Privacy Policy
Effective date: September 19, 2026
[Jurisdiction], for the controlling jurisdiction. Confirm which regional privacy regimes apply (e.g. GDPR, CCPA) based on where users are located before relying on this document legally.1. Introduction
This Privacy Policy explains what information Gurr (“Gurr,” “we,” “us”) collects through the Gurr app and related services (the “Service”), how we use it, who we share it with, and the choices you have. It should be read together with our Terms of Service.
2. Information We Collect
We collect the following categories of information:
- Account information: your name, email address, and authentication data when you sign in with Apple or email.
- Phone number: if you add one to your profile, we store it so friends can find you. We do not send an SMS code to verify you own the number — it is stored as provided.
- Contacts (opt-in only): if you turn on friend matching, your device hashes the phone numbers in your contacts before they are sent to our servers; we compare those hashes against existing users to suggest matches. We do not store your contacts’ names or unhashed numbers, and this only happens if you explicitly enable it.
- Location data: precise GPS location while you record a trip, and — only if you turn it on — your real-time location shared with the friends you choose, for the duration you set.
- Vehicle information: details you add about your car(s), such as make, model, and year.
- Push notification tokens: a device identifier used to deliver notifications (e.g. a friend started a trip, or a live share ended).
- Device and crash analytics: device type, OS version, app version, and crash/error diagnostics collected automatically through Sentry to help us fix bugs.
3. How We Use Your Information
We use the information above to:
- Create and secure your account and authenticate you;
- Operate core features — trip recording, maps and routing, live location sharing, leaderboards, and friend connections;
- Match you with friends who are already on Gurr, only when you opt in to contacts matching;
- Send push notifications and transactional emails (e.g. account, security, or friend-activity notices) via Resend;
- Diagnose crashes and errors and improve app stability and performance;
- Comply with legal obligations and enforce our Terms.
We do not sell your personal information, and we do not use your precise location or contacts data for advertising.
4. Location Data, In Detail
Gurr only accesses your precise location while you are actively recording a trip, or, if you enable it, for the specific window you choose to live-share your location with selected friends. You can revoke location permission at any time in your device settings, and you can stop an active live share from within the app. Maps, routing, and points of interest are powered by Mapbox, which receives location and route data necessary to render maps and calculate directions — see Mapbox’s own privacy policy for how it handles that data.
5. Contacts & Friend Matching, In Detail
Contacts matching is off by default. If you turn it on, your device converts each contact’s phone number into a one-way cryptographic hash locally, before anything is sent to us. Our servers compare those hashes against hashes of existing users’ phone numbers to find matches — we never receive or store your contacts’ raw names, numbers, or any other contact-card detail. You can turn contacts matching off at any time in the app’s settings.
6. Who We Share Information With
We share information with the following categories of third parties, only as needed to run the Service:
- Apple — for Sign in with Apple authentication.
- Mapbox — for maps, routing, and location-based points of interest.
- Resend — for sending transactional emails (account and security notices).
- Sentry — for crash reporting and error diagnostics.
- Hosting providers — our backend runs on a self-managed Coolify VPS and our web properties are hosted on Vercel; these providers store and process data on our behalf under their infrastructure security controls.
- Friends you choose to share trips, stats, or your live location with, as directed by your own use of the app.
- Law enforcement or regulators, only where required by law or to protect the rights, safety, or property of Gurr or our users.
We do not share your data with data brokers or for third-party advertising purposes.
7. Data Retention
We keep your account information and trip history for as long as your account is active. Crash and analytics data collected through Sentry is retained according to Sentry’s standard retention window, primarily for debugging recent issues. When you delete your account, we delete or anonymize your personal data as described in Section 8, subject to any legal retention requirements.
8. Your Choices & Data Deletion
You can:
- Delete your account directly from the app’s account settings, which removes your profile, trip history, and friend connections;
- Or request deletion by emailing xdniklaus@gmail.com from the email associated with your account;
- Turn off contacts matching and live location sharing at any time in the app;
- Revoke location, contacts, and notification permissions from your device’s OS settings.
See our Support page for step-by-step deletion instructions.
9. Children’s Privacy
Gurr is not intended for children. We do not knowingly collect personal information from anyone under 13, and in jurisdictions that set a higher age of digital consent (up to 16), we do not knowingly collect personal information from anyone under that age without the consent required there. If you believe a child has provided us with personal information, contact us at xdniklaus@gmail.com and we will delete it.
10. Data Security
We use industry-standard measures — including encryption in transit, access controls, and hashing of contacts data — to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. International Data Transfers
Our infrastructure and service providers (including our hosting on Coolify and Vercel, and processors such as Apple, Mapbox, Resend, and Sentry) may process data in countries other than where you live. Where required, we rely on appropriate safeguards for these transfers.
12. Governing Law & Your Rights
This Policy is governed by the laws of [Jurisdiction]. Placeholder — owner to confirm the controlling jurisdiction and add region-specific rights language (e.g. GDPR access/erasure/portability rights for EU/UK users, or CCPA/CPRA rights for California residents) once the primary user base and legal entity location are known. Depending on where you live, you may have additional rights to access, correct, export, or delete your personal data, or to object to certain processing. To exercise any such rights, contact us at xdniklaus@gmail.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email before they take effect.
14. Contact Us
Questions about this Privacy Policy or your data? Email xdniklaus@gmail.com.