Corner Research

The long way is the point.

Privacy

What we collect, and what we refuse to.

Last updated 29 July 2026

Unreviewed draft. This document describes what the product actually does, but it has not been reviewed by a lawyer and is not yet a binding agreement. It is published here so the description can be checked against the software.

This app knows where good roads are and, unavoidably, where you are while you drive them. The design rule we work to is that the safest data is the data that was never written down. Most of this policy is therefore a list of things we do not keep.

The short version

Location

What we ask for, and when

The app requests location when in use the first time it needs to plan from where you are standing, and the request appears immediately after the screen explaining why. Declining is a supported path, not a dead end: you can type or search a starting point instead and everything else works.

The app also uses background location, and only for one thing: keeping turn-by-turn navigation and the corner count working while you are mid-drive with the screen off or another app in front. It is active during a drive you started and stops when the drive ends.

What happens to it

Rules that limit location even when it is allowed

Presence is not a safety feature and we will never describe it as one. It is suppressible, switchable and ephemeral by design, which means it cannot carry a reliability promise.

Microphone

The microphone is used for one feature: push-to-talk inside a group drive. It is half-duplex and deliberate — you hold a button to transmit, and there is no open mic. Audio is relayed live to the other cars in your convoy and is never written to disk, by the app or by the server. There is no transcript, no recording and no playback.

Speech recognition is not used. If a public radius channel between strangers ever ships, it will disclose its own rules at the moment you join, including the one exception under consideration — retaining the last few seconds of audio when somebody presses Report. That does not exist today.

Usage counts

Until July 2026 this page said the app contained no analytics SDK, and that was true. It is not true any more, so here is exactly what changed and why.

The app now includes PostHog, an analytics service, to answer one question we have never been able to answer: does anyone actually share a drive when they finish one? That is the whole reason it is here. It is not a dashboard of user behaviour, and it is deliberately incapable of being one.

It is on by default, and you can switch it off

It is on when you install the app. We have been straightforward about that rather than burying it, because the alternative — a consent card on the first screen — asked you for something before the app had given you anything, and it was inconsistent with the link counts described below, which have never asked anyone.

The switch is in Garage → Privacy & data, which lists every one of the events on this page inside the app itself, so you can read exactly what is collected and turn it off in the same place. If you switch it off, the analytics library is torn down — nothing further is queued, and nothing further is sent.

Switching it off stops collection immediately and discards anything queued but not yet sent. It cannot recall what was already sent, and we would rather say that than imply a delete button we do not have. Write to privacy@cornerresearch.com and we will delete what is there.

What it sends

Exhaustively — there are sixteen events in the app and no others:

Two things that were on this list in the first draft and are not sent after all. Which screen you are on is no longer collected: screen names on iOS are taken from what the screen is titled, and some of ours are titled with a crew's name or a run's name, which is derived from a road. And nothing that identifies a specific run or drive is sent: the identifiers on these events are separate random ones, generated for the count and used for nothing else, because a shared run's own identifier can be exchanged for the run — start point included.

What it cannot send

This is the part worth checking rather than believing. The list of values analytics is allowed to carry is fixed when the app is compiled, and a coordinate is not one of them — sending your position is not a policy we chose to follow, it is a program that would not build. Specifically, none of the following can leave the device through analytics:

If a future feature genuinely needs to know roughly where people drive, the only thing the app is able to send is a geographic cell about 156 km across — an area containing several counties and millions of homes. Nothing sends one today.

Who we are and who they are

Analytics events are anonymous. The app never calls the “identify this person” part of the service, so no profile of you is created; the only identifier is a random one generated on your phone, in the same way the app already identifies your install to our own API. PostHog Inc. processes the events on our behalf, on their US infrastructure.

The question this whole section exists to answer is whether anybody shares a drive and somebody opens it. The second half cannot come from the app, because it happens on whatever phone or laptop the link was sent to — often one with no app on it. So two counts happen outside the app, and the switch in Garage does not govern them, because they are not about you:

Both counts identify the link by a keyed hash of the link code, never the code itself. That matters more than it sounds: a link code can be exchanged with our API for the run behind it, which contains the sender's start point, so a list of codes would be a list of keys to people's houses. A hash cannot be turned back into a code, and it lets us match “a link was made” to “a link was opened” without anything in the analytics service pointing at anything real.

If you are the person who received a link: nothing is stored in your browser, no cookie is set, no identifier is created for you, and your IP address is discarded rather than turned into a city. You never agreed to anything and we have not treated you as though you did. What is recorded is that a link was opened — not that you opened it, and nothing that could distinguish you from the next person.

No ad tracking, and no tracking permission prompt

You will not see iOS's “Allow app to track your activity across other companies' apps and websites?” dialog, because we are not doing that and it would be dishonest to ask. There is no advertising identifier, no ad network, no data broker, and nothing is combined with data from anyone else. Apple's tracking dialog is for advertising measurement, and adding it when you do not need it is a way of implying you do.

Crashes and diagnostics

When the app crashes or freezes we would like to know, and we do it without a crash-reporting company:

There is no third-party crash SDK in the app, and no error-reporting SDK. The cost of that choice is real and worth stating: we get less detail than a product that ships one, and we accepted that in exchange for not adding another company to this page.

What is stored on our servers

Exhaustively, this is it:

Accounts use Sign in with Apple and nothing else. There are no passwords, so there is no password reset flow and no password breach to disclose, and there is no email magic link — we decided against building one rather than take on the ability to send you mail. Apple's Hide My Email is fully supported and changes nothing about how the app works. What we deliberately do not store, for any account: your home address or home coordinates, which stay on the phone and are why drive routes are trimmed before upload.

This website

The route demo on the front page is the real engine. When you use it:

Hosting and processors: this website runs on Vercel; the API runs on a server we rent from Hetzner in Germany, with its database on Neon; usage counts are processed by PostHog Inc. in the United States — the app's only if you have turned them on, and the two shared-link counts described above regardless, because those are counts of a link rather than of a person and there is no person to ask. Those providers process data on our behalf in order to run the service. That is the complete list — if a name is not on it, we are not sending anything to them.

Apple's App Privacy questions, answered

The App Store requires every app to declare what it collects, whether it is linked to you, and whether it is used to track you across other companies' apps and sites. Our answers:

The machine-readable version of these answers ships inside the app as PrivacyInfo.xcprivacy, so what Apple is told and what this page says are generated from the same decisions.

Your choices

If you are in the EU, the UK, or California

You have rights over personal data about you — access, correction, deletion, portability, objection, and in California the right to know and to opt out of sale or sharing. Write to privacy@cornerresearch.com and we will act on it.

We do not sell personal information and we do not share it for cross-context behavioural advertising. There is no advertising in this product and no plan for any.

Because most of what the app knows is never written down, some requests have short answers. If you have never signed in, there is no location history to hand over, because there is no location history — and no name or email either. If you have signed in, everything we hold is in Garage → Account → Export and everything we hold can be erased from Garage → Account → Delete account, both without asking us.

Children

Corner Research is for licensed drivers and is not directed at children. We do not knowingly collect personal data from anyone under 16.

Security

Everything is served over TLS. Access tokens are stored hashed, never in plain text. Positions and audio are not persisted, which is the strongest security control available: a breach cannot leak a dataset that does not exist.

Changes

If this policy changes in a way that affects what we collect, we will change the date at the top and say so in the app before the change takes effect.

Contact

privacy@cornerresearch.com for anything in this document, hello@cornerresearch.com for everything else.