Privacy Policy
Last updated: 2026-08-12
Privacy policy
This policy explains what GYST ("the app") collects, why, and how you can control it.
What we collect
Account. You can sign in with Apple or with an email address and password through Supabase. You can also use GYST as a guest where guest access is available. Sign in with Apple does not give GYST your Apple ID password.
Trip and vehicle data. Vehicle details and app preferences are stored on your device and may also be stored in our hosted backend when you sign in. Signed-in users may also have saved trips, shared or collaborative trips, and trip-history records stored in the backend. The Trip History Sync setting controls automatic trip-history synchronization. Turning it off stops future automatic uploads and removes automatic cloud history. Manually saved trips and shared or collaborative trips are separate and are not removed by this setting.
Location. GYST uses your location — including in the background during an active trip — to plan routes, find nearby chargers and places, update active-trip progress, and support Live Activities. Current-trip state and route breadcrumbs may remain on your device during the trip. Depending on the feature, GYST may send locations, search terms, route details, or charger coordinates to mapping, place-search, routing, weather, elevation, and charging-data providers. GYST does not provide remote live-location following.
Optional analytics. Cloud analytics is optional. If you opt in, GYST may upload account-linked usage and trip events to our backend, including destination, route-result, or charger context. When cloud analytics is off, those cloud uploads are disabled, but a limited event history may remain on your device. Turning cloud analytics off does not necessarily delete events already uploaded.
AI interactions. Trip Concierge sends your prompt and the relevant trip context to our AI provider. Restaurant classification sends restaurant descriptions, but not your personal cuisine preferences, to a separate AI provider.
Website waitlist and support. If you join the waitlist, we store your email address in our hosted backend for beta invitations and GYST updates. Resend receives your email address so we can notify our team about the signup. The waitlist endpoint also keeps a rate-limit record derived from a hash of the request IP address. If you contact support, Apple iCloud Mail receives your email and whatever message, screenshots, or app and device details you choose to send.
Camera and photo library. GYST may request access if a photo-reporting feature is made available and you choose to attach a photo.
Calendar. If you choose to connect your calendar, GYST can read selected event details, such as the title, location, and time, to surface useful trip and charging context. An event location may be sent to Apple for geocoding. GYST does not use Apple Reminders.
Crash and diagnostic reports. GYST uses Sentry and also records some error information in its Supabase backend. Reports may include crash or error details, sessions, performance traces, app-hang information, device and app information, your GYST account UUID, screen or operation breadcrumbs, and destination or station names that appear in breadcrumbs.
Purchase and entitlement information. GYST uses RevenueCat to manage entitlement and purchase status. RevenueCat initializes when GYST starts and may receive an anonymous RevenueCat customer identifier or your signed-in GYST account identifier, along with entitlement and purchase status. Apple processes App Store transactions; GYST does not receive your card or payment details.
Advertising data. GYST may show ads served by Google AdMob. Google may process a device identifier, advertising data, and your interactions with ads to deliver and measure them. On iOS, GYST asks for permission through App Tracking Transparency before allowing access to the device's advertising identifier or tracking activity across other companies' apps and websites. If you decline, you can keep using GYST and may still see ads.
Your trips stay out of advertising. GYST does not explicitly add your location, destinations, trip history, vehicle data, or personal preferences to AdMob ad requests. The Google SDK may separately collect device, network, and ad-interaction information as described above.
Who processes it
We use service providers to operate GYST. The information they receive depends on the feature you use:
- Supabase — provides authentication, database, Storage, and Edge Functions for account, trip, vehicle, app, and operational data.
- Apple — provides Sign in with Apple, maps and geocoding, APNs notifications, Live Activities, and App Store transactions where applicable.
- Mapbox; OpenChargeMap; NREL/AFDC; OpenStreetMap/Overpass; TomTom; Open-Meteo; and Open-Elevation — provide mapping, routing, place, charger, status, weather, and elevation services and may receive coordinates, searches, destinations, or route details for those requests.
- Anthropic and Hugging Face — process the AI requests described above.
- Sentry — processes crash, diagnostic, session, and performance information.
- RevenueCat — manages customer identifiers, entitlements, and purchase status.
- Google AdMob — delivers and measures ads.
- Expo — provides EAS Update delivery and push-token services and receives related app, update, device, and token information.
- Cloudflare — hosts and protects the website and may process IP addresses and request data.
- Resend — delivers internal waitlist and charger-review notification emails and may receive the email address or contribution details needed for those messages.
- Apple iCloud Mail — handles support email and attachments.
- Google Maps or Waze — receives a destination or route handoff only when you choose that navigation app.
Some of these providers may process information outside Québec, including in other countries where they operate.
Retention
Account and synced data may remain while your account is active. When you delete your account in Settings, GYST deletes your authentication account and core account-linked GYST data, including applicable profile, vehicle, preference, saved-place, owned-trip, device-registration, diagnostic, and owned Storage records. Collaborative content owned by another user remains, while your membership or account identifier is removed or disassociated. Some information may remain independently or without your account identifier, including waitlist records, support communications, non-identifying operational aggregates, certain community or operational records, and historical records retained by service providers under their own practices. Waitlist records, support communications, and account-deletion receipts do not currently have a fixed automatic deletion schedule. You may contact us about waitlist or support records.
Children
GYST is not directed at children under 13, and we don't knowingly collect data from anyone under 13.
Your rights and choices
From Settings, you can delete your GYST account and begin the deletion process described above — no email is required. You can manage Location, Calendar, and any other permissions GYST has requested in iOS Settings → GYST.
Privacy contact
The Person Responsible for the Protection of Personal Information at GYST can be reached at [email protected].
You can contact us at [email protected] to request access to personal information we hold about you or to ask us to correct information that is inaccurate or incomplete. We may need to verify your identity before responding.
Where applicable, you may also request eligible computerized personal information in a structured and commonly used technological format.
For privacy questions or complaints about how GYST handles personal information, contact [email protected] and indicate that your message concerns privacy. We will review the request and respond in accordance with applicable privacy law.
Changes
If this policy changes, we'll update this page and the date above.
Help us build it
The GYST TestFlight beta is free. Invitations are sent in batches.
