Your information
Privacy Policy
This Privacy Policy explains how Routr collects, uses, discloses, and protects information when you use our mobile application, websites, and related services.
Effective September 17, 2026
1. Scope and eligibility
This policy applies to the Routr iOS application, Routr websites that link to it, and related support and operational services. Routr is a general-audience service intended for adults age 18 and older. It is not directed to children.
2. Information we collect
Account and profile information
We collect your mobile phone number for account authentication. We may also collect a username, profile image, selected city, interests, and status or mood. Business accounts use email and password authentication. During personal signup, we ask for your birthday to check that you are 18 or older. The birthday is processed temporarily and discarded; we retain only the adult-eligibility result, not your birthday or birth year. This is based on the birthday you provide and is not identity verification. Phone authentication happens first, so an authentication record may exist even if you do not finish signup. Existing accounts are not retroactively birthday-verified.
Routes, places, and community content
We collect content you choose to provide, including route titles and descriptions, route stops and notes, route and profile photos, posts, comments, ratings, reports, and related metadata. Published content, profiles, follower relationships, and certain activity may be visible to other users. Draft routes, blocks, saved routes, and similar personal controls are not public unless the service expressly indicates otherwise.
Activity and service information
We collect information about how you interact with Routr, such as routes opened, saved, started, and completed; check-ins; likes; follows; shares; notifications; search and map actions; device and operating-system details; app version; crash diagnostics; performance timing; and approximate event timestamps. Analytics are designed to exclude phone numbers, raw coordinates, authentication codes, access tokens, addresses, and user-entered text.
Support and safety information
If you contact support or report content, we collect the information you submit and operational records needed to investigate, respond, prevent abuse, and maintain an audit trail. Please do not include sensitive personal information that is unnecessary for your request.
Website request information
Our website hosting provider may process standard request data such as IP address, browser type, requested page, and timestamp to deliver and secure these pages. Routr does not use this legal site to run behavioral advertising.
3. Location information
With your permission, Routr accesses precise location to show nearby routes, center maps, support in-app navigation and an active-route Live Activity, and verify check-ins. Foreground location is used while relevant features are open. Background tracking requires a separate choice for the active route and background permission in iOS. If enabled, location may be processed while Routr is backgrounded or your screen is locked to update distance, estimated arrival time, and guidance.
For check-in verification, Routr sends a current coordinate, accuracy estimate, timestamp, and route identifiers to our server to determine whether you are near the relevant stop. We discard the submitted raw coordinate after verification. We retain the stop, account and route-attempt identifiers, time, and derived facts such as verification distance, accuracy, and method. Because a stop identifies a place, these records can reveal which places you visited and when. Individual check-in records are private through normal user access; completion activity may be visible through social features. Place coordinates and published route stops also remain as part of route content.
When you start turn-by-turn navigation, Routr sends your current and destination coordinates to Mapbox to calculate directions and reroute. With background tracking enabled, those directions requests can continue outside the foreground. Routr also keeps the current stop's coordinates and derived progress/guidance on your device to update the Live Activity; this is not a stored continuous history of your GPS positions. Stop names and guidance may be visible on your Lock Screen.
End or complete the route to stop live tracking. Closing the turn-by-turn view alone returns to the active route and does not end it. You can revoke foreground or background location access in iOS Settings. Background access is optional: declining it leaves foreground navigation and check-ins available with foreground permission. Without foreground permission, location-based navigation and check-in verification are unavailable; you can still browse routes and copy a stop's address.
4. How we use information
We use information to:
- create, authenticate, secure, and support accounts;
- provide route discovery, creation, navigation, check-ins, completion records, social features, and business profiles;
- display content according to its selected visibility and your actions;
- send requested authentication codes and service notifications;
- automatically screen public text and uploaded images for safety, abuse, and policy violations before public release;
- detect spam, fraud, attacks, misuse, and technical failures;
- measure feature adoption, reliability, and performance using privacy-limited analytics;
- respond to support, privacy, legal, and moderation requests; and
- comply with law and enforce our Terms & Conditions.
5. How we disclose information
Other users and the public
Information you publish—such as your username, profile image, routes, photos, posts, comments, ratings, and follower relationships—may be available to other users or the public depending on the feature and selected visibility. Do not publish information you want to keep private.
Service providers
We disclose information to vendors that process it for us to operate Routr. These may include Supabase for authentication, databases, storage, and server functions; Twilio for authentication texts; Mapbox and device mapping services for maps and navigation; OpenAI or another safety provider for automated public-text and uploaded-image moderation; Sentry for crash and performance diagnostics; PostHog for product analytics; Expo for application builds and updates; Apple for app distribution and platform services; and website hosting providers. These providers receive only information reasonably needed for their services and are required to protect it under their applicable agreements and policies.
Analytics and moderation
PostHog receives product events linked to an internal account identifier, such as feature use, screens visited, and app and device context. These records are pseudonymous, not completely anonymous, and help us understand engagement and retention. Sentry receives error and performance information and may receive the same internal identifier. We apply filters intended to exclude credentials, phone numbers, raw coordinates, and user-written content from diagnostics and product analytics. Session replay, Sentry screenshots, and Sentry view-hierarchy capture are disabled in our app configuration.
Public text and uploaded images are sent to OpenAI for automated safety classification. Pending posts and comments are visible to their author while checks run and are not released publicly until approved. Uploaded images remain in private quarantine until approved. These checks can make mistakes; contact support to request review. We do not use these submissions to train our own AI models.
Mapbox receives search queries and relevant map and navigation coordinates. Its SDK may also process location telemetry to improve its services, subject to its applicable policies and telemetry choices. Provider retention, subprocessors, and any independent processing are governed by the applicable service terms and policies; we do not represent every provider as using data solely on our instructions. The SMS-specific restrictions below continue to apply.
Legal, safety, and organizational purposes
We may disclose information when reasonably necessary to comply with law or valid legal process; protect users, the public, Routr, or others; investigate fraud or abuse; enforce agreements; or support a merger, financing, acquisition, reorganization, or transfer of the service. Where required, we will provide notice and honor applicable choices.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use your phone number to advertise to you. The SMS-specific restrictions in Section 6 apply to every disclosure described in this policy; none of the provisions above authorizes sharing mobile information or messaging consent for marketing or promotional purposes.
6. SMS privacy
Routr authentication messages
Cooper & Co. Technology, LLC. operates the Routr authentication SMS program. We use your mobile phone number to send one-time verification codes when you request to create or sign into your Routr account. These messages help verify that you control the phone number associated with the account. We do not send marketing or promotional text messages.
How we protect mobile information and consent
We never sell or rent your mobile phone number, mobile messaging information, text-message opt-in records, or messaging consent. We do not disclose this information to affiliates or other third parties for advertising, marketing, or promotional use.
We share the information needed to provide authentication messages with service providers such as Supabase, Twilio, and telecommunications carriers for authentication, message delivery, fraud prevention, and support of this SMS program. This operational sharing does not permit those providers to use your mobile information or messaging consent for their own marketing. Disclosures required by law remain subject to applicable legal requirements.
Your requests, message frequency, and choices
You request authentication messages by entering your phone number in the Routr app and requesting a verification code. Creating an account does not enroll you in promotional messaging. Message frequency varies according to your sign-up, sign-in, and resend requests. Message and data rates may apply. Consent to receive authentication messages is not a condition of purchase.
Reply STOP to stop authentication texts or HELP for assistance. You can also contact support@cooperco.tech. Opting out prevents further authentication codes and may prevent phone-based access until you opt back in. Contacting support alone does not re-enroll you in text messages. See the Routr SMS Terms for additional details.
7. Retention and deletion
We retain information for as long as reasonably necessary to provide Routr, maintain security and integrity, comply with legal obligations, resolve disputes, and enforce agreements. Retention varies by data type and context.
- Account closure: when you request account deletion, your profile is hidden and scheduled for permanent closure after a 30-day recovery period. During that period, signing in may allow recovery.
- After the recovery period: sign-in is disabled and directly identifying profile details are removed. An internal account identifier and linked shared content and activity records may remain under a generic former-user profile. This is not a guarantee that every retained record is irreversibly anonymous or that every outside provider has erased its records.
- Your content: while your account is active, you can delete eligible posts, comments, and routes individually. If you want content removed rather than anonymized, delete it before closing your account or contact support.
- Location: raw coordinates submitted for check-in verification are discarded after the verification calculation. Derived verification records may remain with route-attempt and completion history.
- Images: images awaiting moderation remain private. Rejected or abandoned uploads are removed; approved images may remain with the content to which they are attached.
- Operational records: limited security, audit, backup, and legal records may remain for a reasonable period where necessary, with access restricted and identifying data minimized when feasible.
- SMS protection: the app’s server-side SMS guard retains hashed phone/request reservation records for 48 hours. This does not set the retention period for Supabase Auth, Twilio, or carrier delivery records.
Account closure and a broader privacy deletion request are distinct. Contact us if you want us to review retained activity, identifying information in shared content, or records held by our providers. We assess those requests under applicable law, including any lawful retention requirements. Backups and provider records may have separate retention periods; we will not describe a request as complete while required follow-up remains unresolved.
8. Your choices and privacy rights
Depending on your account and applicable law, you may:
- review and update profile information in the app;
- manage drafts, blocks, follows, saved routes, posts, comments, routes, and photos;
- request an in-app export of personal data or contact us if the export is too large;
- delete your account and use the 30-day recovery period;
- control location, camera, photo-library, and notification permissions in iOS Settings;
- turn off product analytics in Account settings on app versions that provide this control; the choice applies to that installation, does not erase previously received events, and does not disable crash, security, or authentication processing;
- opt out of authentication texts by replying STOP; and
- request access, correction, deletion, or another privacy right available under applicable law by emailing us.
We may need to verify your identity before completing a request. Do not email passwords, verification codes, or government identification. We will explain any additional verification needed through an appropriate channel. To ask us to review a privacy-request decision, email support@cooperco.tech with the subject “Privacy request review.” We will respond in accordance with applicable requirements and will not discriminate against you for exercising an applicable privacy right.
We will acknowledge your privacy request within five business days of receipt and aim to resolve it within 30 calendar days of receipt. We will respond sooner where required by applicable law. If we cannot resolve your request within that timeframe, we will explain the reason and next steps; any extension must be permitted by applicable law.
9. Security
We use administrative, technical, and organizational safeguards intended to protect information, including access controls, encrypted network transport, server-side authorization, private image quarantine, and limited diagnostic data. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Contact us promptly if you believe your account or information has been compromised.
10. Children’s privacy
Routr is intended for adults age 18 and older and is not directed to children. During personal signup, phone authentication happens before the birthday check. If the birthday provided indicates an age under 18, we do not allow that signup to create a personal profile. A phone authentication record and related operational records may already exist even when signup is denied or abandoned; denial does not automatically delete those records. If you believe someone under 18 has provided information to Routr, contact support@cooperco.tech to request review and removal. We will investigate and take appropriate action under applicable law.
11. Changes to this policy
We may update this policy as Routr changes or legal requirements evolve. We will post the revised policy here and update its effective date. If a change materially affects how we use information, we will provide additional notice when required.
12. Contact us
Cooper & Co. Technology, LLC.
Routr Privacy
Tennessee, United States
Email: support@cooperco.tech