NitoPath Privacy Policy

Last updated 2026-10-02

This policy explains what NitoPath collects when you use NitoPath, why, who else sees it, and what control you have.

Short version: the app works without an account and we keep as little as we can. We do not sell your personal information and we do not use it for advertising.

Location

Your device location is used to centre the map, to plan routes from where you are, and to warn you about nearby cameras. Camera alerts are calculated on your phone.

When you plan a route or search for an address, the start, destination and search text are sent to our servers and on to our routing and search providers (openrouteservice, and Photon or OSRM as fallbacks) so they can return a route or results. Those requests are not tied to your account.

We do not track your location in the background. The app only receives location while it is open and you have granted permission, and you can revoke that permission in Android settings at any time.

Your continuous location trail is never uploaded. If you are signed in and you start a trip, we store a record of that trip (start, destination, distance, duration, camera counts) in your history, which you can delete.

Account information

If you create an account we store your email address, a password (hashed, never in readable form), and an optional display name.

With an account we also store your settings, saved places (such as home and work), saved routes, and trip history — so they follow you between devices.

Without an account, settings and recent searches stay on your phone only.

Camera reports

If you report a camera we store the coordinates you reported, any note you add, the direction you selected, and your account ID so we can review it and so you can withdraw it.

Approved reports may become part of the shared camera map, and may be contributed to OpenStreetMap, where they become public open data. Do not include personal information in report notes.

Technical data

Our servers keep short-lived logs containing request details such as IP address, timestamps and error messages. These are used to keep the service running and to investigate abuse, and are kept only as long as needed for that.

The app stores data on your device (settings, recent searches, your login session) using your phone's own storage.

Who processes your data

Supabase — hosting, database and authentication (servers in the United States).

Google Maps SDK for Android — displays the map. Google receives map usage data directly under its own privacy policy.

openrouteservice (HeiGIT, Germany) — routing and address search. Receives the coordinates and search text needed to answer a request.

Photon by Komoot and the OSRM demo service — fallbacks when the above is unavailable.

OpenStreetMap Overpass servers — our servers download camera locations by geographic region. These requests come from our servers and contain no user data.

We do not sell personal information, we do not share it with data brokers, and we do not use it for advertising or profiling.

Legal requests

We will only disclose personal information if we are legally required to, and we will resist requests we believe are invalid or overbroad, to the extent the law allows.

Keep in mind that we cannot hand over what we never collected: without an account, we hold no profile of you, and we never store your continuous location trail.

Keeping data and deleting it

Account data is kept while your account exists. Deleting your account in the app (Account → Delete account) permanently removes your profile, settings, saved places, saved routes, trip history and reports.

You can clear trip history and recent searches separately at any time in the app.

If you cannot access the app, you can request deletion by emailing Nitopath@gmail.com from the address on the account.

Backups may retain copies for a short period before being overwritten.

Security

Traffic between the app and our servers is encrypted in transit. Database access is restricted by per-user security rules, so one account cannot read another account's data.

No service is perfectly secure. Use a strong, unique password.

Your rights

You can access, correct, export or delete your data. Most of this is available directly in the app; for anything else, contact us.

Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to processing or to complain to a regulator. We do not sell or share personal information as those laws define it. To exercise any right, contact Nitopath@gmail.com.

Children

The Service is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us information, contact us and we will delete it.

Changes and contact

If we make a significant change to this policy we will ask you to review it in the app.

Questions, requests or complaints: Nitopath@gmail.com