Privacy Policy
Your run belongs to you.
Effective September 3, 2026
Ghost Racer: Route Rematch is developed by Simeon Cekov (“Ghost Racer: Route Rematch,” “we,” or “us”). This policy explains what information the app processes, why it is used, how long it is kept, and the choices available to you.
Information processed by Ghost Racer: Route Rematch
- Run and location information. With your permission, the app uses precise location, route points, distance, pace, timing, lap results, and related run information to record runs, show nearby saved routes, and compare a run with a saved route. Ghost Racer requests While Using the App, not Always, location access. Nearby-route browsing uses location only while the app is open. When you start a run in the foreground, that active run can continue receiving location updates after you lock the screen; tracking stops when you end or cancel the run and does not restart after you force-quit the app. Saved run summaries, full GPS tracks, and run chat remain on your device. The app does not upload them to an account or cloud run-history database in this version.
- Map requests. When an online map is shown, the app requests map tiles covering the visible area from MapTiler. At close zoom levels, the requested tile coordinates can reveal a precise or sub-kilometer area, together with ordinary network information, to MapTiler and its delivery providers. A request does not include your saved route file, run history, or purchase identity.
- Purchase identity. When you buy or restore content or connect a purchase identity, the app uses Sign in with Apple through Firebase Authentication. It requests only a stable account identifier and does not request your Apple name or email address. The app sends that account identifier, a derived Apple app-account token, and device-level identifiers used by the purchase SDK to Adapty so purchases can be associated with the same purchase identity.
- Purchase and subscription information. Apple or Google Play, together with Adapty, process product identifiers, purchase status, subscription status, refunds, and restoration information so the app can unlock purchased content and understand aggregate revenue and paywall performance. Ghost Racer: Route Rematch does not receive your full payment-card details.
- Technical information. Firebase Authentication may process unlinked diagnostic information needed to operate and diagnose authentication. Firebase App Check uses Apple App Attest or DeviceCheck on Apple production builds and Google Play Integrity on Android production builds to help verify genuine app requests. Ghost Racer: Route Rematch disables Adapty’s collection of Apple’s advertising identifier, Android advertising identifier, and IP-address collection in the SDK. The app does not use these identifiers for advertising or cross-app tracking.
- Optional app analytics and diagnostics. In builds where this feature is enabled, PostHog receives a pseudonymous installation identifier, app/OS/device metadata, fixed screen names, and coarse events such as whether onboarding, a permission choice, a run, a run panel, a feedback submission, a purchase attempt, or a restore reached a particular state. The random identifier persists across app launches so PostHog can recognize a returning installation and calculate aggregate retention and feature-frequency statistics. It is not connected to your name, email, Ghost Racer purchase identity, Apple account, or advertising identifier, and it does not let us recognize the same person on another device. Sentry receives crash, app-hang/ANR, and stack information plus app/OS/device context and normalized operation/error types. These services do not receive Ghost Racer purchase identity, precise location, GPS points, routes, run IDs, route names, distance, pace, duration, run chat, support text, email, transaction IDs, or avatar images. Ghost Racer does not call PostHog's user-identification API. Session replay, screenshots, view hierarchy, request capture, logs, advertising attribution, and automatic user-interaction tracking are disabled. PostHog is instructed not to enrich request IP addresses into location fields; ordinary network transport still necessarily exposes an IP address to the receiving service.
- Support messages. If you choose Send a message, the app sends the selected message type, the text you enter, the mobile platform, the build mode, a one-time message identifier, any reply email address you voluntarily add, and a random app-installation identifier to a Firebase Cloud Function. The function verifies a Firebase App Check token, stores a one-way hash of the installation identifier in a separate short-lived spam-prevention record, and saves the message in a private, server-only Firestore support collection. If you are signed in, the function also uses a separate short-lived one-way hash of your verified Firebase user ID to enforce the same daily message limit across reinstallations; the user ID is not placed in the support message. A reply email is optional; when provided, it is stored with that message and used only for support correspondence. The message does not include saved runs or precise location. The app asks you not to put other private information in the free-form message. Without a reply email, we cannot respond directly.
Service providers
Ghost Racer: Route Rematch currently relies on:
- Apple for App Store purchases, subscriptions, refunds, Sign in with Apple, and related store services.
- Google Play for Android app distribution, purchases, subscriptions, refunds, and related store services.
- Firebase Authentication, App Check, Cloud Functions, and Firestore for the optional purchase identity, authenticated account deletion, app attestation, and the private support-message inbox.
- Adapty for paywall product delivery, purchase validation, entitlement status, subscription events, and purchase analytics.
- MapTiler and its content-delivery providers for online map tiles.
- Proton for the developer's support mailbox.
- PostHog for optional product analytics.
- Sentry for optional crash and app-reliability diagnostics.
These providers process information under their own terms and privacy policies. Ghost Racer: Route Rematch does not sell personal information, show third-party ads, or use personal information for cross-app tracking in this version.
Storage, retention, and deletion
- Saved run data stays on your device until you delete a run, use Settings → Account → Delete all local run data, or delete the app. The delete-all action removes saved run summaries and their full GPS track files. It does not delete purchases, your purchase identity, app settings, or voice packs.
- Your Firebase purchase identity and linked Adapty purchase profile remain until you use Settings → Account → Delete Ghost Racer: Route Rematch account. After you confirm with Apple, the app deletes the identified Adapty profile, revokes the Apple authorization used by Firebase, and deletes the Firebase user.
- Deleting an account does not cancel a subscription, issue a refund, or erase Apple App Store or Google Play transaction history. The applicable store controls those records and may retain transaction, fraud-prevention, tax, accounting, and legal records under its own terms and legal obligations. The same store account may restore eligible purchases later, which can create a new Ghost Racer: Route Rematch purchase profile.
- MapTiler states that its content-delivery provider may hold end-user IP addresses in memory for security checks for up to 20 minutes. Other service providers may retain limited security, diagnostic, or legally required records according to their policies.
- Support messages are saved in a private Firestore collection for review and assigned an automatic expiration time 90 days after submission. Firestore TTL deletion is asynchronous, so removal may occur after that expiration time. An optional reply email is deleted with its support message. App Check tokens are used only to verify the app request and are not stored in the support document. A project owner may delete a message sooner.
- Support rate-limit records contain a one-way hash of a random app-installation identifier and recent submission timestamps. For signed-in users, a separate record contains a one-way hash of the Firebase user ID and the same timestamps. Account-deletion abuse-prevention records similarly contain only a one-way hash of the Firebase user ID and recent attempt timestamps. These records expire 48 hours after the latest accepted request; Firestore TTL deletion may occur shortly afterward.
- PostHog is configured to retain Ghost Racer analytics for no more than 12 months and Sentry diagnostics for no more than 90 days. Turning analytics off stops future collection but does not automatically remove earlier pseudonymous records, which remain until their configured deletion or retention period.
Ghost Racer: Route Rematch does not claim a general right to retain a deleted Firebase or Adapty profile. If a law requires the developer to retain a specific record in the future, this policy will identify the category, purpose, and retention period.
Your choices
You can decline or later revoke location permission in iOS or Android Settings. Precise location is required to start a run because approximate location is not accurate enough for route distance or ghost position. Nearby-route suggestions and run recording may not work without the required location access. You can manage or cancel subscriptions and request eligible refunds through Apple or Google Play, depending on where the purchase was made. You can use the core running features without connecting a purchase identity until you choose to buy or restore content. You can also turn Share app analytics off in Settings → Legal at any time. This stops both PostHog analytics and Sentry diagnostics on that device. The core running and purchase features continue to work.
Children
Ghost Racer: Route Rematch is not directed to children under 13. If you believe a child has provided personal information through the app, contact us so we can review and address the request.
Changes
We may update this policy when the app or its service providers change. The effective date above identifies the latest published version.
For privacy questions, support, or deletion assistance, email support.ghostracer.routerematch@proton.me.