Privacy Policy for Revly
Effective date: 23 June 2026 Last updated: 18 August 2026
This Privacy Policy explains how Revly (“Revly,” the “App,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal data when you use the Revly mobile application and related services. Please read it carefully. If you do not agree with this Policy, please do not use the App.
1. Who We Are
Revly is a native iOS driving and ride-tracking journal and social application. It lets you record your drives with a live GPS map and metrics, keep a virtual vehicle garage, share posts and stories in a social feed, join clubs and convoys (including real-time live location sharing with convoy members), and earn achievements, levels, and streaks.
The data controllers responsible for your personal data are (acting as joint controllers):
- Controllers / Publishers: Gökdeniz Kaymaz and Suat Emir Atabey
- Address: Available on request via the contact email above
- Contact email: support@joinrevly.com
We have not appointed a Data Protection Officer (DPO). For any privacy question, please contact us at support@joinrevly.com.
2. Scope
This Policy applies to personal data we process through the Revly iOS app, its backend services, and our website at joinrevly.com. It does not apply to third-party services that are not operated by us, even where we integrate with them (for example, Apple and Google sign-in). Those services have their own privacy policies, and we encourage you to read them.
3. What Data We Collect, and How
We only collect data that is necessary to provide and improve the App’s features. The table below ties each category of data to the feature that generates it.
3.1 Account and identity data
- Email address — collected when you create an account or sign in with email/password, Sign in with Apple, or Google Sign-In. Used to authenticate you and to operate your account.
- Name / display name — the name you choose to display on your profile, posts, and to other members of your clubs and convoys.
- User ID — a unique identifier we assign to your account to link your data across the App’s features (garage, rides, feed, clubs, convoys).
3.2 Location data (the most sensitive data we process)
- Precise location (GPS) — collected continuously while you are actively recording a drive/ride. This is the core function of the App: we use your GPS position to draw your live route on the map and to calculate ride metrics such as speed and distance. The recorded route is saved to your ride history.
- Motion sensors — lean angle and G-force do not come from GPS; they are measured by your device’s accelerometer and gyroscope, sampled only while a recording is running and stopped when you leave the recording screen. What leaves your device is the derived figures (a smoothness score, peak G, peak lean) and, inside the saved route file, lean readings tagged with the point on the route where they occurred.
- Precise location shared live with convoy members — when you join a convoy and enable live location sharing, your precise GPS position is shared in real time with the other members of that convoy for as long as the convoy session is active and you remain in it. This live-sharing is a deliberate, member-facing feature: other convoy members can see where you are on the map. Live convoy locations are transmitted through Firebase Realtime Database and are removed when the session ends or you leave.
- Coarse location — we may use approximate location to support features such as city exploration and to provide location-relevant context.
- Location outside recording, only if you turn it on — the optional drive reminder watches for significant location changes and reads iOS motion activity to notice when you appear to be driving, so it can remind you to start recording. It is off until you enable it, it never starts a recording by itself, and it is the only feature that uses location while you are not recording.
Location we send to Apple. Two features send ride coordinates to Apple, which processes them under Apple’s own privacy policy rather than ours:
- Weather — one point from the middle of your route is sent to Apple WeatherKit so the ride can be stamped with the weather at the time.
- Place names — several route points, including the start and the end of your ride, are sent to Apple’s geocoding service to turn coordinates into city and country names for the exploration map. Note that your privacy-zone setting trims the start and end of the route you share; it does not currently apply to these geocoding lookups.
- Map display and route previews use Apple Maps, which receives the map region being drawn.
We do not track your location in the background for advertising or profiling purposes. Location is used to deliver the ride-recording, reminder, exploration and convoy features you choose to use.
3.3 Photos, videos, and other media
- Photos or videos — images you add as your profile picture, vehicle photos in your garage, photos you take during a ride, and media you attach to posts or ephemeral stories. Large media files are stored in Cloud Storage rather than in the database.
- Camera — with your permission, the App can take photos during a ride and can scan another rider’s profile QR code. Scanning happens on your device; we do not store camera frames.
- ⚠️ Embedded metadata is not removed. Photos and videos are uploaded as they are, so any metadata your camera embedded travels with them — which for a geotagged photo includes the exact coordinates where it was taken, and the capture time and device. If you attach such a photo to a post, anyone who can see that post can read that metadata. Your privacy-zone setting trims the route line; it does not strip photo metadata. If this matters to you, turn off location for the Camera app in iOS Settings, or avoid attaching geotagged photos.
3.4 User-generated content
- Other user content — posts, comments, likes, ephemeral stories, and your saved ride data (routes, metrics, achievements, levels, streaks). This content is created by you and, depending on the feature, may be visible to other users (for example, posts in the social feed, or your presence in a club or convoy).
- Direct and club messages — the App includes private messaging. The text and any images you send, together with the sender name and timestamp, are stored on our backend so the conversation is available to its participants across devices. Messages are readable by the people in that conversation. They are not end-to-end encrypted, and we can technically access them where required to investigate abuse reports or to comply with a legal obligation.
- Reports you file — when you report a user or a post, the free-text reason you write and the identity of the person reported are stored so we can act on it.
- Your garage records — the vehicles you add and everything you keep about them: make, model, year, nickname and colour, and optionally the registration plate, technical specifications, modifications, and your maintenance and expense log. These are stored against your account and are private to you. When you choose “Show on my profile”, we publish a separate, reduced copy that deliberately leaves out the plate, the log and the expenses — turning the showcase off removes that copy and its photos.
3.5 Diagnostics and product data
- Crash data — collected via Firebase Crashlytics to detect and fix crashes and stability problems.
- Product interaction / usage data — collected via Firebase Analytics to understand how features are used so we can improve the App. These events are tied to your account, and the ride event carries basic ride figures — distance, duration, average speed and vehicle type. They never carry your route, coordinates, photos or messages. You can switch this off at any time in Settings → Privacy → Share usage data; crash reporting is separate and is not affected.
- Crash context — crash reports are sent with your account identifier attached, so we can tell whether a crash hit one person repeatedly or many people once. This is why crash data is declared as linked to you rather than anonymous.
- Device ID — a device-level identifier. Several things produce one: Firebase Analytics assigns an app instance identifier, Firebase Cloud Messaging issues a push token for your device (see 3.6), and App Check attests your app installation to prove requests come from the genuine Revly app rather than a script. The App Check identifier is a security measure and is not affected by the usage-data switch.
3.6 Push notifications
If you allow notifications, Firebase Cloud Messaging issues a push token identifying your device installation, and we store it against your account so we can deliver notifications you have asked for — such as a direct message, a friend request, a club event reminder, or a convoy invitation. We use it only to send you these notifications; we do not use it for advertising or profiling.
Notifications are delivered through Apple’s Push Notification service (APNs), so the content of a notification passes through Apple on its way to your device. Because our notifications are visible alerts, that content can include the sender’s name and a short preview of a message.
You can turn notifications off at any time in iOS Settings. Deleting your account deletes the stored tokens along with the rest of your account data.
3.7 Subscriptions and purchases
Revly offers an optional paid subscription. Purchases are handled entirely by Apple through the App Store: we never see or receive your payment card, billing address or Apple ID. Whether your subscription is currently active is resolved on your device from Apple’s StoreKit records each time the App needs to know. We do not store your subscription status on our servers, and we hold no purchase history.
3.8 Tracking
We do not use your data for cross-app or cross-site tracking, and we do not ask for permission under Apple’s App Tracking Transparency framework, because we do not track you across other companies’ apps and websites.
4. Why We Use Your Data, and Our Legal Bases (GDPR Article 6)
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and operate your account; authenticate you | Email, name, User ID | Contract (Art. 6(1)(b)) — necessary to provide the service you signed up for |
| Record drives and calculate ride metrics (route, speed, distance) | Precise location, ride data | Contract (Art. 6(1)(b)) — the core feature you request |
| Measure lean angle, G-force and smoothness | Accelerometer and gyroscope readings, taken only while recording | Contract (Art. 6(1)(b)) — part of the ride recording you request |
| Share your live location with convoy members | Precise location | Consent (Art. 6(1)(a)) — you choose to join a convoy and enable live sharing; you can stop at any time |
| Social feed, clubs, posts, comments, stories | User content, media, name | Contract (Art. 6(1)(b)) and, where you post optional content, Consent (Art. 6(1)(a)) |
| City exploration and location context | Coarse location | Consent (Art. 6(1)(a)) / Legitimate interest (Art. 6(1)(f)) |
| Keep the App stable, secure, and free of abuse; moderation (report/block) | Usage data, crash data, content reports | Legitimate interest (Art. 6(1)(f)) — operating a safe, working service |
| Diagnostics and analytics | Crash data, usage data, Device ID | Legitimate interest (Art. 6(1)(f)) — you can object at any time by turning off Settings → Privacy → Share usage data, which stops usage-data collection immediately |
| Send push notifications you have asked for (messages, friend requests, club events, convoy invitations) | Push token, Device ID | Consent (Art. 6(1)(a)) — iOS asks you before any notification is sent, and you can withdraw it in Settings |
| Comply with legal obligations | As applicable | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time (for example, by leaving a convoy, turning off live sharing, revoking the App’s location permission in iOS Settings, turning off notifications, or deleting your account). Withdrawing consent does not affect processing carried out before withdrawal.
Where we rely on legitimate interest, you have the right to object (GDPR Art. 21). For analytics you can exercise this directly in the App at Settings → Privacy → Share usage data; collection stops as soon as you switch it off.
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to this processing (see Section 9).
5. Third-Party Processors and Where Data Is Stored
We use the following third parties to process data on our behalf or to provide sign-in. We share with them only the data needed for their function.
- Google Firebase — our backend platform, used for:
- Firebase Authentication (account sign-in)
- Cloud Firestore (account and app data)
- Cloud Storage (photos, videos, ride route files)
- Realtime Database (live convoy location sharing)
- Crashlytics (crash reporting)
- Analytics (usage/product data and Device ID)
- Cloud Messaging (push notifications and the push token that addresses your device)
- Cloud Functions (server-side code that maintains your social graph, delivers notifications, computes your statistics and enforces abuse limits)
- App Check (abuse protection / verifying requests come from our genuine app)
- Apple — Sign in with Apple authentication; WeatherKit and Apple Maps / geocoding (see Section 3.2 for the ride coordinates these receive); and the App Store, which processes subscription purchases.
- GitHub, Inc. — hosts our website joinrevly.com (GitHub Pages). Like any web host it records standard server request data, such as your IP address and browser user-agent, when you visit a page. We do not run analytics, advertising or cookies on the website.
- Google — Google Sign-In authentication.
Where your data is stored. App data is hosted on Google Cloud infrastructure used by Firebase. Apple and Google process sign-in data under their own privacy policies.
We do not sell your personal data, and we do not share it with advertising networks for cross-context behavioral advertising.
6. Data Retention
- Account, profile, garage, and ride data are retained for as long as your account is active.
- Live convoy location is ephemeral: it exists only during an active convoy session and is removed when the session ends or you leave the convoy.
- Ephemeral stories are designed to expire automatically after their display period.
- Crash and analytics data are retained for limited periods in accordance with Firebase’s default and configured retention settings, for diagnostics and product improvement.
- Push tokens are kept while your account is active so notifications can reach your device, and are deleted when you delete your account.
- When you delete your account, we delete your account record and the data filed under it in Cloud Firestore and Cloud Storage — profile, garage, rides and routes, achievements, feed posts and their likes and comments, stories, your social graph, saved places, push tokens and uploaded media — and we clear the app’s data on your device. We also release your username so it returns to the pool.
- What deletion does not remove, and why. Some records involve other people and cannot be erased unilaterally without destroying their copy of a shared history:
- Messages you sent remain in the conversations you were part of, so the other participants keep their own thread. Your profile is gone, so you appear as a removed account.
- Club and convoy records you took part in, and content other members created in response to yours, remain with those groups.
- Aggregated or de-identified records that no longer identify you, and anything we must keep to comply with a legal obligation, resolve a dispute, or enforce our terms.
- If you want any of the above removed, contact support@joinrevly.com and we will handle it as an erasure request under Section 9.
We may retain backups for a limited period and minimal records (such as moderation or abuse logs) where necessary for safety and legal reasons.
7. International Data Transfers
Your data is stored and processed on Google Cloud infrastructure, and our processors (Google/Firebase, Apple) may process data in countries outside your own, including outside the EU/EEA and the UK. Where data is transferred internationally, we and our processors rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where applicable), or other lawful transfer mechanisms. You may contact us at support@joinrevly.com for more information about these safeguards.
8. Security
We take reasonable technical and organizational measures to protect your data, including:
- Encryption in transit — data exchanged between the App and our backend is encrypted using TLS/HTTPS.
- Server-side access rules — Firestore, Cloud Storage, and Realtime Database access is restricted by security rules that enforce per-user ownership, so users can generally only read and write their own data and the data they are explicitly permitted to access (for example, convoy members during an active session).
- Firebase App Check — used to help ensure that requests to our backend come from the genuine, untampered Revly app.
- Authentication — accounts are protected through Firebase Authentication and the sign-in providers you choose (Apple, Google, or email/password).
- On-device storage — app data cached on your device is scoped to the signed-in account and cleared when you sign out or when a different account signs in.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please protect your account credentials and your device.
9. Children’s Privacy
Revly is not directed to children under 16, and we do not knowingly collect personal data from anyone under that age. You must be at least 16 years old (or older where required by your local law) to use the App. If you believe a child under the applicable age has provided us with personal data, please contact us at support@joinrevly.com and we will take steps to delete it.
10. Your Rights
We provide core privacy rights to all users wherever they live, with additional rights for residents of the EU/EEA and the UK (under the GDPR) and California (under the CCPA/CPRA). We honor verifiable requests as required by applicable law and do not discriminate against you for exercising them.
10.1 GDPR (EU/EEA and UK)
If you are in the EU/EEA or the UK, you have the right to:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure (“right to be forgotten”) — have your data deleted, subject to legal exceptions.
- Portability — receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
- Restriction — ask us to limit how we use your data in certain circumstances.
- Objection — object to processing based on our legitimate interests, and object at any time to direct marketing (we do not use your data for direct marketing).
- Withdraw consent — where processing is based on consent (such as live convoy location sharing), withdraw it at any time.
- Lodge a complaint — file a complaint with your local data protection supervisory authority. In the EU, this is your national authority; in the UK, it is the Information Commissioner’s Office (ICO). We would, however, appreciate the chance to address your concerns first.
10.2 CCPA / CPRA (California)
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the CPRA.
Categories of personal information we collect (as defined by the CCPA): identifiers (email, name, User ID, Device ID); precise geolocation data; internet or other electronic network activity (product interaction / usage data); audio/visual information (photos and videos you upload); and other information you provide (posts, comments, ride data). We collect these for the business purposes described in Sections 3 and 4.
Your rights:
- Right to know — request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to delete — request deletion of personal information we have collected from you, subject to legal exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of “sale” or “sharing” — we do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. Because we do not sell or share personal information in this sense, there is nothing to opt out of; we will update this Policy if that ever changes.
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
You may exercise these rights as described in Section 11. We will verify your request using the information associated with your account. You may use an authorized agent to submit a request on your behalf where permitted by law.
10.3 All Users (Wherever You Live)
Regardless of your country of residence, and to the extent the law of your country provides them, you may:
- Access a copy of the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your data — most easily via in-app account deletion (see Section 11);
- Export your data in a portable format;
- Object to or restrict certain processing, and withdraw consent where processing is based on it (such as live convoy location sharing).
If your country has its own data-protection law, you may have additional rights and the right to lodge a complaint with your local data-protection authority. Contact us as described in Section 11 to exercise any right.
11. How to Exercise Your Rights, and In-App Account Deletion
- In-app account deletion — you can delete your account directly in the App. It removes your account and the data filed under it, subject to the limits described in Section 6 (records that involve other people). This is the fastest way to exercise your right to erasure; for anything Section 6 lists as remaining, write to support@joinrevly.com.
- Content controls — the App provides report and block tools so you can moderate user-generated content you encounter.
- Requests by email — for access, correction, portability, objection, restriction, or any other right, contact us at support@joinrevly.com. We may need to verify your identity (typically via the email address on your account) before acting on a request. We aim to respond within the timeframes required by applicable law (for example, generally within one month under the GDPR and 45 days under the CCPA, each extendable where permitted).
12. Cookies and SDKs
Revly is a native mobile app and does not use browser cookies for its core functionality. It does use third-party software development kits (SDKs), principally the Firebase SDKs (Authentication, Firestore, Cloud Storage, Realtime Database, Crashlytics, Analytics, Cloud Messaging, App Check). These SDKs may set local identifiers (such as a Device ID or a push token) and process data as described in this Policy and in Google’s privacy documentation. We do not use these SDKs to track you across other companies’ apps or websites.
13. Changes to This Policy
We may update this Policy from time to time, for example to reflect new features or legal requirements. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide a more prominent notice in the App. Your continued use of the App after an update means you accept the revised Policy.
14. Contact Us
If you have any questions, requests, or complaints about this Policy or your personal data, contact us at:
- Gökdeniz Kaymaz and Suat Emir Atabey
- Email: support@joinrevly.com
- Address: Available on request via the contact email above
Governing law: This Policy is governed by the laws of Poland, without prejudice to any mandatory data-protection rights you have under the laws of your country of residence.