Privacy policy

7 min readApp and website

This policy covers the FlockDetour app and this website. It is written to be read rather than to be survived, and it says the uncomfortable part out loud: a routing app cannot compute a route without knowing where you want to go.

The short version

What we never do

  • No FlockDetour account

    There is no FlockDetour sign-up or sign-in. We do not ask for your name, email address, or phone number. A purchase uses your Apple or Google store account, but it does not create a FlockDetour account.

  • No behavioral analytics, advertising, or tracking

    The app ships with no behavioral/product analytics SDK, crash-reporting SDK, attribution SDK, or advertising SDK. RevenueCat does process purchase history for entitlement operation and purchase analytics such as customer history and subscription charts. Our iOS privacy manifest declares five collected categories — precise location, user content, user ID, purchase history, and search history — and declares no tracking.

  • No advertising, and nothing sold

    We do not sell, rent, or share your data with data brokers or advertisers. There is nobody to sell it to who would want it, because we do not build a profile of you in the first place.

  • No plate data

    FlockDetour reads no license plates and stores none. We map where cameras are. We have no access to what any camera sees, and no relationship with any camera operator.

What stays on your device

  • Your preferences

    Alert distances, voice guidance, map style, how much detour you are willing to accept. Kept locally so the app behaves the way you left it.

  • Recent and saved places

    Places you searched for or saved, held on the device so you do not retype them. This is a history of where you have been interested in going, which is why the app can erase it on demand.

  • Turn-by-turn guidance, computed here

    Once a route is loaded, screen-off turn prompts are worked out entirely on the phone. That part of navigation makes no network calls at all — it reads the route already on the device and matches your position against it locally.

  • A cached copy of the camera map

    So the map works with a poor signal or none. It is a copy of public data about camera locations, not a record of anywhere you went.

  • A random installation identifier

    A randomly generated identifier, stored with the operating system's secure storage. It is not derived from your hardware and cannot be used to sign in. It scopes community reports and is attached to provider-backed route and place-search requests for fair-use throttling. The in-app privacy reset deletes and reads back this value after the backend confirms that its exact purchase binding was released or absent. If that check cannot complete, reset reports the partial failure and retains this identifier so paid access is not stranded. On iOS, Keychain-backed values can survive uninstall, so deleting the app alone is not a reliable way to erase it.

What leaves your device, and why

Plenty of apps claim nothing ever leaves your phone. For a navigation product that is rarely true, so here is ours in full.

  • Route calculation

    When you ask for a route, the start and end coordinates and your random installation identifier are sent to our backend, which computes and returns the route. The identifier spends a short-lived fair-use allowance before we call the routing provider. Trips that start or end in Canada, or cross it, are routed by the FOSSGIS community Valhalla server in Germany. It receives the start and end coordinates, not your identifier. We do not store the endpoints or returned route in a trip-history table, and there is no FlockDetour account for them to be filed against.

  • Place search

    What you type, your random installation identifier, and — if you have granted location — an approximate position are sent to our backend. The identifier is used for fair-use throttling, and an open geocoding service returns the matches. We do not keep a server-side search-history table. To answer a repeated search faster, the backend keeps the matches for up to 10 minutes. They are filed under a one-way hash of the search text and a rough area about 1 km across, with no installation identifier attached.

  • Proximity alerts, if you switch them on

    This is the most sensitive thing the app does, so it gets its own entry. When proximity alerts are enabled, the app periodically sends your current position to our backend to ask which cameras are near you. That lookup is a read-only query — it cannot write to our database, and there is no table for it to write to. It happens only while the feature is on, and it stops when you turn it off or force-quit the app.

  • Remote push is not enabled in this release

    Proximity notifications, turn prompts, and the weekly summary are delivered locally and do not need a remote push token. The current release has no user-facing switch that registers a remote token, so ordinary use does not create one. A dormant opt-in implementation exists for a future controlled release; if enabled later, we will update this policy and the store disclosures first. That path requests server deletion on opt-out or reset and reports an offline failure. An unheard token becomes eligible for deletion after 60 inactive days; bounded daily cleanups remove eligible rows.

  • Purchases and Pro verification

    If you view plans, buy, or restore Pro, RevenueCat receives an anonymous App User ID plus app, store, product, transaction, entitlement, and limited device information needed to operate purchases and purchase analytics. Apple or Google handles your store account and payment card; FlockDetour and RevenueCat do not receive your full card number. Our backend receives the anonymous RevenueCat ID for paid-route verification and through authenticated purchase webhooks. Entitlement-cache rows become eligible for deletion after 30 inactive days, and the binding between that ID and the random installation ID becomes eligible after 90 inactive days; bounded daily cleanups remove eligible rows and schedule another batch when needed. Webhook handling retains minimal event ID, type, and time data for replay prevention and anonymous IDs in a retry job. Successful or terminal jobs are deleted immediately; abandoned rows become eligible for deletion after 90 days and are swept every 15 minutes in bounded self-draining batches. After privacy reset, an exact released-pair security fence can remain so an already-running request cannot recreate the old binding; it becomes cleanup-eligible after 90 days and is removed by the bounded daily cleanup. If you redeem a promo code, the backend records that your anonymous RevenueCat ID used it, so the same ID cannot redeem one code twice. That record is kept while the code exists. Failed attempts are counted per ID and cleared after a day. No route history is stored with these records.

  • Camera place labels

    To show which town a camera sits in, the app asks an open geocoding service directly rather than through our backend, which means that provider sees your device's IP address for that request. What it is given is the camera's own public coordinates, not your position.

  • Nearby camera lookups

    To show cameras around you, the app asks the backend for a map area. That request describes a region of the map, not a person.

  • Map tiles

    Map imagery is served by third-party open tile providers. As with any request to any server on the internet, those providers can see the IP address making the request and which part of the map was asked for. We do not control their logs, and we would rather say so than imply a guarantee we cannot make.

Behind our backend sit open services — OpenStreetMap-derived routing and geocoding. Because our server makes those calls rather than your phone, they see our address, not yours. Map imagery is the exception: tiles are fetched by your device directly from open providers, with no API key or account attached, so they see an IP address and which squares of the map were requested.

Provider-backed route and place-search requests spend two hourly allowances: one for the random installation identifier and one shared by everyone. The short-lived counter holds only a bucket name, count, and expiry. No route history is stored with it: the route endpoints, search text, and returned route are not retained. It is a throttle, not a travel history.

The speed limit sign and Just Drive work the same way. While you drive, the app sends your most recent positions (at most 30 points, covering under 2 miles) along with the random install ID. Pro’s road-ahead check also sends the direction you are heading. Our server matches that stretch to a road on the routing service, sends back the limit and what is ahead, and keeps only the throttle count. The positions themselves are not stored.

Reports you submit

If you report a camera, that report is stored on our servers so it can be verified and, if it holds up, added to the shared map. It carries the location and details you entered, and a random identifier for your installation — not for you.

Your device also holds a secret proving the report is yours. We store only a cryptographic hash of that secret, never the secret itself, which is what lets you view and delete your own submissions without ever creating an account. New reports expire from app and public reads 90 days after submission and are then removed by bounded cleanup jobs that run every 15 minutes. If a report is merged into the public map, the resulting camera location is public data and remains after your report is gone — the camera’s location, not anything about you.

Two limits worth knowing. Reports submitted by very early builds of the app predate this ownership mechanism and cannot be retrieved or deleted from the app — they fail closed, which is the safe direction but means the control is not available for them. And photo attachments are switched off entirely: the app has no camera or photo-library access, and the server refuses a photo upload even if one were attempted. There is no image pipeline to describe because there are no images.

Permissions, and why each one is asked for

  • Location, while using the app

    To show where you are on the map, start a route from where you are standing, and place a camera report at the right spot.

  • Location, in the background

    Only if you switch on proximity alerts or screen-off turn prompts. It stops when you turn those features off, and it stops if you force-quit the app.

  • Motion

    The map's heading arrow uses the phone's magnetometer and accelerometer to point the way you are actually facing. These readings are used on the device as they arrive and are never stored or transmitted.

  • Microphone and speech recognition

    Only if you turn on voice search in the car. Your iPhone turns what you say into words itself: the audio never leaves the phone, and only those words are sent, the same as a typed search.

  • Notifications

    To display alerts you asked for. Turn prompts and the weekly summary are computed locally. Proximity alerts use an opt-in backend nearby-camera lookup, then display the result locally. This release does not expose remote-push registration.

Every one of these is optional. Decline any of them and the features that need it stop working, while the rest of the app carries on.

Your controls

  • Erase everything local

    The app's privacy reset attempts to clear saved and recent places, preferences, cached map, downloaded offline areas, local entitlement display state, and the installation identifier. It reads back its named secure-storage keys, privacy files, and offline packs and reports if deletion or verification fails. Server push-token and RevenueCat-binding cleanup require a connection. If push deletion fails, the app reports it; the token becomes cleanup-eligible after 60 inactive days and bounded daily cleanups remove eligible rows. If the purchase-binding check fails, the app reports the partial reset and retains the installation identifier so an unchanged paid bearer is not locked out; the binding becomes cleanup-eligible after 90 inactive days and is removed by the bounded daily cleanup. Reset does not cancel a store subscription or erase Apple, Google, or RevenueCat purchase records.

  • Delete reports first, then reset — in that order

    The local reset does not reach reports already on our servers, and it erases the on-device key that proves those reports are yours. Once that key is gone you can no longer delete them yourself, though they still expire on their own schedule. If you want both, delete your reports first and reset afterwards. We would rather tell you that plainly than let you find out later.

  • Delete reports you submitted

    Your device holds a secret that proves a report is yours. The server stores only a cryptographic hash of it, never the secret itself, which is what lets you manage your own submissions without ever having an account.

  • Turn off permissions

    Location, background location, motion and notifications can each be revoked in your operating system settings at any time. The app degrades feature by feature and keeps working.

  • Delete the app

    Removing FlockDetour normally removes its app-container files, but iOS may preserve Keychain-backed secure values, including the random installation identifier, across uninstall and reinstall. Use the in-app privacy reset first if you want verified local deletion. Uninstall does not cancel an Apple or Google subscription, erase store or RevenueCat purchase records, remove server entitlement/binding records immediately, or delete reports already submitted. Delete reports first, reset while online, and manage purchases in your store account before removing the app if you want those separate actions too.

Children

FlockDetour is a driving tool intended for licensed drivers and is not directed at children. We do not knowingly ask children to submit personal information. If you believe a child sent personal information in a report, contact us so it can be reviewed and removed as applicable.

Changes and contact

If we change how any of this works, we change this page in the same release and update the date at the top. We will not quietly begin collecting something this page says we do not.

Questions, or something here that does not match what you observe in the app? FlockDetour is operated by Block Browser INC. Email FlockDetour@gmail.com or see our position for how we handle corrections. The terms of service cover the rest of the relationship.