Signal RunnerA Little Proof Labs / Everhold project

Public information

Privacy transmission // 001

Privacy Policy

Last updated August 24, 2026

Signal Runner is private by default. This policy explains how the Signal Runner mobile app and public website handle information. Signal Runner is presented as a Little Proof Labs / Everhold project. Questions and data requests can be sent to hello@littleprooflabs.com.

1. Information we collect

Account and consent information

Account-enabled versions may process your email address, verification and sign-in timestamps, internal account identifier, session state, account status, and records of privacy or sharing notices you accepted. If Apple or Google sign-in is offered and you choose it, that provider may also send us a provider identifier and profile details such as an email address or name, depending on your provider settings.

Anonymous sign-up is disabled. Earlier limited-test account data was exported and the test accounts were removed during a clean reset. Current testers create verified email/password accounts; Apple and Google sign-in are not yet offered.

Location, ride, and participation information

After you grant permission and intentionally start a drive, Signal Runner may process precise foreground or background location samples. A sample can include coordinates, capture and receipt times, accuracy, altitude, heading, speed, and location source when your device supplies them. We also process drive state, route or event participation, Light, Proofs, and privacy-safe completion summaries.

Vehicle, media, and app information

We may process a vehicle label, appearance settings, a private source vehicle photo you choose, and a derived vehicle avatar. The source photo remains private; an approved derived avatar may be displayed to another driver only when the current product sharing rules authorize it. The app also stores settings and owner-scoped ride state on your device.

Website, waitlist, and support information

When you join the founding waitlist, we store your normalized email address, submission time, consent version, page source, and subscription status. If you contact support, we process your email address, message, and anything you intentionally attach. Our hosting providers may process standard request, security, and delivery metadata needed to operate the site.

Diagnostics

Signal Runner keeps bounded, privacy-safe operational records such as an allowlisted event category, broad failure class, and aggregate count. If crash reporting is enabled in a release, a sanitized crash report may include limited app, device, operating-system, stack, and symbolication details. Our diagnostic boundary is designed to remove messages, users, requests, breadcrumbs, arbitrary context, precise location, ride paths, account identifiers, storage paths, URLs, and tokens before reporting.

2. How we use information

  • Provide authentication, account migration, recovery, and support.
  • Record and restore your private ride history and produce owner-only exports.
  • Run the safety, privacy, route, event, Private Ride, Light, Proof, and vehicle-avatar features you intentionally use.
  • Protect accounts, enforce sharing boundaries, prevent abuse, and investigate privacy-safe operational failures.
  • Send founding-run invitations and occasional product updates you requested through the waitlist.
  • Meet legal obligations and protect people, rights, and services.

3. Location, recording, and sharing

Granting GPS permission does not publish your location. Free Roam begins Signal Off. Starting an ordinary Free Roam drive records for you privately unless you separately turn on a sharing mode.

When you turn on Public Signal, other reciprocal drivers receive only a broad, deliberately offset presence zone. Live Event participants receive only approximate route-relative presence. These public and event views do not receive your exact point or trail.

When you explicitly start a selected Private Ride with its reviewed rider list, each actively reciprocal rider may receive your exact current point. They do not receive your trail, history, speed, heading, accuracy, or account, driver, or vehicle identifier. Creating or joining the Private Ride lobby does not itself start GPS, recording, or location publication.

New exact-current updates stop when you leave the Private Ride or end the drive. A last delivered point may remain visible to an authorized rider for up to 30 seconds. The service then stops returning it and targets the transient row for routine cleanup, although authorized recipients can independently retain information they already received.

You can stop new collection by ending the drive, and stop new sharing with Signal Off, Leave Ride, or End Drive as applicable. You can also change foreground or background location permission in your device settings. Changing permission does not by itself delete ride history already saved.

4. Permissions and sources

We receive information from you, from your device while you use an enabled feature, and from service providers that support the product. Precise foreground or background location requires operating-system permission and an active drive. Camera or photo-library access occurs only when you choose a vehicle image. Local notifications may be used for a drive reminder after permission. Authentication providers send information only when you choose that provider.

5. Service providers and disclosures

We use service providers for specific operational purposes, including:

  • Supabase for mobile authentication, database, private storage, and backend processing.
  • Google Cloud and Firebase for public-site hosting and the waitlist database, and Google email services for support or authentication email when configured.
  • Sentry for sanitized crash and operational diagnostics when that integration is enabled in a release.
  • Apple or Google for platform services and, only when offered and selected, federated sign-in.
  • Apple Maps or Google Maps for native map display, depending on platform. Those providers may process mapping requests and device or network information under their own privacy terms.

We may also disclose information when you direct a sharing feature, when reasonably necessary to comply with law or protect safety and rights, or as part of a merger, financing, acquisition, or transfer of the product, subject to appropriate protection and notice where required.

6. Retention and deletion

Waitlist records are kept while you remain subscribed or while reasonably needed to administer the waitlist. Email support to unsubscribe or remove your waitlist record. Support messages are kept as long as reasonably needed to resolve the request, maintain security, and meet legal duties.

Owner-private ride history, account information, vehicle data, and Proofs are generally kept while your account remains active so the app can provide history, recovery, export, and participation features. Where the app offers an individual ride-delete control, you can use it to remove that drive's exact history; privacy-safe Proof and Light records may remain. Complete account deletion is the whole-account removal path, including for earlier records that do not support individual deletion.

A production account-enabled release is designed to provide Export my data and Delete account + all data in Settings. The export is assembled for you before deletion and is not retained as a server-side export file. The queued cloud-deletion path is not yet deployed in the current limited-test service. Until it is released, or if you use an earlier test build without these controls, contact support.

After that production path is released and the service authoritatively accepts a deletion request, account access and new sharing are blocked, the app signs out, and owner-scoped local data is removed. A background process then removes database records, private storage objects, linked provider material where applicable, and finally the authentication identity. Processing can take time and may be retried if a service is unavailable; access remains blocked while it is pending. Once accepted, deletion cannot be undone.

Deleted material may remain for a limited period in encrypted backups or disaster-recovery systems before normal overwrite. We may retain a privacy-scrubbed deletion receipt containing opaque digests and aggregate lifecycle state when needed to prove completion, keep the account fenced, help suppress accidental restoration, protect security, or meet legal obligations. It does not retain the deleted email address, raw location, or provider identity. We may delay or limit deletion only when law or a legitimate security need requires it.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing, withdraw consent, and complain to a data-protection authority. These rights may have lawful limits. Use the in-app controls where available or email us. We may need to verify that a request belongs to you without asking for your password or exact ride trail.

Where applicable, our reasons for processing include providing the service you request, your consent, our legitimate interests in security and reliable operation, and compliance with law. Withdrawing consent does not make prior lawful processing invalid.

8. Security and international processing

We use access controls, owner-scoped authorization, private storage, short-lived sharing, data minimization, and tested deletion boundaries to protect information. No system is perfectly secure. Our providers may process information in the United States and other countries, with the contractual or legal protections required for the transfer.

9. Children

Signal Runner is not directed to children under 13, and we do not knowingly collect their personal information. Vehicle features must be used only by a person legally permitted to use them, or by a passenger in a lawful and safe manner. Contact us if you believe a child provided information.

10. Changes and contact

We may update this policy as the product changes. We will update the date above and provide additional notice when required. For privacy questions, data requests, or waitlist removal, visit Support or email hello@littleprooflabs.com.