RAILCHASE

Privacy Policy

Effective date: 2026-06-17

Last updated: 2026-07-01

App: RailChase

Operator: Helion LLC


1. What we collect and why

1.1 Email address and account

When you create an account, we collect your email address. It is used for:

  • Magic-link sign-in (Supabase Auth)
  • Stripe billing (subscription management)
  • Transactional emails related to your account (e.g. payment receipts)
  • Your email is stored in Supabase Auth and passed to Stripe when a subscription is created. It is not shared with any third party for advertising purposes and is not sold or rented.

    1.2 Subscription and purchase history

    We store your subscription status (plan tier: Spotter or Chaser), subscription start/end dates, and Stripe customer ID. This data is used to determine which features you can access. It is stored in our Supabase database and also exists within Stripe as part of the billing record.

    1.3 Approximate location (coarsened to ~110 m)

    When you submit a train sighting, the app reads your device GPS and rounds the latitude and longitude to three decimal places (approximately 110 m) before the coordinates leave your device or are stored. We never store or serve your precise GPS position. We use the coarsened coordinate to place your pin on the community map and to label your sighting with a nearby city name.

    Note: the device provides high-accuracy GPS to the app while the report form is open. The coarsening happens server-side before any coordinate is written to storage. Apple and Google consider the collected type "Precise Location" because that is what the device provides to the app, even though only the coarsened value is stored.

    1.4 Photos (EXIF stripped)

    If you attach a photo, the server strips all image metadata (Exif, GPS tags, XMP, IPTC) before the bytes are stored. The photo bytes (without metadata) are stored on Vercel Blob and served publicly so other users can see the train.

    1.5 IP address (rate-limiting and report dedup)

    Your IP address is used to enforce rate limits. For rate-limiting it is held in process memory for the duration of the rate-limit window only and is never written to disk.

    If you report a sighting, we store a salted, one-way cryptographic hash derived from your IP alongside that sighting so that one person cannot hide a post by reporting it repeatedly. The hash cannot be reversed to your IP, is used only for this anti-abuse deduplication, and is deleted with the sighting (within ~48 hours). The raw IP address is never written to disk or a database.

    1.6 Sighting content

    The label, operator, note text, and coarsened coordinates you submit become part of the public community sightings board. Do not include personal information in these fields.


    2. How we use your information

    DataPurposeRetention
    Email addressSign-in, billing, transactional emailAccount lifetime; deleted on account deletion
    Subscription / purchase historyFeature entitlement (tier gating)Subscription lifetime; purged ~30 days after cancellation
    Coarsened coordinatesMap pin, city label48 hours on the public board
    EXIF-stripped photoCommunity board display48 hours on the public board
    IP addressRate limiting (memory only)Duration of rate-limit window
    Salted IP hashReport deduplication (anti-abuse)~48 hours (deleted with the sighting)
    Sighting textCommunity board48 hours

    3. Sharing and sub-processors

    We do not sell, rent, or trade your data. Photos and sighting text are shared publicly on the community board by design. Coarsened coordinates are included in the public board response.

    We use the following sub-processors:

  • Supabase (database, authentication) -- United States. Stores email, account data, subscription records, and sighting content.
  • Stripe (payment processing) -- United States. Stores email, payment method, and billing history for subscription management.
  • Vercel (hosting, Blob storage) -- United States. Stores EXIF-stripped photos and serves the application.
  • Anthropic (optional AI photo identification) -- United States, used only when you tap "Identify" and only for the duration of that call.

  • 4. UGC reporting and moderation

    Any user can flag a sighting using the report button. After a threshold of reports (currently 3), a sighting is automatically hidden from the public board pending review. The AI moderation system also screens photos at submission time; a moderation error causes the post to be held for review rather than published.


    5. Data retention

    Community sightings (coarsened coordinates, text, photos) are removed from the public board after 48 hours. Account data (email, subscription) is retained for the lifetime of your account. On account deletion, your email and subscription records are deleted from our database; Stripe retains billing records as required by financial regulations.


    6. Your rights and account deletion

    You can delete your account from within the app: open the Account menu and choose "Delete my account". Account deletion cascades: your profile and subscription records are deleted from our database. We also process a deletion request with Stripe via the billing portal cancel flow.

    If you cannot access the app, you can request account deletion at railchase.com/legal/delete-account or by emailing contact@helionhq.com from your account email.

    If you believe a sighting you submitted contains personal information you want removed, contact us at contact@helionhq.com. Describe the sighting (approximate time, location, and content) and we will remove it manually.

    Depending on where you live, you may have additional rights (access, correction, portability, objection) under applicable law. Contact us at contact@helionhq.com to exercise them.


    7. Children

    RailChase is not directed at children under 13. We do not knowingly collect data from children.


    8. Governing law

    This policy is governed by the laws of the State of Missouri. Disputes are subject to the jurisdiction of the courts of Jackson County, Missouri.


    9. Changes

    We will update the effective date at the top when this policy changes. For material changes, we will post a notice in the app.


    10. Contact

    Helion LLC

    contact@helionhq.com