Skip to content
Vibe Pacenotes
How it worksHighlightsSupport中文
←Back to home

Legal & transparency

Vibe Pacenotes Privacy Policy

How Vibe Pacenotes handles location, account, sharing, subscription, feedback, and diagnostic data.

  • Effective2026-08-13
  • Version0.4.2
  • 8sections
P

Privacy first

Our privacy baseline

No ads. No sale of personal information. Location is used only for the driving features you choose.

On this page

  1. 1. Information We Process
  2. 2. Location Data
  3. 3. Account, Device, and Safety
  4. 4. Notifications, Subscriptions, and Purchase History
  5. 5. User Content, Sharing, and Clipboard
  6. 6. Feedback, Diagnostics, and Sentry
  7. 7. Retention and Controls
  8. 8. Contact
Continue to Terms of Service↗

1. Information We Process

Vibe Pacenotes is a driving safety reminder app. We process data only to provide trip reminders, account sync, share receiving, user contribution review, subscription entitlements, abuse prevention, customer support, diagnostics, and app stability. We do not serve ads, sell personal information, or use data to track users across apps or websites.

2. Location Data

When you start a trip manually or through a Shortcut automation you configured, such as connecting CarPlay, the app calculates on device how close you are to nearby reminder areas and plays driving safety reminders near complex intersections or safety reminder areas. Background location is enabled only during a trip started in one of those user-configured ways, so assistance can continue while the screen is locked or the app is backgrounded. You can stop the trip at any time.

A trip started manually while the app is in the foreground can use When In Use location authorization. If a CarPlay or similar Shortcut automation you configured must create or restore a trip while the app is in the background, Always and Precise Location authorization are required. The app does not configure or start that automation on its own.

For local-only functionality, location data stays on the device. When you use server-backed nearby search, user contribution, cloud sync, or sharing features, the app may send your current location, reminder coordinates, or share snapshots to our server. Nearby search uses the current location only for that real-time query, returns a non-cacheable response, and the server must not record or store that live location. Coordinates that you intentionally create, submit, or share may be stored to provide reminders, review contributions, sync data, and share reminders.

3. Account, Device, and Safety

When signed out, the app runs in local guest mode and creates no server account. Private sharing, reporting, and paid-content verification may send an irreversible installation identifier and DeviceCheck/App Attest proof only for installation validation and abuse prevention, not advertising or profiling. Only after you explicitly use Sign in with Apple does the app send the Apple identity token and one-time authorization code; the resulting app-account session is stored in the iOS Keychain. If you choose to provide your name during the initial authorization, the app stores Apple’s formatted display name with the account only for the private account interface and cross-device restoration. It is optional profile data, not an identity credential, and is not used for public attribution, logs, advertising, or tracking. Separate name components are not stored.

4. Notifications, Subscriptions, and Purchase History

If you allow notifications, the app uses Apple Push Notification service for contribution review results, reward notices, withdrawal or restoration status for your published contributions, similar updates, and silent background invalidations that accelerate removal of public alerts withdrawn by operations. A contributor status notice contains only the contribution ID and an optional generation. A global silent invalidation contains only the public-alert ID, publication ID, and generation; it contains no coordinates, route, name, spoken text, contributor, or region, and it does not display a notification or open a screen. APNS only accelerates notifications and cache invalidation; server-backed history and region sync still determine the final state.

If enabled, Vibe Pacenotes Pro will be offered through Apple StoreKit auto-renewable subscriptions. Purchase, restore, and paid Pro do not require Sign in with Apple; the app uses Apple-verified current transactions to unlock the current device. You can restore the purchase on other compatible devices using the same App Store purchase account. For paid server content, the server verifies the signed transaction and installation proof and returns a short-lived installation entitlement without creating a user account. A purchase is associated with an app account only when you explicitly choose that action for cloud or cross-device services.

5. User Content, Sharing, and Clipboard

Reminder names, voice text, conditions, coordinates, and share snapshots you create are user content. You can create and receive private shares without signing in. The landing page shows only the reminder name, type, expiration date, and an optional pseudonymous creator name; guest shares use generic creator text. It does not expose coordinates, account identifiers, or installation identifiers.

The share web landing page writes our own HTTPS share URL only after you tap an open or copy action. When the app returns to the foreground, it detects only system-recognized app share URLs and does not read the full clipboard text.

Reporting a public reminder does not require sign-in. We process the reminder ID, selected reason, details you provide, an irreversible installation hash, an optional account internal ID, processing status, and operator audit records for deduplication, abuse prevention, and content review. Reporter identity and installation identifiers are not disclosed to the contributor.

6. Feedback, Diagnostics, and Sentry

When you intentionally send feedback, the app creates a diagnostic package that can include app version, device model, authorization states, optional contact email, your issue description, recent log text, and a local summary. GPS coordinates and sensitive identifiers are redacted at the logging source. The app does not include the full local database in feedback packages. Optional contact email is used only for human support replies.

We use Sentry crash reporting to improve app stability. Sentry is not used to collect your location data, serve ads, or track you.

7. Retention and Controls

Local reminders and trip state are stored on the device, and guest mode creates no server account. When a guest uses private sharing, reporting, or online paid content, the server keeps only the installation-scoped, share, report, or subscription records needed for that feature, abuse prevention, and purchase reconciliation. After Sign in with Apple, cloud sync, public contributions, notifications, account entitlements, and rewards may be associated with the app account. Share links are valid for 30 days by default.

After Sign in with Apple, you can request account deletion from the in-app Account screen. The app asks for confirmation and sends an authenticated deletion request to the server. The request disables the Apple-linked app account, immediately clears its display name, detaches device and notification state, deletes server-backed reminders, share and redemption records, collection subscriptions, and original contribution records, and clears the Keychain session on the current device. Reminders or collections that have become public content may remain, but their contributor or curator link to the account is removed. The encrypted refresh token is marked for revocation; its ciphertext is cleared after Apple confirms revocation or reports that the credential is already invalid, while temporary failures are retried in the background. Deleting the app account does not automatically cancel an App Store subscription, so the screen provides access to Apple subscription management.

Our current retention limits are: device-scoped daily contribution-limit counters are kept for 30 days and are deleted immediately when account deletion detaches the device; subscription chains remain while active or in billing retry. After a chain becomes expired or revoked, its subscription, transaction, ownership-recovery, and unattributed audit records are kept for 24 months. Reward ledger entries are kept for 180 days after account deletion completes, deletion-request audit records are kept for 24 months after completion or rejection, and Sign in with Apple replay-prevention records are kept for 90 days. These records reference only an internal pseudonymous account after Apple identifiers, device data, and user content have been removed. Encrypted refresh-token ciphertext exists only while revocation is pending and is deleted immediately after successful revocation, an already-invalid response from Apple, or a terminal state where key loss makes confirmation impossible. The last case creates a high-priority compliance ticket and is not represented as a confirmed revocation. A limit may change only for a documented legal obligation, with a corresponding update to this policy.

For data export, supplemental deletion of server-side personal data, or human support, you can also contact us at the feedback email below. The email request path does not replace the in-app account deletion entry.

Reports and content-moderation records are retained while a case is handled and for a reasonable period needed for abuse prevention, safety review, and dispute handling. After account deletion, those records retain only an internal pseudonymous identifier that does not directly identify you. Public content may remain after its contributor association is removed.

8. Contact

Feedback email: feedback@vibe-pacenotes.orignosis.com

The public privacy policy canonical path is https://vibe-pacenotes.orignosis.com/en/privacy.

Vibe Pacenotes

A timely heads-up for the road ahead.

ICP filing: 沪ICP备2026031731号-1
PrivacyTermsSupportDelete Account