Privacy Policy
This is the privacy policy for Trail Status Pro ("the app"), an iOS and Android app made by Eric Forbes (Trail Status Pro). Questions? Email info@trailstatuspro.com.
- You can use Trail Status Pro fully anonymously — sign-in is optional.
- We never sell or share your data with advertisers.
- We only collect what's needed to make the app work — your followed trails, your push token, and coarse location (only when you enable Near Me).
- You can delete your account and data any time (Profile → Sign out + Delete account).
What we collect, and why
When you use the app anonymously
- Push notification token (APNS on iOS, FCM on Android) — so we can send the "Blankets Creek is OPEN" push. Stored keyed to the trails you've toggled on. Deleted when you uninstall or revoke notifications.
- Approximate location — only when you tap "Near Me" on the Discover map. Used on-device to sort trails by distance; not transmitted to our backend.
- Precise location — only if you grant it explicitly. Same on-device-only use.
- Trails you follow — stored locally on your device (SwiftData on iOS, Room on Android). Your phone tells our backend which trail URLs to subscribe your push token to; the backend doesn't know who you are.
When you sign in
Sign-in is optional (Apple ID on iOS, Google, or email + a 6-digit code). We use it to sync your followed trails across devices, attribute community trail submissions to your account (for moderation, never shown publicly), and let you take down a trail you submitted.
When you sign in we collect: email address (your account identifier), display name (from Apple/Google; editable), profile photo URL (from Google; we don't host the image), and a randomly generated user ID.
We do not collect: phone number, address, gender, age, race, religion, sexual orientation, financial info, health data, or contacts.
Where your data lives
- On your device — followed trails, last-known status, weather, activity preferences (SwiftData / Room). Deleting the app deletes them.
- On our backend — Cloudflare D1 (US region): user accounts, the trail catalog, push subscriptions, event logs. Encrypted in transit (HTTPS-only) and at rest.
- On our R2 bucket — only trail banner images uploaded by verified trail organizations. Publicly served.
Third parties
Each gets only what it needs to make the app work:
- Cloudflare — backend hosting (Workers, D1, KV, R2). Sees request metadata (IP, user agent) for caching + DDoS protection. Doesn't profile users.
- Anthropic — Claude classifies trail status pages. We send the public page text (no personal data). Not stored after the response.
- Apple Push Notification Service — delivers iOS push. Sees your APNS token + notification body.
- Firebase Cloud Messaging (Google) — delivers Android push. Sees your FCM token + data payload.
- WeatherKit (Apple) — local forecast per trail, keyed by lat/lng.
- Google Maps SDK (Android) / Apple Maps / MapKit (iOS) — render the Discover map.
- Resend — sends sign-in and account emails.
- Sign in with Apple / Google — verify your identity; we receive email + name (+ photo URL from Google).
We do not use advertising SDKs, analytics SDKs, third-party trackers, or data brokers.
Your rights
- Access: email info@trailstatuspro.com for everything associated with your account.
- Correction: edit your name and email in the Profile screen.
- Deletion: Profile → Sign out → Delete account.
- Portability: request a JSON export at the email above.
- Withdraw consent: revoke notification or location permissions any time in your phone's Settings.
For users under CCPA, GDPR, or other formal data-rights regimes: same email above. We respond within 30 days.
Children
Trail Status Pro is not directed to children under 13, and we don't knowingly collect data from anyone under 13. If you believe a child has signed up, email us and we'll remove the account.
Security
- HTTPS-only transport. No plaintext HTTP.
- Session tokens stored in iOS Keychain / Android EncryptedSharedPreferences.
- Server-side session tokens are revocable per row — sign out anywhere kills that token.
- Passwordless (magic-link) auth — no passwords stored.
Spotted a security issue? Email info@trailstatuspro.com before disclosing publicly.
Changes to this policy
We'll update this page when something material changes; significant changes get an in-app notice. The "Last updated" date above tells you when the current version went live.
Contact
- General: info@trailstatuspro.com
- Privacy: info@trailstatuspro.com
- Security: info@trailstatuspro.com
Trail Status Pro · Cartersville, GA, USA
