Privacy Policy
Civic Route Kit
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Civic Route Kit stores the visits, institution names and optional addresses, appointment dates, document names, step details, notes, folder checks, reminder preferences, and language preference that you enter on your device. The app also keeps two random installation secrets in the device Keychain: one authorizes backup requests and one encrypts and decrypts backups. If you use backup, the service receives an encrypted snapshot, its nonce, the authorization secret in an HTTPS request header, and a time of update. It hashes the authorization secret for storage and does not retain the raw value in the application database. It does not receive the separate encryption key or readable visit content. Railway, which hosts the service, necessarily processes request metadata such as network address, time, and route to deliver HTTPS requests and may retain infrastructure logs. The app has no account, registration, advertising identifier, or analytics SDK.
How we use information
Local visit and document information powers the document chain, revised plan, folder check, archive, and optional device reminders. After you first save a backup, the app retries pending local changes when a network connection returns. The backup service uses the installation credential to authorize storage, retrieval, and deletion of the encrypted snapshot for that installation. Request metadata is processed to operate, secure, and diagnose the hosted service. The public website and privacy page can be viewed without signing in.
Service providers and sharing
The encrypted snapshot and limited request metadata are processed by Railway as the hosting provider for this service. Apple processes optional local notification delivery on your device as part of iOS. Civic Route Kit has no advertising, analytics, support-message, or email-delivery provider. We do not sell visit information. The service does not expose one installation's backup to another installation secret.
Data retention
Your local records and preferences remain on your device until you change or remove them or delete the app. The live server backup remains until you replace it, use Delete Server Backup in the app, or the service ends; no fixed automatic expiry is promised. Deleting a backup removes its live SQLite record. Railway may retain infrastructure logs or volume backup copies, if made, according to its own operational retention; we do not claim an exact duration or immediate erasure of those copies.
Deleting your information
You can change visit information in the app and use Settings to delete the current installation's server backup and stop its automatic updates. Deleting the app removes app-managed local records, while iOS may retain Keychain items or device backups under your device and Apple settings. Removing the authorization or encryption secret makes the existing encrypted server backup unrecoverable from that installation; there is no account recovery or cross-device transfer. To ask about data or deletion beyond the in-app control, write to fergus.macRaee@icloud.com.
Permissions and your choices
Notifications are optional and are requested only if you enable visit reminders. iOS uses that permission to deliver reminders on the device; the backup server is not used to deliver them. You can turn notifications off at any time in iOS Settings and can adjust reminder preferences in the app. The app does not request location or map access.
Your privacy rights
You control the visit information stored in the app and can edit it there. The app can retrieve and delete the backup associated with its current installation secrets. For privacy questions or requests concerning information that cannot be handled in the app, contact fergus.macRaee@icloud.com. We may need enough information to locate a request, and a lost installation secret cannot be used to recover or identify an encrypted backup. Rights may vary by location.
Security
The app encrypts backup content on the device with AES-256-GCM using a separate random encryption key kept in Keychain. Backup requests use HTTPS and a different random Keychain secret for authorization; the service stores only its SHA-256 hash as the lookup key. The service validates request sizes and formats and limits access to the record associated with the presented secret. No system can guarantee absolute security, and anyone with both device-held secrets could access and decrypt that installation's backup.
Children’s privacy
Civic Route Kit is designed for adults preparing documents for appointments and is not directed to children. We do not ask users for their age or knowingly seek children's information. A parent or guardian with a concern can contact fergus.macRaee@icloud.com.
Changes to this policy
We may update this policy when the app, service, or handling of information changes. The current version and effective date will be published on this page. Contact fergus.macRaee@icloud.com with questions about a change.