Skip to policy
TTrackMe
Home Support Account

Privacy, in plain language

Privacy Policy

TrackMe is a local-first GPS tracking app for Android, with optional account, cloud-sync, live-sharing, emergency, analytics, and Web account-management features. This policy explains the data those features handle and the choices available to you.

Effective and last updated: August 2, 2026
On this page 1. Scope 2. Data we handle 3. How data is used 4. Sharing and processors 5. Local and cloud storage 6. Retention and deletion 7. Security and transfers 8. Device permissions 9. Your choices 10. Children 11. Contact and changes

1. Scope and operator

This policy applies to the TrackMe Android application (package in.shvms.trackme), the TrackMe website, public Live Share pages, and related account-management services. TrackMe is the product and operator named in this policy.

Core promise: TrackMe does not sell, rent, or trade your personal information or precise location data. It has no third-party advertising SDK.

2. Data we access, collect, or process

Location and ride records

During active tracking, TrackMe handles precise and approximate location, latitude, longitude, altitude, accuracy, speed, heading, timestamps, route points, distance, duration, and related ride statistics. TrackMe does not use Android's background-location permission. Location is collected only while a ride or safety session you started is running; that session runs as a foreground service with a persistent notification, so recording continues when the app is not on screen, but it never starts without a session you began and never continues after you end one. Outside a session, TrackMe asks for your location only while the app is open on screen, and only to center the map on you. Those readings are not added to a ride, uploaded, or shared.

Account information

If you choose Google Sign-In, Firebase Authentication provides your display name, email address, account identifier, and authentication/security metadata. An account is optional for local-only recording.

Emergency information

If you configure SOS, TrackMe stores the contact names and phone numbers you enter or select, your message template, SOS settings, and delivery logs. A delivery log can include the recipient number, message text, type, and timestamp.

Live Share information

When you start Live Share, the service processes the active session identifier, exact location, speed, heading, battery information, and timestamps needed to show your progress to people holding the link.

Group Ride information

When you create or join a Group Ride, TrackMe processes a group identifier, a membership list of account identifiers, the group's state and expiry time, and a per-member position record. The position, the group's name, and every member's display name and photo are encrypted on your device before they are sent, with a key derived from the invite link. TrackMe's servers store them as data they cannot read. The server does hold, in readable form, the group identifier, which accounts are members, when the group was created, when it expires, and a timestamp for each position so it can tell how recent it is. Group data is held only in short-lived server memory with an expiry, is overwritten rather than appended, and is deleted when the group ends. No group data is written to your cloud ride storage.

Feedback and support

TrackMe processes feedback text and an optional account-deletion reason that you submit. Authenticated feedback is associated with your account identifier so it can be removed with your account.

Analytics and diagnostics

Product events can include screen names, ride/SOS/Live Share lifecycle events, identifiers, durations, distances, counts, and interaction data. Current PostHog event payloads do not include raw latitude or longitude. Firebase Crashlytics can process crash reports, non-fatal errors, diagnostic logs, device/app information, and the Firebase user ID when signed in.

TrackMe uses the Android SMS permission to send an SOS message you initiate or configure. It does not read your SMS inbox or message history. The app does retain its own SOS configuration and delivery-log data as described above.

3. How data is used

  • Record routes and calculate distance, speed, altitude, duration, maps, charts, and ride summaries.
  • Provide optional sign-in, cloud backup, synchronization, data export, and account management.
  • Send SOS messages to contacts you configure and report whether Android accepted each send request.
  • Create a time-limited Live Share experience when you explicitly start it.
  • Show group members to each other on a map, for as long as a Group Ride you joined is running.
  • Protect accounts, prevent abuse, diagnose crashes, measure reliability, and improve product flows.
  • Respond to support requests and process account/data deletion requests.

4. Sharing, recipients, and service providers

TrackMe discloses data only for the features and processing described here:

  • Google Firebase: Firebase Authentication, Cloud Firestore, and Crashlytics process account, optional cloud, and diagnostic data as service providers. See Firebase privacy and security information.
  • PostHog: PostHog's EU-hosted service processes product analytics and app-interaction events. Raw precise GPS coordinates were removed from TrackMe analytics events. See the PostHog privacy policy.
  • People you choose: Anyone with an active Live Share link can see the live-session data exposed by that link until the session ends or expires.
  • Members of a Group Ride: While a group is running, every member can see every other member's current position on their own map. Visibility is mutual — there is no way to see others without being visible yourself. Members see only where you are now, never where you have been. You can leave at any time, in one action, and no one is notified that you left.
  • Emergency recipients and telecom providers: Android and your mobile carrier deliver the SOS SMS, including the message and location link, to contacts you selected.
  • Legal and safety requirements: Data may be disclosed if required by applicable law or necessary to protect users, the public, or the service from fraud, abuse, or security threats.

Service-provider processing is not a sale of personal data. TrackMe does not use location data for advertising.

5. Local-first and optional cloud storage

Ride recording is local-first and does not require an account or mobile-data connection. Data remains in the app's local database unless you enable an online feature, such as account sync, Live Share, cloud export, or SOS logging while signed in.

When cloud features are used, data is stored within the authenticated user's Firebase namespace or in the limited service record needed for that feature. Public Live Share data is accessible through the unguessable link supplied to you; treat that link as sensitive and share it only with people you trust.

6. Retention, export, and deletion

  • Local records: remain on your device until you delete a ride, clear app data, uninstall according to Android backup behavior, or otherwise remove them.
  • Cloud ride/account data: remains while your account and cloud features are active or until you delete it.
  • Live Share: remains available only for the session lifetime and stops being public when the session ends or expires.
  • Export: signed-in users can request a ZIP containing their profile, ride history, and GPX traces through the Android app or Web account portal.
  • Account deletion: TrackMe attempts to delete rides and GPS points, emergency configuration, emergency delivery logs, and feedback associated with your user ID before deleting the Firebase Authentication account. If the cloud purge fails, the account is not silently removed and the app reports the failure so you can retry or contact support.
  • Analytics and diagnostics: processor-managed analytics, security, and crash records may follow Firebase or PostHog retention controls and may not be individually accessible through the TrackMe account screen.

You can start account deletion from Android Settings or the Web account portal. For help with a failed request, email the privacy contact below.

7. Security and international processing

TrackMe uses HTTPS/TLS for service traffic, authenticated user namespaces, platform security controls, and restricted database rules. No system can guarantee absolute security, so keep your account and Live Share links private and report suspected misuse promptly.

Firebase and PostHog may process data in countries outside your own. Firebase states that Authentication runs from United States data centers and that other Firebase services may use global infrastructure; the providers' terms and privacy materials describe their safeguards.

8. Android device permissions

  • Precise/approximate and foreground-service location: route recording, maps, Live Share, and location-based SOS.
  • SMS: sending an SOS message to contacts you configure; TrackMe does not read the inbox.
  • Notifications: persistent tracking status, safety results, sync, and other operational alerts.
  • Vibration and battery-optimization request: tactile feedback and reliable long-running ride recording.

Android presents permission controls in system Settings. Denying a permission limits the related feature but does not prevent unrelated local features from working.

9. Your choices and rights

You can use TrackMe without signing in, decline optional permissions, stop Live Share, delete individual rides, export supported data, delete your account, and contact us about access, correction, deletion, or privacy questions. Rights vary by location; TrackMe will respond in accordance with applicable law.

10. Children

TrackMe is intended for an adult audience and is not designed or marketed for children. If you believe a child provided personal data without appropriate authorization, contact us so the matter can be reviewed and addressed.

11. Contact and policy changes

For privacy questions, account-deletion help, or data enquiries, email dev.shvms@gmail.com or use the in-app feedback mechanism.

This policy may change when TrackMe's features, processors, or legal obligations change. Material updates will be reflected by the date at the top of this page and, where appropriate, an in-app or website notice.

TTrackMe
HomeSupportPrivacy contact

© 2026 TrackMe. Privacy-first by design, transparent by policy.