Privacy Policy
Last updated: August 2026.
What we collect
To operate the service, TransitStats collects:
- Trip data — routes, stops, timestamps, and your phone's GPS reading at trip start and end, tied to your account
- Contact info — your phone number and/or email address, used for authentication and to send trip-related SMS/MMS
- Imported activity — if you import a PRESTO Transit Usage Report or similar, the fare, date, agency, and location fields from that file
- Stop-sign photos — sent via MMS to log a trip. These are processed in memory and immediately discarded; they are never written to storage or disk, and photo metadata (which can carry a phone's own GPS location) is never read
We do not read image EXIF metadata, and the only location data we store is your phone's GPS reading at trip start/end — never a location pulled from a photo.
Who we share it with
TransitStats runs on a small set of third-party services, and doesn't sell or share your data beyond what's needed to operate on them:
- Twilio — sends and receives your SMS/MMS trip messages
- Google Gemini — parses stop-sign photos and answers natural-language stats questions (premium feature). Your data is never used to train Google's models, and is processed in an isolated session that isn't shared with other users
- Google Firebase — authentication, database, hosting, and backend functions
- Google Analytics — anonymous website usage data such as page views, scrolls, and outbound-link clicks, to help improve TransitStats. TransitStats does not send trip details, route names, stop names, GPS data, or AI questions to Analytics.
- Atlas — a public, read-only transit data source we use to enrich stop and route metadata. No user data is ever sent to it
What other users can see
Your trips are private by default and are never publicly readable, even when a Public Profile is enabled — Firestore access rules restrict trip documents to your own account. If you opt into a Public Profile, it exposes only aggregate stats (trip/hour totals, an anonymized location heatmap) — never individual trip details, routes, or exact timestamps.
Trips also contribute to shared, aggregate predictions (for example, confirming a stop serves a given route) that make the service smarter for everyone. Those shared records never carry your account ID — only the anonymous fact. Your personal prediction data is tied to your account but isn't exposed to other users or readable from the browser at all.
How long we keep it
Trip and account data is kept for as long as your account is active. You can request deletion of your account and all associated trip data at any time — see Contact below.
Your choices
- Reply STOP to any TransitStats text to stop receiving messages and unregister your number
- Request a copy or deletion of your data at any time
- Turn Public Profile sharing on or off from Settings whenever you like
Changes
This policy may change as the service changes. Continued use after an update means you accept the revised policy. See our Terms of Service for the rest of the rules around using the service.
Contact
Questions, data requests, or concerns: GitHub Issues or the contact method the operator has given you directly.