Privacy without an account
NavOSS is operated by Yassin Soliman as an individual developer in Alberta, Canada. It is an account-free navigation technical beta with Calgary and Kelowna search and routing plus selected official regional overlays.
Location and active navigation
When you grant When in Use location permission, precise location shows your position, chooses a route origin, matches progress to an active route, detects rerouting and arrival, and checks whether an official safety camera is ahead.
After you start turn-by-turn navigation, location updates continue while the phone is locked, another app is visible, or CarPlay is connected. iOS displays its background location indicator. NavOSS does not request Always location. Updates stop on End or confirmed arrival. The current active route is stored transiently on the phone for operating-system recovery, then erased when navigation ends or arrival is confirmed; NavOSS does not maintain a trip-history database.
Search and routing
Search text and, when available, a search origin rounded to three decimal places, or roughly 100-meter granularity, are sent in an encrypted request body to the NavOSS API. Route requests send precise origin and destination coordinates. An automatic reroute sends the latest route origin and destination. Search uses self-hosted Alberta and British Columbia OpenStreetMap data plus a local mirror of public Calgary business and parcel-address data used only for Calgary searches. Current production uses Valhalla on the operator-controlled server in Alberta. A future licensed live-traffic deployment may forward route endpoints and preferences to Mapbox Directions; that mode remains disabled until its commercial vehicle-use license and release gates are complete.
These values are processed in memory for the response and then discarded. They are not written to a NavOSS database, access log, or backup. Active route matching and camera eligibility run on the phone.
Tapping a named map place sends that public place name and map coordinate to the same NavOSS API to find the nearest matching OpenStreetMap record. When available, the response may include a public address, category, opening hours, business phone number, official website, and wheelchair-access tag. The request is processed in memory and discarded like typed search. NavOSS does not fetch Google review content in this lookup.
In a build where Google Places details are explicitly enabled, opening a point-of-interest sheet also sends that selected public name and coordinate directly to Google Places. Google's Places UI Kit chooses the place and renders available photos, the star rating and rating count, review text, and required Google attribution inside its own visually separated component. NavOSS reads only the returned display name and coordinate to reject a mismatched place; it does not read, persist, combine, or send the photo, rating, count, or review values to its server. A build without the restricted Google key makes no place-details request and shows that Google photos, ratings, and reviews are unavailable.
Before an enabled phone opens Google's component, it asks the NavOSS API to reserve one anonymous monthly query grant. That request contains no place name, coordinate, account, device identifier, or search text. NavOSS stores only the UTC month, an aggregate used count, and its last update time. The server denies grants after 8,000 in a month, below Google's current 10,000-event no-charge allowance, and fails closed if the counter is unavailable.
An enabled build links GooglePlacesSwift 10.15.0 and its underlying Google Places SDK. The SDK's embedded Apple privacy manifest declares Google collection of precise and coarse location for analytics and app functionality; device ID linked to identity for analytics and app functionality; other data linked to identity for analytics; and unlinked performance data, product interaction, and search history for analytics. It declares no tracking. These are Google-controlled SDK declarations beyond the place details NavOSS displays, and enabled-build App Privacy answers must include them.
Map style, navigation orientation, tilt, map-content visibility, safety-camera marker visibility, and route-color choices are stored only inside the app on the device. NavOSS does not receive these settings or use them for analytics. Hiding camera markers does not disable active-navigation safety warnings.
Sharing and external place actions
Place sharing and Share ETA use Apple's system share sheet. Place share text contains a public place name, displayed address or category, and OpenStreetMap link. ETA share text contains the chosen destination name, arrival estimate, remaining time, and remaining distance. It does not contain the current coordinate, route geometry, live tracking, or automatic updates. NavOSS does not read Contacts or request Contacts permission; it does not receive or store the recent recipients Apple may suggest.
Call and website actions open an external system app only after the user chooses them. More reviews on Google Maps is a separate external action and sends the selected public place name and coordinate to Google only when chosen. NavOSS does not scrape or cache review text. In a Google-enabled build, the place-details request described above can occur when a point-of-interest sheet opens; the external Google Maps search still occurs only after the user chooses it.
Contribute sends private beta feedback to NavOSS without an account, device identifier, or precise coordinate. To limit abuse, the API keeps a salted, process-local fingerprint of the source network address for up to one hour; it is not logged or stored in PostgreSQL. Accepted submissions contain a fixed type, description, optional place or road label, timestamps, random identifiers, and review status. They are not public and are scheduled for deletion from the live database after 90 days; bounded backups may retain a deleted row for up to 14 additional days. Failed submissions remain only on the device for retry, up to 25 attempts.
NavOSS does not automatically transmit raw feedback descriptions to an AI provider. Operator policy requires reviewing raw text outside an AI conversation. After manually removing names, private addresses, contact details, exact personal trips, credentials, and unnecessary timestamps, the operator may create a separate deidentified engineering summary stored in an ignored local workspace artifact. Only when the operator explicitly invokes AI-assisted triage is that summary transmitted to the configured coding-assistant provider under its terms, to group reports, draft issues, or help implement a human-approved item. The summary contains no account or contributor identifier.
During active navigation, the report button can store up to 25 structured road-report test drafts on the device. Each contains one of four fixed report types, the current precise coordinate, creation time, and a two-hour expiry time. Test drafts contain no free text, photo, account, or public user name. They are not sent to NavOSS or shown to other drivers. Expired drafts are discarded when the local list is next read or written, and removing the app removes all remaining drafts.
No advertising or cross-app tracking
The default Google-disabled build has no account system, ads, analytics SDK, advertising identifier, data broker integration, or cross-app tracking. Location is not used by NavOSS for advertising or user profiling. A separately enabled Google place-details build links the Google Places SDK and is subject to the SDK declarations above; NavOSS does not receive or operate that Google analytics data.
Map and camera data
The phone requests map styles, tiles, fonts, and sprites directly from OpenFreeMap. The requested resources can indicate the viewed map area. OpenFreeMap says regular logs omit IP addresses, while it may retain incident IP logs for up to 30 days. Regional data can include Calgary and Toronto enforcement cameras, Ontario 511 and DriveBC road events, DriveBC ordinary traffic webcams, and fixed public Kelowna RCMP facilities. The phone selects a region locally and sends only the region identifier for those requests. DriveBC webcams are not enforcement cameras, and RCMP facilities are not live police locations.
Providers and retention
Cloudflare provides DNS, TLS, traffic delivery, and the outbound tunnel. It processes client IP and network/request metadata on its global network under its policy. NavOSS does not enable raw Cloudflare request-log export. Map delivery uses OpenFreeMap; TestFlight feedback uses Apple; and user-initiated support may use GitHub. Optional Google-rendered place details and a user-selected external reviews action use Google under Google's policy. Optional licensed live-traffic routing may use Mapbox and send route endpoints, preferences, and request network metadata; it is disabled in current production.
NavOSS keeps operational, SSH, and firewall logs for no more than seven days. Routine HTTP access logging is disabled. Logs exclude request bodies, search text, and route coordinates. The report database has 14-day backups that may contain accepted private beta feedback; route and search requests never enter those backups, and reproducible public search-index tables are excluded. The Google query safety counter stores only the UTC month, aggregate used count, and last update time.
Operational logs may contain timestamps, service identity, severity, lifecycle or health events, error names, and random request IDs. SSH and firewall logs may contain source IP and port, local account, action, and outcome. Cloudflare applies its own variable network and security retention. OpenFreeMap says anonymized logs may be retained indefinitely and incident IP logs for no more than 30 days.
Your choices and deletion
You can deny or revoke location permission in iOS Settings and can stop an active trip with End navigation. Search and map browsing may remain available, while current-position routing and active guidance will be limited.
NavOSS stores up to 12 recent destinations and 20 places you save, including their names, labels, and coordinates, only on the device for phone and CarPlay shortcuts. Use Clear saved and recent destinations in About and Privacy to erase both local lists. Pending contribution retries can be deleted individually on Contribute. Accepted feedback expires automatically after 90 days; its displayed random reference can be provided to support for earlier deletion. Road-report test drafts expire after two hours. Removing the app removes the remaining local records.
Sharing and the external reviews link are optional. Dismissing the system share sheet sends nothing to a recipient. In a Google-enabled build, opening a POI sheet can send its public coordinate for Google-rendered photos, ratings, and reviews; not choosing the external link sends no Google Maps review search. NavOSS does not ask for Contacts access.
Because NavOSS has no account and does not retain server-side search, route, or trip records, it normally has no server history to export or delete. A rights request may identify a support message or recent security event, but NavOSS may be unable to associate a transient, IP-only request with a person. Requests about provider-controlled data may also need to be directed to that provider.
Security and international processing
App-to-API traffic uses HTTPS through Cloudflare. The Alberta origin uses an outbound tunnel rather than a public inbound port, key-only SSH, a default-deny firewall, least-privilege containers, security updates, bounded logs, and read-only filesystems where practical. No security measure can guarantee absolute protection.
The NavOSS origin is in Alberta. Cloudflare, OpenFreeMap, Apple, Google when place details are enabled or the external reviews link is chosen, GitHub, and a user-selected share destination may process data outside Canada as described in their policies.
Children and changes
NavOSS is a general-audience navigation utility and is not directed to children. It does not create profiles or knowingly maintain children's personal information. A parent or guardian should supervise a minor's use of navigation and support channels.
Material changes will appear here with a revised effective date. During beta testing, material data-use changes will also be identified in TestFlight release notes before the changed feature is tested.
Contact
Use the repository's
public issue tracker only for
non-sensitive questions. Use
private vulnerability reporting
for a security issue or sensitive privacy request. Internal testers may also use
TestFlight feedback. Never publish a private address or precise trip history. The planned
address navoss@yassin.app is not presented as active until delivery and reply
handling are tested.