1. Overview
Railfan Copilot ("the app", "we", "us") is a railfan utility application for Android and iOS. This policy explains what data we collect, how we use it, and your rights regarding that data.
2. Data we collect
2.1 Location
What: Precise GPS coordinates (latitude/longitude)
Why: To show nearby trains on the map, sort scanner feeds by proximity, tag community sighting reports, and send proximity alerts when trains approach your saved locations
When: While the app is in use (foreground). Background location is used only to send approach alerts when the app is closed, and only if you grant "Allow all the time" permission
Stored: Your current location is never permanently stored by us. Sighting reports you submit include your GPS coordinates and are stored in Google Firebase
2.2 Photos
What: Photos you choose to submit for AI analysis
Why: To identify locomotives, analyze consists, and enhance photos using Anthropic's Claude AI
Stored: Photos sent for AI analysis are transmitted to Anthropic's API and are not stored by us. Photos you attach to community sighting reports, railfan spots, or roster entries are stored in Google Firebase Storage
2.3 Anonymous device ID
What: A randomly generated anonymous identifier assigned by Firebase Authentication on first launch
Why: To associate your watchlist, profile, and follows with your device so we can deliver push notifications and power social features
Stored: This ID is stored in Google Firebase. It contains no personal information — no name, email, or account, unless you choose to claim a public username
Reset: Uninstalling and reinstalling the app generates a new ID and clears your watchlist and profile
2.4 Push notification token (FCM token)
What: A device token issued by Google Firebase Cloud Messaging
Why: To deliver watchlist alerts, approach notifications, and nearby-sighting alerts to your device
Stored: Stored in Google Firebase alongside your anonymous device ID
2.5 Community content
What: Sighting reports, comments, railfan spot submissions, roster entries, and upvotes you submit
Why: To power the community feed and shared locomotive roster visible to all app users
Stored: Stored in Google Firebase Firestore and Firebase Storage. Community content is public and visible to all users of the app
2.6 Public profile (optional)
What: A username you choose to claim, display name, and follower/following relationships
Why: To let other railfans find, follow, and recognize your contributions
Stored: Stored in Google Firebase and visible to any authenticated user of the app. Claiming a username is optional
2.7 In-app purchases
What: Purchase records for Railfan Copilot Pro
Why: To verify Pro status and unlock Pro features
Stored: Purchase history is managed by Google Play Billing / Apple's App Store. We receive only a confirmation of purchase — we do not receive your payment details
2.8 App preferences
What: Settings such as refresh interval, railroad toggles, display name, and alert preferences
Why: To persist your configuration between sessions
Stored: Locally on your device. Not transmitted to any server, except where a preference (like nearby-alert settings) requires server-side delivery
3. Third-party services
| Service | Purpose | Privacy policy |
|---|---|---|
| Google Firebase (Firestore, Storage, Auth, Cloud Messaging, Cloud Functions, Hosting) | Community data storage, anonymous auth, push notifications, AI API proxy, this website | firebase.google.com/support/privacy |
| Anthropic Claude API | AI locomotive identification, consist analysis, train symbol decoding | anthropic.com/privacy |
| Google Maps SDK | Interactive map display | policies.google.com/privacy |
| Google Play Billing / Apple App Store | In-app purchases | policies.google.com/privacy |
| OpenRailwayMap / OpenStreetMap | Railroad infrastructure map overlay tiles | osmfoundation.org privacy policy |
| Nominatim (OpenStreetMap) | Reverse geocoding for city names in approach alerts | nominatim.org |
| Railroad scanner streams (railroadradio.net and others) | Live railroad radio audio | Streamed over standard HTTP audio — no personal data transmitted |
4. Data we do NOT collect
- Your name, email address, or any account credentials (unless voluntarily provided, e.g. in a bug report)
- Browsing history or activity outside the app
- Contacts or call logs
- Payment card or financial information
- Persistent device identifiers (IMEI, IDFA, etc.)
5. Scanner audio
Live railroad scanner audio is streamed directly from public radio sources (such as railroadradio.net) over standard HTTP connections. This is an industry-standard protocol for public scanner audio feeds. No personal data is transmitted over these connections. Audio is not recorded or stored by the app.
6. Data retention
| Data type | Retention |
|---|---|
| Community sightings, comments, roster entries | Stored indefinitely unless deleted by us for policy violations, or by you |
| Railfan spot submissions | Stored indefinitely |
| Spot, sighting, and roster photos | Stored indefinitely in Firebase Storage |
| Anonymous device ID, FCM token, profile | Retained until you uninstall the app or we delete inactive records |
| App preferences | Stored locally; deleted when app is uninstalled |
| AI analysis photos | Not retained — transmitted to Anthropic and discarded |
| Bug reports submitted via this website | Retained until resolved; email address (if provided) used only for follow-up |
7. Data security
- All communication between the app and Firebase/Anthropic uses HTTPS
- Railroad scanner audio streams use HTTP (required by source providers — no personal data involved)
- Firebase security rules restrict access so users can only read/write their own watchlist, profile, and following data
- Community content is publicly readable but write-protected by Firebase authentication and field-level rules
- App backup is disabled — your local preferences and history are not backed up to Google or transferred to other devices
8. Children's privacy
Railfan Copilot is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information through the app, please contact us.
9. Your rights
You may:
- Delete community content — most sightings, spots, and roster corrections can be deleted or edited directly from the app; contact us for anything you can't remove yourself
- Reset your anonymous ID — uninstall and reinstall the app
- Disable location — revoke location permission in your device Settings at any time. Core map and alert features will not function without it
- Disable notifications — revoke notification permission in your device Settings
- Request data deletion — contact us at the address below
10. Refunds
Google Play: In-app purchases can be refunded through Google Play within 48 hours of purchase. Open Google Play → profile icon → Payments & subscriptions → Order history → Request a refund.
App Store: Refunds are handled by Apple at reportaproblem.apple.com.
11. Changes to this policy
We may update this policy as new features are added. The "Last updated" date at the top will reflect any changes. Continued use of the app after changes constitutes acceptance of the updated policy.
Railfan Copilot is an independent app and is not affiliated with any railroad company, Amtrak, or transit agency.