Privacy Policy
RallyTrax is an app for recording drives, generating pace notes, and replaying routes with a synthetic co-driver, with an optional Social layer for sharing drives with people you follow. This page describes what data the app collects, how it is used, and the choices you have. It applies to RallyTrax on Android (Google Play and the GitHub Releases sideload channel), iOS, watchOS, and macOS. The platforms do not all behave identically — where they differ (for example, how usage-analytics diagnostics are keyed on Android vs. iOS, or how crash reports are keyed on macOS), the difference is called out explicitly rather than described as if every platform worked the same way.
Summary
- RallyTrax records GPS data on your device while you are recording a drive. Recorded drives sync to your account so you can see them across your devices.
- Signing in (Google on Android and iOS; Sign in with Apple or email/password on iOS) gives RallyTrax your account name and email address, used for sign-in and cloud sync. We do not store or use your profile photo — public Social identities use only your initials or a generated avatar, never a photo.
- Social features are opt-in: a public profile, following other users, and sharing a drive replay are all things you choose to turn on. Nothing about your drives is public by default.
- Wrist heart rate captured by the watch companion never leaves your device — it is not written to RallyTrax's cloud storage under any circumstance. Saving a workout to Apple Health is a separate, opt-in step.
- A handful of convenience features on Android — receipt scanning, license-plate/odometer photo checks, suggested drive and trip names, share captions, route briefings, Year in Review — send text (never images, never GPS coordinates) from your device to Google's Gemini service to generate a suggestion. Section 3 lists exactly what each feature sends.
- On Android, RallyTrax uses Firebase Analytics and Crashlytics to understand which features are used and to diagnose crashes; these are keyed to an install ID, not tied to your name or email. On Android and iOS, RallyTrax also sends a closed set of product-interaction events (for example, opening the replay screen or starting a recording) to a first-party analytics pipeline, keyed to a pseudonymous ID linked to your account — not your account ID itself, see section 1.2 — and kept 90 days; a "Share anonymous usage statistics" toggle in Settings, on by default, controls it. iOS crash reports (Crashlytics) are keyed to a separate one-way pseudonym, not your account. On macOS, crash reports (Crashlytics) are currently keyed to your account ID — unlike iOS, they are linked to your account (see section 1.2).
- RallyTrax does not sell your data, does not show ads, does not use advertising or tracking identifiers, and does not share your data with advertisers or data brokers.
1. Information we collect
1.1 Information you provide
- Account information. To sign in, RallyTrax receives your name and email address — from Google Sign-In on Android and iOS, or from Sign in with Apple or an email/password account on iOS. RallyTrax never sees your password (Apple/Google handle authentication). We do not request or store a profile photo.
- Vehicle and content you create. Vehicles in your garage, fuel logs, service records, modifications and parts, pace notes, recorded drives (tracks), routes, and trips.
- Co-drivers and crews. Co-driver profiles you create, and crews — small private groups you form with other users. Crew check-ins carry an optional status message and, if you choose to share it, your current location.
- Social profile and activity, if you opt in. A public handle and display name, who you follow and who follows you, and any drive replays you choose to publish. See section 1.3.
- Receipt images and PDFs (Android only). When you use the "Scan receipt" feature, the file you pick is processed on your device by Google ML Kit. The image itself is never uploaded. The parsed text is stored locally (and synced to your cloud account if cloud sync is on), and the text read from the receipt, along with the parsed fields (shop name, totals, odometer), is sent to Google's Gemini API to structure the line items and draft a short summary note. See section 3 for details on the AI step.
1.2 Information collected automatically
- Precise location (GPS). Collected while you are actively recording a drive, and stored as part of that drive so it can sync and be replayed. On iOS, recording continues in the background (screen off, phone in a cradle) via a background-location permission. Location also appears, only if you choose to include it, in a crew check-in, and in a drive replay you publish (see Social, below).
- Sensor and vehicle data. During recording, RallyTrax reads device motion (accelerometer, gyroscope, barometer where available) to improve pace-note accuracy and power the cornering/g-force display, plus OBD-II vehicle telemetry if you connect a compatible adapter over Bluetooth. This data is treated as part of the drive you recorded.
- Wrist heart rate (watchOS, opt-in). If you record a drive from the RallyTrax watch companion, heart rate is read from the workout session but never leaves your device or your watch — it is not written to Firestore, not included in any synced drive, and not part of any Social surface. Saving the session to Apple Health is a separate opt-in step, and that copy stays inside Apple Health.
- Identifiers. Your account is keyed by a Firebase user ID, and, if you claim one, a public handle. The app also uses a Firebase installation ID, generated per install and used internally by Firebase/Crashlytics for install-level grouping — it is not linked to your account by anything in RallyTrax.
- Weather data (iOS). To show a forecast for a planned drive, RallyTrax sends the relevant coordinates to Apple's WeatherKit.
- Diagnostics and app activity. On Android: app usage and crash data via Firebase Analytics and Firebase Crashlytics, keyed to an anonymous install ID — which screens you view, which features you interact with, device model, OS version, and crash stack traces. On Android and iOS: RallyTrax also sends product-usage analytics through a separate, first-party pipeline — a fixed, closed list of interaction events (for example, opening the replay screen, starting or saving a recording, using a specific feature, reacting to a feed post, or the app hitting an error). Every event is one of a small set of pre-defined types carrying only pre-defined values: there is no free-text field, and an event can never carry your name, handle, email, GPS coordinates, or a specific drive/route/vehicle identifier. Events are keyed to a pseudonymous ID that our servers derive from your account ID — not your account ID itself, and never computed by or visible to the app — but because our servers can re-derive it, it is linked to your account, which is how we find and remove these rows if you delete yours (section 6). Events are kept 90 days and used only to understand product usage: never for advertising, and never sold or shared with anyone for tracking. A "Share anonymous usage statistics" toggle in Settings controls this on both platforms — on by default; turning it off stops new events immediately, though it doesn't retroactively delete what's already been sent (those rows still age out after 90 days, or sooner if you delete your account). Crash reporting is a separate system: on iOS, Crashlytics crash reports are keyed to a pseudonym derived on-device from your account ID plus a device-local secret (a one-way hash, reset if you reinstall) rather than your account ID directly, and crash breadcrumbs are scrubbed of your email, handle, display name, and coordinates before they're sent. On macOS: RallyTrax uses Crashlytics for crash reports, and those reports are currently keyed to your Firebase account ID — unlike iOS's pseudonym, a macOS crash record is linked to your account until it ages out (section 5). We intend to bring macOS to the same pseudonymous scheme as iOS; until this page says otherwise, treat macOS crash data as account-linked. Neither macOS nor watchOS sends the product-usage events described above today.
1.3 Social — what's public and what isn't
RallyTrax's Social features are opt-in. Nothing below happens until you choose it.
- Public profile. If you claim a handle, your public profile shows your handle, display name, and an avatar — either your initials or a small set of generated designs. RallyTrax does not support photo avatars; there is no upload path for one.
- Following. You can follow other users; some accounts require the account holder to approve a follow request before you can see their gated content. Public feed cards never include raw route geometry or a precise bounding box.
- Drive replays. Publishing a replay is a separate, explicit action per drive. Published replay data is visible only to your approved followers, trims at least 100 meters off each end of the route to obscure your start/end address, and includes only a fixed set of drive channels — never vehicle telemetry, never heart rate or other biometric data.
- Crews. A crew is a small private group. Members can post check-ins that optionally include location and an optional status; check-in data is visible only to other members of that crew, not the public.
- Trip-intent signal. If you and others opt a shared trip into "anticipation," the app can show a coarse, banded read (e.g. "a few people are around") once at least 3 people qualify — it never reveals who, or an exact count below that threshold.
1.4 Information we do not collect
- Photos or videos — there is no camera, photo library, or photo-upload path anywhere in the app. Public avatars are limited to initials or a small set of generated designs.
- Audio or microphone recordings — the app does not record audio; the co-driver's spoken pace notes are on-device text-to-speech playback only.
- Wrist heart rate or other biometric data on any server — it never leaves the watch/device (see 1.2).
- Contacts, messages, calendar, or browser history.
- Advertising or tracking identifiers (e.g. IDFA) — RallyTrax does not show ads and does not use data for tracking, as defined by Apple or otherwise.
- Payment or purchase history — RallyTrax is free today; there is no in-app purchase flow. If that changes, this policy and the App Store privacy label will be updated first.
2. How we use your information
| Purpose | Data used |
|---|---|
| Record and replay your drives | GPS location, sensor/vehicle telemetry |
| Generate pace notes and replay audio | GPS location, sensor data |
| Sync your garage, drives, logs, and trips across your devices | Account ID, vehicle/drive/trip data |
| Show a coordinated forecast for a planned drive (iOS) | The drive's coordinates — sent to Apple WeatherKit |
| Publish and display Social profiles, follows, and replays | Handle, display name, avatar mode, follow edges, and (only for drives you publish) trimmed replay geometry — all only what you opt in to share |
| Crew check-ins and coordination | Optional location and status message, visible to crew members only |
| Extract values from receipts you pick (Android) | The selected image / PDF — processed on-device by ML Kit, never uploaded |
| Suggest names, notes, captions, briefings, and summaries (the AI features listed in section 3) | Text assembled on your device — place names, headline stats, and text read from photos you pick; no images, no GPS coordinates — sent to Google's Gemini API via Firebase AI Logic. Names, receipt notes, and plate/odometer checks fall back to a local, non-AI version when the call fails; captions, briefings, and the Year in Review summary have no fallback — the call failing just means nothing is suggested. See section 3 for the fallback per feature. |
| Understand which features are used (Android, iOS); diagnose crashes (Android, iOS, macOS) | Anonymous diagnostics via Firebase Analytics on Android; pseudonymous, account-linked product-analytics events on Android and iOS, with a Settings opt-out; pseudonymous Crashlytics crash data on iOS; account-linked Crashlytics crash data on macOS (see 1.2) |
| Display map tiles and route previews | Your current viewport — sent to Google Maps (and OpenStreetMap as fallback) to fetch tiles |
| Show in-app update notifications (Android sideload channel) | Your current app version — checked against the public GitHub Releases manifest |
3. AI features — what is sent to Google
Several convenience features are processed by Google — the app sends a request to Google's Gemini service (via Firebase AI Logic) and shows you the result. In every case the request is text assembled on your device: no images and no GPS coordinates are ever included. Requests go from your device to Google directly — they are not routed through RallyTrax's own servers, and RallyTrax does not store them server-side. The result (a name, note, caption, or summary) is saved only as part of your own content, where you can edit or delete it like anything else you typed. What happens if a request fails differs by feature — some fall back to a plainer, non-AI result; others simply don't offer a suggestion. Each bullet below says which. Feature by feature, what is sent and why:
- Receipt scanning (Android). When you scan a service receipt, the text read from it on your device (see section 1.1) — plus the parsed shop name, totals, and odometer — is sent to structure the line items and draft a short service note for the maintenance log. The receipt image itself is never uploaded. If the request fails, RallyTrax falls back to a short local summary built from the parsed line items.
- License-plate and odometer photo check (Android). When you add a vehicle from a photo of your plate or dashboard and the on-device reader is unsure, the text it extracted — which can include your plate number — is sent to pick the most likely plate code or odometer reading. The photo itself is never uploaded. If the request fails, RallyTrax falls back to the on-device reader's own best guess.
- Suggested drive and trip names (Android). After a recording (and for trip suggestions), place names along the drive — from reverse geocoding, e.g. "Mill Valley → Stinson Beach", not coordinates — plus headline stats (distance, duration, surface, difficulty, time of day) are sent to suggest a name. You can always rename. If the request fails, RallyTrax falls back to a locality- and time-based name it builds on-device.
- Share captions (Android). If you tap "Suggest caption" when sharing a drive, its headline stats, character tags, your vehicle's nickname, and an optional place name are sent to draft a caption. There is no non-AI fallback for this feature — if the request fails, no caption is suggested and the field is left for you to fill in.
- Pre-drive route briefings (Android). When you tap "Preview briefing" on a curated route in Explore, that route's name, region, and stats, plus the current weather, are sent to write the short spoken briefing. There is no non-AI fallback for this feature — if the request fails, no briefing plays.
- Year in Review (Android). Aggregate stats for your year of driving — totals, surface mix, time-of-day mix — are sent to write the closing persona and summary. There is no non-AI fallback for this feature — if the request fails, that closing slide is skipped.
There is no in-app setting that turns these AI features off today. Some run only when you use the feature (receipt scanning, caption suggestions); name suggestions run automatically after a drive is recorded. When an AI control ships, this section will be updated first (see section 10).
4. Sharing and disclosure
RallyTrax does not sell your data and does not share it with advertisers or data brokers. Data is shared only with the third-party service providers below, and only as needed to deliver the corresponding feature. Your Social profile, follows, and any drive replays you publish are visible to other RallyTrax users as described in section 1.3 — that visibility is a feature you opt into, not third-party sharing.
- Google Firebase (Authentication, Firestore, Storage, Analytics, Crashlytics, App Check, Cloud Functions, BigQuery) — backs sign-in, cloud sync, Social, crew, and crash-reporting features across RallyTrax's apps; backs anonymous usage diagnostics on Android, and — via Cloud Functions and BigQuery — the pseudonymous product-analytics pipeline on Android and iOS described in section 1.2 (crash reporting is keyed per platform as also described there). See Firebase Privacy Notice.
- Apple — Sign in with Apple (iOS sign-in), WeatherKit (forecasts for planned drives), and HealthKit (opt-in workout save; heart rate never leaves your device). See Apple Privacy Policy.
- Firebase AI Logic (Gemini) — processes the AI features described in section 3: receipt line items and service notes, plate/odometer photo checks, drive and trip names, share captions, pre-drive briefings, and Year in Review summaries. Receives text only — OCR text, parsed receipt fields, place names, and headline stats. Receives no images and no GPS coordinates. See Firebase AI Logic Policies.
- Google Maps — fetches map tiles for the in-app maps. See Google Privacy Policy.
- OpenStreetMap (OSMDroid) — fallback map provider when Google Maps is unavailable. See OpenStreetMap Privacy Policy.
- Google ML Kit — on-device text recognition for receipt scanning (Android). Runs entirely on your device; receipts are not uploaded.
We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, or property of users or the public.
5. Data retention
- On-device data (drives, garage, logs) — kept until you delete the entry or uninstall the app.
- Cloud-synced data (drives, trips, garage, Social profile, follows, published replays, crew data) — kept in Firebase while your account exists. You can delete individual items any time from within the app, or delete everything by deleting your account (see below).
- Diagnostics. On Android, Firebase Analytics retains event-level data for up to 14 months. The first-party product-analytics events described in section 1.2 (Android and iOS) are retained 90 days on a rolling basis; deleting your account removes them sooner (see "Delete your account" in section 6). Crashlytics retains crash records for up to 90 days on every platform that sends them (Android, iOS, macOS) — how a crash record is keyed differs by platform; macOS records are account-linked (see section 1.2).
6. Your choices and rights
- Decline location. RallyTrax requests precise location only to record drives. You can decline at install or revoke it later in system Settings. Drive recording will be unavailable, but the rest of the app continues to work.
- Keep Social off. Claiming a handle, following people, and publishing a replay are all separate opt-in actions. If you never claim a handle, no public profile is created.
- Control who sees a crew check-in. Location on a check-in is optional per post and visible only to that crew's members.
- Export your drives. Each drive can be exported as a GPX file from the share menu on its detail screen. On Android, you can also enable Google Drive backup of your GPX files from Settings.
- Delete your account. RallyTrax offers an in-app "Delete account" action on Android and iOS (macOS has no in-app delete yet — use the email route below). Deleting your account removes your cloud-synced drives, cloud GPX backups, routes, trips, and vehicle data; your public profile, handle, and avatar; your follow relationships in both directions; your crew memberships and check-ins; your published replays and Social cards; and your notifications and registered devices — and, as its final step, it deletes your sign-in account itself. (Crash records and Android's Firebase Analytics diagnostics are not removed by this purge — they age out on the retention schedules in section 5; on macOS crash records remain account-linked until then, see section 1.2. The first-party product-analytics events described in section 1.2, on Android and iOS, are removed by this purge.) The server-side operation that performs this full purge is deployed and in service today; the gap we are closing is in the apps — in app versions shipped to date, on every platform that offers the button, the in-app delete action has not always routed through every step of that purge. Updated apps that always run the complete purge are rolling out: the iOS update is finished and ships with the next App Store release, and the equivalent Android update is in review. Until you've confirmed a delete completed — or if you'd rather have us handle it directly — email the address below and we will remove your cloud-synced data within 30 days.
- Opt out of analytics. The first-party product-analytics events described in section 1.2 — live on Android and iOS — have a one-tap opt-out: the "Share anonymous usage statistics" toggle in Settings, on by default. Turning it off stops new events immediately; it doesn't delete what's already been sent — those rows still age out after 90 days (section 5), or sooner if you delete your account. Separately, on Android, email the address below to opt out of Firebase Analytics diagnostics and Crashlytics crash reporting tied to your install; an in-app toggle for those is still on the roadmap.
- GDPR / CCPA. If you are in the European Economic Area, the UK, or California, you have the rights of access, correction, deletion, restriction, and portability over your personal data. To exercise these rights, email the address below.
7. Children
RallyTrax is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children under that age. If you believe a child has provided us personal information, please contact us and we will delete it.
8. Security
Cloud-synced data is transmitted over HTTPS and stored in Firebase using Google's standard encryption at rest and in transit. Authentication tokens are stored in the platform's encrypted keystore (Android Keystore / iOS Keychain). No method of transmission or storage is perfectly secure; we make commercially reasonable efforts to protect your information.
9. International transfers
Firebase, Google Maps, and Apple's services may process data on servers located outside your country of residence, including in the United States. By using the app you consent to this transfer.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes — including adding any new category of data collection, such as an in-app purchase flow — will be reflected here and, where required, announced in-app before they take effect.
11. Contact
Questions about this policy or your data? Email arnavsacheti@outlook.com.