Privacy Policy
What Clearpath collects, why, and what you can do about it.
Clearpath Privacy Policy
Effective: TBD (first public release)
Last updated: 19 August 2026
Clearpath is a Cape Town navigation app built solo by Edward Leonard. This policy describes what data the app handles, where it goes, and what you can do about it.
TL;DR
- We don't run ads, we don't sell your data, and there is nothing to sign up for — no email, no phone number, no password. (Live location sharing uses an invisible, anonymous technical account — see 'About the device identifier'.)
- Your favourites, route history, and settings live only on your device. We never see them.
- Your live location stays on your device unless you explicitly use a feature that sends it somewhere: calculating a route (Mapbox), submitting a report (our database), or starting a live location share (your chosen recipients).
- The only stable identifier is a random code the app makes up on first launch. It's not tied to your name, your Apple ID, or your hardware, and it disappears when you uninstall.
What stays on your device
The following data is stored locally on your phone and is never uploaded:
- Favourites — the places you've saved.
- Route history — the start and end points of routes you've calculated (capped at the 50 most recent).
- App settings and preferences.
Deleting any of these in the app deletes them for good. Uninstalling the app deletes all of it.
Location
Clearpath asks for your location so it can centre the map, calculate safe routes from where you are, and warn you near higher-risk areas. The app only ever requests the 'While Using the App' permission — never 'Always'.
- Background location happens only during something you started. While a turn-by-turn trip is running, or while a live location share you started is active, location updates continue when you switch to another app or lock the screen — so guidance doesn't die mid-drive and the person following you doesn't lose you. iOS shows the blue location indicator the entire time this is happening. Updates stop the moment the trip ends, the share ends or is stopped, or you force-quit the app.
- Outside of an active trip or share, backgrounding the app stops location updates entirely.
- We don't keep a history of where you've been — not on your device beyond the route history above, and not on our servers.
Your coordinates leave your device only in these cases, each triggered by something you do:
- Calculating a route or searching for a place — sent to Mapbox (see "Service providers").
- Submitting an incident or pothole report — the location you're reporting is stored in our database, because that's the point of the report.
- Live location sharing — only while a share you started is active (see below).
Community reports (incidents & potholes)
When you submit a report, we store: the report type, the location, your optional description, and a one-way hash of your device's random identifier (so you can delete your own report later — see "Your rights").
- Reports are public to other Clearpath users, but never shown with any identifier.
- Reports expire automatically: incident reports after 24 hours, pothole reports after 30 days (extended when other users confirm them).
- If a report fails to send (e.g. you're offline), it's queued on your device for up to 7 days and retried, then discarded.
- To keep spam out, submissions, votes, feedback, share creation, and zone uploads are rate-limited. For that purpose we briefly retain a one-way hash of your network (IP) address — never the address itself — and delete it within about a day.
Custom danger zones
Zones you draw live on your device, and that local copy is the one the app uses. In addition, a copy of each drawn zone (its shape and the name you gave it) is uploaded to our database, tagged with the same one-way device hash as your reports. We use this to understand how the zone-drawing feature is used and to improve the built-in safety data.
When you delete a zone in the app, the local copy is removed immediately and the server copy is marked as deleted — it stops being used, but the record is retained. If you want your zone data fully scrubbed from our database, email us (see "Contact") and we'll delete it by hand.
Live location sharing
If you start a live location share, the app generates a private link you can send to someone. While the share is active:
- Your position (with heading, speed, and accuracy) is transmitted roughly every 5 seconds through our realtime infrastructure (Supabase) to whoever has the link open.
- These positions are relayed, not recorded. No position history is stored on our servers.
- What is stored: the share's random token, when it was created, when it expires, and whether it's still active — tagged with the device hash so you can revoke it.
Shares expire automatically after the duration you pick (1, 4, or 24 hours) and you can stop a share at any time from inside the app. Anyone with the link can view the share while it's active — treat the link like you'd treat your location. Recipients follow you inside their own Clearpath app; the link itself opens a small web page that hands them over to the app (or to the App Store if they don't have it yet).
To make sure only your phone can broadcast on your share (and nobody who merely holds the link), the app signs in to our infrastructure with an anonymous technical account the first time you share — see 'About the device identifier'.
Feedback
The in-app feedback form sends us your message, optional reproduction steps, your app version, and your platform (iOS/Android). No location, no device identifier.
You can optionally include your email address if you'd like a reply. If you do, it's used solely to respond to you: the feedback is forwarded to the developer's inbox via Resend (an email delivery service) with your address as the reply-to. Leave it blank and the feedback is fully anonymous.
Purchases
Clearpath Premium is sold through Apple's App Store. Payment is handled entirely by Apple — we never see your payment details. To manage subscriptions and unlock features, the app uses RevenueCat, which processes an anonymous app-user ID (generated by RevenueCat, not linked to the identifier above) and your App Store purchase receipts. Their privacy policy: https://www.revenuecat.com/privacy.
Diagnostics & analytics
When Clearpath crashes, a crash report is sent to Sentry (an error-monitoring service) so we can find and fix the bug. A crash report contains the technical stack trace, your device model, OS version, and app version — no location, no identifiers linked to you. Crash data only: no session replays, no performance tracing. Processed on Sentry's EU servers. Their privacy policy: https://sentry.io/privacy/
Beyond crash reports there are no analytics: no third-party trackers, no advertising SDKs, no usage tracking. Mapbox's built-in telemetry is explicitly turned off. (The only usage signal we see at all is the anonymous zone copy described under "Custom danger zones".)
About the device identifier
On first launch the app generates a random code and stores it on your device. It's not derived from your hardware, your Apple ID, or anything about you. It's sent along when you submit a report, draw a zone, or start a share — and our database stores only a one-way hash of it. This is what lets your device (and only your device) retract its own reports and revoke its own shares.
Uninstalling the app destroys the identifier. After that, nothing on our servers can be connected to you — but it also means you can no longer retract old reports or revoke old shares yourself (they still expire on their own).
The anonymous sharing account. The first time you start a live location share, the app also creates an anonymous account with our database provider (Supabase). It contains no email, no phone number, no name — it is a random ID whose only job is to prove that your phone, and not someone who merely has your share link, is the one broadcasting your position. It is stored on your device, reused for later shares, and destroyed when you uninstall the app; the orphaned server-side record contains nothing that can be connected to you and is periodically cleaned up.
Service providers
- Mapbox (maps, routing, search): receives map tile requests, route waypoints (including your live position when you route from it), the text you type into search, and coordinates it turns into street names for the report feed. Offline map downloads cover a fixed Cape Town area, not your location. Privacy policy: https://www.mapbox.com/legal/privacy
- Supabase (database & realtime): hosts the community reports, zone copies, share records, and feedback described above, and relays live-share positions. Privacy policy: https://supabase.com/privacy
- RevenueCat (purchases): see "Purchases". https://www.revenuecat.com/privacy
- Resend (email delivery): forwards feedback submissions to the developer. https://resend.com/legal/privacy-policy
- Sentry (crash reporting): receives crash reports as described under "Diagnostics & analytics", processed in the EU. https://sentry.io/privacy/
- Expo (EAS Update): on launch the app checks Expo's servers for over-the-air updates. This sends basic app/platform info, nothing personal. https://expo.dev/privacy
Nobody else. No ads, no data brokers, no analytics companies.
Your rights
You can, directly in the app:
- Delete favourites, route history, and custom zones (zones: see the note above about the retained server copy).
- Retract your own incident and pothole reports — this permanently deletes them from our database.
- Revoke a live location share at any time.
For anything you can't do in-app — including fully scrubbing zone copies or old share records — email us and we'll handle it manually.
If you're an EU/UK resident, you have rights under GDPR / UK GDPR, including access, deletion, and portability. Most of these are exercisable directly through the UI; for the rest, contact the developer.
Children
Clearpath is not directed at children under 13 and we do not knowingly collect data from them.
Contact
This is a solo project. For privacy questions, data deletion requests, or to report a vulnerability:
- Privacy contact: privacy@clearpathroutes.com
- General support: support@clearpathroutes.com
Both addresses forward to the developer's personal inbox.
Changes
We'll update this document if anything material changes and bump the "Last updated" date. Significant changes will be announced in-app on next launch.