CurbScout (“CurbScout”, “we”, “us”, or “our”) helps drivers find street parking and understand parking rules. This Privacy Policy (“Policy”) explains what information CurbScout processes, the purposes for which it is used, the parties that receive it, how long it is retained, and the choices available to you. We do not sell your personal information and we do not show you ads.

CurbScout is operated by Kanha Narla, doing business as CurbScout (a sole proprietorship), 1 Cascade Dr, Fairfax, CA 94930. This Policy covers the CurbScout mobile application and the curbscout.app website (together, the “Service”). The Service is offered in the United States. Contact for anything in this Policy: support@curbscout.co or the postal address above.

1. Information we collect

Location

Motion and device signals

With your permission, CurbScout uses on-device motion activity (e.g., the transition from driving to walking) and related device signals to detect when you have likely parked. When it does, the app shows a confirmation that starts the parking session automatically after a short countdown unless you dismiss it. These signals are processed on your device for the purpose of park detection; you can decline the permission and start sessions manually instead.

Car Bluetooth (optional): if you enable it, the app watches for your phone connecting to and disconnecting from your car’s audio system to detect that you have parked. The car’s audio device name is stored only on your phone and is never sent to us.

Account information

Guest account by default. When you first use CurbScout it automatically creates a guest account identified by a random Firebase account identifier — no name, e-mail, or password — so your settings and free period can be kept. You can use CurbScout entirely as a guest.

Optional sign-in. You can sign in with Apple, with Google, or with an e-mail address and password. From Apple or Google we receive the basic profile the provider shares (such as your name and e-mail address, or Apple’s private relay e-mail if you choose to hide yours). If you use e-mail and password, Google Firebase Authentication processes and stores the credentials used for email sign-in; CurbScout does not receive your password in readable form. Signing in links your guest data to the account and syncs your saved places, vehicle type, permit settings, and preferences across reinstalls and devices.

Preferences and app data

Saved locations (e.g., Home, Work — a label, the address, the place’s coordinates, and any parking details shown when you saved it), vehicle type, residential-permit settings, notification preferences, and your preferred navigation app are stored with your account so the app works the way you set it up; your intended parking duration is kept only on your device. Your parking sessions (where you parked, deadlines, and session history) are stored only on your device. If usage analytics is on, account-linked events about a session (that you parked, how long it lasted, whether it had a deadline, the city) are sent — never where you parked.

Free-period record

To help enforce the 14-day card-free period once per person, account, and device, we store the date the period started in your device’s secure keychain (which persists if you reinstall the app) and, while your account exists, under your account in our database. The keychain entry is a timestamp only — not a hardware identifier — and is not used for advertising or cross-app tracking.

Purchases

Purchases and subscriptions are processed by Apple through the App Store. We never see or store your payment card details. We use RevenueCat, a subscription-management service, to validate purchase receipts and know which features your account has unlocked. RevenueCat receives a pseudonymous app user ID and purchase receipt data from Apple.

Usage analytics (on by default; turn it off any time), and reports

The following streams are optional and, like most apps, are on by default. We tell you this on the first screen, before anything is collected, and you can turn them off any time in Profile → Data collection (the switch is labeled “Help improve CurbScout”). Turning them off stops collection immediately and clears anything not yet sent; records already sent are deleted with your account or at the retention limit in Section 5. No paid feature depends on this choice. The last item below — feedback and reports — is different: those are things you choose to send us, one at a time, and are not controlled by that switch. We describe how each stream is linked to you rather than calling it “anonymous”.

Launch waitlist (website)

If you give us your e-mail address through a download button on this website so we can tell you when the app is available in the App Store (the “launch waitlist”), the record contains only the address, submission time, and button used; no app account is created. It is used for a single availability announcement and then deleted. The website host may separately process IP address and standard request metadata in short-lived security/access logs described in Section 5. We do not sell or share the waitlist, and you can have your entry removed at any time by emailing support@curbscout.co.

Website usage events

Our website records a small set of usage events that carry no name, e-mail, account, or device identifier, so we can tell whether the site works and where visitors give up: page and section views, which download button was used and where it led (App Store, QR code, or the waitlist), FAQ questions opened, the page path, the host name of the site that referred you, campaign parameters in the link you arrived from (utm_*), and whether the browser is a phone or a desktop. These events carry no name, e-mail, account, or device identifier and use no cookies; a random visit identifier lives only in the browser tab’s session storage so we can count visits rather than clicks, and it disappears when the tab closes. If your browser sends the Global Privacy Control or Do Not Track signal, no usage events are sent at all. Events are stored in our Firebase database in the United States and deleted automatically after 400 days. We do not sell or share them.

2. How we use information

3. What we share — and what we don't

We do not sell your personal information. We do not share it with data brokers. We do not run third-party advertising.

We share data only with the service providers that make the app work, and only what each one needs:

Some telemetry is stored without a CurbScout account identifier or install identifier. Depending on its contents—such as an approximate area or the time of a request—it may still be considered personal information. We use it only for the purposes described in this Policy and do not intentionally attempt to identify the person who generated it. We use the term “deidentified” only for information subject to measures designed to prevent it from reasonably being linked to a person or device.

For providers operating under contracts or accepted service terms, we require handling consistent with those terms and the protections described in this Policy. Where a public provider does not offer a negotiated agreement, CurbScout limits the data it receives and routes those requests through infrastructure we operate, so the provider receives our relay’s IP address rather than yours. We tell users about optional collection before it starts and let them turn it off at any time, and we do not authorize providers to use CurbScout data for advertising or data-broker purposes.

We may also disclose information if required by law, or to protect the rights, safety, and security of CurbScout, our users, or the public.

4. City parking data

The parking regulations, meter, and schedule data shown in CurbScout come from public sources — city open-data portals, public-records requests, and other published datasets. That data flows into the app. When the app checks a city’s live feed, it sends the map area through a CurbScout relay. The public service receives the requested area and relay IP, never your CurbScout account or parking history.

5. Data retention and deletion

CategoryExamplesLinkagePurposeMaximum retentionDeletion behavior
Account datasaved places, vehicle and permit settings, preferences, your Terms acceptance recordaccount-linkedprovide the service you set upwhile your account existsdeleted immediately when you delete your account
Sign-in credentialse-mail, name, provider identifiersaccount-linkedauthenticationwhile your account existsdeleted with your account (Google Firebase Authentication)
Free-period recordthe date your card-free period started (the server copy is kept under your random account identifier)on your device (secure keychain) and, while your account exists, under your accountkeep the free period to one per device / accountserver copy: while your account exists; device copy: until the app’s keychain entry is removedserver copy deleted with your account; the device copy stays on the device
Usage analytics (optional)screens/features used, ranks tapped, cityaccount-linked + install identifierproduct improvement24 monthsdeleted with your account; otherwise deleted at 24 months
Parking outcome data, search shape, query telemetry, product-experiment records, diagnostics (optional)found/not found, coarse area, search category (not the text), error codesstored without account or install identifierproduct improvement, debugging24 monthsdeleted at 24 months (cannot be tied to an account, so account deletion does not reach them)
Feedbackthe text you send from Profile → Feedback, optional reply e-mailaccount-linkedreply and act on your feedback24 monthsdeleted with your account; otherwise deleted at 24 months
Suggestion reportsreason, note, suggested curb, optional your positionaccount-linkedcorrect parking data24 monthsdeleted with your account; otherwise deleted at 24 months
Purchase evidencethe product, transaction id, price, billing period and renewal terms shown when you bought a plan; the Terms/Privacy versions you had accepted; and your usage-analytics setting at the timeaccount-linkedproof of what you were shown (auto-renewal compliance)4 years from the date of the recordretained after account deletion for that compliance period, then deleted automatically
Parking sessions and history, recent searcheswhere you parked, deadlines, addresses you searchedon your device onlyrun your parking session; convenienceuntil you delete the app or your accountremoved from the device when you delete your account or the app
Website waitliste-mail, time, which buttone-mailone launch announcementdeleted after the announcement, at latest 180 daysdeleted on request at any time
Website usage eventspage/section views, download-button clicks and where they led, QR/waitlist/FAQ opens, page path, referrer host, campaign parameters, device class, per-tab visit idnone (no account, no persistent identifier, no cookies)see whether the site works; measure the install funnel400 days (automatic)not linked to a person; browsers sending Global Privacy Control / Do Not Track send nothing
Infrastructure security/access logstime, endpoint, status and limited technical metadata; the map-tile relay keeps no request log and the public-feed relay keeps no per-request URL log; our routing and street-data servers log the requested coordinates without your IP address or account; destination text is never loggednetwork/request-linked; no app account identifier by designsecurity, abuse prevention, reliabilityup to 30 days (Google Cloud) and about 7 days (Fly.io)automatically deleted at the end of those periods

The 24-month limit is enforced by automatic expiration on each record. Where a record was created before this Policy’s effective date, a scheduled job deletes it once it is older than 24 months.

6. Security

We use authentication, access controls, role-based administrative access, encryption in transit, and other safeguards designed to limit access based on operational need. No system can be guaranteed completely secure.

7. Your rights and choices

8. Children

CurbScout is intended for adults and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we collected such information, we will take appropriate steps to delete it.

9. Changes to this Policy

If we make material changes, we will post the updated policy with a new effective date and version, and the app will ask you to acknowledge it before you continue. Earlier versions are available on request.

10. Contact

Questions, requests, or complaints: support@curbscout.co, or by post to Kanha Narla, doing business as CurbScout (a sole proprietorship), 1 Cascade Dr, Fairfax, CA 94930.