Privacy Policy
RouteDrop · Last updated: July 22, 2026
RouteDrop plans multi-stop routes and sends them to your Tesla. Most route
data stays on your device. Route data reaches our service only when you choose
an action that needs it: Send to Tesla, Schedule Send, Share Link, or sharing a
route with a Convoy. When the Fast charging map layer is enabled (on by
default), the app sends the four coordinates of the currently visible map
rectangle to RouteDrop so the service can return nearby charging sites from
its local catalog. The request does not require your account, is not retained
as map or location history, and does not contact a charging-network data
provider. Explicitly asking Grok to draft a stop announcement also sends
that stop's place context as described below. Explicitly enabling Pro+ Live
Drive sends a short current-to-lookahead route segment as described below. If commercial terrain lookup
is enabled, choosing Load Elevations sends the missing stops' coordinates once
so the service can return terrain elevations. In a developer build where the
experimental Dynamic Max Speed control and its server lookup are both enabled,
recent precise points are sent transiently to look up the current road's posted
speed limit.
Subscriptions and test access. RouteDrop Plus, Pro, and Pro+
are monthly auto-renewable subscriptions. Apple shows the price, period, and
renewal terms before purchase and processes payment. Plus adds scheduled routes
and higher send allowances; Pro adds Drive Mode, Route Radar, Convoys, and Grok
announcements; Pro+ adds Live Drive with Grok. RouteDrop verifies Apple's signed
transaction and App Account Token before enabling paid service features.
Approved TestFlight/internal QA may exercise those features at no charge after
RouteDrop verifies Apple's signed Sandbox app transaction for the connected
account. Dynamic Max Speed is absent from the current public Release build and
its production lookup stays disabled. Audio already embedded in an imported
route can still play locally.
What stays on your device
- Your route library. Routes, names, stops, notes, icons,
photos, and sound files are stored first on the device and privately synced
through Apple's iCloud Drive when it is available. This private iCloud copy
is handled by Apple and is not uploaded to RouteDrop's service. File and
AirDrop exports go directly
through Apple's share system and are not uploaded to RouteDrop. Curated-route
hero images are downloaded as part of the team-published catalog, cached for
offline viewing, and stored with an installed route. File and AirDrop exports
can embed that image in the route package.
- Your location. For planning, location is used on-device
to center the map and, if you ask, to add your current position as a stop.
With the Fast charging layer enabled, RouteDrop receives the visible map's
minimum and maximum latitude and longitude; a tightly zoomed map may make
that rectangle precise. The service uses it transiently to query its local
charging-site snapshot and does not store the rectangle. Live location
reaches our service only for explicitly enabled features: development-only
Dynamic Max Speed, when both client and server gates are enabled (a short
sequence of precise Drive Mode points sent for one road lookup), Route Radar
(a coarse area plus a direction of travel while
the phone has a valid moving course), and Convoys (precise location shared
with a group you join). Dynamic Max and live locations are processed
transiently and are not written to the database. Pro+ Live Drive is off by
default. After you explicitly enable it in Profile, it runs only during active
Drive Mode. RouteDrop then receives two to eight points
from your current position through a forward route anchor, rounded to four
decimal places. The route segment is processed transiently and is not written
to the database or object cache.
What we store on our servers
- Tesla account tokens. When you sign in, Tesla gives
RouteDrop access tokens. They are stored encrypted (AES-256) on our
servers and used only to list your vehicles, read connectivity and charge
state, wake the vehicle you choose, run the Garage media shortcuts you tap,
and deliver routes you send or schedule.
Your Tesla password never touches RouteDrop — sign-in happens on Tesla's
own page.
- Your RouteDrop account and feature eligibility. We retain Tesla's
stable pseudonymous sign-in identifier, an internal RouteDrop account ID,
account status, and creation and update timestamps so the app can authenticate
requests and restore access. RouteDrop does not request Tesla's profile-data
scope and does not receive or store your actual Tesla account email. Any
email-shaped alias in Tesla's sign-in token is not extracted, displayed, or
used as profile, contact, or identity data. Provider-issued claims may remain
inside the encrypted OAuth credential used for Tesla Fleet API calls. For
app-integrity protection, RouteDrop sends Apple's opaque App Attest
installation-key identity and verified attestation material to its service.
The service links a domain-separated HMAC-SHA256 digest of that key identity,
its verified public key, and a replay counter to your RouteDrop account so it
can bind sessions to this app installation, prevent unsafe account switching,
and reject replayed requests. RouteDrop does not use this device identifier
for tracking or advertising. For
approved TestFlight/internal QA, we may retain an HMAC digest of Apple's App
Transaction ID plus the app version and proof, verification, and expiry
timestamps. We do not retain the raw signed transaction or raw App
Transaction ID. StoreKit's raw device-verification identifier is checked only
in memory while validating that signed proof and is not logged or retained.
For RouteDrop Plus, Pro, or Pro+, RouteDrop creates a random App Account Token
for your authenticated account before purchase and
gives it to StoreKit. Apple signs that token into the purchase and renewal
records. RouteDrop verifies Apple's signed data and retains the token, product
and tier, StoreKit environment, purchase/expiry/grace/revocation state, and
HMAC-SHA256 digests of Apple transaction identifiers. It does not retain the
raw transaction JWS or raw transaction identifiers. Compact notification
receipts contain only an HMAC of Apple's notification UUID, event class,
environment, outcome, and timestamps and are removed after about 400 days.
This purchase history is linked to your RouteDrop account only to provide,
restore, change, expire, or revoke the plan. Apple processes payment; RouteDrop
never receives your payment-card details.
- Elevation lookups. When commercial terrain lookup is
enabled, and only when you choose Load Elevations, the missing stops'
coordinates are sent to our elevation proxy. The returned elevations are
saved in your local route; the coordinates and elevations are not stored by
RouteDrop's service.
- Scheduled sends. A schedule stores its vehicle
identifier, route name, ordered stops, time, recurrence, and result so
our server can wake your vehicle and send the route at the requested time.
You can delete a schedule in the app; completed one-time schedules are
removed automatically after 30 days.
- Routes you share as links. Choosing "Share Link"
uploads that route (stops and drive settings, not your sound files) so
the link works for its recipients. Anyone with the unlisted link can open
it. Shared links expire after 90 days and are deleted immediately when you
delete your RouteDrop account.
- Spoken with Grok announcements. When a Pro or Pro+ member,
or an approved TestFlight/internal QA tester, explicitly chooses this option,
the normalized announcement text is sent
through RouteDrop to xAI's Text to Speech API. RouteDrop does not write the
text to its database or logs. It stores the resulting MP3 for up to 30 days
in a private Cloudflare object cache, keyed by a one-way HMAC of the text and
fixed voice settings, so another request for the same announcement can reuse
audio without another xAI call. The MP3 is downloaded into your local route
package; anyone to whom you export that package can receive and play it. xAI
states that ordinary API requests and responses may be retained for 30 days for
abuse and misuse auditing unless a separately contracted zero-data-retention
arrangement applies.
- Grok-generated stop announcement text. When a Pro or
Pro+ member, or an approved TestFlight/internal QA tester, explicitly asks
RouteDrop to draft historical or relevant context for a stop, RouteDrop
sends xAI the stop name and the place context you
supplied, which may include its coordinates, address, or locality. xAI may
use web search to research the place and returns generated announcement text
and supporting source links. RouteDrop does not send your RouteDrop or Tesla
account identifier. To avoid repeating the same paid generation, RouteDrop
may keep the generated response for up to 30 days in a private Cloudflare
object cache keyed by a one-way HMAC of normalized place context and fixed
generation settings. The generated text is saved in your local route package,
where you can review or edit it; anyone to whom you export that package can
receive it. xAI's ordinary API retention described above also applies to this request.
- Live Drive with Grok. This optional Pro+ feature is off
by default. A Pro+ member or approved TestFlight/internal QA tester explicitly
enables it in Profile, and it runs only during active Drive Mode. RouteDrop
receives a bounded two-to-eight-point current-to-lookahead route segment,
rounded to four decimal places. It derives a single forward anchor rounded to
three decimal places (roughly 110 meters), an eight-way travel direction, and
the fixed
en-US locale. Only that reduced context is sent to xAI;
RouteDrop does not send xAI your current point, full route segment, destination,
recent-topic list, vehicle, or RouteDrop/Tesla account identifier. xAI may use
one web search and returns a short factual narration, or a quiet result when
it cannot establish a worthwhile fact. RouteDrop neither requests nor returns
URL/title citation metadata for Live Drive because provider URL lists identify
encountered search results, not verified support for a narration. RouteDrop may keep
that derived response for up to 30 days in its private Cloudflare object cache,
under a one-way HMAC key derived from the reduced anchor context and fixed
generation settings. Quiet results may be cached for a shorter period to
prevent repeated paid searches. RouteDrop stores only account-level and
anonymous aggregate research request, generation, cache-hit, token, web-search, narration, and
provider-cost counters; it does not store the submitted points, reduced
anchor, direction, narration topic, or cache key in D1. When RouteDrop has
accepted a narration, the app may request that exact topic in the Grok voice
you selected. RouteDrop revalidates the cached topic server-side and sends
only the accepted narration text, selected voice, and fixed language setting
to xAI's Text to Speech API — not your route segment, location, vehicle,
account identifier, or topic identifier. The resulting MP3 may be kept for up
to 30 days in RouteDrop's private Cloudflare object cache under a one-way HMAC
key. The app
holds the returned clip only in memory for the active Drive Mode session; it
is not saved to a route package. If voice generation is unavailable or too
slow, RouteDrop speaks the accepted text with Apple's system text-to-speech.
xAI states that ordinary API requests and responses may be retained for 30
days unless a separately contracted zero-data-retention arrangement applies.
RouteDrop can disable Live Drive independently with a server-side kill switch.
- Private Grok caches. Every generated-content object cache
described above has no public address and is not linked to an account.
- Service and diagnostics records. We count sends,
commands, wakes, reads, Google Geocoding, Find Place, and experimental Roads
Speed Limits requests, cached Place-ID reuse, and Grok speech generations,
input characters, and cache hits. For Grok-generated stop text, we count
generations, input and output tokens, web searches, recorded provider cost,
and cache hits. For Live Drive, we count requests, generations, input and
output tokens, web searches, returned narrations or quiet results, provider
cost, and cache hits. For Live Drive voice rendering, we separately count
audio requests, generations, input characters, and cache hits
to operate limits, show estimated service costs, and prevent abuse. Send-attempt
records contain vehicle identifiers, stop counts, a one-way route
fingerprint, status, and error text — not stop coordinates —
and expire after 90 days. Exact daily abuse-prevention totals contain only
your RouteDrop account identifier, date, and action counts and are retained
for up to 90 days. MetricKit sharing is off by default. If you opt in from
Profile while signed in, the app sends Apple MetricKit performance and crash
payloads, which are retained for up to 30 days. Turning the setting off stops
future uploads. Separately, RouteDrop keeps anonymous hourly provider-cost,
send-outcome, diagnostic-category, and feedback-category totals for up to 24
months. Those totals contain no account, vehicle, route, location, feedback
note, or diagnostic payload and cannot be linked back to your account.
- Feedback you submit. The in-app feedback form stores the
category, 1–5 rating, optional note, app version, and your RouteDrop
account identifier so we can prevent abuse and honor account deletion. It is
retained for up to 180 days. The internal operations dashboard exposes only
anonymous category/rating totals, never your account, app version, or note.
- Multi-stop navigation Place-ID cache. Tesla's ordered
multi-stop command requires a Google Place ID for each stop. RouteDrop first
reuses the ID saved in your route package. If one is missing, the service may
retain the resolved Place ID for your account so another device or retry does
not repeat a provider lookup. The Place ID is AES-256-GCM encrypted; its lookup
key is a one-way, account-scoped HMAC of resolver provenance and a rounded
coordinate, plus the normalized place query for name-based results. The
service does not retain the coordinate, query, or Plus Code in this cache. Entries expire
within 12 months and are deleted with your account.
Dynamic Max Speed
Dynamic Max Speed is retired in every current build because Tesla maximum
writes require the vehicle to be parked. RouteDrop does not send recent driving
points to Google Roads or attempt to rewrite that maximum while you drive.
Route Radar (optional)
- Off by default; opt-in. Route Radar only runs when
you turn it on. While Radar remains selected, including when your phone is
locked or another app is open, your device sends a
coarse area (a ~2-mile / 3-km grid cell), never your precise
location, plus a normalized direction of travel while iOS provides a valid
moving course. The direction is cleared when that course is unavailable.
Switching away from Radar or turning it off stops sharing. You see
a cell only when it contains at least two other opted-in drivers; your own
presence never helps reveal it.
- Live server presence is not stored. Server presence lives
in memory only while you're connected and is discarded moments after, so
RouteDrop keeps no live-location history. If you submit a safety report, one coarse
Radar cell may be retained with that report as context for manual review.
Safety reports are retained for up to 180 days.
- On-device driver log. Your phone keeps an account-separated,
bounded list of up to 100 pseudonymous handles and car avatars it displayed,
first/latest-seen times, and up to 50 received emoji-wave times per driver.
The protected file contains no cell, coordinate, route, Tesla-account
identity, server public ID, or moderation credential; it is excluded from
backups and never sent to RouteDrop. Leaving Radar or signing out hides but
does not delete it. Use Clear Log to erase it; uninstalling also removes it.
- Pseudonymous by design. Others see qualifying nearby
coarse cells, not your Tesla-account identity or a track. In a
qualifying cell, your chosen handle, car avatar, and current direction of
travel (when available) are visible to nearby drivers. Your handle and avatar
are also attached to any emoji you send. Your profile, mute/block choices,
and safety reports are stored so those controls persist. Display handles
are filtered server-side. Turn Route Radar off to stop presence sharing.
Convoys (optional)
- Off by default; opt-in per convoy. A convoy is a group
you explicitly create or join with a code. Only then, and only while the
convoy screen is open, does your device share its precise live
position — with the members of that convoy, so you can see each other
on the map.
- Relayed, never stored. Positions pass through our
server only to relay them to your convoy in real time; they live in memory
for that instant and are not written to the database. Bounded Convoy text
messages are normalized, filtered, rate-limited, relayed only to current
authenticated non-blocked members, and likewise never stored as message
history. Your device keeps only a small in-memory tail while that room is
open. Your convoy name, membership, roles, and optional shared route are
stored for the life of the convoy.
- No voice in this release. The current Convoy feature set
includes the shared map, structured pings, and bounded live text chat. It
does not include Convoy voice and does not transmit Convoy microphone audio.
- You control it. Close the convoy screen or leave the
convoy to stop sharing immediately; the leader can remove anyone; and every
convoy expires within 24 hours. Expired convoy membership and route data are
deleted.
Service providers and recipients
- Tesla. Route stops and vehicle commands are sent to
Tesla when you request a send or when a schedule fires.
- Cloudflare. Cloudflare hosts the RouteDrop API,
database, local charging-site catalog, private generated-audio and
generated-text caches, and real-time relays. Visible map rectangles used for
charging-site lookups are processed there transiently and are not retained
by RouteDrop as map or location history.
- Apple. Apple supplies mapping, operating-system sharing,
app distribution, and (only after your opt-in) MetricKit diagnostics used by the app.
- Google Maps and Open-Meteo. Coordinates may be sent to
Google to resolve place identifiers for multi-stop Tesla navigation or,
only while experimental Dynamic Max Speed is explicitly enabled in Drive
Mode, to obtain a transient current-road speed-limit match; and to
Open-Meteo if commercial terrain lookup is enabled and you request route
elevation data. RouteDrop does not send
your Tesla-account identifier to either service. Open-Meteo elevation data is
licensed under CC BY 4.0;
RouteDrop displays the returned point elevations and derives grade hints.
- xAI. Only when you choose a Grok feature does xAI receive
data: Spoken with Grok sends the announcement text and returns synthetic
speech; Generate with Grok sends the selected stop's name and available
place context, which may include coordinates, address, or locality, and may
use web search to return draft announcement text and source links; optional
Pro+ Live Drive sends only a three-decimal forward anchor, eight-way direction,
and fixed locale and may use one web search to return narration text. After
RouteDrop accepts a topic, it may separately send that narration text, your
selected Grok voice, and the fixed language setting to create synthetic
speech. The voice request does not contain route or location context.
RouteDrop
does not send your RouteDrop or Tesla account identifier. xAI's handling is
described in its
API security FAQ
and Privacy Policy.
- YouTube and Spotify. When you configure one of these
stop actions, RouteDrop queues it at arrival. The selected link opens in
its associated app or the system browser only after you tap the pending
action control in RouteDrop. RouteDrop has no embedded web browser and does
not receive your YouTube or Spotify credentials.
- People you choose. Link recipients receive the route
package you shared. Convoy members receive the convoy route, your selected
handle/avatar, structured pings, live text messages, and your live position
while sharing is on.
RouteDrop shares user data with service providers only when their applicable
contracts or platform terms require the same or equivalent protection described
in this policy and required by Apple's App Review Guidelines. RouteDrop does
not authorize those providers to use the data for advertising, cross-app
tracking, or their own unrelated purposes.
What we don't do
- No advertising tracking. RouteDrop has no advertising
SDK and does not use data for cross-app tracking. Charging-site lookups do
not create map or location history. Dynamic
Max Speed sends recent points only during the explicitly enabled Drive Mode
feature and does not store them. Live Drive is off by default, processes its
bounded route-ahead segment transiently, and does not retain it as location
history. Live Route Radar server presence is a coarse cell plus an optional
moving direction and is not stored (except that a user-submitted safety
report may retain one coarse cell); convoy positions
are relayed to your group only and never stored.
- No ads. We do not show advertising.
- No data sales. We do not sell personal data or share it
for cross-app advertising.
Removing your data
Use Delete Account in RouteDrop's Profile screen to delete
your account, encrypted Tesla tokens, schedules, owned share links, Radar
profile and relationships, associated safety reports, diagnostics, usage
records, feedback submissions, encrypted cached Place IDs, and convoy data tied
to you. Anonymous system-level totals, generated speech cache objects, and
generated stop-text cache objects cannot be tied back to an account; cached
announcement and Live Drive voice MP3s expire within 30 days, and stop-text
and Live Drive narration responses expire within 30 days.
This is irreversible. Logging out only
ends the app session and does not delete server data. To revoke RouteDrop's
access at Tesla as well, remove it at
accounts.tesla.com under third-party
apps. Deleting RouteDrop's account-linked purchase mapping does not cancel an
Apple subscription. Manage or cancel the subscription with Apple before
deleting the RouteDrop account if you no longer want it; it cannot be
automatically reassociated with a newly created RouteDrop account. You may
also contact us for privacy help.
Contact
Questions about this policy or your data? Email
routedrop@baristalabs.io.