Privacy Policy
The short version
OpenRydr is built privacy-first. We collect as little as possible, we never sell your data, and we never share it with advertisers or data brokers for marketing.
A few things that matter most:
- Your solo ride and location data stays on your device by default. It only leaves your phone if you turn on cloud sync, start a Safety SMS session, join or host a Group Ride, or opt into the Community Road Database.
- You're in control. You can export everything we hold, or delete your account and all associated data, from inside the app at any time.
- No ads, ever.OpenRydr shows no ads on any tier, and we don't embed advertising or tracking SDKs.
This policy explains the details.
Who we are
OpenRydr is operated by OpenRydr LLC, a Minnesota limited liability company (“OpenRydr,” “we,” “us,” “our”). This policy covers the OpenRydr mobile app, the OpenRydr website at openrydr.com, and shared-content and tracking links served at openrydr.app.
How OpenRydr is built (and why it matters for your privacy)
OpenRydr uses a local-first design: your device is the source of truth for your rides, routes, points of interest, and preferences. That data is stored on your phone and is not automatically uploaded to us. Cloud features are opt-in. When data does leave your device — because you chose a feature that requires it — we describe exactly what is sent and why below.
Information we collect
Information you provide
- Account information.You create an account using Sign in with Apple or Sign in with Google. We receive the basic profile information those services share with us (such as your name and email address, or Apple's private relay email if you choose it). We never receive your Apple or Google password.
- Profile and garage. Your display name, unique handle, optional public profile details, and any motorcycles, gear, or photos you choose to add.
- Safety contacts.The names and phone numbers you enter for emergency and ride-notification contacts, plus a record of your confirmation that you have each contact's permission to receive automated safety texts (a timestamp and the version of the confirmation text). We store these so the Safety SMS and crash-alert features can reach them.
- Community contributions. Route reviews, ratings, character tags, comments, and community routes you create. These are attributed to your profile when your profile is public, and otherwise stored without public attribution.
- Support messages. Anything you send us when you contact support.
- In-app feedback. When you submit feedback from within the app, we collect the message you write along with basic diagnostic context so we can reproduce and fix issues: your device model, operating-system version, the app version, and the screen you were on when you opened feedback. If you choose to attach a screenshot, a diagnostic trace, or your location at the time of submission, those are included too — they are optional and are sent only if you add them.
Information created as you use the app
- Ride and location data. GPS tracks, recorded rides, planned routes, and ride statistics. This is stored on your device by default. It is transmitted off your device only when you take an action that requires it: enabling cloud backup/sync, starting a Safety SMS session, joining or hosting a Group Ride, or opting into the Community Road Database.
- Background location. When you start a ride, begin navigation, or start a safety session, OpenRydr may collect your location in the background — while the app is closed or not in use — so that ride recording and turn-by-turn navigation continue while your phone is stowed or your screen is off, and so crash detection can include your last known location in an alert to your emergency contacts. Background collection only happens during an activity you start, and you can decline it and keep using OpenRydr with location only while the app is open. As with all location data, your solo ride and location data stays on your device by default and only leaves your device when you turn on cloud sync, start a Safety SMS session, join or host a Group Ride, or opt into the Community Road Database.
- Routing requests. When you plan a route, the start point, destination, and any waypoints are sent to our routing servers to calculate the route. We use these to return your route; we do not build advertising profiles from them.
- Map data. Map tiles are delivered from our tile servers and cached on your device for offline use.
- Group riding. During an active Group Ride (a Premium feature), your real-time location is shared with the other members of that ride so the group can coordinate. Sharing stops when the ride ends.
- Safety SMS and live tracking links. When you start a Safety SMS session, we generate a time-limited link that shows your live location to the recipient you chose. The link expires when the ride ends, and in any case no later than 24 hours.
- Crash detection. If the app detects a possible crash and you do not cancel the alert, we send a text message through our SMS provider to your safety contacts, including a short alert message and your last known location. Crash alerts and Safety SMS are best-effort features and are described further in our Terms of Service — they are not a guaranteed emergency service and are not a substitute for calling 911.
Safety contacts and automated messages
When you use OpenRydr's safety features, we process the names and phone numbers of the safety contacts you choose, in order to send the notifications you configure and — if crash detection triggers and you do not cancel — to send an automated crash-alert message to those contacts. Automated crash alerts are delivered through our messaging provider (Twilio) from an OpenRydr messaging number. Routine ride-start and arrival notifications, by contrast, are sent from your own phone using your device's messaging app, and are not transmitted by OpenRydr.
We use safety-contact phone numbers only to deliver these safety messages. We do not use them for marketing, and we do not sell or share them. When you add a contact (or change their number), the app requires you to affirmatively confirm that you have that contact's permission to receive these automated messages, and we record that confirmation — a timestamp and the version of the confirmation text — as evidence of consent for the messages we send (see our Terms of Service). A contact can stop receiving OpenRydr safety messages by replying STOP to a message; doing so may prevent them from receiving future alerts, including crash alerts.
Information collected automatically
We keep this to a minimum.
- Analytics are off by default. We use a self-hosted analytics tool (PostHog) only if you opt in. You can turn it off again at any time. We do not use third-party analytics that phone home without your consent.
- Subscription status.We receive your purchase and entitlement status from the app stores and our subscription manager so we can unlock the features you've paid for. We do not receive your full card number (see Payments).
- Basic operational and diagnostic information necessary to run the service securely and to detect abuse.
How we use information
We use the information above to:
- Provide and operate the app's features, including navigation, ride recording, safety features, group riding, community features, and offline maps.
- Sync and back up your data when you turn those features on.
- Send the safety messages and tracking links you trigger.
- Process subscriptions and unlock paid features.
- Respond to support requests.
- Improve routing quality and the community road database (using opt-in, de-identified contributions — see below).
- Maintain security, prevent abuse, and comply with legal obligations.
We do not use your information to build advertising profiles or to track you across other apps and websites.
How information is shared
We do not sell your personal information, and we do not share it with advertisers or data brokers for their marketing — ever.
Information is shared only in these limited ways:
- Service providers (subprocessors). Vendors that operate parts of the service on our behalf, under contract, listed below.
- People you choose. Group Ride members see your location during a ride; recipients of a share link or Safety SMS link see what that link contains; your safety contacts receive the messages you (or crash detection) send them.
- Public content you publish. Community routes, reviews, and a public profile are visible to others if you make them public. Rides are private by default and are only shareable after you explicitly mark them public.
- Legal and safety. When required by law, or to protect the rights, safety, and security of users, the public, or OpenRydr.
- Business transfers. If OpenRydr is involved in a merger, acquisition, or sale of assets, your information may transfer as part of that transaction, subject to this policy.
Service providers we use
- Supabase — database, authentication, and storage. Hosted in the United States.
- Vercel — website and web-page hosting.
- Cloudflare — delivery of map tiles and related web infrastructure.
- Hetzner — hosting for our self-hosted routing servers.
- Twilio — delivery of crash-alert SMS messages to your safety contacts.
- Resend — delivery of transactional email and management of our email signup list.
- Apple — Sign in with Apple and App Store in-app purchases.
- Google — Sign in with Google and Google Play billing.
- Stripe — payment processing for web subscriptions.
- RevenueCat — subscription and entitlement management across platforms.
- Open-Meteo — weather data (location coordinates are sent to retrieve a forecast for Premium weather features).
Each provider is used strictly to operate the features described and is bound by its own terms and privacy commitments.
Payments
In-app purchases are billed by Apple or Google under their respective terms. Web subscriptions are processed by Stripe. Card numbers are tokenized and handled by the payment processor — they never touch OpenRydr's servers. For web subscriptions we store only the references Stripe issues (a customer ID and a subscription ID) and your resulting subscription tier and status. RevenueCat helps us recognize your entitlements consistently across iOS, Android, and web.
Advertising
OpenRydr shows no ads — on any tier, anywhere in the app, ever. There is no ad-supported tier. We don't embed advertising SDKs, we don't use tracking identifiers for advertising, and we never sell or share your personal information for advertising. The app is funded entirely by optional Rydr and Premium subscriptions.
Analytics
If you opt in, we use a self-hostedPostHog instance to understand how features are used and to improve the app. Because it is self-hosted, this usage data stays within OpenRydr's own infrastructure rather than being sent to a third-party analytics company. Analytics are off by default, and you can turn them off at any time in settings.
Separately, if you turn on “Help improve address coverage”in Settings → Privacy (off by default), OpenRydr records anonymous, aggregate statistics to help us decide where to add better address data. When you search for an address or drop a pin, we record only a coarse approximate area (rounded to roughly 11 km / 7 miles), whether the action was a search or a reverse lookup, and whether our own address database or an external mapping service answered it. We do not record your account, device identifier, precise location, the text you searched, or any timestamps, and the data is stored only as aggregate counts that cannot be tied back to you. You can turn this off at any time.
Community Road Database (opt-in, off by default)
If you opt in, OpenRydr can contribute de-identified road quality signal from your rides to improve scenic and twisty route scoring for everyone. This contribution path is designed so that it cannot be tied back to you:
- The contribution request carries no account ID, no authentication token, and no session identifier — it is anonymous.
- Your raw GPS trace is never stored, never logged, and never linked to your identity. It is map-matched in memory and then discarded.
- The first and last portion of each trace (roughly 500m) is trimmed on your device before anything is sent, to avoid revealing start and end points.
- Only road-segment identifiers and aggregate statistics are retained.
Route reviews you submit are handled separately and are attributed to your account (publicly if your profile is public), because their purpose is to share your assessment of a road.
How long we keep information
- On-device data stays until you delete it.
- Cloud backup on the free tier is limited to a rolling recent window (currently about 20 days); on paid tiers, synced data is retained while your subscription is active.
- Live tracking links expire when a ride ends and no later than 24 hours.
- Anonymous road-database contributions are retained as aggregate, non-identifying data.
- When you delete your account, we delete the personal data associated with it, except where we are required to retain limited records by law.
Your choices and rights
- Export. You can export all of your data (rides, routes, points of interest, settings) from within the app at any time.
- Delete.You can delete your account and its associated data from within the app (Settings → Account → Delete Account), instantly.
- Email. Every email we send includes a one-click unsubscribe link.
- Device permissions.You control location, motion/fitness, and notification permissions in your device settings. Some features won't work without the permissions they depend on.
- Text-message opt-out.Recipients of OpenRydr's automated safety messages can reply STOP to stop receiving them, or HELP for help.
- Preference signals.We do not sell or “share” your personal information for cross-context behavioral advertising. Where applicable, we treat a recognized opt-out preference signal (such as Global Privacy Control) consistently with this commitment.
Depending on where you live, you may have additional rights — for example under the EU/UK GDPR or the California Consumer Privacy Act (as amended by the CPRA) — including the right to access, correct, delete, or port your personal information, and to opt out of “sale” or “sharing” of personal information (which we do not do). We do not discriminate against you for exercising any of these rights. We extend core access and deletion rights to all users, wherever you live. To make a request, use the in-app tools above or email privacy@openrydr.com.
Security
We protect your information with encryption in transit, database-level access controls, tokenized payments, and access restricted to OpenRydr maintainers. No method of transmission or storage is ever completely secure, but we work to protect your data and to limit what we collect in the first place.
International users
OpenRydr is operated from the United States, and the providers we use may process data in the United States or other countries. Where required, we rely on appropriate safeguards for international data transfers.
Children
OpenRydr is intended for adults. The app and website are not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from someone under 18, we will delete it. If you believe a minor has provided us information, contact privacy@openrydr.com.
Changes to this policy
As OpenRydr evolves, we may update this policy. When we make material changes, we will update the “Last updated” date and — consistent with our commitment to the people on our email list — notify subscribers before the changed practices take effect.
Contact
Questions, concerns, or privacy requests: privacy@openrydr.com