only members of an event you are both in, until 24 hours after that event ends. Never on public pages |
| Events you create or join, your role and RSVP, the meeting point | When you use Together | Supabase (Singapore) | Members of that event |
| Live position and status during a group ride | While the live map is open | A Cloudflare live room that keeps only the latest position per rider; statuses clear after 30 minutes and the room empties after 6 hours without traffic | Members of that ride, and anyone with a family link (see below) |
| Published routes: the line after privacy zones and share range, name, description, distance, your display name and avatar | When you publish a ride as a route | Supabase (Singapore) | Anyone with the link, while it is published. Unpublish or delete at any time |
| Feed posts: the line after privacy zones and share range (or none, for a day post), distance, moving time, climb, the date, caption, up to four photos, your display name and avatar, and if you choose your bike's make and model; likes and comments you leave; who you follow and block; reports you send | When you post, react, follow, block or report | Supabase (Singapore); photos in Cloudflare R2 | Posts, likes and comments: signed-in Selekoh riders (followers, and anyone browsing the week's popular posts). Follows: shown as counts. Blocks and reports: only us |
| Emails you send us, with the line the app adds to support mail (app and iOS version, phone model, language, Pro or not, units) | When you write to us | Your mail provider and ours | Us, to answer you. Deleted within a year of the last reply |
| Subscription status: whether you have Pro, until when, and Apple's identifier for the subscription. Never card or billing details: Apple takes the payment | When you buy, renew or restore Pro, and when Apple tells us of a renewal, refund or expiry | Cloudflare, in a record kept for your account | Only us, to set your cloud storage limit |
| Usage statistics (see next section) | While you use the app, unless switched off | Cloudflare R2, as pseudonymous event lines and daily totals | Us only, in aggregate |
Usage statistics
To know which features matter and where the app fails, the app sends counts of what happens in it: a ride was recorded and how long it was, a feature was opened, a bike of this make and model was added, a sync failed, the app and iOS version. Each line carries a random install code, and, if you are signed in, a one-way salted hash of your account id. That hash lets us count returning riders; it cannot be reversed into your account, and after you delete your account nothing links to it any more. Cloudflare adds the country and state your request came from. There is never a GPS position, a track, a name, a note or a route name in these lines.
Settings → Privacy → Share usage statistics switches this off. Turning it off sends one last line saying so, then nothing more, and the install code is discarded. These lines are kept indefinitely because their value is in the trend.
The feed
Posting is always your decision: nothing from a ride reaches the feed until you tap Post, and a day summary is only ever offered, never posted on its own. A post shows the date but never the time of day. A post with a map also names the country and, in Malaysia, the state it was ridden in; the phone works that out from the shared line against outlines built into the app, so no position is sent anywhere to be named, and a post without a map names nothing. Narrowing the popular feed to your state or country sends that code with the request and nothing else; which place is yours is worked out on the phone from your own rides and is not stored anywhere. Photos are re-encoded on the phone before upload, which removes location and camera metadata. You can hide or delete a post at any time; deleting removes its photos, likes and comments. Comments can be turned off per post. Blocking a rider hides you from each other and removes any follows between you. Reports are private and are handled by human moderators, who can hide or remove content and, for repeated or serious breaches of the community guidelines, remove an account. Removing a post or account removes its photos within the hour. A post that three different riders report is hidden until a moderator has looked. Every write to the feed has a daily limit per account, to keep spam out.
Family links and route links
A family link (live.selekoh.app/share/…) shows the names and live positions of everyone in that group ride to anyone who opens it, for 12 hours, or until the leader ends the ride. Treat it like a key: send it only to people you want watching. A route link shows the route line, the numbers, and the publishing rider's name and avatar to anyone who opens it, while the route stays published.
What is not collected
- Your location when you are not recording, not on a live map, and not picking a place on a map.
- Your contacts, your photo library (only the photos you pick for a post, an avatar or a marker, processed on the phone), other apps, or an advertising identifier.
- Your maximum speed on anything shared, unless you turn that on in Settings.
- Payment details: there is nothing to pay for today.
Who processes data on our behalf
- Supabase (database and sign-in), Singapore region.
- Cloudflare (servers, storage, live rooms, this site).
- Google (Sign in with Google, if you use it). Google confirms who you are and tells us your email address and name; Selekoh asks your Google account for nothing else and calls no other Google service with it.
- Apple (Sign in with Apple, if you use it; App Store). Apple Maps draws the 3D replay and names the towns a replay passes through, so Apple's servers see which map areas a replay covers and the points along it that are asked for a name, under Apple's own privacy policy. Only the shared version of a track is used, so stretches you hide are never sent. The names are kept on the phone and never reach us.
- OpenFreeMap serves the map tiles. Like every online map, its servers see your IP address and which map areas you look at. Areas you have viewed are cached on the phone so they load without a connection.
Nobody else receives your data. Aggregated counts (for example "rides recorded this month") may be shared with partners; nothing in them identifies a rider.
Keeping it safe
Every request to our servers is authenticated with your session token and checked row by row in the database; our servers hold no master key that could read everyone's data. Links that carry access (family links) expire on their own. Uploads have size and storage limits. Errors do not reveal internals. If we ever learn of a breach that affects you, we will tell you and the authority.
Your choices and rights
- Delete your account in the app: Together → profile → Delete account. This removes your profile, phone number, avatar, cloud rides and tracks, published routes, feed posts with their photos, likes, comments, follows, blocks and reports, and your memberships; events you led pass to another leader or are cancelled. Rides on your phone stay.
- Use the app without an account. Recording, replay, sharing videos and the garage work with nothing sent to us except usage statistics, which you can switch off.
- Clear everything on the phone: Settings → Data → Clear all data.
- Get a copy of your cloud data. Email support@selekoh.app from the address on your account and we send everything we hold about you (profile, ride summaries, tracks as GPX, routes, posts, comments) as files within 30 days. Rides on the phone export as GPX from the app at any time.
- Wherever you are, you may ask what we hold about you, have it corrected, restricted, deleted or handed over, object to a use, or withdraw a consent. Email the address above from the address on your account; we answer within 30 days and never charge for it.
If you are in the EU, the UK or Switzerland
The legal bases we rely on: performance of a contract for the account, cloud sync, events, routes and the feed (the things you signed in for); consent for usage statistics (the switch in Settings) and for the phone number you add; legitimate interest for keeping the service secure (rate limits, abuse reports, moderation) and for the aggregate counts that tell us what to build. Nothing is used for profiling or automated decisions about you.
Your data is stored in Singapore (Supabase) and on Cloudflare's network, outside the EEA and the UK. Both providers are bound by their standard data processing terms, which include the European Commission's standard contractual clauses and the UK addendum. We hold no copy anywhere else.
You have the right to lodge a complaint with your supervisory authority; we would rather hear from you first at the address above. There is no representative appointed in the EEA or the UK at this scale; that changes if the law requires it.
How long it is kept
Everything tied to your account: until you delete the account or the item. Live positions: minutes, as above. Pseudonymous usage lines: indefinitely, because their value is in the trend and nothing in them can be traced back to you once the account is gone. Server logs: Cloudflare's default of a few days.
Children
Selekoh is for licensed riders and is not directed at children under 13 (16 where the law sets that age). If you believe a child has created an account, tell us and we will remove it.
Changes
When this page changes in a way that matters, the date above moves and the app says so. Older versions are available on request.