Privacy Policy for MetroPing
Effective date: 16 July 2026 · Provided by the MetroPing developer · Contact: business24guru@gmail.com
MetroPing, iOS bundle ID and Android package com.gaurav.MetroAlertApp, is developed and provided by its independent developer. In this policy, MetroPing is also referred to as “the Application.” It provides metro journey assistance, destination alarms, interchange guidance, route planning, and related transit features.
MetroPing is designed to process as much information as reasonably possible on your device. Some optional features, however, require information to be transmitted to our service providers. This Privacy Policy explains what information is processed, why it is used, when it leaves your device, and the choices available to you.
MetroPing is provided as a free service and is intended for use “AS IS.”
Which Build Are You Using?
This policy covers publicly released MetroPing builds and pre-release builds distributed through Apple TestFlight, Google Play testing, or direct internal testing. The distribution mode is fixed when the build is created and determines which testing collection is enabled.
Production Build
In a production build, first-party product analytics and configured third-party analytics are optional. Collection remains off until you affirmatively choose to share analytics in the Application. Limited server request, security, and failure logs may still be processed when necessary to secure or operate a network feature you request.
Internal Testing
Invited internal builds require limited first-party tester telemetry after the tester accepts the in-app disclosure. The current internal profile also enables Firebase Analytics after acceptance. Microsoft Clarity and Sentry are disabled in this profile.
Apple TestFlight External Testing
External TestFlight builds require limited first-party tester telemetry after the tester accepts the in-app beta disclosure. The current external profile also enables Firebase Analytics after acceptance. Microsoft Clarity and Sentry are disabled in this profile. If you do not agree, do not continue using the TestFlight build.
Google Play Closed Testing
Closed-testing builds require limited first-party tester telemetry after the tester accepts the in-app disclosure. Firebase Analytics, Microsoft Clarity, and Sentry are disabled in the current closed-testing profile.
Required pre-release telemetry helps MetroPing identify failures in journey progress, destination and interchange alerts, background execution, underground fallback, notifications, updates, and journey completion.
Required tester telemetry can include a random installation identifier, session identifiers and timestamps, app/build and operating-system versions, device model, tester classification, screens, buttons and features used, selected station and route names, service-city tags, station-segment durations, journey lifecycle and progress events, tester-participation counts, alert and notification delivery or open status, permission and background-task status, update status, errors and crash context. A notification delivery token may also be registered with the installation identifier so test and service notifications can reach the device.
This required tester telemetry does not include passwords, verification codes, contacts, messages, advertising identifiers, typed private content, raw GPS coordinates or a continuous location trail. Photos, videos, files, support text or location context leave the device only when you deliberately submit them through support or use a sharing feature. Account identity and synced travel data are handled separately when you choose to sign in.
When Firebase Analytics is enabled in a testing profile, it may receive product events and relevant app, platform, operating-system, and general device context after the tester accepts the disclosure. Advertising storage, ad personalization, and ad user data remain denied. MetroPing does not authorize a provider to use tester data for advertising or unrelated cross-app tracking.
If you do not agree to required testing collection, do not continue using the pre-release build. You may leave the testing programme, uninstall the build, and request deletion of server-side tester information using the methods below. Production releases use the separate production rules described above.
1. Information Processed on Your Device
1.1 Precise and Approximate Location
MetroPing may request access to your device’s precise or approximate location to provide features such as:
- Detecting nearby metro stations;
- Monitoring progress during an active journey;
- Estimating when your destination or interchange is approaching;
- Triggering destination and interchange alerts;
- Detecting possible wrong-direction movement;
- Supporting journey progress while the screen is off or the Application is in the background.
When background location permission is enabled, MetroPing may continue receiving location updates during an active journey so that destination alerts can work when the Application is not open on screen.
For normal route tracking and destination-alarm functionality, location coordinates and station-proximity calculations are primarily processed locally on your device.
If you sign in and enable account sync, the current journey or station state sent to MetroPing may include the most recent latitude, longitude, and accuracy needed to restore or coordinate that state. Precise or approximate coordinates may also leave the device when you deliberately start Meet or another location-sharing feature, or include location context in a support submission.
MetroPing does not include raw GPS coordinates or a continuous GPS history in optional usage-analytics events.
Location information may leave your device only in the limited circumstances described below, such as when you deliberately use a location-sharing or Meet feature, submit feedback containing location context, or use another feature that clearly explains the transmission before it occurs.
1.2 Route, Journey and Travel History
MetroPing may store the following information locally:
- Selected source and destination stations;
- Calculated routes and interchange information;
- Current and previously detected stations;
- Completed journey history;
- Destination-alarm settings;
- Smart Commute preferences and frequently used route patterns;
- Notification, appearance and performance preferences.
Local travel history can be removed through the Trips or History section using the available deletion controls.
Uninstalling MetroPing normally removes information stored locally by the Application. Uninstalling does not automatically delete information that you separately chose to transmit to MetroPing’s servers.
1.3 Motion Sensors and Barometer
When supported and enabled, MetroPing may use device motion sensors such as the accelerometer, magnetometer and barometer to estimate movement patterns, detect possible deceleration, or support experimental journey-detection features.
Motion and barometer analysis is intended to take place locally on your device. MetroPing does not use these sensors for advertising or cross-app tracking.
1.4 Voice, Speech and Vibration Alerts
MetroPing may use your device’s text-to-speech, vibration, haptic and notification functions to alert you about an approaching destination or interchange.
MetroPing does not require microphone access to generate text-to-speech alerts. It does not record your voice through these features.
1.5 Device Health and Performance State
MetroPing processes coarse battery level, charging state, low-power mode, memory class, and available-storage status on your device to recommend reliable tracking settings and Lite Mode. These readings are not uploaded, linked to your account, used for advertising, or included in analytics. The latest coarse state remains on your device until app data is cleared or the app is uninstalled.
2. Production Optional Analytics and Testing Telemetry
In production builds, MetroPing may ask whether you want to share optional usage analytics. Production optional analytics remains disabled unless you provide affirmative permission. In internal and TestFlight testing builds, the required testing collection described in “Which Build Are You Using?” applies after acceptance of the combined tester disclosure.
When enabled, MetroPing may transmit:
- Application version and build information;
- Platform and operating-system information;
- General device or capability information;
- A randomly generated installation identifier;
- A randomly generated session identifier;
- Feature-engagement events;
- Session start, heartbeat and end events;
- Journey started, live, completed or stopped events;
- Selected source, destination and current station names;
- Route length and number of stations remaining;
- Coarse service-city, state or country tags derived from the supported metro area, without raw coordinates;
- Station-to-station segment duration used to understand crowding and journey reliability;
- During an active journey, a one-way hashed station-segment key, coarse connection availability, duration buckets and, only in testing tiers, a normalized carrier class or cellular generation;
- Destination-alert or journey-feature status;
- Notification delivery, open and action status;
- Tester tags in authorized testing builds.
The random installation identifier is pseudonymous. It is not an advertising identifier, but it can allow multiple analytics events from the same installation to be associated with one another.
MetroPing does not copy your provider name or email address into product-analytics events. When you are signed in, however, first-party events may include or be associated with your internal account identifier, installation identifier, session identifier, or journey identifier. Those events are therefore not necessarily anonymous even when they omit your name and email address.
Optional analytics does not include:
- Your name;
- Your phone number;
- Your email address;
- Advertising identifiers;
- Contacts;
- Photos or files;
- Message content;
- Raw GPS coordinates;
- A continuous location trail.
- Call content, call history or phone numbers contacted;
- Wi-Fi names, router identifiers, IP addresses or browsing activity.
We use optional analytics to:
- Understand whether journey and alert features are functioning;
- Identify unreliable alerts and technical problems;
- Improve route and station handling;
- Understand feature usage;
- Prioritize Application improvements;
- Measure performance and stability.
Production users can disable optional analytics from MetroPing’s settings. Disabling production analytics stops future optional analytics collection from that device and clears analytics events waiting locally for upload. Internal testers can leave the testing programme or uninstall the testing build to stop required future tester collection. Information already transmitted may remain until it is deleted or aggregated under our retention practices.
MetroPing does not use optional analytics for third-party advertising or cross-app tracking.
3. Optional Persona and Commute Survey
MetroPing may offer an optional personalization survey. The survey may ask about:
- Whether you are a student, working professional or transit explorer;
- Gender, including a “Prefer not to say” option;
- How frequently you use the metro;
- Whether you normally use the same or varying routes;
- Commute challenges such as sleeping during travel, missing stops, missing meetings or missing interchange connections.
The gender question is optional.
Survey answers can be used locally to adjust settings such as destination-alert timing and Smart Commute suggestions.
At the final survey step, MetroPing provides separate choices:
- Save on Device: The answers remain stored locally and are not submitted to the admin panel.
- Save & Share Insights: The selected answers are transmitted to MetroPing’s service so that they can be viewed in the admin panel and used to improve alert defaults, product decisions and commute features.
Sharing survey answers is optional. Refusing to share does not remove local personalization features.
Unless clearly stated in the survey disclosure, a persona submission does not include your name, phone number, email address, account ID, precise GPS coordinates, contacts, photos, messages or advertising identifier.
Survey submissions are not used for third-party advertising or cross-app tracking.
4. Optional Account and Cloud Sync
MetroPing offers optional Google and Apple sign-in. Firebase Authentication verifies the provider identity token and MetroPing creates or restores the linked MetroPing account.
When you use this feature, MetroPing may process:
- Your Google, Apple or Firebase account identifier, sign-in provider, verification status and any name or email address the provider makes available;
- An internal account identifier;
- The installation identifier and general device record linked to the account;
- Account status;
- Credits, referrals, feature tier and optional rider-feedback-panel choice;
- Synced current-station or active-journey state, which may include the most recent latitude, longitude, and accuracy;
- Technical information required to prevent abuse and maintain account security.
While you are signed in, MetroPing can sync supported completed-journey records, recent destinations, station-visit timeline, current station state and related travel-history fields to the server. The sync merges the server copy with supported data on signed-in devices so it can be restored after app data is cleared or the Application is reinstalled.
You are not required to create an account to use the core local destination-alarm and route features unless the Application clearly states otherwise.
Signing out does not by itself delete the server copy. “Deactivate beta account” is also not deletion: it blocks sign-in but keeps the account and linked beta data so the tester may return. “Delete account permanently” removes the active server-side account, Firebase Authentication identity, sessions, installation links, and raw account-linked data as described in Sections 12 and 13. Local journey history may remain on your device until you delete it separately or uninstall the Application.
Production builds present permanent deletion as the primary account-removal action. External TestFlight and other pre-release builds may additionally offer beta deactivation, but that supplementary choice never replaces permanent deletion: the permanent-deletion action remains separately available to the signed-in tester.
5. Meet and Location-Sharing Features
MetroPing may provide optional Meet, friend-coordination or journey-sharing features.
When you deliberately activate such a feature, MetroPing may process or transmit information such as:
- A meetup or sharing code;
- Your selected route;
- Source and destination stations;
- Current station or journey progress;
- Approximate or precise location where required by the feature;
- Timestamps and sharing-session status;
- Information necessary for the invited participant to view your progress.
Location or journey information is shared only after you deliberately start the relevant feature. You should share meetup codes only with people you trust.
End the sharing session when coordination is complete. MetroPing does not use Meet-session location information for advertising or cross-app tracking.
6. Feedback, Support and Corrections
When you contact MetroPing, report a problem or submit feedback, we may receive:
- Your name or preferred contact details when you enter them;
- Feedback text;
- Suggested station or route corrections;
- Your email address when you contact us by email;
- Current station, journey phase or diagnostic context included in the submission;
- Screenshots, photos or files that you deliberately attach;
- Application version, device information and technical diagnostics;
- Submission timestamps and support correspondence.
Do not include sensitive information in feedback unless it is necessary for us to handle your request.
Feedback information is used to investigate problems, respond to support requests, correct route data, improve the Application and prevent abuse.
7. Operational Diagnostics and Security Information
MetroPing and its hosting providers may process limited operational information necessary to operate and secure network services, including:
- Request date and time;
- Internet Protocol address;
- General browser, operating-system or device information;
- Server request and error logs;
- Security events;
- Rate-limit information;
- Crash or failure information;
- Information necessary to prevent fraud, abuse or unauthorized access.
This information is not intended for advertising or cross-app tracking.
Strictly necessary diagnostics are separate from optional usage analytics and may be processed when required to secure or operate the service. We aim to minimize this information and avoid including raw location coordinates, survey answers or unnecessary personal information in diagnostic logs.
8. Notifications and Advanced Alarms
MetroPing may request notification permission so it can deliver destination, interchange, journey and reminder notifications.
On supported devices, MetroPing may offer stronger destination-alarm capabilities, such as Android full-screen destination alarms, Android notification-policy access, iOS Time Sensitive notifications or iOS Critical Alerts.
These capabilities are controlled by the operating system and may require separate permission or platform approval. MetroPing should use stronger interruption capabilities only for a journey you started and an urgent final destination or interchange warning.
Notification permission can be changed through your device settings.
When notification permission is available, MetroPing may obtain a Firebase Cloud Messaging or Apple push token and send it to MetroPing’s service with a random installation identifier, platform and app variant. The token is used to address requested journey, reminder, testing, service or update notifications to the device. MetroPing may also record whether a notification was sent, delivered, opened or acted on to operate and evaluate notification reliability.
8A. Apple App Privacy Category Mapping
Apple uses standardized App Privacy labels that can be broader than MetroPing’s feature names. To report conservatively, MetroPing maps the information described throughout this policy as follows:
- Search History: route or station search terms, source and destination selections, and recent-destination activity transmitted to provide route results or cloud sync and, when the applicable telemetry is enabled, to understand route-feature use. This means searches inside MetroPing, not web-browser history;
- Customer Support: support or feedback messages, route corrections, correspondence, and any screenshots, files, contact details, or diagnostic context that you deliberately include in a support submission;
- Other Usage Data: session, journey, alert, notification, testing-participation, and other app-use events that are not fully described by Apple’s narrower Product Interaction category; and
- Other Data Types: optional commute-survey answers, beta or app-service submission fields, and other information described in this policy that does not fit a narrower Apple category.
Search History, Other Usage Data, and Other Data Types are used for Application Functionality and analytics as described above. Customer Support information is used for Application Functionality, including responding to and investigating the request. Depending on the feature and sign-in state, these records may be associated with an internal account, installation, session, journey, email address, or another locator needed to provide the feature. MetroPing does not use any of these categories for advertising or cross-app tracking.
9. Information We Do Not Sell or Use for Advertising
MetroPing does not sell your personal information.
MetroPing does not use your information for:
- Third-party targeted advertising;
- Creating advertising profiles;
- Data-broker activities;
- Cross-app or cross-website tracking;
- Selling precise location information.
MetroPing does not request access to contacts, messages, microphone recordings or the advertising identifier for its core journey-alert service.
10. Service Providers
MetroPing may use contracted service providers to operate network-connected features. Depending on the current build and enabled features, these may include:
- Google Firebase Authentication, Google Sign-In and Sign in with Apple, for optional identity verification;
- Google Firebase or Firestore, for optional account and travel-data sync, database, feedback, sharing or Application-service functionality;
- Firebase Cloud Messaging and Apple Push Notification service, for notification delivery and device tokens;
- Google Firebase Analytics, for product and testing events when enabled in the applicable build;
- Microsoft Clarity, for interaction and usability diagnostics when enabled after consent; text and image masking depend on the applicable Clarity project settings and must not be assumed for material you deliberately submit;
- Sentry, for crash, error and performance diagnostics when enabled in the applicable build;
- Vercel, for hosting APIs, web pages, analytics endpoints, admin services or related infrastructure;
- Apple and Google platform services, for notifications, application distribution, device permissions and operating-system functionality.
These providers may process information on our behalf under their own security and privacy obligations.
We do not authorize service providers to use MetroPing information for their own advertising or unrelated independent purposes.
Information may be processed in countries other than the country where you live, depending on the infrastructure used by these providers.
10A. MetroPing Website and Beta-Access Form
The MetroPing website works without optional behavioural analytics. If you choose “Allow analytics,” the website may use first-party analytics, Vercel Analytics, Microsoft Clarity, and Google Analytics to process page views, clicks, blog-reading progress, form and conversion events, coarse device/browser and country information, referral or campaign parameters, an A/B-test variant, and randomly generated visitor and session identifiers. Blog-reading progress is limited to the public article path, public title, and 25%, 50%, 75%, or 100% milestones; it does not collect selected text or typed content. Advertising storage is denied. The optional visitor identifier and analytics-consent choice may remain in first-party cookies or browser storage for up to one year; an A/B-test assignment cookie may remain for up to 30 days. Short-lived aggregate page-view counters are retained for up to seven days.
If you request Android beta access on the website, MetroPing receives your Google Play email address, optional phone number, selected platform and city, request source, status, and timestamps. These details are used to manage beta access and contact you about the request. The iPhone TestFlight link does not require the website beta form. You may request removal of a beta-access record by contacting us.
11. Legal Disclosure
We may preserve or disclose information when reasonably necessary to:
- Comply with applicable law, legal process or a valid government request;
- Protect the rights, security or property of MetroPing, its users or others;
- Investigate fraud, misuse, security incidents or violations;
- Respond to an emergency involving a risk of harm;
- Establish, exercise or defend legal claims.
We will disclose only the information reasonably necessary for the relevant purpose.
12. Data Retention
We retain information only for as long as reasonably necessary for the purpose for which it was collected, including operation, analytics, support, security, dispute resolution and legal compliance.
Retention depends on the type of information:
- Local journey history and settings remain on your device until you delete them, reset the Application or uninstall it;
- An active optional account and its synced travel data remain until you choose permanent deletion;
- A beta account you only deactivate remains stored with its linked beta data; deactivation blocks access but is not a deletion request;
- Notification tokens remain while needed to address notifications to the installation and may be replaced when the platform rotates the token or removed when they are no longer operationally required;
- Optional analytics and persona submissions may be retained while needed for product analysis and may later be deleted or converted into irreversibly de-identified aggregate statistics;
- Raw tester telemetry may be retained for the relevant test and a reasonable defect-investigation period, then deleted or irreversibly de-identified; permanent account deletion removes raw records that MetroPing can locate through the deleted account, installation, session, or journey identifiers;
- Feedback and support correspondence may be retained while the issue is being investigated and for a reasonable period afterward;
- Meet or sharing-session access expires automatically after the short sharing period, and associated records are removed when linked to an account that is permanently deleted;
- Security and server logs may be retained for a limited operational period or longer where required to investigate abuse or comply with law.
Permanent in-app deletion removes the active account, Firebase Authentication identity, account sessions, installation links, and raw account-linked application data from active stores. MetroPing may keep an opaque, non-reversible deletion receipt for up to seven days so retries do not recreate the account. Isolated disaster-recovery backups may take up to seven days to expire and are not used for normal product or analytics access; if a backup is restored, outstanding deletions must be reapplied before the restored data is returned to service.
MetroPing may retain statistics only after they have been irreversibly de-identified so they can no longer be associated with your account, installation, sessions, journeys, or other identifiers. We may also retain the minimum information required by law, to investigate security or fraud, or to establish or defend a legal claim, and will restrict it to that purpose. We otherwise delete or de-identify information when it is no longer required.
13. Your Choices and Deletion Rights
Depending on the feature and platform, you may:
- Deny or revoke location permission;
- Deny or revoke notification permission;
- Use foreground location without granting background location where supported;
- Disable optional usage analytics in production builds;
- Leave an internal testing programme or uninstall a testing build to stop future required tester collection;
- Save persona answers locally without sharing them;
- End a Meet or journey-sharing session;
- Delete local Trips or History records;
- In an external beta build, choose “Deactivate beta account” to block sign-in while retaining the account and beta data;
- Choose “Delete account permanently” to erase the optional account and raw account-linked server data;
- Sign out to stop future account synchronization from that session;
- Open the Application’s “Delete account & data” page;
- Uninstall the Application;
- Contact us to ask about, correct or request deletion of server-side information.
Some server-side information may be associated only with a random installation identifier rather than your name. We may need reasonable information from you to locate the relevant records.
A deletion request may not apply to the minimum information that we are legally required to retain, information temporarily restricted for a documented security, fraud-prevention, or legal-claim purpose, or information that was already irreversibly de-identified before the request.
14. Security
MetroPing uses reasonable technical and organizational safeguards intended to protect information against unauthorized access, alteration, disclosure or destruction.
Network-connected MetroPing services should use encrypted HTTPS connections. Service providers may apply additional access controls, authentication, monitoring and infrastructure protections.
No electronic storage or transmission system can be guaranteed to be completely secure. You should protect your device, account credentials, verification codes and meetup codes.
15. Children’s Privacy
MetroPing is not directed toward children under the age of 13, or a higher minimum age where required by local law.
We do not knowingly use the Application to solicit personal information from children for advertising. If you are a parent or guardian and believe a child has submitted personal information to MetroPing without appropriate permission, contact us so that we can investigate and delete the information where required.
Students may use local transit features, but optional account creation, survey sharing, Meet sharing and other network-connected features should be used with appropriate consent and supervision where legally required.
16. Third-Party Links and Other Applications
MetroPing contains links to websites, application-store pages, support pages, privacy pages or other applications.
MetroPing is not responsible for the privacy practices of an external service after you leave the Application. Review the external service’s privacy policy before providing information.
17. Changes to This Privacy Policy
We may update this Privacy Policy when MetroPing’s features, service providers, legal requirements or information practices change.
The updated policy will show a revised effective date. Where a change introduces a new material collection or use that requires consent, MetroPing will request the appropriate permission rather than treating changed use alone as consent.
18. Contact Us
For privacy questions, support requests, account deletion or data-deletion requests, contact:
Email: business24guru@gmail.com
Please include enough information for us to understand and process your request, but do not send passwords, verification codes or unnecessary sensitive information.