ThrottleRun Safety and privacy
Google Play transparency

ThrottleRun Data Safety

A plain-language summary of the data used by the ThrottleRun Android application and connected rider account.

Effective July 24, 2026

Location

ThrottleRun may collect approximate and precise location when a rider uses maps, searches near a route, records a ride, shares an active ride, reports a hazard, or completes location-based event verification. Ride recording is rider initiated, uses a persistent notification, can be stopped immediately, and does not request Android background-location permission.

Personal information

Name, email address, account ID, optional profile information, and manually entered emergency-contact or passenger names and phone numbers support account management, rider safety, clubs, and organized rides. ThrottleRun does not read the Android address book or call log.

Ride, route, and user-created content

Saved routes, waypoints, ride history, motorcycle and maintenance records, event registrations, waivers, checkpoint results, notes, club and event messages, GPX-derived route data, and organizer-provided document links are stored only when a rider or authorized organizer uses those features.

Purchases

The app receives subscription plan, entitlement, receipt, amount, status, and provider-reference information. Android opens website-managed checkout. Square secures and tokenizes payment-card fields; raw card numbers and card security codes do not reach ThrottleRun.

App activity and diagnostics

ThrottleRun records account actions, synchronization and delivery status, errors, application version, and security audit events needed to operate, protect, and troubleshoot the service. It does not include an advertising SDK, build an advertising profile, or sell rider activity.

Device identifiers

Paired-device IDs and an optional Firebase push token are used for device authentication, push delivery, session security, and revocation. Push tokens are encrypted in server storage.

Not collected by the Android package

The current Google Play package does not request contacts, call-log, SMS, microphone, camera, background-location, installed-app inventory, or broad file-system permissions. It does not collect raw payment-card details, advertising IDs, health records, or web-browsing history.

Encryption and deletion

Supported app and API traffic uses HTTPS. A signed-in rider can export account data and schedule account deletion in the rider profile. Public deletion instructions are available at throttlerun.org/data-deletion/. Privacy and data-safety questions can be sent to privacy@truecourse.tech.

Operational retention schedule

Temporary contact live-share links expire after 12 hours. A scheduled account deletion has a seven-day recovery period. API rate-limit and replay-protection records expire after 24 hours. Successful API telemetry is removed after 90 days, and resolved failure telemetry is removed after 365 days. Account, motorcycle, route, ride, maintenance, club, event, and message records remain available while the account or applicable workspace is active unless an authorized user deletes them. Limited de-identified event, security, billing, and audit evidence may remain when needed for disputes, fraud prevention, accounting, or legal obligations.

Sensitive values and credentials

Emergency-contact phone numbers, optional VIN values, push tokens, provider credentials, and webhook secrets use encrypted server storage. Passwords, device secrets, share tokens, invitation codes, and one-time credentials are stored as non-reversible hashes where the feature does not need to recover the original value. Payment-card numbers and card security codes are not stored by ThrottleRun.

Service providers and user-directed sharing

Configured map, routing, search, public-safety, payment, hosting, email, and push providers process only the request data needed to operate the selected feature. A rider may also direct ThrottleRun to share an active location with a club, event, emergency contact, or temporary link recipient.

Play Console declaration boundary

The Google Play Data Safety form must cover every released build, region, feature, and third-party software development kit for the Play package. This page describes version 0.19.7 behavior and must be reviewed again before each production submission.

Built for visible, rider-controlled operation.

ThrottleRun keeps route planning, ride recording, location sharing, event participation, and maintenance records under the signed-in rider's control.

Back to ThrottleRun