Skip to main content

Trust

Privacy

This interim notice describes the current local fixture-backed build and its integration boundaries. It will be reviewed whenever those boundaries change.

Last reviewed 24 August 2026

What this build does now

This build requests location only after you choose Use my location. It uses that position in session memory to select a nearby supported origin. Geoapify geocoding and map tiles remain disabled until a server-only key is configured; production Google and Apple sign-in are not configured.

Product analytics is disabled. An explicitly enabled local fixture can demonstrate short-lived sessions and in-memory saved routes without real credentials or a passenger database. Restarting the server clears that saved data. Theme preference may be stored in your browser and contains no journey or account information.

Location and route searches

The browser asks for location only after you choose Use my location. An approved position stays in memory for the active tab or session and is used only to resolve that search.

Exact coordinates will not be placed in URLs, browser storage, analytics, saved routes or application logs. They may be sent to the configured geocoding provider or MAT3 service only for the active search. Manual entry will remain available.

Accounts, cookies and saved routes

Google and Apple are separate sign-in boundaries. The local fixture uses a signed, HTTP-only, SameSite session cookie and never stores provider tokens in local storage or client-readable cookies. Production providers remain unavailable without independently configured credentials.

MAT3 Web does not keep a passenger database. The fixture stores only canonical route IDs and names in server memory. Its deletion confirmation removes that local fixture account's saved list; production account deletion must be reported as complete only after the shared MAT3 service confirms it.

Service providers and monitoring

A configured MAT3 service will receive the place IDs needed for route discovery. Geoapify may receive an active search or approved position for geocoding. Google or Apple will process sign-in under their own notices if their providers are enabled.

Product analytics will remain off unless a later setup is confirmed to be cookieless and consistent with this notice. It must never contain coordinates, raw From or To text, identifiable journeys, account identifiers or provider payloads. Runtime logs must be minimal, request-ID based and redacted.

Your choices

You can enter an origin manually instead of sharing location. When accounts are available, you will be able to remove saved routes, sign out, and request irreversible deletion of the account and its saved data through the MAT3 service.

No privacy contact channel has been published yet. This notice will be updated with a staffed pathway before a public release that collects account or location information.