Privacy Policy - Punctra
Punctra does not contain advertising or analytics and does not sell personal data. Ordinary journey questions are processed as stateless requests and are not saved as a user travel history.
1) Who we are
Punctra is provided by Saifullah Ahad. Website: https://saifullah.ai. Privacy contact: [email protected].
2) What Punctra does
Punctra compares public-transit departures against an arrival deadline using public timetable and realtime feeds plus a bounded history of observed delays. It can also create an optional, expiring protected-trip watch and send a warning if the estimated reliability changes.
Transit feeds and reliability estimates can be late, incomplete, or incorrect. Punctra is independent of the transit agencies it supports, and its estimates are not guarantees.
3) Information handled
- Anonymous app session: Firebase Authentication creates a random anonymous identifier. Punctra does not ask for or attach a name, email address, phone number, password, or profile.
- Journey request: the selected agency, timetable identifiers, departure and arrival times, and deadline are sent to a Firebase callable function to calculate the answer. The request is not stored as a personal journey history.
- Protected-trip watch: if you choose to protect a trip, Punctra stores a Firebase Cloud Messaging token, departure key, route label, threshold, trip window, and automatic expiry time.
- Public transit data: the backend stores bounded delay histograms, timetable templates, and feed freshness information shared by all users. This is operational transit data, not personal data.
- Local app data: recent agency/journey selections and protected-trip display summaries are stored on your device.
- Service metadata: Google/Firebase may process IP address, device/app integrity signals, and routine security or service logs to deliver and protect the cloud services.
4) Location
Location is optional. Punctra requests foreground location only after you choose Find the nearest supported feed. Your coordinates are compared with supported agency centers on your device. Punctra does not store or send your coordinates to its backend and does not request background location.
5) Notifications
Notification permission is requested only when you protect a trip on Android versions that require permission. Firebase Cloud Messaging uses the device registration token to deliver the requested warning. Punctra does not use notifications for advertising.
6) How information is used
- Answer the journey reliability question you submit.
- Maintain bounded aggregate transit reliability evidence.
- Evaluate and deliver an optional protected-trip warning.
- Protect the backend from unauthorized or automated abuse using Firebase Auth and App Check.
- Remember your latest selection locally for convenience.
7) Service providers and public sources
Punctra uses Google Firebase services: Authentication, App Check, Cloud Functions, Cloud Firestore, and Cloud Messaging. Those services process data under Google's applicable terms and privacy practices. Punctra also retrieves public GTFS and GTFS-Realtime feeds published by supported transit data providers.
We do not sell data, share it with advertisers, or use it for cross-app tracking. Information may be disclosed when legally required or when necessary to protect users and the service.
8) Retention
- Ordinary journey questions are not retained as user history.
- Protected-trip watches are deleted after a warning, when you use the in-app delete control, or when their Firestore TTL expires.
- Local selections and summaries remain until you clear app storage or uninstall Punctra.
- Bounded aggregate transit evidence is retained for the reliability service and is not tied to a user profile.
- Cloud providers may retain limited security and service logs according to their own retention rules.
9) Your controls and deletion
- Open Data inside Punctra to inspect and delete protected-trip watches for the current device token.
- Revoke location or notification permission in Android Settings at any time.
- Clear Punctra storage or uninstall the app to remove its local data and reset its anonymous session.
- Read the complete deletion guide at https://privacy.saifullah.ai/punctra-delete.html.
10) Security
Punctra uses encrypted HTTPS transport, Firebase Authentication, Play Integrity App Check in release builds, server-only Firestore access, bounded instance limits, and automatic expiry for short-lived records. No method of storage or transmission is completely risk-free.
11) Children's privacy
Punctra is a general transit utility and is not directed to children under 13. It does not provide social features, public profiles, chat, or user-generated content, and we do not knowingly collect personal information from children.
12) International processing
Firebase services may process information in countries other than your own. We rely on provider safeguards and applicable legal mechanisms for this processing.
13) Changes
We may update this policy when the app or its services change. The current version will be posted at https://privacy.saifullah.ai/punctra.html with a revised effective date.
14) Contact
Saifullah Ahad
Email: [email protected]
Website: https://saifullah.ai
Location: Dhaka, Bangladesh