Privacy Policy

We value your privacy and design MeTrail around an “offline-first, minimum data” principle. This policy reflects the real permissions the app uses and how its architecture keeps your data in your hands.

What we don’t do

  • No account is required; we don’t create identities or collect personally identifiable information.
  • No third‑party ads or analytics SDKs; we never sell or share your data.
  • No server-side storage of your visits, locations, photos, or notes unless you explicitly turn on iCloud sync.

How we use permissions

  • Location (Always + Precise): Enables background Visits logging, keeps Today/Footprints maps centered, and maintains geofence accuracy. With “While Using,” only manual pinpointing and basic map display work; continuous trip recording is not available.
  • Notifications: Used for arrival/departure alerts and status tips, enabled only after your consent and can be turned off anytime in system settings or Today > Settings > Notifications. If you turn on “Show Current Stay,” the place and elapsed time of the current stay appear as a Live Activity on the Lock Screen and in the Dynamic Island; it is shown on this device only and never uploaded.
  • Photos (read & add): Read to attach photos to places/visits; Add Photos to save share cards or exports to your library when you choose “Save to Photos.” No writes occur unless you trigger a save.
  • File access / iCloud Drive: Used only when you initiate export or backup, to write archives into Files or your personal iCloud Drive.
  • Network access: Runs offline by default, and we operate no servers of our own. Online calls are limited to (1) iCloud/CloudKit sync if you enable it, (2) Apple reverse geocoding to turn coordinates into place names, (3) Apple Weather (WeatherKit), queried once per new visit only after you turn on “Record weather at arrival,” (4) arrival/departure automation if you enable it and enter a destination yourself, such as Bark, Telegram, or your own service, and (5) smart summaries if you configure your own endpoint in Today > Settings > Intelligence. No other external endpoints.
  • Smart summaries (optional): You supply the endpoint, model, and API key yourself; requests go straight from your device to the provider you chose. MeTrail never receives, relays, or stores what is sent. Only place names (optionally masked as Home / Work / Place A), cities, dates and hours, stay durations, visit counts, tag names, and search queries are sent; coordinates, addresses, notes, and photos never are. You can preview the exact payload for every scenario in Settings. The API key lives only in the on-device Keychain.

Data storage and sync

  • Local: Visits, locations, attachments, and logs stay in the device’s encrypted sandbox (Core Data + file system).
  • Cloud: Only if you enable iCloud in Today > Settings > iCloud Sync; data goes to your private iCloud database that we cannot access.
  • Export: Advanced Export writes to a temp directory then hands off to the iOS share sheet; the app keeps no copy afterward.

Logs and diagnostics

  • Logs stay on-device by default and contain debug info and error codes, not sensitive content.
  • You may export logs for self-help or support; nothing leaves the device unless you do so.

Your control

  • Revoke any permission in system settings; related features degrade or turn off automatically.
  • Delete local data or back up/restore via iCloud Drive at any time; when sync is off, everything remains on-device only.

If you have questions about this policy or how permissions are used, please contact us via in-app feedback.