Privacy Policy
OpenTrains stores only what it needs to show you your trains and your trips. In short:
- No ads, no analytics, no tracking, and your data is never sold.
- You sign in with iCloud. We never see a password and never store your Apple identifier in clear.
- You can export or delete everything from the app, at any time.
1.Who is responsible
The data controller is Florian Mari, an individual based in France. For any question about your data, write to support@opentrains.site.
2.What we collect and why
| Data | Why |
|---|---|
| Account identity. A keyed hash of your iCloud user record and a random account ID we generate. | To recognise you when you sign in again. Your iCloud identifier itself is never stored. |
| Profile. Display name and profile photo, if you set them. | To show them in the app. |
| Trips. The train, boarding and alighting stops, and optionally coach, seat, and booking reference you enter. | To track the trip, send alerts, and keep your history. |
| Notifications. Your Apple push token and alert preferences, if you enable alerts. | To deliver delay, platform, and boarding alerts for tracked trips. |
| Device sessions. A random session identifier per device and its sign-in tokens. | To keep you signed in and let you revoke a device. |
| Technical logs. IP address, request path, user agent, and timestamps. | To operate and secure the service. Kept for a short period only. |
The legal basis is the performance of the service you asked for (Art. 6(1)(b) GDPR) and, for security logs, our legitimate interest in running the service safely (Art. 6(1)(f)).
3.What we do not collect
- Your device's location. OpenTrains does not request location permission; train positions come from operator data.
- Contacts, photos other than the one you choose as a profile picture, or calendar data.
- Advertising identifiers, analytics events, or usage profiles.
- Passwords. Sign-in is handled by iCloud on your device.
4.Third parties
We share data only with the providers needed to run the app:
- Apple for iCloud sign-in (CloudKit), push notifications (APNs), and maps (MapKit). Apple's privacy policy applies to these services.
- Cloudflare as DNS and reverse proxy in front of our servers.
- Our hosting providers in the European Union, where the database and servers run.
- SNCF onboard Wi-Fi. When your phone is connected to a train's Wi-Fi, the app may query the onboard portal directly for the train's position. That request goes from your phone to SNCF, not through our servers.
We do not sell personal data and do not share it for advertising.
5.Retention
- Account, profile, trips, and notification settings: until you delete them or delete your account.
- Sign-in tokens: access tokens expire after 72 hours; refresh tokens after 90 days without use.
- Technical logs: a few weeks at most.
6.Your rights
Under the GDPR you can access, correct, export, and erase your data, and object to or restrict its processing. The app gives you the main ones directly:
- Export Profile JSON in Settings › Privacy & Data downloads everything we hold about you.
- Delete Profile Data removes your name, photo, trips, notifications, and history but keeps the account.
- Delete Account removes everything, including the account itself.
For anything else, email support@opentrains.site. You also have the right to lodge a complaint with the French supervisory authority, the CNIL, or with the authority in your country.
7.Security
All traffic between the app and our servers is encrypted with TLS. Identifiers are hashed with a secret key before storage, sign-in tokens are stored only as hashes, and no passwords exist to be leaked.
8.Children
OpenTrains is not directed at children under 15. We do not knowingly collect data from them; if you believe a child has created an account, contact us and we will delete it.
9.This website
This website sets no cookies and loads no scripts, fonts, or other third-party resources. Cloudflare, which serves the site, may keep standard access logs.
10.Changes
We may update this policy as the app evolves. The current version is always published on this page with its "last updated" date.