Version 1.0 · Effective August 3, 2026
The App uses outside services to draw maps, find addresses and calculate routes. It sends the minimum each needs, only when you use the feature.
1. Mapbox (maps, directions, geocoding) — api.mapbox.com
Receives: your device's location while navigating; the coordinates of the route you are driving; street names and addresses you look up. Used to draw the map, calculate routes and give turn-by-turn guidance, and for nothing else.
We have switched Mapbox's analytics off. Their SDK collects usage and navigation telemetry — including traces of the drive — by default. We disable it at launch, so the only thing Mapbox receives is the map, routing and address requests needed to answer them.
2. Apple (place search, map display) — MapKit
Receives: what you type into the search box, and the area of the map you are looking at. Governed by Apple's privacy policy. Apple states that Maps search is not tied to your Apple Account.
There is no third destination for route sheets. Scanned sheets are read entirely on your device — by the on-device model where the hardware supports it, otherwise by the app's own layout reader. The photograph never leaves your phone.
3. OpenStreetMap / Overpass (local road network) — overpass-api.de and mirrors
Receives: the geographic bounding box of the district you entered — a rectangle, not an address. Used to download the local street network once per district so street and intersection matching works accurately and offline. No personal information is sent.
4. Apple Maps links — maps.apple.com
Only when you tap Share on a place and choose where to send it. Nothing is sent otherwise.
The App requests location to show where you are on the map and to give turn-by-turn guidance. Location is used while you are driving and is sent to Mapbox for that purpose. It is not stored by us, not sold, and not used to build a profile of you. You can revoke location access at any time in iOS Settings; navigation will not work without it.
The camera and photo library are used only to capture or select route sheets you choose to scan. Photos are processed entirely on your device and are not uploaded. The App does not read your photo library on its own.
This App is for adult professional drivers and is not directed at children. But a route sheet is a record about students, and under the federal student-privacy law (FERPA) it is likely to count as personally identifiable information even though no child is named on it.
The U.S. Department of Education's guidance is explicit that indirect identifiers count: information is PII if "a reasonable person in the school community could identify individual students" from it together with other reasonably available information. A pickup corner, at a known time, on a known bus route, meets that test — anyone at the school can tell you which child stands there.
Treat every route and route sheet accordingly:
If you are a school district or transportation contractor: see "For school districts" below.
Student information may also be protected by your state's student-privacy law and by your district's own contracts. Those obligations rest with you and your district; nothing in this policy alters them.
We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not use it for advertising or marketing of any kind. We have no advertising identifiers and do not track you across apps or websites, so the App does not present an App Tracking Transparency prompt.
Because we hold nothing, we have nothing to retain. Data lives on your device until you delete a route, empty Recently Deleted, or delete the App. Route deletion is reversible for 30 days from within the App, then permanent.
If you are in California, the EU/UK, or another jurisdiction with data-protection law, you have rights to access, correct, delete and port your personal information, and to opt out of its sale or sharing.
You can exercise all of these yourself, immediately, without contacting us, because your data is on your device: view and edit it in the App, delete individual items, or delete the App to remove everything. There is nothing for us to sell, so there is nothing to opt out of. For anything else, write to looplabs730@gmail.com.
Your data is protected by iOS's own file protection and, for your API key, by the iOS Keychain. Network requests use HTTPS. No system is perfectly secure; protect your device with a passcode and keep iOS up to date.
We may update this policy. The version and effective date at the top will change, and material changes will be announced in the App. The current version is always under Menu ▸ About.
If you are evaluating this App against the U.S. Department of Education's PTAC guidance on vendor terms of service, the short answers:
adds an optional cloud reader, it will be off by default and lockable by managed configuration
(cloudScanAllowed = false in com.apple.configuration.managed), and this policy will say so
before it ships.
Loop Labs LLC, a New Jersey limited liability company (\(entityID)).
Email: looplabs730@gmail.com
Verify our registration with the New Jersey Division of Revenue at
https://www1.state.nj.us/TYTR_StandingCert/JSP/Verify_Cert.jsp