Version 2026-10-06-r1 | Last updated October 6, 2026
Privacy Policy
This Privacy Policy explains how Roadsy handles personal information through the Roadsy Android app, roadsy.app, and related services. Roadsy is accountable for the information under its control. The Roadsy Privacy Officer can be reached at privacy@roadsy.app.
Key privacy points
- Roadsy is local-first. Your journal is written to an encrypted database on your device.
- An account is required to record your own drives. Some earlier versions or designated test accounts provide sample data that is separate from real driving evidence.
- In the journal app, private cloud backup requires verified Pro access and explicit enablement. Signing in alone does not upload the local journal.
- Roadsy does not sell or rent personal information or use private driving records for targeted advertising, insurance underwriting or employment decisions.
- Google Maps can load in core app screens. DB-IP receives the public request IP to supply an approximate city/country hint. These services operate separately from optional app analytics.
- Analytics and crash reports have separate controls. Builds with regional privacy defaults require explicit opt-in in protected or unknown regions. Website Google Analytics and PostHog stay off until you opt in and stay off when Global Privacy Control is enabled.
- Images and exports leave your device when you choose to share them through another app or service. Review the preview and recipient. Community is not part of the current journal feature set.
Important risk: precise route history can reveal homes, workplaces, routines and associations. Someone with access to your device, account, export, shared image or notification may learn information about you. Use device security and review what you share.
Information handled by the Android app
Legal setup, settings, and device state
Roadsy stores onboarding and permission state, display and measurement preferences, selected cities, backup and notification preferences, and optional telemetry choices. Account setup records the legal document accepted as described below. Older app versions can also retain a local legal-capacity confirmation. Roadsy does not ask for a birth date, street address, province or territory during this setup.
Trip, precise location, and sensor data
When you record a drive with the required Android permission, the journal app processes precise latitude and longitude, timestamps, speed, bearing, accuracy and signal quality. It derives distance, driving events, classifications, scores and confidence, and stores the titles, notes and other supported metadata you supply. Earlier versions and restored records can also contain altitude, acceleration, gyroscope, orientation or phone-stability evidence collected by those versions. Available evidence depends on the app version and device. The current journal does not access your contacts, microphone, call history or text messages.
Manual recording starts after you choose Start and grant the required permission. Automatic recording is optional. When enabled with the required permissions and access, it uses physical-activity transitions and location in the background to recognize, record and finish drives while the app is not open. Android displays a foreground-service notification while recording. Device conditions and permissions can prevent detection or interrupt a recording.
Local diagnostics
Technical information can be produced by Android and the SDKs used by Roadsy. Optional crash reporting is described below. Some earlier app versions also kept rotating local diagnostic files and exposed controls to clear or share them; those features are not present in every journal build. Roadsy does not automatically attach your journal, routes or device logs to the in-app feedback form. Do not send sensitive routes, credentials or unnecessary personal information in a support message.
Accounts and private backup
If you create or use an account, Roadsy and its authentication provider handle your email address, authentication provider and state, account identifier, available profile fields, settings, sign-in/security metadata and accepted account actions. Google sign-in does not disclose your Google password to Roadsy. Password authentication is handled by the account provider; Roadsy does not retain a readable copy of your account password.
Account setup asks you to confirm a country. The app may suggest one from an approximate IP lookup, your chosen city or device locale. You can correct it before saving. The confirmed country is self-declared and used for account administration, legal notices, availability and regional defaults. It is not verified residence, citizenship or current physical location. Use the available country control or contact support to request a correction.
Roadsy privately records the accepted Terms document/version and effective date, server acceptance time, country at acceptance, acceptance surface/method, app version and language. These are not public profile fields. Access is restricted to you and authorized service operations. The current app opens the immutable document associated with its acceptance record; a newer website document does not rewrite a past acceptance.
The journal app uploads private backup only after you enable it for your signed-in account with verified Pro access. Backups can include summaries, exact coordinates and timestamps, recorded sensor/event evidence, scores, notes, edits and deletion state. Uploads pause when the required access or backup setting is unavailable. Pausing backup does not delete existing cloud copies. You can delete cloud backup separately; local records remain unless you also delete them. Older versions may have synchronized account records under the controls and notices that applied to those versions.
Migration and restore can recover compatible earlier records, including guest records where supported. Recovery does not make those records public. Backup is server-recoverable, not end-to-end encrypted: authorized service operations can process it to validate, restore and delete your records. The configured account and backup region is Oregon, United States.
Preview and subscription records
The current Pro offering can include an eligible 14-day full-Pro Google Play trial. Google Play determines eligibility and presents trial and renewal terms. Older versions may retain records from a separate non-renewing automatic-detection preview; that legacy preview is not the current subscription trial.
For subscriptions, Roadsy can process your Roadsy account identifier, product/plan, billing-provider identifier, test or production environment, trial/purchase/entitlement status, renewal or expiry time, store transaction references and reconciliation or ownership-recovery records. Google Play handles payment details. RevenueCat helps display offers and verify and synchronize access against the signed-in Roadsy account. Roadsy does not receive your full payment-card number.
Notifications
After sign-in, account setup and notification permission, Roadsy may register a Firebase Installation ID, messaging token, environment, app version and refresh time with the notification service. These support eligible account and subscription notices. Active-drive, saved-drive and recap notices can be generated locally. Promotional notices depend on the available notification preference.
Android permission and channel settings control most notifications. Recording uses a foreground-service notification. Delivery systems can process an opaque notification identifier, type, destination, delivery status and technical retry metadata. Some earlier versions offered an inbox, additional categories and quiet hours; these controls are not available in every journal build.
Community information
Community is planned for a future release. This section describes processing only where a Roadsy version provides Community, or where Roadsy retains information from earlier Community use.
If you use Community, Roadsy handles the profile information you submit; follow or friend relationships; blocks; posts; selected trip statistics; the route view you explicitly choose; kudos and comments; and reports, appeals, and moderation records. Profile and post visibility determine who can retrieve that information. Free-form text can contain information Roadsy cannot automatically recognize as sensitive.
When a generalized route map is available, Roadsy selects it inside the explicit Community share confirmation. You can turn the map off before publishing. The generalized route removes exact endpoints and reduces detail before upload. This flow never uploads a full route, exact pins, timestamps, speeds, or driving events. Other users may save or redistribute content they can see, so deleting it from Roadsy cannot remove copies made outside the service.
Crash reporting and app Analytics
Usage analytics and crash reports are optional and controlled independently in onboarding or Privacy settings. In journal builds with regional privacy defaults, an approximate IP hint is used to keep both off without explicit opt-in for the EU, Iceland, Liechtenstein, Norway, the United Kingdom and Switzerland. An unknown, failed or malformed lookup is also treated as requiring opt-in. Outside those configured regions, the defaults activate after setup unless you have opted out. A saved explicit choice is retained. Earlier installed versions may use different defaults shown by their controls. IP location is imperfect and does not determine citizenship, residence or the full scope of your legal rights.
When enabled, Firebase Analytics and PostHog can receive allowlisted feature events and screen names, app/build information, SDK or installation identifiers and technical request/device metadata. Firebase may generate SDK lifecycle, session or purchase events and derive approximate geography from an IP address. Roadsy asks PostHog to disable GeoIP enrichment and does not create person profiles. These provider identifiers are pseudonymous; the data is not guaranteed to be anonymous.
Roadsy's manual events cover onboarding, recording start/save, paywall and purchase actions, verified access and share creation. They do not include the journey's coordinates, route, city, account identifier, email, notes, trip identifier or other free-form fields. Advertising-ID collection and personalized-ad signals are disabled. PostHog automatic lifecycle, screen, deep-link, push, error and session-replay capture are disabled; Roadsy sends only its allowlisted events and screen names.
When enabled, Firebase Crashlytics can receive app and operating-system details, device information, crash time, installation identifiers, stack traces, thread/ANR information and enabled analytics breadcrumbs. In the current journal app, uncaught Java/Kotlin exception messages are replaced with exception class names while code stack locations are retained. Earlier versions may use different filtering. Roadsy does not intentionally attach routes, account identifiers, credentials or free-form journal text.
Turning a control off stops future collection controlled by that setting and requests deletion of unsent crash reports where supported. Restart the app after changing crash reporting to fully apply SDK startup behavior. Opting out does not automatically erase data already received by a provider. Contact the privacy address for applicable rights requests. Google Maps, account services, IP lookup and necessary notification functions are separate from these optional telemetry controls.
Google Maps
The journal app uses Google Maps in map-containing screens, including onboarding, Home, Explore, active recording and trip views where available. Map requests can begin when those screens open, without a separate live-map button. The SDK can receive the map area being viewed, IP address, device/SDK/request metadata, a Maps-specific pseudonymous identifier, crash metrics and map interaction events. Google uses information under its Privacy Policy to provide, secure, maintain and improve its services.
Roadsy draws route geometry through the map renderer. It does not call Google's Directions, Roads, Places, traffic, navigation or map-matching services for this journal feature. Local recording and road matching remain separate from map delivery. Disabling Roadsy analytics or denying GPS permission does not by itself prevent map requests on a screen that loads Google Maps. Some versions can show a local illustration or route fallback; this is not a promise that every app screen operates without Google processing.
Approximate IP location and city road data
On app startup, journal builds can request an HTTPS self lookup from DB-IP. DB-IP sees the public request IP and network metadata and returns approximate city/country information. Roadsy uses that hint for a suggested city/country and regional telemetry defaults. It discards the IP value returned in the response. It does not send GPS coordinates, account credentials or journal content to DB-IP. A provider EU-membership flag may be used when available; otherwise the app compares the country code with its configured regional list.
The lookup is an approximation and can be wrong because of a VPN, travel or provider error. You can choose another city and correct the suggested account country. A missing lookup does not block manual city selection.
City-name searches and selected city identifiers go to Roadsy's city-data gateway. That service uses cached and rate-limited Nominatim search and Overpass queries for OpenStreetMap road data. Those providers can process the public place query, city/boundary identifiers and server request metadata. Roadsy does not send your private drive route to these services for matching. Downloaded road packages, saved city choices and drive-to-road matching are kept on your device. Multiple city packages can remain available offline.
Website information
Delivery, security, and Cloudflare Web Analytics
Cloudflare delivers and protects roadsy.app and can process IP address, request time, requested host and path, user agent, device and network information, security signals, and similar HTTP data.
Cloudflare Web Analytics is always enabled on roadsy.app and operates independently of the optional analytics choice. Its performance beacon records page and performance measurements such as country, path without URL query strings, referrer, device type, browser, and operating system. Cloudflare states that Web Analytics does not use cookies to track visitors across sites or collect personal data for its customers. Cloudflare processes its service data under its Privacy Policy.
Website analytics
Google Analytics and PostHog load only after Allow analytics, and stay off with Global Privacy Control.
Each receives a manual page-view with path-only location/referrer and pseudonymous identifiers. Queries, fragments, form entries, email, trips, precise locations, and Android account data are excluded. Google also receives page titles, session/browser/device data and IP-derived geography, and may generate session, first-visit and engagement events. Google Signals, ad storage/personalization and Enhanced Measurement are disabled. See Google's Privacy Policy.
PostHog receives browser/session IDs, browser/OS/device/screen data and a website source label through n.roadsy.app to US Cloud. Providers process IP/network metadata for delivery. GeoIP enrichment, person profiles, autocapture, replay, surveys, flags, performance/error capture and campaign collection are disabled. See PostHog's Privacy Policy.
Consent is stored locally. Google can set _ga cookies; PostHog can store identifiers and session/consent state. Analytics choices in the footer lets you deny both: Google receives denied consent and its cookies are removed where permitted; PostHog stops and clears SDK persistence. Cloudflare stays enabled. Previously received data is not deleted by withdrawal.
Launch updates and published articles
If and when the Android launch list is available, joining it sends your email address, consent time, source and wording version, subscription status, and delivery or unsubscribe status to Resend. The consent box starts unchecked. The form must identify the sender and its mailing and contact details before registration is enabled. Launch-update emails include an unsubscribe method. You can also withdraw consent at hello@roadsy.app. Joining does not create an app account or guarantee testing access or a release date.
Hygraph manages published legal documents and articles. Your browser may request article images from its asset network. Roadsy does not run advertising scripts on the website.
Support and feedback
When you send the website support form or in-app feedback, Roadsy handles the email address, message, category and consent information you submit. The website form can also include app or Android version details if you supply them. Cloudflare processes the request and security/rate-limit metadata, and Resend delivers the support email. The current journal feedback form does not automatically attach your route, journal, account credentials or device logs. Only include information needed for the request. Support responses use the contact information you provide.
Why Roadsy uses information
Roadsy uses information to provide requested recording, local scoring/history, maps, city downloads, account, optional backup, subscription, export, sharing, support and notification functions; secure and troubleshoot the service; prevent abuse; comply with law; and handle legal claims. Earlier Community or research data is processed only for the uses and choices applicable to those features.
Where a legal basis is required, processing needed to provide a requested account or service is based on performing the agreement; optional analytics, research and marketing use consent where required; security and abuse prevention can rely on legitimate interests subject to your rights; and legally required records rely on the relevant obligation. Location permission supports the functions you choose, not unrelated advertising. Optional website analytics and launch-list emails require their separate choices.
Roadsy will seek a new choice before a materially different optional use where required. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
Automated analysis
Roadsy analyzes recorded location and available motion evidence to classify trips, detect driving events, estimate confidence and calculate informational scores. Results can be wrong. This analysis does not produce a legally binding decision and is not supplied by Roadsy for insurance, employment, credit, policing or legal adjudication. You can change supported classifications, such as Driver or Passenger, edit available metadata, delete records, export retained data and contact privacy@roadsy.app about the use of your information.
When information is disclosed
Roadsy discloses information to providers for the functions described in this Policy:
- Supabase and its hosting providers: accounts, authentication, database, optional private backup and server functions, including retained earlier Community data.
- Google: sign-in, Google Maps, Google Play billing, Firebase Installations and messaging, optional app Analytics and Crashlytics, and consented website Google Analytics.
- PostHog: optional app product analytics with allowlisted manual events and screens, and consented website page-view analytics. Automatic capture and session replay are disabled.
- RevenueCat: subscription offers, purchase verification, entitlement synchronization, restores and ownership recovery.
- DB-IP: approximate IP-based city/country hints and regional defaults.
- Nominatim and Overpass providers: public place searches and OpenStreetMap road queries through Roadsy's city-data gateway.
- Cloudflare: website and city-data delivery, security, rate limiting and Web Analytics.
- Resend: support email delivery and any consented launch-list email service.
- Hygraph: published website legal documents, articles and media.
Choosing an Android share destination sends your selected export or image to that app or recipient. Where earlier Community features are available, the audience you select can receive the content you publish. Roadsy may also disclose information where reasonably necessary to comply with law or valid legal process, or to protect rights, safety, users and the service. A change of ownership can involve a transfer subject to appropriate confidentiality, notice and applicable law.
Roadsy does not sell or rent personal information, supply private driving records to data brokers, advertisers, insurers or employers, or use trip data for targeted advertising.
Retention and deletion
Trip records
In the current journal app, summaries and detailed records remain in encrypted local storage until you delete them, clear app data or uninstall. Free detail access lasts 72 hours after a drive ends; verified Pro unlocks retained older details. This is an access restriction, not an automatic 72-hour or 14-day deletion rule. Local export includes retained data. Device loss or clearing app data can make local records unrecoverable without a usable backup.
Earlier app versions and their legacy backup format used rolling detail retention, including Free limits and a post-Pro grace period. Such records may already have expired under the notice applicable to that version. The newer journal does not recreate details already deleted from an earlier store.
Optional journal backup remains in the account until you delete the cloud record or backup, or the account is permanently deleted, subject to necessary legal/security retention. Pausing backup or losing Pro stops eligible uploads but does not itself erase existing backups. A deleted journal backup is replaced with a minimal account/journey deletion marker to stop an older device from uploading the deleted record again. The marker has no route or sensor payload and remains while needed for account sync; it is removed with permanent account deletion. Legacy-format trip tombstones use a separate expiry of up to 365 days.
Diagnostics, analytics, and website records
Crashlytics, Firebase, PostHog and website Google Analytics retain received information under the configured provider retention settings and their applicable policies. Aggregate reports may remain longer than individual event records. Turning off a collection setting does not delete provider records already received. Some earlier app versions kept local diagnostic files limited to five compressed files and seven days; that description does not imply the current journal has a log-export feature.
Support correspondence and voluntarily supplied attachments are retained as needed to handle and document the request, protect accounts and meet legal obligations. Do not include unnecessary personal information. Launch-list contacts are retained while subscribed; after withdrawal, information is removed or restricted subject to minimal consent and suppression records needed to honour the withdrawal. Security, transaction, consent and legal records are retained only as long as needed for their stated purposes and applicable obligations. Contact the privacy address for a request concerning your information.
Optional research
The current journal does not include research enrolment. If Roadsy separately offers a study, it requires a specific notice and separate consent identifying the data, purpose, recipients, retention and withdrawal effect. Earlier enrolment and withdrawal records may remain where needed to honour those choices. A study's notice must explain any effect of withdrawal on information already lawfully de-identified or retained for a stated legal or study-integrity reason.
Account deletion
An accepted account-deletion request restricts affected account services and makes existing Community content unavailable. The backend includes a 30-day cancellation period before the account becomes eligible for permanent deletion. Processing may take additional time. Contact privacy@roadsy.app for status or to request cancellation before that period ends if your app has no cancellation control. Signing in again does not cancel the request. Applicable statutory deadlines and rights still apply.
Permanent account deletion removes account-linked journal backup and other associated cloud data, subject to necessary legal/security records. It does not erase trips still on your device, cancel a Google Play subscription or remove copies you sent to someone else. The account-deletion page explains in-app and external request paths.
Your choices and rights
Android settings control location, background location, physical activity and notification permissions. Roadsy provides controls for available automatic recording, backup, notifications, analytics and crash reports. You can choose cities, correct supported trip classifications and metadata, delete local records, export retained local data, sign out and request account deletion. Controls such as quiet hours, research participation, Community audiences or local diagnostic export depend on the installed version and enabled features.
When you create a share image, the current journal defaults to hiding the first and last 500 metres of a route. You can change that trimming or choose a map-free image before sharing. Review the actual preview: trimming is not a guarantee of anonymity. Exports can include precise untrimmed coordinates, timestamps, notes and other journal fields. Android's share chooser sends the chosen artifact to the destination you select; that recipient's handling is outside Roadsy's control.
Depending on applicable law, you may request access, correction, deletion, restriction or portability of your personal information, object to certain processing, or withdraw an optional consent. Some requests require identity verification or are subject to legal exceptions. Disabling a functionally necessary permission can prevent that function from working. Information that has been properly anonymized and cannot be linked back to you may not be recoverable for an individual request.
Send requests to the Roadsy Privacy Officer at privacy@roadsy.app. Roadsy will explain any refusal permitted by law. You can complain to the Office of the Privacy Commissioner of Canada or the competent data-protection authority where you live, work or believe an infringement occurred.
Security and international processing
Roadsy uses safeguards appropriate to driving and location information, including encrypted local storage, protected session material, HTTPS, server authentication, owner-scoped access rules, bounded uploads, rate limits and restricted administration. No storage or transmission method is completely secure.
The configured account and backup region is Oregon, United States. The providers described above and their subprocessors can process information in countries where they operate, including the United States, Canada and European countries. Foreign laws and lawful government access can apply. Where applicable law requires a transfer safeguard, Roadsy must use an appropriate mechanism, such as an applicable adequacy decision or contractual safeguards. Contact privacy@roadsy.app for information about the arrangements relevant to your data.
Young people
Roadsy is not directed to people who lack the legal capacity or minimum age required to agree to the Terms where they live. Roadsy does not collect a birth date, driver's licence or residential address to verify eligibility. Some earlier setup flows included a separate capacity confirmation. If an ineligible person provided information without valid authorization, contact privacy@roadsy.app so it can be reviewed and deleted where required.
Changes and contact
Roadsy may update this Policy prospectively as its practices or legal obligations change. The effective date will be updated, and material changes will receive an in-app or website notice when appropriate. Roadsy will request a new choice before a materially different optional use when required by law.
The person accountable for Roadsy privacy compliance is the Roadsy Privacy Officer. Email privacy@roadsy.app for privacy questions, rights requests, complaints, or the current mailing address. Email security@roadsy.app for security reports. General support and moderation appeals can be sent to hello@roadsy.app.