Security & Privacy

Your data belongs to you

DayRoute is built with privacy at its core. We collect minimal data, store receipts on your device, and give you full control over your information.

How we protect your data

Passwordless Authentication

Login with a magic link sent to your email. No passwords to remember or leak. Powered by Supabase Auth.

  • Magic link + OTP verification
  • No password storage
  • Secure email verification
  • Session management

On-Device Data Storage

Your receipts, expenses, and business data are stored locally on your device — not on our servers.

  • Receipts stored on-device only
  • Local filesystem for images
  • AsyncStorage for app data
  • Your data stays on your phone

Location Privacy

GPS tracking only runs when you explicitly start a trip. We never track your location in the background without your action.

  • No background location by default
  • Trip tracking is opt-in
  • Location data stays on device
  • Clear permission requests

Minimal Data Collection

We collect only what's needed for the app to work. Your email for login. That's the only personal data stored on our servers.

  • Email for authentication only
  • No analytics tracking
  • No selling of data
  • GDPR-compliant practices

Where is my data stored?

On your device (local storage)

  • • Receipt images
  • • Expense records
  • • Client information
  • • Job details
  • • Vehicle logbook entries
  • • Invoices
  • • App settings and preferences

On our servers (Supabase)

  • • Your email address (for login only)
  • • Authentication tokens

That's it. We don't store your receipts, clients, jobs, or business data on our servers.

Important: Backup your data

Since data is stored locally, it's important to back up your device regularly. If you delete the app or lose your phone, local data may be lost. We recommend using iCloud backup for iOS devices.

Third-party services

DayRoute uses a small number of trusted third-party services to provide core functionality:

Supabase Auth

User authentication (magic link login)

Data shared: Email address

Google Maps

Route planning and optimisation

Data shared: Job addresses (for routing only, not stored)

RevenueCat

Subscription management

Data shared: Anonymous user ID, subscription status

Google Gemini AI

Receipt text extraction

Data shared: Receipt images (processed, not stored)

Your controls

Manage permissions

You can grant or revoke app permissions (location, camera, calendar, contacts) at any time in your device's Settings app.

Delete local data

Delete all local data by uninstalling the app, or use the in-app settings to clear specific data types.

Manage subscription

Subscriptions are managed through your Apple ID settings. Cancel anytime, no questions asked.

Request account deletion

Contact us at yourhelp@dayroute.com.au to request deletion of your account and any data we hold.

Questions about security?

Read our full privacy policy or contact us with any questions.