Coast

Privacy Policy

Last updated: 14 September 2026

The short version

Coast records your rides on your phone. There is no Coast account and no server of ours — your rides are never sent to us.

Your GPS track and motion sensor readings are written to a database and to files in the app's own private storage on your device. The app never uploads them. There is no login, and nothing of ours holds a copy. If you want a ride somewhere else, you export or share it yourself.

Coast records only a ride you start, from the moment you tap Start until you tap Stop. That ride keeps recording with your phone locked or another app in front: on Android with an ongoing notification, and on iPhone with the system's location indicator. Coast never asks for “Always” location access. This describes Coast 1.1: Coast 1.0 records a ride only while Coast is open and in front.

One caveat we would rather state plainly than bury: on iPhone, Apple includes Coast's files in your device backup, so with iCloud Backup switched on a copy of your rides is in that backup. It is your backup, it goes to your Apple account, and we never receive it and cannot read it. On Android, Coast switches Android backup off, so your rides and settings are not copied off the phone. Both cases are explained below.

The rest of this page explains all of that in detail, and is honest about the things that do leave your phone: requests for map data, purchase checks, a push registration with Google on Android, notifications if you turn them on, and diagnostic logs from Google's billing software on Android.


Who we are

Coast is published by Vibe6 Digital LLP (“we”, “us”). This policy covers the Coast app on Android and on iPhone. You can reach us at the email address at the bottom of this page.


What Coast collects, and when

Location

While a ride is recording, Coast records your GPS location to draw your route and calculate distance, speed, and other ride statistics.

Motion sensors

During a ride, Coast reads your phone's accelerometer and gyroscope about fifty times a second, including with the phone locked. It uses them to work out how you braked and pulled away: the hard moments, and how firmly you used the brakes and the throttle the rest of the time. That is what it scores. It recognises cornering in order to throw it out — a hard corner shakes the phone much the way a hard brake does, and Coast has to tell them apart so a corner is not counted as a brake. There is no cornering score. Same rules as location: recorded only during a ride, stored on the device, and never sent to us.

One reading happens outside a ride, so we would rather name it than let “only during a ride” cover it. Coast reads the accelerometer and the magnetometer — the compass sensor — to turn the compass arrow on the map. It does this from the moment the Ride screen is built, ride or no ride, and pauses it while a ride's GPS supplies a heading instead. Those readings are used for the arrow as they arrive and are never written down and never sent anywhere.

What Coast does not collect


Where your ride data lives

All ride data is stored on your device and never sent to us, in two places inside the app's own private storage (on iPhone, a device backup can include a copy; see “Backups” below):

That storage is sandboxed — other apps on your phone cannot read it — and Coast never uploads it. There is no server of ours holding a copy. Coast does not delete rides on a schedule; see “Data retention”.

Your settings

Coast keeps a handful of preferences in the app's private settings store: your unit choice, the vehicle you last rode, the map style (light or dark), the display theme, whether you have finished the first-run setup, whether the notification opt-in has been offered and whether you accepted or declined it, and, on Android, whether a code has unlocked Coast Pro. Each is a single word or a yes/no. They are never sent to us. If you turn notifications on, the vehicle you ride is one of the labels sent to OneSignal, as described below, and on iPhone these settings are part of your device backup. The RevenueCat and OneSignal kits described below also keep their own identifiers and status in the app's storage on the phone, and on Android, once you have bought Coast Pro, RevenueCat's kit also saves its ID with Google, as its section explains.

The map stores, which are a third thing on your phone

Coast keeps map data it has already downloaded, so that an area you have seen before draws quickly and is not fetched again every time. There are two stores:

Neither store downloads areas in advance. Each holds only map data Coast has already fetched to draw a map. Map cache in Settings shows how much the two hold together.

This is map data, not your ride data — no route, no speed, no sensor readings. But it does imply which areas you have looked at, so we would rather list it here than leave it out. Both stores sit in the app's own private storage, separate from your rides, and the phone does not empty them by itself.

Deleting a ride does not clear them, and neither does Delete All Rides. Clear map cache in Settings clears both, and so does deleting Coast. On Android, Clear cache under Settings → Apps → Coast → Storage does not reach them; Clear storage does, and takes your rides and settings with it. On iPhone they are part of your device backup in the same way your rides are, which the next section explains.

Backups: this part genuinely differs by phone

On Android, Coast switches automatic backup off. Many apps let Android copy their data to your Google Drive in the background; Coast opts out of both cloud backup and device-to-device transfer, so your rides are not silently duplicated off the phone. The trade-off is deliberate: if you move to a new phone or reinstall the app, your ride history does not come with you. Export anything you want to keep first. One small exception, and it is not ride data: once you have bought Coast Pro, RevenueCat's kit saves its anonymous ID in Google's Block Store, which Google can include in your Google account backup. The RevenueCat section explains why.

On iPhone, we cannot honestly make that claim, so we will not. Coast's ride database and raw ride files live in the app's Documents folder, and its map stores and settings live in other parts of the app's storage that Apple also backs up by default. Coast does not mark any of them as excluded. With iCloud Backup switched on, a copy of your rides forms part of that backup, the same as most apps' data. The same applies to a backup you make to your own computer.

That backup is yours, not ours. It goes to your Apple account under Apple's privacy policy rather than this one; we never receive it, and we could not read it if we wanted to. If you would rather your rides were not included in your iCloud backup, switch Coast off under Settings → [your name] → iCloud → Manage Account Storage → Backups, or turn iCloud Backup off.

Exporting and sharing your rides

Settings → Your data → Export My Ride Data hands your raw ride files to your phone's system share sheet, so you can send them to yourself or to another app. It is available on every tier. The files contain the full GPS track of each ride as well as its sensor readings.

This is entirely user-initiated. Nothing is shared unless you tap export and then choose a destination. Once you share a file with another app or service, that data is in their hands and this policy no longer covers it — their privacy policy does.

The export hands over every raw log still on the phone. That can include a log with no matching ride in History: the partial log of a ride that was never ended with Stop, or one an older version of Coast left behind. Coast counts those and tells you how many there were when it shares. If you want them gone rather than exported, Settings → Delete All Rides sweeps the whole folder.


Services Coast connects to

Coast is not fully offline. Here is every outside service the app talks to and what it gets.

The sections below name everything Coast itself chooses to send. Several of these services are software kits that run inside the app — RevenueCat, OneSignal, and on Android Google's Play Billing Library and Firebase Cloud Messaging — and like almost every such kit they attach ordinary technical metadata of their own to the requests they make: typically your device model, its operating system version, the app and kit version, your language and your time zone. Every internet request also carries your device's IP address, from which a service can work out roughly where you are, usually to the level of a country or a city. We do not choose to send any of that, and we cannot switch it off; it comes with using their service at all. Each of these services receives data from Coast only to provide its service, and we use them on terms under which they must protect that data at least as well as this policy describes. How each company handles what it receives is set out in its own privacy policy, linked in its section. What we can be exact about is what leaves Coast, and that is what these sections set out. None of them receives your routes, your ride history, or your raw sensor data from Coast.

RevenueCat — purchases and subscriptions

receives: anonymous app user ID + purchase data + device metadata

Coast uses RevenueCat to manage in-app purchases and subscription status, on both stores. RevenueCat receives an anonymous app user ID generated for your install, along with purchase and transaction data (what was bought, when, and whether it is still active), plus the device and app metadata described above. It does not receive your rides, your location, or your name, and it never sees your card details.

Where purchasing is switched on in the copy of Coast you have installed, RevenueCat is contacted when the app starts and each time you come back to it, to check your Coast Pro status, whether or not you have ever bought anything. This does not depend on the notification opt-in. Where purchasing is not switched on, the kit stays dormant and RevenueCat is not contacted at all.

On Android, once you have bought Coast Pro, RevenueCat's kit also saves that anonymous ID in Google's Block Store, which Google can include in your Google account backup, so that reinstalling Coast on the same Google account can find your purchase again. It holds only that ID and no ride data.

Privacy policy: revenuecat.com/privacy

Payments — Google Play and the App Store

receives: your payment details, never shared with us

Coast never sees or handles your payment details. When you buy Coast Pro, the purchase is processed by the store you installed Coast from: Google Play Billing on Android, or Apple's App Store payment processing on iPhone. Your card and billing details go to Google or to Apple, under their own privacy policies. They are never sent to Coast, and never to RevenueCat. On iPhone, Redeem a code on the purchase screen opens Apple's own code sheet, and Apple processes the code.

Google Play Billing Library — diagnostic logs (Android)

receives: the billing library's diagnostic logs + device metadata

On Android, purchases go through Google's Play Billing Library, which Coast includes as part of RevenueCat's kit. That library includes a Google component called Data Transport, which can send Google logs about the library's own operation to firebaselogging.googleapis.com, together with figures about its own deliveries. We believe this is the source of the requests to that address we have seen from Coast on Android. We do not choose what those logs contain and cannot switch them off; Google handles them under its own privacy policy. Coast gives the billing library nothing about your rides or your location. Coast does not include Firebase Analytics or Firebase Crashlytics.

Privacy policy: policies.google.com/privacy

OneSignal — push notifications and in-app messages

receives: push token + install and subscription IDs + five ride labels + four events + session and message reports + device metadata

If — and only if — you accept the notification opt-in, on Coast's first-run setup or later with Turn On Notifications in Settings, Coast uses OneSignal to deliver push notifications and the occasional in-app message — a message shown inside Coast rather than in your notification tray, sometimes with a button that takes you to Trends or History. Until you accept, OneSignal is held behind a consent gate: Coast sets the kit's “no consent yet” switch before it starts the kit at all, and every label, event and report listed below is sent only once you have agreed. Nothing Coast chooses to send goes before that point. The one thing we cannot vouch for is the kit's own crash reporter, described further down.

Two prompts can look alike here, so: your phone's own notification permission is not that consent. Coast asks the phone for that permission the moment you accept the opt-in. It also asks when you start a ride, if the permission has not been granted, unless you have said no to the opt-in: Not now on the first-run setup, or refusing the phone's prompt that accepting it raises, is remembered, and after that Coast does not ask at the start of a ride. One exception: if Coast's notification service was not ready or did not answer when you accepted, a refusal of that prompt is not remembered, and Coast asks again when you next start a ride. Granting the permission lets Coast post its own on-device notices, described further down; it does not switch OneSignal on. OneSignal is switched on only by the opt-in itself, and on later launches only if you had accepted it before and the permission is still on.

Once you accept, OneSignal receives a device push token, an anonymous subscription ID, and five labels describing how your riding is going. We use those labels to decide which messages you are sent and what they say — including messages encouraging you to go for another ride, and messages about Coast Pro. That is marketing, and we would rather call it that: it is our own messaging about our own app, sent to people already using Coast. Nothing here is shared with another company, and nothing about you is used to advertise anything other than Coast.

The five labels are:

  • your most recent ride score, when that ride could be scored
  • your total number of rides
  • how many of those rides could be scored — a very short or poorly tracked ride cannot be
  • which direction your scores are moving, or that it is not yet known, which is what it says until you have five scored rides behind you
  • which vehicle type you selected

Which in-app message you are eligible to see is worked out on the phone itself, from the same ride figures as the labels above. Coast sets those values locally and sends nothing extra to do it.

Coast also reports four events to OneSignal, so we can measure whether a message actually led to anything rather than only that it was delivered. This is analytics on our own messaging:

  • that you recorded a ride
  • the score of that ride — but only when the ride was long enough and well enough tracked to be scored at all
  • that you opened the Trends screen — counted once per message rather than once per open, so checking Trends every day does not keep re-crediting the same notification
  • that you bought Coast Pro, with the plan's listed price

Each label is a single number or word, and each event is a name plus at most one number. None of them contains a location. Alongside them the kit sends the device and app metadata described at the start of “Services Coast connects to” — device model, operating system version, app and kit version, language, time zone — and, as with any internet request, your IP address. OneSignal never receives your routes, your location, your ride history, or your raw sensor data from Coast.

The kit also tells OneSignal when you open Coast and how long you keep it open, as a session count and duration, sends an identifier for this install with its requests, reports when a notification from Coast is opened and can report when one arrives, and reports when an in-app message is shown or tapped.

The OneSignal kit also contains a reporter for crashes and freezes involving the kit, which OneSignal switches on or off from its side. It is part of the kit from the moment Coast starts, and we have not been able to confirm that it waits for your consent, or that it stops when you withdraw it. When it is on, those reports go to OneSignal with the device metadata described above.

In the other direction, a push notification or in-app message can carry a one-word hint telling Coast which screen to open when you tap it — Trends or History — and nothing else is read from it. While a ride is recording, in-app messages are paused, so none appears over the ride screen. A push that arrives mid-ride while Coast is on screen is dropped rather than shown. Coast does not hold back a push that arrives while the phone is locked or Coast is in the background, so one can appear during a ride. A message you tap mid-ride is remembered, and the screen it points to opens once the ride ends.

If you decline, or turn Coast's notifications off later in your system settings, none of this applies to you and nothing is sent — Coast checks that permission and withdraws consent when it sees you have turned it off. Withdrawing consent stops both halves: the push notifications and the in-app messages. Coast deliberately has no in-app switch to turn notifications off: your phone's own notification settings are the place that controls all of it. While notifications are off, or you have not accepted the opt-in, Settings in Coast shows a Turn On Notifications button, which asks the same way the first-run setup does. On Android that is Settings → Apps → Coast → Notifications; on iPhone, Settings → Notifications → Coast.

On iPhone, accepting notifications also lets the system briefly wake Coast in the background so a delivered message can be processed, and no location or ride data travels with it. Coast's only other background mode on iPhone is location, used for nothing but keeping a ride you started recording.

One detail worth being precise about, because it is easy to assume otherwise. On Android, Coast's notifications are sorted into channels, and you can silence each one separately: Ride feedback (your score after a ride), Reminders (where Coast's OneSignal messages are meant to land; one sent without that setting appears under a channel Android lists as Miscellaneous), and Ride recording (the ongoing notice while a ride records, described under Location). The score note and the recording notice are raised on the phone itself, with no server involved. The score note is posted only if you accepted the opt-in, and only after a ride good enough or rough enough to be worth a word. Muting a channel changes what Coast shows you; it does not withdraw consent, because the consent gate follows Coast's overall notification permission. If your intent is that nothing is sent, turn Coast's notifications off as a whole rather than muting a single channel.

Privacy policy: onesignal.com/privacy_policy

Push delivery — Firebase Cloud Messaging and Apple Push Notification service

receives: push token + installation ID + the notification, in transit

Delivering a notification to your phone needs the platform's own transport: Firebase Cloud Messaging on Android, and Apple Push Notification service (APNs) on iPhone. To be reachable, the app is registered with that service and given a push token. On Android, Firebase does this when Coast first starts, and refreshes the registration from time to time, whether or not you have turned notifications on, and it gives the installation an identifier of its own. Both services carry the notification; neither receives your ride data.

Privacy policies: Google policies.google.com/privacy, Apple apple.com/legal/privacy

OpenFreeMap, CARTO and Esri — map data

receives: approximate map area + IP address

The map you see is built from OpenStreetMap data. The standard map requests its map data from OpenFreeMap's servers. Its look is Coast's own, adapted from CARTO's map styles and built into the app, so drawing it sends nothing to CARTO. The fallback map requests image tiles from CARTO, and those requests also carry Coast's own CARTO access key, which identifies our account with CARTO rather than you, and name the app as the requester. If a build of Coast has no CARTO access key, the fallback map comes from Esri's World Gray Canvas service instead, with the same kind of request. Like any app that shows a map, all of these requests necessarily reveal the approximate area being shown and your IP address to the map server.

This is a normal consequence of loading a map from the internet, and it is the one place where something location-related leaves your phone.

One of those requests happens before you have looked at anything. If you have granted location permission, then while the opening screen is still up Coast takes your phone's last known position and draws a map at it off-screen, purely so the map data is already on the phone and the Ride tab opens on a drawn map instead of a grey one. That happens on every launch, so the map server is asked for the area around you each time you open Coast, unless that area is already stored and recent enough not to need refreshing. It is the same kind of request as any other, for map data, and nothing about your ride goes with it.

It is worth being blunt about what that means during a ride, because “the map view, not your ride track” is true but easy to read as more comforting than it is. While Coast is on screen during a ride, the map moves with you. So the areas requested over the course of a ride do broadly follow where you went, at the coarse resolution of a map tile. What is never sent is the ride itself — the precise GPS track and the raw sensor file stay on your phone. Opening a saved ride draws its route on a map as well, so data for that area is requested if it is not already stored. Once an area has been loaded, Coast draws it from the map stores described above, and asks the map server again only once the stored copy has passed the age set out there.

Map data is © OpenStreetMap contributors. The standard map's tiles come from OpenFreeMap, in the OpenMapTiles schema, and its style is adapted from CARTO's; the fallback map's tiles are © CARTO, or © Esri.

Privacy policies: OpenFreeMap openfreemap.org/privacy, CARTO carto.com/privacy, Esri esri.com/en-us/privacy/privacy-statements/privacy-statement


Data retention

Deleting Coast removes the app's storage and everything in it: the ride database, every raw log, the map stores, and your settings. Two things are worth knowing on iPhone: Offload App deliberately keeps an app's data, so it does not delete your rides; and if your rides were part of an iCloud or computer backup, restoring that backup can bring them back. Deleting rides inside the app removes them from the phone, but it cannot reach into a backup that has already been made — that is managed in your Apple account's backup settings.

Deleting rides does not reach anything already held by the services above: RevenueCat's purchase records, OneSignal's push subscription and the labels, events and reports already sent to it, the ID RevenueCat saves in Google's Block Store on Android, and Google's and Apple's own records. Those are kept according to each company's own policy, linked in its section. If you want us to ask for records about your install to be removed, write to us at the address below. Because Coast has no account, we may not be able to tell which records are yours, and if so we will tell you.


Security


Your rights and how to exercise them

Because your rides are on your device and not on a server, you do not need to ask anyone's permission to control them:

Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA — for example the right to access, correct, or delete personal data held about you. We hold no copy of your rides, so for rides those requests are answered by your own device. For the records held by the services above, contact us at the address below and we will help you reach the relevant company.


Children's privacy

Coast is not directed at children under 13, and we do not knowingly collect personal information from children under 13. Coast has no age check. If you believe a child has used the app in a way that concerns you, note that any rides recorded are on that child's device and can be removed by deleting the rides or uninstalling the app. You are welcome to contact us with questions.


Changes to this policy

If Coast changes what it collects or which services it uses, this policy will be updated and the “Last updated” date at the top will change. Material changes will be noted in the app release notes. Continuing to use Coast after an update means you accept the revised policy.

The update of 14 September 2026 describes Coast 1.1. A ride you start now keeps recording with the phone locked or another app in front, until you end it; Coast 1.0 records a ride only while Coast is open and in front. The policy also now covers the standard map and OpenFreeMap, which serves its data, the limits on both map stores, the diagnostic logs sent by Google's billing library on Android, push registration with Firebase on Android, OneSignal's session and message reports, RevenueCat's use of Google's Block Store, security, and who publishes Coast.


Contact

Questions about this policy or about privacy in Coast: