← Back to Metro Tracker

Privacy Policy

Last updated September 7, 2026

This policy covers Metro Tracker's web app, iOS app, and Android app -- all built and run by one independent developer, not by WMATA. If something here is unclear, the contact info at the bottom is the fastest way to reach me.

The short version

Metro Tracker doesn't have accounts, doesn't run ads, doesn't use analytics or tracking SDKs, and doesn't sell or share your data with anyone. Your location, if you grant it, is used to show what's nearby and is never stored on any server. Favorites and settings live only on your own device.

No accounts

There's no sign-up, login, or user profile of any kind. Nothing you do in the app is tied to an identity I can look up.

Location

If you allow location access, it's used on-device to sort nearby stations, bus stops, and bikeshare docks by distance, and to center the map on where you are. To show live results for your area, your coordinates are sent to Metro Tracker's own server, which forwards just the coordinates (nothing that identifies you) to WMATA, Capital Bikeshare, and a weather provider to fetch what's nearby, then returns the result. Your coordinates aren't logged or stored anywhere along the way. You can deny or revoke location access at any time in your device's settings; the app still works without it, just without distance sorting or auto-centering.

What's stored, and where

Favorite stations/stops/routes, your theme, notification preferences, and other settings are stored only on your own device (localStorage on web; UserDefaults on iOS; DataStore on Android). None of it is sent to or stored on any server I control. If you uninstall the app or clear your browser's site data, it's gone.

Notifications

Arrival, service, and elevator/escalator alerts are generated entirely on your device from data the app already fetched -- there's no push notification service, and no third party is ever told what you're watching for.

Third-party services this app talks to

  • WMATA's public API -- live train/bus data, fares, and station info. Requests are proxied through Metro Tracker's own server so your device never contacts WMATA directly.
  • Capital Bikeshare's public GBFS feed -- nearby bike station availability, proxied the same way.
  • A weather provider -- current conditions for nearby cards, proxied the same way.
  • Map rendering -- the web and Android apps use Google Maps; the iOS app uses Apple Maps. Loading the map is subject to Google's or Apple's own privacy policy, independent of anything covered here.
  • Buy Me a Coffee -- an optional link in Settings to a separate site (buymeacoffee.com) if you'd like to support development. Metro Tracker doesn't process or see any payment info -- that happens entirely on their site, under their own privacy policy.

Server logs

Like effectively every website, the hosting provider and Metro Tracker's server keep brief, standard access logs (things like IP address and timestamp) for security and abuse prevention -- for example, a short-lived, in-memory rate limit keyed by IP address that resets every few seconds and is never written to disk. This is infrastructure-level logging common to nearly any web server, not app-specific tracking, and it's never used to build a profile of you or shared with anyone.

No ads, no analytics, no data sales

There are no ad networks, no analytics or crash-reporting SDKs, and no advertising or tracking identifiers anywhere in this app. Your data is never sold, rented, or shared with third parties for marketing.

Children's privacy

Metro Tracker isn't directed at children under 13 and doesn't knowingly collect information from them.

Changes to this policy

If this policy changes, this page will be updated and the date at the top will reflect it. Given how little data this app touches, changes here should be rare.

Contact

Questions about this policy or the app in general: jeremylgrice@gmail.com