Privacy Policy
Last updated 21 August 2026 · Effective 21 August 2026
Noricho records train rides. That means it handles location data, which is about as personal as app data gets. This page describes what the app actually does with it — not what a template says a policy should claim.
The short version. Noricho reads your location only while a hunt is running and when you check in at a station. It never asks for “Always” location. A ride uploads a sampled trail of at most 300 points along with the stations and segments it resolved; the full trail stays on your phone. Your profile is private by default. There are no ads, no analytics SDKs and no third-party trackers. You can delete your account, and everything attached to it, from inside the app.
Who is responsible
Noricho is an independent project run by an individual developer, not a company, and it is not affiliated with, endorsed by or connected to any railway operator. For anything in this policy, write to privacy@noricho.com.
What Noricho collects
Location, while you are hunting
The whole app rests on one idea: a station stamp means you were actually there. That only works with real location data.
- Noricho requests “While Using the App” location permission together with the iOS background location mode, so a hunt keeps crediting segments with your phone in your pocket. It never requests “Always” location.
- Location is read while a hunt is running, and when you check in at a station to claim a stamp. It is not read at any other time.
- Stopping a hunt stops the tracking. There is no passive or background collection between hunts.
What a completed ride uploads
When you confirm a hunt while signed in, the app sends the ride to the Noricho server so it can be credited and so your collection survives losing your phone. That upload contains:
- the station and segment identifiers the engine resolved — which stations you boarded and alighted at, which stretches of track you covered, and which stations were stamped;
- the start and end time of the ride, and its duration;
- a sampled GPS trail of at most 300 points — latitude and longitude rounded to six decimal places, plus a timestamp, an accuracy figure and a speed for each. The full trail your phone recorded is not uploaded; it stays in the app’s local database;
- a confidence tier and any quality flags the engine raised, and the version of the rail dataset the ride was matched against;
- on the fifteen lines with a realtime train feed, the train number your ride was matched to, so the server can resolve which rolling-stock class you were on.
Rides you never confirm are not uploaded. If you use Noricho without signing in, nothing is uploaded at all — your collection lives only on your phone, and is lost if you delete the app.
Account
Signing in is optional and uses Sign in with Apple or Sign in with Google. Noricho never sees or stores your password. From the provider it receives an account identifier, an email address and, where the provider supplies one, your name. If you use Apple’s Hide My Email, Noricho only ever sees the relay address.
Your account also holds a display name and an optional handle, your XP, level and unlocked achievements, and a switch controlling whether your profile is public.
Support messages
If you report a problem or a data error from inside the app, Noricho sends the message you wrote, what it was about (a station, a line, a ride), the dataset version and the app version. Reports made while signed in are attached to your account so a reply is possible.
What Noricho does not collect
- No advertising identifiers, and no advertising.
- No analytics or crash-reporting SDK, and no behavioural tracking.
- No contacts, photos, calendar, microphone, camera, or health and fitness data.
- No payment details. Noricho does not sell anything.
- No location at all when a hunt is not running and you are not checking in.
Why Noricho holds it
| Data | Purpose | Basis |
|---|---|---|
| Location during a hunt | Working out which segments and stations you actually rode | Performing the service you asked for |
| Sampled ride trail | Letting you review a ride, correct a mis-credited one, and letting the developer diagnose a ride you report as wrong | Performing the service; legitimate interest in the app working |
| Collection and progress | Keeping your collection across devices and reinstalls | Performing the service you asked for |
| Account identifiers | Signing you in and attaching your collection to you | Performing the service you asked for |
| Handle and display name | Showing you on leaderboards — only if you turn the public profile switch on | Your consent, withdrawable at any time |
| Support messages | Answering you and fixing rail data | Legitimate interest in supporting the app |
Who can see your data
Your profile is private by default. While it is private, other riders cannot see your name, your handle, your rides or your collection, and you appear on leaderboards only in anonymised form.
If you switch your profile to public, other signed-in riders can see your handle or display name, your level and XP, your rank on the leaderboards, and summary counts of what you have collected. They never see your GPS trails, the individual rides behind those counts, or your email address. Turning the switch back off removes your identity from those boards again.
Your display name is filled in from your Apple or Google account when you first sign in, so it may be your real name. Check it before you make your profile public — you can change it in the app.
Where it is stored, and who processes it
Ride and account data is stored on Supabase (Postgres and authentication), hosted in the Tokyo region (ap-northeast-1) — the same country as the railways the app is about. Supabase acts as a processor on the developer’s instructions.
Sign-in is handled by Apple and Google, each under their own privacy policy. Realtime train information comes from the Open Data Challenge for Public Transportation through a server-side proxy that asks about a railway line and never sends your location or any identifier to it.
This site is served by Vercel and Cloudflare, which process the usual web-server request logs. The site sets no cookies and runs no analytics. It loads a webfont from Google Fonts, which means Google receives the request for that font file.
Noricho does not sell your data, does not share it for advertising, and does not use it to train machine-learning models.
How long it is kept
- Rides, stamps and collection data are kept while your account exists — that is the point of a collection.
- Sampled ride trails are capped at 300 points per ride and are deleted with the ride.
- Deleting a single ride in the app deletes its trail with it.
- Deleting your account deletes everything attached to it, immediately and by cascade.
- Support messages are kept while they are useful for fixing the thing you reported.
Your choices and your rights
- Delete everything. There is a delete-account control inside the app. It removes your account and, by database cascade, your rides, trails, stamps, progress and profile. It is immediate and cannot be undone.
- Stop location access. Revoke location permission in iOS Settings at any time. Hunts will stop crediting segments; nothing else breaks.
- Go private again. Turn the public profile switch off.
- Use it signed out. Noricho works without an account. Nothing leaves your phone.
- Access, correction, portability and objection. If you are in the EU, the UK or another region with equivalent rights, write to privacy@noricho.com and you will get a copy of your data, a correction, or an erasure. You also have the right to complain to your local data protection authority.
Children
Noricho is not directed at children. It is rated 12+ and should not be used by anyone under 13. The developer does not knowingly collect data from children under 13; if you believe a child has an account, write to privacy@noricho.com and it will be deleted.
Changes
If this policy changes in a way that affects what is collected or who can see it, the date at the top changes and the app will tell you before the change takes effect. Older versions are in the site’s git history.
Contact
privacy@noricho.com for anything on this page, or the support page for everything else.