CurbScout (“CurbScout”, “we”, “us”, or “our”) helps drivers find street parking and understand parking rules. This Privacy Policy (“Policy”) explains what information CurbScout processes, the purposes for which it is used, the parties that receive it, how long it is retained, and the choices available to you. We do not sell your personal information and we do not show you ads.
CurbScout is operated by Kanha Narla, doing business as CurbScout (a sole proprietorship), 1 Cascade Dr, Fairfax, CA 94930. This Policy covers the CurbScout mobile application and the curbscout.app website (together, the “Service”). The Service is offered in the United States. Contact for anything in this Policy: support@curbscout.co or the postal address above.
1. Information we collect
Location
- While using the app: your device location is used to find parking near you, rank suggestions by distance, evaluate the parking rules that apply where you are, and provide turn-by-turn guidance to a spot.
- In the background (optional): if you grant “Always” location access, CurbScout can detect when you have parked, keep your parking session accurate, and alert you before street sweeping or a meter deadline affects your parked car. Background location is entirely optional — the core app works with “While Using” access only, and you can change or revoke access at any time in iOS Settings.
- Searched addresses: when you type a destination, the text is sent to Apple Maps (MapKit local search) and, when Apple returns weak results, to Google Places / Maps — and, only if Google is unavailable, to Photon, a public geocoder run by Komoot, through our relay — to return matching locations and geocode addresses. When your location is known it is sent with the search so nearby matches rank first. The destination coordinates are used to compute parking suggestions and routes. CurbScout does not store the destination text on its servers. Unless you have turned usage analytics off, the app classifies the search on your phone and stores only the category, a token-count bucket, and the city, as described below.
- Map tiles, routes, street data, and city feeds: to draw the navigation map, compute a driving or walking route, or check a city’s live parking feed, the app sends the map area or route coordinates involved to the provider described in Section 3. CurbScout-operated servers and relays receive the request coordinates and your IP address but no CurbScout account identifier. Public tile and city-feed providers receive the requested map area or bounding box and the relay’s IP address, not your device’s IP address.
Motion and device signals
With your permission, CurbScout uses on-device motion activity (e.g., the transition from driving to walking) and related device signals to detect when you have likely parked. When it does, the app shows a confirmation that starts the parking session automatically after a short countdown unless you dismiss it. These signals are processed on your device for the purpose of park detection; you can decline the permission and start sessions manually instead.
Car Bluetooth (optional): if you enable it, the app watches for your phone connecting to and disconnecting from your car’s audio system to detect that you have parked. The car’s audio device name is stored only on your phone and is never sent to us.
Account information
Guest account by default. When you first use CurbScout it automatically creates a guest account identified by a random Firebase account identifier — no name, e-mail, or password — so your settings and free period can be kept. You can use CurbScout entirely as a guest.
Optional sign-in. You can sign in with Apple, with Google, or with an e-mail address and password. From Apple or Google we receive the basic profile the provider shares (such as your name and e-mail address, or Apple’s private relay e-mail if you choose to hide yours). If you use e-mail and password, Google Firebase Authentication processes and stores the credentials used for email sign-in; CurbScout does not receive your password in readable form. Signing in links your guest data to the account and syncs your saved places, vehicle type, permit settings, and preferences across reinstalls and devices.
Preferences and app data
Saved locations (e.g., Home, Work — a label, the address, the place’s coordinates, and any parking details shown when you saved it), vehicle type, residential-permit settings, notification preferences, and your preferred navigation app are stored with your account so the app works the way you set it up; your intended parking duration is kept only on your device. Your parking sessions (where you parked, deadlines, and session history) are stored only on your device. If usage analytics is on, account-linked events about a session (that you parked, how long it lasted, whether it had a deadline, the city) are sent — never where you parked.
Free-period record
To help enforce the 14-day card-free period once per person, account, and device, we store the date the period started in your device’s secure keychain (which persists if you reinstall the app) and, while your account exists, under your account in our database. The keychain entry is a timestamp only — not a hardware identifier — and is not used for advertising or cross-app tracking.
Purchases
Purchases and subscriptions are processed by Apple through the App Store. We never see or store your payment card details. We use RevenueCat, a subscription-management service, to validate purchase receipts and know which features your account has unlocked. RevenueCat receives a pseudonymous app user ID and purchase receipt data from Apple.
Usage analytics (on by default; turn it off any time), and reports
The following streams are optional and, like most apps, are on by default. We tell you this on the first screen, before anything is collected, and you can turn them off any time in Profile → Data collection (the switch is labeled “Help improve CurbScout”). Turning them off stops collection immediately and clears anything not yet sent; records already sent are deleted with your account or at the retention limit in Section 5. No paid feature depends on this choice. The last item below — feedback and reports — is different: those are things you choose to send us, one at a time, and are not controlled by that switch. We describe how each stream is linked to you rather than calling it “anonymous”.
- Usage analytics (account-linked). Which screens and features you use — for example that a search ran, how many results were shown, which ranked suggestion you tapped, whether you started navigation or arrived, and paywall/trial events — together with the city, an install identifier, and your account identifier, so we can see where the app loses people. These events are structurally prevented from containing an address or coordinates. Stored in our own database (Google Firebase Firestore), not in an advertising system.
- Parking outcome data (stored without your account or install identifier). Whether parking was found at a suggestion (or it was skipped or the search abandoned), how long the search took, the hour and weekday, the suggestion’s characteristics, and the coarse area of the suggested block. Has its own sub-switch, Profile → Data collection → Share parking outcome data (available while the main switch is on).
- Search shape and query telemetry (stored without your account or install identifier). We do not store the text you type into destination search. The app classifies it on your phone into a category (address, intersection, place, or other) and stores only that category, a rough word-count bucket, and the city. Separately, to debug results, we store a fingerprint of each parking query — a hash of the searched area (rounded), time bucket, city, duration and vehicle type — together with which suggestions were returned and how long the query took. Because an approximate area can itself be personal information, we treat these rows as personal information (see Section 3).
- Product-experiment records (stored without your account or install identifier). When we test a ranking change in the background, a record of how the two rankings differed for a searched area (a map grid cell roughly 150 m on a side), so we can evaluate the change without showing it to you.
- Diagnostics (non-essential; stored without your account or install identifier). Diagnostic codes (for example an error, a data fallback, or a load-time result), a short fixed description written by us, the platform, and the city. Only a fixed set of fields can be recorded; coordinates, addresses, and anything you typed are removed on your phone before anything is queued.
- Feedback and reports you send us. Feedback from Profile → Feedback is stored with your account identifier, the category you chose, the app version, platform, city, whether you were signed in, and, if you choose to give it, your e-mail address so we can reply. “What was wrong?” reports about a suggestion are stored with your account identifier so they can be deleted with your account; they include the suggestion’s location, your note, and optionally your own position at the time. Reports and feedback are text only; the app does not accept photo attachments.
Launch waitlist (website)
If you give us your e-mail address through a download button on this website so we can tell you when the app is available in the App Store (the “launch waitlist”), the record contains only the address, submission time, and button used; no app account is created. It is used for a single availability announcement and then deleted. The website host may separately process IP address and standard request metadata in short-lived security/access logs described in Section 5. We do not sell or share the waitlist, and you can have your entry removed at any time by emailing support@curbscout.co.
Website usage events
Our website records a small set of usage events that carry no name, e-mail, account, or device identifier, so we can tell whether the site works and where visitors give up: page and section views, which download button was used and where it led (App Store, QR code, or the waitlist), FAQ questions opened, the page path, the host name of the site that referred you, campaign parameters in the link you arrived from (utm_*), and whether the browser is a phone or a desktop. These events carry no name, e-mail, account, or device identifier and use no cookies; a random visit identifier lives only in the browser tab’s session storage so we can count visits rather than clicks, and it disappears when the tab closes. If your browser sends the Global Privacy Control or Do Not Track signal, no usage events are sent at all. Events are stored in our Firebase database in the United States and deleted automatically after 400 days. We do not sell or share them.
2. How we use information
- Find, rank, and route you to parking near your location or destination.
- Evaluate parking regulations, meter schedules, sweeping schedules, and permit zones for a specific place and time.
- Detect parking events and run parking-session timers and reminders you configure.
- Send the local notifications you ask for (sweeping alerts, meter/time-limit expiry warnings).
- Maintain your account, preferences, and purchases.
- Debug problems, prevent abuse, and improve the product.
3. What we share — and what we don't
We do not sell your personal information. We do not share it with data brokers. We do not run third-party advertising.
We share data only with the service providers that make the app work, and only what each one needs:
- Apple — Sign in with Apple if selected, App Store purchases, app distribution, and destination text sent to Apple Maps. Parking reminders are scheduled locally on your device; CurbScout does not send their content through a CurbScout remote-push service.
- Google Firebase — authentication; Firestore storage for account data, preferences, optional telemetry, reports, feedback, trial records, and purchase-compliance records; and the file storage that serves our city parking datasets to the app (each download names the city and, for larger cities, the area being loaded, and carries your IP address). CurbScout does not use the separate Firebase Analytics product for the telemetry described here.
- Apple Maps (MapKit) — the first provider for destination search (receives the text you type and, when known, your current location as the search region), and the base map on the Quick Park suggestions, arrival, and parking-session screens (Apple receives the map area you are viewing and your IP address, as with any Apple Maps use).
- Google Places / Maps — destination search when Apple’s results are weak (receives the text you type and, when known, your current location as a search bias), and geocoding of addresses.
- Photon (Komoot) — a public geocoder used only if Google is unavailable; receives the text you type and, when known, your current location as a search bias (or the center of a city you named in your search), through our relay (it sees the relay’s IP, not yours). Public service; no contract.
- Navigation apps you choose (Apple Maps, Google Maps, or Waze) — when you tap to get directions outside CurbScout, the app opens the navigation app you selected with the destination coordinates and, when known, your current location as the starting point. That app’s own privacy policy applies from there.
- RevenueCat — purchase receipt validation and subscription status (receives a pseudonymous app user ID and Apple receipt data).
- Our routing and street-data servers — when the app computes a driving or walking route or snaps a suggestion to the curb, the relevant coordinates go to routing servers we operate (hosted on Fly.io); street geometry comes from an OpenStreetMap Overpass server we operate. Release builds send these requests only to infrastructure we operate; if it is unavailable the feature degrades (for example, a straight-line walking estimate) rather than using a public server. These requests carry coordinates and your IP address, not your account.
- CurbScout tile relay and OpenFreeMap — the app requests navigation-map tiles through a CurbScout-operated relay. The relay receives your IP address and requested map area. OpenFreeMap receives the requested map area and the relay’s IP address, not your device’s IP address. OpenFreeMap is a public service and CurbScout has no negotiated contract with it.
- City and state open-data services (through the CurbScout public-feed relay) — in some cities the app requests a live parking or traffic feed through a CurbScout-operated relay. The relay receives your IP address and requested bounding box. The public provider receives the bounding box and relay IP, not your device IP or CurbScout account identifier. These are public services and generally have no negotiated contract with CurbScout.
- Event data providers (e.g., Ticketmaster) — our servers periodically download public event listings for the areas we cover so the app can warn you about parking crunches near a destination. The app reads those listings from our own servers; the provider does not receive your location, your IP address, or any CurbScout identifier.
- Expo Application Services — delivers over-the-air updates to the app’s code; receives your IP address, device platform, and app version when the app checks for updates.
Some telemetry is stored without a CurbScout account identifier or install identifier. Depending on its contents—such as an approximate area or the time of a request—it may still be considered personal information. We use it only for the purposes described in this Policy and do not intentionally attempt to identify the person who generated it. We use the term “deidentified” only for information subject to measures designed to prevent it from reasonably being linked to a person or device.
For providers operating under contracts or accepted service terms, we require handling consistent with those terms and the protections described in this Policy. Where a public provider does not offer a negotiated agreement, CurbScout limits the data it receives and routes those requests through infrastructure we operate, so the provider receives our relay’s IP address rather than yours. We tell users about optional collection before it starts and let them turn it off at any time, and we do not authorize providers to use CurbScout data for advertising or data-broker purposes.
We may also disclose information if required by law, or to protect the rights, safety, and security of CurbScout, our users, or the public.
4. City parking data
The parking regulations, meter, and schedule data shown in CurbScout come from public sources — city open-data portals, public-records requests, and other published datasets. That data flows into the app. When the app checks a city’s live feed, it sends the map area through a CurbScout relay. The public service receives the requested area and relay IP, never your CurbScout account or parking history.
5. Data retention and deletion
| Category | Examples | Linkage | Purpose | Maximum retention | Deletion behavior |
|---|---|---|---|---|---|
| Account data | saved places, vehicle and permit settings, preferences, your Terms acceptance record | account-linked | provide the service you set up | while your account exists | deleted immediately when you delete your account |
| Sign-in credentials | e-mail, name, provider identifiers | account-linked | authentication | while your account exists | deleted with your account (Google Firebase Authentication) |
| Free-period record | the date your card-free period started (the server copy is kept under your random account identifier) | on your device (secure keychain) and, while your account exists, under your account | keep the free period to one per device / account | server copy: while your account exists; device copy: until the app’s keychain entry is removed | server copy deleted with your account; the device copy stays on the device |
| Usage analytics (optional) | screens/features used, ranks tapped, city | account-linked + install identifier | product improvement | 24 months | deleted with your account; otherwise deleted at 24 months |
| Parking outcome data, search shape, query telemetry, product-experiment records, diagnostics (optional) | found/not found, coarse area, search category (not the text), error codes | stored without account or install identifier | product improvement, debugging | 24 months | deleted at 24 months (cannot be tied to an account, so account deletion does not reach them) |
| Feedback | the text you send from Profile → Feedback, optional reply e-mail | account-linked | reply and act on your feedback | 24 months | deleted with your account; otherwise deleted at 24 months |
| Suggestion reports | reason, note, suggested curb, optional your position | account-linked | correct parking data | 24 months | deleted with your account; otherwise deleted at 24 months |
| Purchase evidence | the product, transaction id, price, billing period and renewal terms shown when you bought a plan; the Terms/Privacy versions you had accepted; and your usage-analytics setting at the time | account-linked | proof of what you were shown (auto-renewal compliance) | 4 years from the date of the record | retained after account deletion for that compliance period, then deleted automatically |
| Parking sessions and history, recent searches | where you parked, deadlines, addresses you searched | on your device only | run your parking session; convenience | until you delete the app or your account | removed from the device when you delete your account or the app |
| Website waitlist | e-mail, time, which button | one launch announcement | deleted after the announcement, at latest 180 days | deleted on request at any time | |
| Website usage events | page/section views, download-button clicks and where they led, QR/waitlist/FAQ opens, page path, referrer host, campaign parameters, device class, per-tab visit id | none (no account, no persistent identifier, no cookies) | see whether the site works; measure the install funnel | 400 days (automatic) | not linked to a person; browsers sending Global Privacy Control / Do Not Track send nothing |
| Infrastructure security/access logs | time, endpoint, status and limited technical metadata; the map-tile relay keeps no request log and the public-feed relay keeps no per-request URL log; our routing and street-data servers log the requested coordinates without your IP address or account; destination text is never logged | network/request-linked; no app account identifier by design | security, abuse prevention, reliability | up to 30 days (Google Cloud) and about 7 days (Fly.io) | automatically deleted at the end of those periods |
The 24-month limit is enforced by automatic expiration on each record. Where a record was created before this Policy’s effective date, a scheduled job deletes it once it is older than 24 months.
- Deleting your account: open Profile → Delete Account in the app (guests: Delete My Data). Deletion is initiated immediately: your profile and sign-in are deleted right away, and a server-side job then deletes your server free-period record, feedback, suggestion reports, and account-linked usage analytics — normally within minutes. The app also removes parking sessions, history, recent searches, saved settings, and queued analytics from the device and cancels scheduled reminders; if any device step fails, the app tells you which one. A non-identifying trial-start timestamp remains in the device Keychain to enforce one card-free period per device. If a parking session is active, the app tells you it will be ended and asks you to confirm. What is not deleted: records that never carried your account or install identifier and cannot be found from the account (they expire at 24 months), and purchase evidence retained for the 4-year compliance period stated above. If you no longer have the app installed, e-mail support@curbscout.co from the address associated with your account and we will verify and honor the request within 30 days. A guest user without an associated e-mail must use the in-app deletion flow while access to that guest account remains available.
- Deleting your account does not cancel an App Store subscription. Manage or cancel your subscription through Apple before deleting your account. Purchases stay with your Apple ID and can be restored.
- Sign in with Apple: when you delete an account created with Sign in with Apple, the app asks you to confirm with Apple and then asks Apple to revoke CurbScout’s sign-in grant. If that step cannot be completed, the app tells you, and you can remove CurbScout under Settings → Apple ID → Sign-In & Security → Sign in with Apple. Your CurbScout data is deleted either way.
6. Security
We use authentication, access controls, role-based administrative access, encryption in transit, and other safeguards designed to limit access based on operational need. No system can be guaranteed completely secure.
7. Your rights and choices
- Location and motion permissions can be changed anytime in iOS Settings → CurbScout.
- Notifications can be turned off per-type in the app or in iOS Settings.
- Access, correction, deletion: email us to request a copy of your data, correct it, or delete it.
- Usage analytics is on by default and can be turned off any time in Profile → Data collection (see Section 1).
- California residents (notice at collection): we collect these categories of personal information — identifiers (a random account identifier, an install identifier, network IP, and your e-mail and name if you sign in); account information (vehicle and permit settings, saved places, preferences); precise geolocation (while you use the app, and in the background only if you allow it); commercial and subscription information (purchases and subscription status); internet or application activity (optional usage analytics and diagnostics); search activity (an optional on-device-derived category and token-count bucket, not the destination text); user-submitted text (feedback and report notes); and device and diagnostic information (platform, app version, error codes). We do not store user-specific inferences about preferences or parking behavior. Sources: you and your device; Apple or Google when you sign in; Apple/RevenueCat for purchases; and service providers' ordinary request logs. Purposes: Section 2. Retention: Section 5. We use precise geolocation to provide requested parking, navigation, parking-session and reminder features; to process user-initiated reports; and to maintain the security and reliability of those features. We do not use precise geolocation for advertising or sale. These are permitted purposes for which sensitive personal information may be used without offering a separate right to limit that use, as described in Cal. Civ. Code §1798.121(a). We do not sell or share personal information as those terms are defined by the CPRA. Whether or not CurbScout is legally required to provide a particular CCPA right at a given time, we provide the access, correction, and deletion choices described in this Policy, subject to verification and applicable exceptions: in the app (Profile) or by e-mailing support@curbscout.co; we verify e-mail requests by replying to the address on the account. We will not discriminate against you for exercising these rights.
- Outside the United States: the Service is offered and supported in the United States. If you use it elsewhere, you understand that your information is processed in the United States under this Policy.
8. Children
CurbScout is intended for adults and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we collected such information, we will take appropriate steps to delete it.
9. Changes to this Policy
If we make material changes, we will post the updated policy with a new effective date and version, and the app will ask you to acknowledge it before you continue. Earlier versions are available on request.
10. Contact
Questions, requests, or complaints: support@curbscout.co, or by post to Kanha Narla, doing business as CurbScout (a sole proprietorship), 1 Cascade Dr, Fairfax, CA 94930.