Privacy Policy

Backtrack Place Finder

Effective date: 2026-09-29

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Backtrack Place Finder stores the item name and category you enter, the last known place, route place names, times, activity types, durations, notes, check statuses, search results, photo marks and a compressed photo of a place when you choose to add one. The app keeps this search data and photo on your device. It creates a random installation secret in the device Keychain. When connected, the app sends the search data and compressed photos to its backup service, which stores them under a one-way hash of that secret. The service does not ask for your name, account, email address or precise location. Its hosting infrastructure receives network requests and may process IP addresses, request times and technical request metadata. The public website and privacy page can be visited without the app secret.

How we use information

The app uses the data to build a route, prioritize places to check, remember search progress, show previous results and calculate personal patterns from actual finds. The server stores an installation-scoped backup so the same installation can restore local data while its secret remains available. Photos and point marks help you remember which part of a place you checked. If enabled, a notification is scheduled locally to remind you about an unfinished search. Technical request metadata is processed to deliver and protect the service and diagnose failures.

Service providers and sharing

The backend runs on Railway, which hosts the application, persistent database volume and network infrastructure. Requests to the service pass through Railway infrastructure; Railway may handle technical access and operational logs. We do not add analytics, advertising, email delivery, account providers or map services. We do not sell search records. A photo chosen from the device is sent only to this backend for the installation backup when network access is available. We cannot state a fixed retention period for Railway infrastructure logs or platform backups because those are controlled by the hosting provider.

Data retention

Searches, route nodes, point marks and compressed photos remain in the app's local storage and in the installation-scoped server database until you delete all data for that installation. Completed searches remain in history until deletion. The installation secret remains in Keychain until deletion through the app, subject to device Keychain behavior. A JSON export is created in temporary app storage only when you tap Export and is removed after the share sheet closes or when you delete all app data. Copies you save to another destination follow that destination's retention. The app does not implement a timed expiry. Railway may retain infrastructure logs or backups under its own operational schedules; those copies may not disappear immediately when the live database record is deleted. The app does not promise recovery after the installation secret is lost.

Deleting your information

In Settings, choose Delete all data while connected. The app first requests deletion of the server records for its installation and then removes local searches, photos and the Keychain secret. If the server request fails, the app reports the failure and leaves data in place so you can retry; it does not claim deletion succeeded. Export local searches as JSON before deleting if you want a copy; the app removes its temporary export after sharing or deletion, while copies you save elsewhere are controlled by that destination. You can also contact InglebyOakenshaw@icloud.com about privacy requests. Without the installation secret, we may be unable to identify or recover a particular installation's backup. Hosting logs and backups may follow Railway's separate retention processes.

Permissions and your choices

Camera access is requested only if you choose to take a place photo. Photo library access is used only when you choose an existing photo. Notification permission is requested only when you enable local reminders. You can deny or withdraw these permissions in iPhone Settings. Searching, route notes and local history remain available without them. The app does not request location or map permissions.

Your privacy rights

You can review and edit search records in the app, export local search data as JSON, and request deletion using Settings. For questions or requests about access, correction or deletion, write to InglebyOakenshaw@icloud.com. The available legal rights depend on where you live. The app has no account or email address tied to an installation, so a request may require the device and its installation secret to identify the relevant backup.

Security

The app uses HTTPS for server requests. A cryptographically random installation secret is stored in Keychain and sent as a bearer credential; the server stores only its SHA-256 hash and checks it for every private data request. Searches, route nodes and photos are scoped to that hash. Local app data is stored in the application's private container. These controls reduce unauthorized access but cannot guarantee absolute security. Exported JSON files and photos shared outside the app are protected by the destination you choose.

Children’s privacy

Backtrack Place Finder is designed for adults managing everyday lost items. It is not directed to children, and it does not include child accounts or child-specific features. If you believe a child has provided data through an installation, use Delete all data on that device or contact InglebyOakenshaw@icloud.com.

Changes to this policy

We may update this policy when the app, backend or hosting practices change. The current version and effective date will be published on this page. Material changes will be reflected here before the updated practice is described as current. For questions about a change, contact InglebyOakenshaw@icloud.com.