Конфиденциальность

CosmicNav · обновлено 26 сентября 2026

Коротко

У приложения нет учётных записей, аналитики и рекламы. Мы не собираем и не храним ваши персональные данные и не передаём их третьим лицам. На наш сервер уходит только то, что нужно для трёх функций по вашему нажатию: позиция участников групповой поездки, пока она идёт; область и параметры поездки, когда вы просите план у ИИ; и один раз — код входа в SoundCloud, если вы подключили музыку. Ничего из этого сервер не хранит; ниже об этом подробно.

Геопозиция

Приложение запрашивает доступ к геопозиции, чтобы вести вас по маршруту: показывать вашу точку на карте часов, считать оставшееся расстояние и вовремя подсказывать повороты голосом. Разрешение на работу в фоне нужно, чтобы подсказки не прекращались, когда телефон лежит в кармане с погашенным экраном.

Координаты обрабатываются на устройстве и передаются на ваши часы по защищённому каналу Apple. Мы их не храним и никуда не выгружаем.

Карты, поиск и маршруты

Карта, поиск мест и построение маршрутов работают через Google Maps Platform. Чтобы показать карту вокруг вас и найти место, приложение отправляет в Google координаты и поисковый запрос. Карту на экране телефона рисует Google Maps SDK, который передаёт Google технические данные об устройстве, отчёты о сбоях и псевдонимный идентификатор SDK. Эти обращения регулируются политикой конфиденциальности Google.

Карту на часах рисует само приложение по тайлам — квадратам карты. Когда квадрат берётся у OpenStreetMap, запрос уходит на серверы OpenStreetMap Foundation. В таком запросе нет ни вашего имени, ни точных координат: только номер квадрата, то есть примерная область, в которой вы находитесь. Скачанные квадраты остаются на часах, чтобы карта работала без сети, и удаляются вместе с приложением. Картографические данные © OpenStreetMap contributors, лицензия ODbL.

Групповая поездка

Если вы создаёте или открываете комнату групповой поездки, ваша текущая позиция и имя, которое вы сами ввели, отправляются на наш сервер (api.cosmicnav.app) и показываются другим участникам этой же комнаты — тем, у кого есть её код. Комната живёт только в памяти сервера, в базу ничего не записывается, и она удаляется через 30 минут после того, как в ней перестают появляться участники. Имя можно не указывать. Вне групповой поездки, ИИ-плана и подключения SoundCloud на наш сервер ничего не отправляется.

План поездки с ИИ

Кнопка «Составить с ИИ» в планировщике маршрута работает через наш сервер (api.cosmicnav.app). Приложение отправляет ему только координаты выбранной области (вашу позицию или выбранный город), радиус, число дней, цель поездки, бюджет, язык и тип транспорта — ни имени, ни аккаунта, ни идентификатора устройства. Сервер берёт настоящие места вокруг этой точки из Google Places API и просит модель Google Gemini разложить их по дням (если Gemini недоступна — OpenAI). Модель видит список мест и параметры поездки, но не вас. Ответ уходит вам по мере готовности и нигде не сохраняется; список мест сервер держит в памяти до 12 часов, чтобы не спрашивать Google дважды об одной точке. Готовый план хранится только на вашем iPhone.

Голосовые команды

Микрофон включается только пока вы держите кнопку голоса, и нужен, чтобы превратить сказанное в команду навигатору — «объезд», «повтори», «поехали в Убуд». Распознавание идёт на самом устройстве, когда iPhone это умеет; на старых моделях речь обрабатывается службой распознавания Apple по политике конфиденциальности Apple. Запись не сохраняется.

Камера

Камера используется только чтобы отсканировать QR-код приглашения в групповую поездку. Ничего не записывается и не сохраняется.

Музыка (SoundCloud)

Музыка в приложении играет из вашего собственного аккаунта SoundCloud по официальному API SoundCloud. Подключение — по вашему нажатию «Connect with SoundCloud»: вы входите на странице SoundCloud, а приложение получает ключ доступа, который хранится только в защищённом хранилище вашего iPhone. Наш сервер участвует один раз — обменивает код входа на ключ и не сохраняет ни ключ, ни что-либо о вашем аккаунте.

Дальше приложение обращается к SoundCloud напрямую: читает ваши лайки, плейлисты, ленту и подписки, ищет треки, получает похожие и воспроизводит поток с серверов SoundCloud. Треки не скачиваются и не сохраняются; лайк, поставленный в приложении, отправляется в ваш аккаунт SoundCloud только по вашему нажатию. Эти обращения регулируются политикой конфиденциальности SoundCloud. Кнопка «Отключить SoundCloud» в настройках музыки удаляет ключ и всё, что приложение знало о вашем аккаунте.

Подпись под треком (автор загрузки, логотип SoundCloud, ссылка на страницу трека) — требование SoundCloud; приложение не связано с SoundCloud и не является его официальным приложением.

Имена и фотографии артистов для выбора любимых и для словаря голосовых команд приложение берёт из открытого API Deezer: туда уходит только текст запроса (имя артиста), музыка оттуда не играет.

Что остаётся на устройстве

История недавних мест и выбранный вид карты хранятся только на вашем iPhone и часах. Удаление приложения удаляет их вместе с ним.

Версия для Android

В приложении для Android нет групповой поездки и камеры, часов тоже нет — поездка идёт на самом телефоне. Остальное так же: без учётных записей, рекламы и аналитики; на наш сервер уходит только код входа в SoundCloud, один раз, если вы подключили музыку.

Музыка (SoundCloud). Работает так же, как на iPhone (см. выше): вход на странице SoundCloud во вкладке браузера, ключ доступа хранится в защищённом хранилище Android (Android Keystore) и удаляется кнопкой «Отключить SoundCloud». Пока играет трек, приложение показывает уведомление-плеер — это служба переднего плана для воспроизведения, чтобы музыка не обрывалась с погашенным экраном.

Геопозиция. Пока идёт поездка, приложение работает как служба переднего плана с уведомлением — так подсказки и приборка продолжают работать с погашенным экраном. Координаты уходят только в Google Maps Platform, чтобы построить и перестроить маршрут, и не сохраняются.

Голос. Микрофон включается только по нажатию кнопки. Речь распознаёт системная служба распознавания Android (на большинстве телефонов — Google) по её политике конфиденциальности; приложение просит распознавать на устройстве, когда это возможно. Запись не сохраняется и на наш сервер не уходит.

Bluetooth. Разрешение на Bluetooth нужно только для приборки мотоцикла: на неё по Bluetooth отправляются кадры карты и стрелка поворота. Приложение не сканирует устройства вокруг и не собирает сведения о них.

Google Maps SDK. Карта на экране телефона рисуется Google Maps SDK для Android, который передаёт в Google технические данные об устройстве, отчёты о сбоях и обезличенный идентификатор SDK по политике конфиденциальности Google.

Журнал поездки. Технический журнал поездки хранится в памяти приложения и покидает телефон только если вы сами отправите его через «Поделиться». Его можно очистить в настройках.

Дети

Приложение не предназначено для детей младше 13 лет и не собирает данные о них.

Связь

Вопросы: hello@cosmicnav.app

Владелец приложения и оператор данных: Alexandr Degteari, Кишинёв, Республика Молдова.


Privacy

CosmicNav · updated 26 September 2026

In short

No accounts, no analytics, no ads. We do not collect or store your personal data and never share it with third parties. Our server only ever sees what three features need, each at your request: the position of group-ride members while a ride is on; the area and trip preferences when you ask the AI for a plan; and, once, the SoundCloud sign-in code if you connect music. It stores none of it — details below.

Location

The app asks for location access to guide you: to show your position on the watch map, count the distance left and speak turn prompts in time. Background access is needed so guidance does not stop when the phone is in your pocket with the screen off.

Coordinates are processed on the device and sent to your watch over Apple's secure link. We do not store or upload them.

Maps, search and routes

Maps, place search and routing are provided by Google Maps Platform. To draw the map around you and find a place, the app sends coordinates and your search query to Google. The map on the phone screen is drawn by the Google Maps SDK, which sends device metadata, crash reports and a pseudonymous SDK identifier to Google. Those requests are governed by Google's privacy policy.

The watch draws the map itself from tiles — squares of the map. When a square comes from OpenStreetMap, the request goes to the OpenStreetMap Foundation servers. It carries no name and no exact coordinates: only the square number, which is the rough area you are in. Downloaded squares stay on the watch so the map works without a connection, and are removed with the app. Map data © OpenStreetMap contributors, licensed under the ODbL.

Group ride

If you create or open a group-ride room, your current position and the name you typed yourself are sent to our server (api.cosmicnav.app) and shown to the other members of that room — the people who have its code. The room lives only in the server's memory, nothing is written to a database, and it is deleted 30 minutes after the last member stops reporting. The name is optional. Outside a group ride, an AI plan and the SoundCloud sign-in, nothing is sent to our server.

Plan with AI

The "Plan with AI" button in the trip planner works through our server (api.cosmicnav.app). The app sends it only the coordinates of the chosen area (your position or a city you picked), the radius, the number of days, the purpose of the trip, the budget, the language and the vehicle type — no name, no account, no device identifier. The server fetches real places around that point from the Google Places API and asks the Google Gemini model to arrange them by day (if Gemini is unavailable, OpenAI). The model sees the list of places and the trip preferences, not you. The answer streams back to you as it is produced and is not stored anywhere; the server keeps the list of places in memory for up to 12 hours so it does not ask Google twice about the same spot. The finished plan lives only on your iPhone.

Voice commands

The microphone is on only while you hold the voice button, to turn what you say into a navigation command — "detour", "repeat", "take me to Ubud". Recognition runs on the device where your iPhone supports it; on older models speech is processed by Apple's recognition service under Apple's privacy policy. No recording is kept.

Camera

The camera is used only to scan a QR code that invites you to a group ride. Nothing is recorded or stored.

Music (SoundCloud)

Music in the app plays from your own SoundCloud account through the official SoundCloud API. You connect it yourself by tapping "Connect with SoundCloud": you sign in on SoundCloud's page and the app receives an access key that is stored only in your iPhone's secure keychain. Our server takes part once — it exchanges the sign-in code for the key — and keeps neither the key nor anything about your account.

From then on the app talks to SoundCloud directly: it reads your likes, playlists, feed and follows, searches tracks, fetches related tracks and streams audio from SoundCloud's servers. Tracks are never downloaded or stored; a like made in the app is sent to your SoundCloud account only when you tap it. These requests are governed by the SoundCloud privacy policy. "Disconnect SoundCloud" in the music settings deletes the key and everything the app knew about your account.

The credit under a track (uploader, SoundCloud logo, link to the track page) is a SoundCloud requirement; the app is not affiliated with SoundCloud and is not an official SoundCloud app.

Artist names and photos for the favourite-artists picker and for the voice-command dictionary come from the public Deezer API: only the search text (an artist's name) is sent there, and no music plays from it.

Stored on device

Recent places and the chosen map style are stored only on your iPhone and watch, and are removed with the app.

Android version

The Android app has no group ride, no camera and no watch — the trip runs on the phone itself. Everything else is the same: no accounts, no ads, no analytics; our server only ever sees the SoundCloud sign-in code, once, if you connect music.

Music (SoundCloud). Works the same way as on iPhone (see above): you sign in on SoundCloud's page in a browser tab, the access key is stored in Android's secure storage (Android Keystore) and is deleted by "Disconnect SoundCloud". While a track is playing the app shows a player notification — a media-playback foreground service, so the music does not stop when the screen goes off.

Location. While a trip is on, the app runs as a foreground service with a notification so that prompts and the dashboard keep working with the screen off. Coordinates are sent only to Google Maps Platform to build and rebuild the route and are not stored.

Voice. The microphone is on only after you tap the button. Speech is recognised by the Android system speech service (Google on most phones) under its own privacy policy; the app asks for on-device recognition where available. Nothing is recorded or sent to our server.

Bluetooth. The Bluetooth permission is used only for the motorcycle dashboard: map frames and the turn arrow are sent to it over Bluetooth. The app does not scan for nearby devices or collect anything about them.

Google Maps SDK. The map on the phone screen is drawn by the Google Maps SDK for Android, which sends device metadata, crash reports and a pseudonymous SDK identifier to Google under the Google Privacy Policy.

Trip log. A technical trip log is kept in the app's storage and leaves the phone only if you share it yourself. It can be cleared in settings.

Children

The app is not directed at children under 13 and does not collect data about them.

Contact

hello@cosmicnav.app

App owner and data controller: Alexandr Degteari, Chișinău, Republic of Moldova.