RouteBraid Privacy Policy
- Effective date: August 20, 2026
- Last updated: August 20, 2026
- Developer and data controller: RouteBraid
- Privacy contact: RouteBraid@gmail.com
- Location: Lebanon, New Hampshire, United States
1. Scope and summary
This Privacy Policy explains how RouteBraid handles personal information when you use the RouteBraid application and RouteBraid-operated account, synchronization, profile, collaboration, support, and subscription-access features (the "Service"). It does not govern a third-party app, website, map provider, identity provider, app store, or payment service acting under its own privacy policy.
RouteBraid is local-first. Core itinerary planning and local JSON backup can be used without an account. Local trip data stays on your device unless you deliberately use a network feature such as map tiles, place search, routing, Google Maps link import, an external map handoff, cloud synchronization, collaboration, profile-photo upload, support, or subscription access.
RouteBraid does not sell personal information, does not share it for cross-context behavioral advertising, and does not use personal information to train an artificial-intelligence model. If RouteBraid introduces materially different data practices, this Policy and any legally required disclosures or choices will be updated before those practices apply.
2. Information you provide or create
- Trips and itinerary content: trip names, destinations, dates, time zones, lodging, saved places, addresses, coordinates, order, visit duration, reservations, notes, manual travel details, and planning preferences.
- Account and identity information: a private RouteBraid account identifier and information returned by the sign-in method you choose, which can include email address, display name, profile image URL, and provider metadata. RouteBraid does not receive your Google or Apple password.
- Profile information: your chosen display name and optional custom profile image. When you choose or take an image, RouteBraid processes it on your device, lets you select a crop, re-encodes the approved square as a metadata-free JPEG, and uploads only that result. The original full-size image is not uploaded by RouteBraid.
- Synchronization and collaboration information: the trip data you choose to synchronize or share; sync revisions and timestamps; invitation codes in hashed or transient form; trip roles and memberships; acceptance of legal-document versions; collaboration activity; blocks; and reports submitted through safety controls.
- Support and privacy communications: messages, contact details, diagnostic details you choose to provide, and records needed to respond, investigate a problem, or document a request.
- Backup, import, export, and clipboard content: RouteBraid accesses pasted text or a shared link only when you initiate an import, restore, or invitation action. When you choose Copy or Share, RouteBraid sends the selected itinerary, link, invitation code, or backup to the operating-system clipboard or share interface. Clipboard and share recipients are controlled by your device and selected apps, not RouteBraid.
Please avoid entering passport numbers, payment-card numbers, authentication secrets, health information, another person's private home location, or other sensitive information that is unnecessary for travel planning.
3. Location, camera, photos, maps, search, and routing
- Device location: RouteBraid asks for foreground location permission only after you use the map's location control. It reads a current high-accuracy position and, while that map remains open, may receive foreground updates to move the on-screen marker. The reading is held in app memory for that map session. Merely centering the map does not upload the GPS reading to RouteBraid's Supabase backend. If you later save, synchronize, share, route from, or open a map around that position, coordinates or map-area information can be sent as described below.
- Map tiles: displaying the map requests visible tile coordinates from OpenStreetMap Foundation infrastructure. The provider can receive the requested tile area and standard network information such as IP address, device or browser information, user agent, and request time.
- Place search: when you press Search, RouteBraid sends the search text and any city context to the OpenStreetMap Foundation's public Nominatim service. Do not put personal or confidential information in a search query.
- Route and matrix requests: for supported walking or driving calculations, RouteBraid can send itinerary coordinates and the selected travel mode to the FOSSGIS routing service at routing.openstreetmap.de. FOSSGIS states that route requests are stored in server logs. RouteBraid can fall back to an on-device straight-line estimate if routing is unavailable.
- Google Maps link import: when you ask RouteBraid to resolve a shared Google Maps link or list, the link, list identifier, and ordinary connection data may be sent directly to Google. RouteBraid extracts place information exposed by the link; it does not access your private Google Maps account or saved lists unless the shared link itself makes the requested information available.
- External map handoff: when you choose Google Maps or Apple Maps, RouteBraid opens a provider URL containing the relevant labels, places, coordinates, route points, and travel mode. The selected provider then handles that information under its own policy.
- Camera and photo library: camera access is requested only when you choose to take a profile photo or scan a trip-invitation QR code. Photo-library access is used when you choose an existing profile photo. QR image frames are processed for scanning; the invitation code is then handled like a pasted code. RouteBraid does not use the camera or photo library for background monitoring.
You can deny or revoke location, camera, or photo access in device settings. The associated optional feature may stop working, but core manual planning remains available.
4. Subscription and purchase information
If RevenueCat or a supported app store is configured, RouteBraid processes a private RouteBraid account identifier together with subscription product identifiers, entitlement status, purchase and restore status, store, environment, renewal state, and expiration information needed to provide Pro access. RevenueCat and the applicable store process purchase receipts and related transaction data.
Google Play or Apple handles your payment method and full payment-card details; RouteBraid does not receive those card details. Store and RevenueCat records can persist under their legal, tax, fraud-prevention, and transaction-retention obligations. Deleting your RouteBraid cloud account does not cancel a store subscription.
5. Technical and network information
When you use an online feature, RouteBraid and its providers can automatically process IP address, request time, endpoint, response status, app or SDK version, device and operating-system type, user agent, authentication and session metadata, and limited security or rate-limit events. Test builds can enable more detailed SDK logs on the device. This information is used for authentication, delivery, reliability, debugging, abuse prevention, security, and legal compliance.
RouteBraid does not intentionally collect contacts, call or SMS history, microphone recordings, background location, or browsing history outside links and provider pages you deliberately open through the Service.
6. How information is used
RouteBraid uses information to:
- create and maintain local itineraries and requested backups, imports, exports, maps, routes, and estimates;
- authenticate accounts and provide profiles, manual synchronization, collaboration, and account deletion;
- identify the correct account for Pro entitlement checks, purchases, and restoration;
- display shared-trip information to authorized members and maintain invitation, role, block, report, revision, conflict, and activity controls;
- respond to support, privacy, safety, security, and legal requests;
- prevent fraud, abuse, unauthorized access, excessive provider use, and violations of the Terms;
- operate, troubleshoot, secure, and maintain the Service; and
- comply with law, enforce agreements, and protect users, RouteBraid, and others.
RouteBraid will not use personal information for a materially unrelated purpose without appropriate notice and, where required, consent.
7. Legal bases where applicable
Depending on where you live and the feature involved, RouteBraid relies on:
- performance of a contract to provide the Service you request, including accounts, synchronization, collaboration, and subscription access;
- consent for optional device permissions and where law requires consent for a particular processing activity;
- legitimate interests in providing and securing the Service, responding to users, preventing abuse, and maintaining reliable operations, balanced against your rights; and
- legal obligations and protection of rights for compliance, valid legal requests, disputes, safety, fraud prevention, and enforcement.
Where processing relies on consent, you may withdraw that consent prospectively. Withdrawal does not make earlier lawful processing unlawful and may prevent the optional feature from working.
8. When information leaves your device
Local trip content leaves your device only when you initiate or enable a feature that requires it. Depending on that action, information may be disclosed to:
- Supabase: authentication, private database records, row-level access controls, cloud synchronization, private profile-photo storage, collaboration, and account deletion;
- Google: Google sign-in if chosen, Google Play billing on Android, Google Maps link resolution, and Google Maps handoff;
- Apple: Apple sign-in if offered and chosen, App Store billing on Apple platforms, and Apple Maps handoff;
- RevenueCat: subscription offerings, receipts, customer identifiers, purchase status, and Pro entitlement synchronization;
- OpenStreetMap Foundation: visible map-tile requests and user-initiated Nominatim search queries;
- FOSSGIS: coordinates and travel mode for user-requested route and route-matrix calculations;
- collaborators you authorize: profile display name and shared-trip content appropriate to the invitation and role;
- apps or people you choose: content sent through copy, share, export, backup, invitation, or external-map controls;
- professional advisers, authorities, or other parties: when reasonably necessary to comply with law, respond to valid process, protect safety and rights, investigate abuse, or establish or defend legal claims; and
- a successor organization: in a merger, acquisition, financing, reorganization, or transfer of the Service, subject to this Policy and applicable notice or consent requirements.
RouteBraid selects service providers for limited operational purposes and expects processors acting on RouteBraid's instructions to use appropriate confidentiality, security, and data-protection safeguards. Google, Apple, the OpenStreetMap Foundation, FOSSGIS, and other services can also act as independent controllers under their own terms and policies. RouteBraid does not control their independent processing.
9. International processing
RouteBraid operates from the United States. Service providers and their infrastructure can process information in the United States, Canada, the United Kingdom, the European Economic Area, Singapore, or other countries where they or their subprocessors operate. Those countries may have different privacy laws.
Where required, RouteBraid will rely on an approved transfer mechanism or another lawful basis for an international transfer. You may contact RouteBraid for available information about safeguards relevant to your request.
10. Sharing within a trip
Trip information is shared only after an owner creates an invitation and a recipient deliberately previews and accepts it. The preview is designed to disclose only limited trip and owner information before acceptance. Once joined, a member can receive the shared itinerary and collaboration activity permitted by the member's role.
Members can leave and owners can remove members. Blocking prevents specified future collaboration actions where implemented. Removal or deletion cannot erase copies another user already exported, copied, screenshotted, or retained outside RouteBraid. Contact RouteBraid to report misuse.
11. Retention
RouteBraid retains information only as long as reasonably needed for the purposes described above, subject to these general rules:
- Local data remains on your device until you delete it, clear app storage, restore over it, or uninstall the app. Copies you place in files, messages, another app, or the system clipboard are controlled by those destinations and their retention settings.
- Active cloud account, profile, sync, and collaboration data remains until you delete or replace it, leave or end the applicable collaboration, or delete the cloud account, subject to feature-specific history and safety controls.
- Deleted cloud information is removed from active RouteBraid-controlled records through the deletion process. Limited copies can remain temporarily in encrypted backups, provider logs, security records, or transaction systems until they age out under provider schedules.
- Subscription and transaction information is retained by RevenueCat and the app store according to their transaction, tax, accounting, security, and legal requirements. RouteBraid can retain limited entitlement records as needed to provide access and resolve purchase disputes.
- Support, safety, fraud, and legal records can be retained as reasonably necessary to respond, prevent repeat abuse, comply with law, establish or defend claims, and document the outcome. RouteBraid will delete or de-identify them when no longer needed.
RouteBraid may retain de-identified information that can no longer reasonably be linked to you.
12. Your controls and privacy rights
Available controls include:
- edit or delete local trips and restore or export local backup data;
- edit the RouteBraid display name and replace or remove a custom profile photo;
- choose whether and when to synchronize, collaborate, search, route, import, copy, share, or use device location;
- revoke app permissions in device settings;
- leave a shared trip, remove members as an owner, and use available block or report controls;
- sign out without deleting local trips; and
- delete the cloud account in Settings > Cloud Account > Delete Account. This removes the active account and associated RouteBraid cloud data but leaves local trips on the device and does not cancel a Google Play or App Store subscription.
You can also email RouteBraid@gmail.com to request access, correction, deletion, restriction, portability, objection, or other rights available under the law where you live. RouteBraid may need to verify your identity and clarify the scope before fulfilling a request. Some information may be retained where law permits or requires it. If RouteBraid denies a request, you may email the same address with the subject Privacy Appeal and explain why you believe the decision should be reconsidered. You may also complain to the privacy or data-protection authority where you live.
Disconnecting Google or Apple at the provider does not necessarily delete the RouteBraid cloud account. Uninstalling the app does not cancel a subscription. Manage billing through the applicable store.
13. Security
RouteBraid uses safeguards appropriate to the type of information handled, including encrypted network transport, authenticated sessions, private storage paths, row-level database authorization, narrow server functions, data minimization, local image re-encoding, request limits, and account-deletion controls. Access to a shared trip is role-based and tied to authenticated accounts.
No app, device, network, or storage system is perfectly secure. Keep your device and sign-in account protected, install updates, review collaborators, and do not place unnecessary secrets in a trip. Notify RouteBraid@gmail.com if you suspect unauthorized access or a security issue.
14. Children
RouteBraid is not directed to children under 13, and RouteBraid does not knowingly collect personal information online from a child under 13. If you believe a child under 13 has provided personal information, contact RouteBraid@gmail.com so RouteBraid can investigate and delete it as appropriate. Users between 13 and the age of legal majority must have permission from a parent or legal guardian.
15. United States state privacy disclosures
RouteBraid does not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics about you. RouteBraid does not offer a financial incentive in exchange for personal information. These practices mean an opt-out of sale or targeted-ad sharing is not currently necessary; if they change, RouteBraid will update this Policy and provide required choices before the change applies.
Residents of a state with an applicable privacy law may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal information and to appeal certain decisions, subject to legal scope, exceptions, and verification. Use the contact and appeal process in Section 12.
16. Changes to this Policy
RouteBraid may update this Policy to reflect feature, provider, security, legal, or business changes. The document will show a new effective date. Material changes may be highlighted in-app and may require acknowledgement before account or collaboration features can be used. Where required, RouteBraid will request consent before applying a materially new use to previously collected information.
17. Contact
Questions, requests, complaints, and privacy appeals may be sent to RouteBraid@gmail.com. Mail location: RouteBraid, Lebanon, New Hampshire, United States.