What we collect, and what we refuse to.
Last updated 29 July 2026
Unreviewed draft. This document describes what the product actually does, but it has not been reviewed by a lawyer and is not yet a binding agreement. It is published here so the description can be checked against the software.
This app knows where good roads are and, unavoidably, where you are while you drive them. The design rule we work to is that the safest data is the data that was never written down. Most of this policy is therefore a list of things we do not keep.
The short version
- No location history unless you ask us to keep it. Nothing about where you have been is stored on our servers for an anonymous install, and never for presence, for analytics, or for advertising. If you sign in, the drives in your logbook are backed up — and a drive includes the route you took, which is location history by any honest reading. It is stored trimmed at both ends, so the start and finish near your home are cut off before it leaves the phone. You can sign out, delete the backup, or never sign in at all.
- Live position is never stored. While you are on a group drive your position is held in memory for seconds and then gone. It is never written to a disk or a database.
- Push-to-talk audio is never recorded. It is relayed between the cars in your convoy and written nowhere.
- No speed leaves your device in any shareable form. Not average, not maximum, not implied by segment times.
- No plate number, no VIN, no home address, no phone number. A plate is a de-anonymiser and a theft target.
- No advertising, no ad identifiers, nothing that tracks you across other companies' apps or sites. The app does contain one analytics SDK, and it counts things like “a drive was finished” and “a card was shared”. It is on by default, you can switch it off at any time in Garage, and it cannot send your location — see Usage counts.
- No account is required to plan or drive. Planning, driving, logging, sharing a run and joining a group drive all work with no account, permanently — not as a trial. Until you sign in, the app identifies your install with a random token, not with you. Signing in is offered only when you have made something you would mind losing, and it exists so your logbook can survive the phone.
Location
What we ask for, and when
The app requests location when in use the first time it needs to plan from where you are standing, and the request appears immediately after the screen explaining why. Declining is a supported path, not a dead end: you can type or search a starting point instead and everything else works.
The app also uses background location, and only for one thing: keeping turn-by-turn navigation and the corner count working while you are mid-drive with the screen off or another app in front. It is active during a drive you started and stops when the drive ends.
What happens to it
- Route planning. Your starting point is sent to our routing service to synthesise drives from it. Planning results are cached by coarse geographic cell — roads do not move — and the cache is keyed on an area, not on you.
- Navigation. Turn-by-turn happens on the device against a route it already has. Your continuous position during a drive is not transmitted to us.
- Your logbook. The record of drives you have taken lives on your device. If you sign in, a copy is also kept on our servers so it survives a lost or replaced phone — including each drive's route, trimmed of the stretches either side of where you set off. If you never sign in, it never leaves the phone.
- Group drives (Convoy). While a convoy is live, your position is relayed to the other cars in that convoy so they can see you on the map. It is coarsened before it leaves the device, held in memory with a lifetime measured in seconds, and never persisted. A position older than about a minute is dropped rather than shown stale.
Rules that limit location even when it is allowed
- Presence exists only while a drive is active. You appear when a drive starts and vanish when it ends. There is no such thing in this product as a pin on a parked car.
- Suppression near your start points. Nothing is broadcast within roughly 1.5 km of a saved start point, so you become visible after you have left and disappear before you arrive. Home is the one location that must never be inferable.
- Precision follows consent. People you explicitly joined a convoy with see a precise position. Anyone else, if that ever ships, sees a road segment or a coarse cell — never a point.
- Sharing a drive currently publishes the whole route, start point included. The intent is to trim the connector legs at either end and publish only the driving corridor, so what you send is the good part rather than your street. That trimming is not implemented yet. Until it is, a share link shows where the sender set off from, and we would rather say so than describe a control we have not built.
Presence is not a safety feature and we will never describe it as one. It is suppressible, switchable and ephemeral by design, which means it cannot carry a reliability promise.
Microphone
The microphone is used for one feature: push-to-talk inside a group drive. It is half-duplex and deliberate — you hold a button to transmit, and there is no open mic. Audio is relayed live to the other cars in your convoy and is never written to disk, by the app or by the server. There is no transcript, no recording and no playback.
Speech recognition is not used. If a public radius channel between strangers ever ships, it will disclose its own rules at the moment you join, including the one exception under consideration — retaining the last few seconds of audio when somebody presses Report. That does not exist today.
Usage counts
Until July 2026 this page said the app contained no analytics SDK, and that was true. It is not true any more, so here is exactly what changed and why.
The app now includes PostHog, an analytics service, to answer one question we have never been able to answer: does anyone actually share a drive when they finish one? That is the whole reason it is here. It is not a dashboard of user behaviour, and it is deliberately incapable of being one.
It is on by default, and you can switch it off
It is on when you install the app. We have been straightforward about that rather than burying it, because the alternative — a consent card on the first screen — asked you for something before the app had given you anything, and it was inconsistent with the link counts described below, which have never asked anyone.
The switch is in Garage → Privacy & data, which lists every one of the events on this page inside the app itself, so you can read exactly what is collected and turn it off in the same place. If you switch it off, the analytics library is torn down — nothing further is queued, and nothing further is sent.
Switching it off stops collection immediately and discards anything queued but not yet sent. It cannot recall what was already sent, and we would rather say that than imply a delete button we do not have. Write to privacy@cornerresearch.com and we will delete what is there.
What it sends
Exhaustively — there are sixteen events in the app and no others:
- The app was installed, opened, or updated. Your app version, iOS version and device model.
- You opened the planner, and which of the buttons you opened it with.
- A run was planned: how long you asked for as a range, loop or coffee run, how twisty you asked for, and whether the start point was your saved one or one you searched for. Not where from, not where to, and never what you typed.
- The plan came back: how many options, how they scored out of 100, how far apart the best and worst were, and how long the request took.
- Planning failed, and which kind of failure it was — a code, never a message — and whether you retried.
- Which option you picked: its position in the list, its score, how far below the top option it was, and which single thing made it different from the other two (twistiest, longest, quickest, most good road, best balanced). This is the one that tells us whether our ranking is any good.
- A drive started and finished: corners counted, minutes of good road, its score, how much of the route you actually did as a range, whether you reached the end, whether it was before 7am, whether you were in a convoy, and distance and duration as a range (“40–69 mi”, “120–179 min”) rather than an exact figure — because an exact distance beside an exact duration is an average speed.
- A Recap was shown; the share sheet opened; a share went through, and the kind of app it went to (messages, mail, saved to photos). Never who you sent it to.
- A shared link opened the app, and whether it arrived as a web link or another kind.
- A place search happened: how many results came back, how many characters you had typed as a range, and how long it took. Never the text.
- A request to our own server failed: which endpoint, and the status code.
- Something went wrong that should not have: which part of the app, chosen from a fixed list written into the program. Never an error message, because error messages get written by hand and end up containing places.
- Whether the app crashed or froze, as a count. See Crashes and diagnostics.
- That you switched usage counts on or off, and where you did it.
Two things that were on this list in the first draft and are not sent after all. Which screen you are on is no longer collected: screen names on iOS are taken from what the screen is titled, and some of ours are titled with a crew's name or a run's name, which is derived from a road. And nothing that identifies a specific run or drive is sent: the identifiers on these events are separate random ones, generated for the count and used for nothing else, because a shared run's own identifier can be exchanged for the run — start point included.
What it cannot send
This is the part worth checking rather than believing. The list of values analytics is allowed to carry is fixed when the app is compiled, and a coordinate is not one of them — sending your position is not a policy we chose to follow, it is a program that would not build. Specifically, none of the following can leave the device through analytics:
- Where you are, where you started, or where you finished.
- The route, or any part of its shape.
- The names of the roads you drove, or the shop you stopped at, or what you called the run.
- Your speed, in any form. (Nothing anywhere in this product publishes speed.)
- Your name, your email, your plate or your VIN.
- Your city or country. This one is worth spelling out because it is the usual way an analytics product learns where you are without being told: the service can look up a rough location from the internet address a request arrives from. Every event we send carries an instruction not to do that, and your address is replaced before the event leaves the phone.
- Anything from the microphone. Any recording of your screen — session replay is off and must stay off.
If a future feature genuinely needs to know roughly where people drive, the only thing the app is able to send is a geographic cell about 156 km across — an area containing several counties and millions of homes. Nothing sends one today.
Who we are and who they are
Analytics events are anonymous. The app never calls the “identify this person” part of the service, so no profile of you is created; the only identifier is a random one generated on your phone, in the same way the app already identifies your install to our own API. PostHog Inc. processes the events on our behalf, on their US infrastructure.
Shared links are counted too, and not by the app
The question this whole section exists to answer is whether anybody shares a drive and somebody opens it. The second half cannot come from the app, because it happens on whatever phone or laptop the link was sent to — often one with no app on it. So two counts happen outside the app, and the switch in Garage does not govern them, because they are not about you:
- When a share link is created, our own server records that one was. Not who made it, not the run behind it — the run is stored as an opaque blob and this count never opens it.
- When a share link is opened, this website records that it was, and whether the request came from a real browser or from a chat app fetching a link preview. That distinction is the only reason the number means anything: a link dropped into a group chat is fetched several times by software before any person taps it.
Both counts identify the link by a keyed hash of the link code, never the code itself. That matters more than it sounds: a link code can be exchanged with our API for the run behind it, which contains the sender's start point, so a list of codes would be a list of keys to people's houses. A hash cannot be turned back into a code, and it lets us match “a link was made” to “a link was opened” without anything in the analytics service pointing at anything real.
If you are the person who received a link: nothing is stored in your browser, no cookie is set, no identifier is created for you, and your IP address is discarded rather than turned into a city. You never agreed to anything and we have not treated you as though you did. What is recorded is that a link was opened — not that you opened it, and nothing that could distinguish you from the next person.
No ad tracking, and no tracking permission prompt
You will not see iOS's “Allow app to track your activity across other companies' apps and websites?” dialog, because we are not doing that and it would be dishonest to ask. There is no advertising identifier, no ad network, no data broker, and nothing is combined with data from anyone else. Apple's tracking dialog is for advertising measurement, and adding it when you do not need it is a way of implying you do.
Crashes and diagnostics
When the app crashes or freezes we would like to know, and we do it without a crash-reporting company:
- Apple's own reporting. If you have Apple's sharing enabled, crash reports reach us through TestFlight and Xcode. They come from Apple, in aggregate, and Apple decides what is in them.
- MetricKit, which is built into iOS. It hands the app a report about a previous crash, freeze or forced shutdown on a later launch. That report — including the call stack — is written to your device only, capped at the five most recent, and deleted with the app. We do not upload it.
- What does leave, if you have usage counts switched on, is a count: “one crash”, “two freezes”. No stack, no memory addresses, no file names.
There is no third-party crash SDK in the app, and no error-reporting SDK. The cost of that choice is real and worth stating: we get less detail than a product that ships one, and we accepted that in exchange for not adding another company to this page.
What is stored on our servers
Exhaustively, this is it:
- A device record. A random identifier and a hashed access token, so the app can talk to the API. Until you sign in, it is not linked to a name, an email or a person.
- If you have signed in — an account. The stable identifier Apple gives us for you, an optional display name, and the email address Apple passes on (which is commonly one of Apple's Hide My Email relay addresses — we cannot tell, and we do not need to). The email is a contact detail, never a login: there is no password anywhere in this system, so there is no password reset and no password breach to disclose. We also keep one row per signed-in device, holding a hashed session token so you can sign out of one phone without touching the others.
- If you have signed in — your logbook. Your drives, your cars, your saved runs and your planning preferences, so a new phone can get them back. Each drive carries the route you drove, stored trimmed of the legs either side of your starting point. Your Roads Passport is derived from those drives on our side rather than uploaded, so there is no separate record of roads you have collected.
- If you report a catalog issue. We keep the road or published loop identifier, the catalog version, a category, the app version, and any short note you choose to write, linked to your account so we can limit abuse and follow the report through review. The report does not include your current location, saved home, route, or raw travel geometry. Reports are private: there is no public comment feed and no customer-to-customer messaging. They are included in your export and deleted with your account.
- A deletion receipt, when you delete your account: a timestamp and counts of what was removed. It carries no name, no email, no identifier and nothing that points back to you — it exists so we can answer “did you really delete it” with something better than our word.
- Shared runs. When you create a share link, the run it points at is stored so the recipient can open it. Share links expire automatically after 30 days and the stored run goes with them.
- Convoys. A code, the convoy name, the run title, and each member's display name and car — the things the other drivers need to see. Convoys expire automatically after 24 hours. Positions and audio are not part of this and are never stored.
- Soundtrack entries you add to a convoy: a title, an artist and an optional link.
- Cached map and road data derived from OpenStreetMap, keyed by geographic area rather than by any user.
- Ordinary server logs — request paths, status codes, timings — kept short and used for keeping the service up.
Accounts use Sign in with Apple and nothing else. There are no passwords, so there is no password reset flow and no password breach to disclose, and there is no email magic link — we decided against building one rather than take on the ability to send you mail. Apple's Hide My Email is fully supported and changes nothing about how the app works. What we deliberately do not store, for any account: your home address or home coordinates, which stay on the phone and are why drive routes are trimmed before upload.
This website
The route demo on the front page is the real engine. When you use it:
- What you type into the starting-point field is sent to Photon, an open geocoder operated by komoot, to turn a place name into coordinates. Photon sees the text and your browser's connection.
- The plan request goes to our own server, which snaps your start point to roughly 110 m before doing anything with it and caches the result by that coarse point. Your exact coordinate is not kept.
- The map draws raster tiles from openstreetmap.org, which sees your browser's connection, as any image host would.
- This website sets no cookies and runs no advertising, and there is no third-party script of any kind in your browser — no analytics library, no tag manager, no pixel. There is nothing stored on your device to consent to, which is why there is no consent banner.
- One thing on this site is counted, and only on the shared-run pages. When a
/r/…link is opened, our server records that a link was opened — identified by a hash of the link code, never by anything about you — and the page asks our own server (not a third party's) to distinguish a real browser from a chat app fetching a preview. That is four lines of first-party JavaScript and one request to this same domain. No cookie, no identifier, no IP address kept, and nothing on any other page of this site. It is described in full under Shared links are counted too. Nothing you do on this site is joined to anything the app records. - If you leave an email address for the beta, there is no list wired up yet, so right now nothing is stored at all — the form says so on submission rather than showing a tick over a dropped address. Once a list exists we keep the address, the date, and a coarse country code that our hosting provider derives from your connection so we know which regions to survey next. No IP address, and nothing shared with anyone.
Hosting and processors: this website runs on Vercel; the API runs on a server we rent from Hetzner in Germany, with its database on Neon; usage counts are processed by PostHog Inc. in the United States — the app's only if you have turned them on, and the two shared-link counts described above regardless, because those are counts of a link rather than of a person and there is no person to ask. Those providers process data on our behalf in order to run the service. That is the complete list — if a name is not on it, we are not sending anything to them.
Apple's App Privacy questions, answered
The App Store requires every app to declare what it collects, whether it is linked to you, and whether it is used to track you across other companies' apps and sites. Our answers:
- Used for tracking you: nothing. There is no advertising identifier, no ad network and no data broker. Apple's definition of “tracking” is linking data to third-party data for advertising or sharing it with a data broker; the analytics described above does neither, so it is declared as collection but not as tracking, and the app does not ask for tracking permission.
- Precise location — collected, used for app functionality (route planning and navigation), and not used for tracking. Linked to your identity if you have signed in, because a backed-up drive carries the route you drove; not linked for an anonymous install.
- Email address — only if you sign in, and only whatever Apple chooses to pass on, which is frequently a Hide My Email relay rather than your real address. Used for app functionality (account identification and support), linked to your identity, not used for tracking.
- User ID — only if you sign in: the stable identifier Apple gives us for you, plus our own account identifier. Used for app functionality, linked to your identity, not used for tracking.
- Audio data — used for app functionality (push-to-talk), relayed live and never stored.
- User content — your display name, your car and your run titles, where you have entered them for a convoy or a shared run, and your logbook once you have signed in. Used for app functionality, not for tracking. Linked to your identity if you have signed in; not linked for an anonymous install.
- Identifiers — two random device identifiers generated on your phone: one for our own API, one by the analytics library. Used for app functionality and analytics. Neither is the IDFA and neither is linked to you.
- Product interaction — the sixteen usage-count events listed above, plus the app-lifecycle events (installed, updated, opened). Not the name of the screen you are on, which is not collected at all. Used for analytics, not linked to your identity, not used for tracking, and only after you have said yes.
- Diagnostics — crash and performance data if you have Apple's sharing turned on, which reaches us through Apple in aggregate; plus, if usage counts are on, a count of crashes and freezes. The detailed on-device diagnostic reports are not collected.
The machine-readable version of these answers ships inside the app as PrivacyInfo.xcprivacy, so what Apple is told and what this page says are generated from the same decisions.
Your choices
- Location. Revoke or downgrade it in iOS Settings at any time. Planning still works from a searched start point.
- Microphone. Revoke it in iOS Settings. Everything except push-to-talk continues to work.
- Usage counts. On by default, and switchable off at any time in Garage → Privacy & data. Nothing in the app is gated on it and nothing nags you about it.
- Go invisible mid-drive. One tap from the drive screen, not buried in settings.
- Delete a share link or leave a convoy at any time; both also expire on their own.
- Delete your account, in the app. Garage → Account → Delete account, with no email to us and no waiting. It removes the account, the identity, every session, and the whole server-side copy of your logbook, and it asks Apple to revoke the app's access to your Apple ID. It does not touch the copy on your phone — that is yours, and deleting an account is not a reason to destroy your own drives. Your phone keeps working afterwards, anonymously.
- Sign out without deleting anything, on one device or all of them. Local data is left alone unless you tick the box that says otherwise.
- Export your logbook as JSON, either from the phone with no account at all or from the server copy if you have one.
- Delete the app. If you never signed in, your logbook only ever lived on the device, so removing the app removes it. If you did sign in, delete the account too — or write to us and we will.
If you are in the EU, the UK, or California
You have rights over personal data about you — access, correction, deletion, portability, objection, and in California the right to know and to opt out of sale or sharing. Write to privacy@cornerresearch.com and we will act on it.
We do not sell personal information and we do not share it for cross-context behavioural advertising. There is no advertising in this product and no plan for any.
Because most of what the app knows is never written down, some requests have short answers. If you have never signed in, there is no location history to hand over, because there is no location history — and no name or email either. If you have signed in, everything we hold is in Garage → Account → Export and everything we hold can be erased from Garage → Account → Delete account, both without asking us.
Children
Corner Research is for licensed drivers and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Security
Everything is served over TLS. Access tokens are stored hashed, never in plain text. Positions and audio are not persisted, which is the strongest security control available: a breach cannot leak a dataset that does not exist.
Changes
If this policy changes in a way that affects what we collect, we will change the date at the top and say so in the app before the change takes effect.
Contact
privacy@cornerresearch.com for anything in this document, hello@cornerresearch.com for everything else.