Privacy Policy
Effective date: June 11, 2026
Gridlock NYC ("Gridlock," "we," "us") is a game about exploring New York City on foot. This policy describes what data Gridlock collects, where it is stored, and your rights.
What stays on your device
Gridlock is designed so your detailed outing history is stored on your iPhone. This includes:
- Your personal explored-hex history and visit timestamps
- Your outing log: dates, distance, new hexes per outing, and the coarse shapes of the hexes you explored (derived from hex IDs, not GPS traces)
- Daily anti-cheat counters derived from motion checks
Raw GPS coordinates and raw motion samples are processed on this device during active outings and are not kept anywhere: Gridlock does not store or upload raw GPS routes or raw motion samples, and no movement path ever leaves your device. This local data is stored in the app's private sandbox and is removed from the device when you delete local data or uninstall the app.
What we receive
Cloud-enabled builds create a Supabase account, which may be anonymous or linked to Sign in with Apple. We receive:
- Account ID and, if you use Sign in with Apple, the email/name Apple shares
- Aggregate gameplay stats such as total hexes, borough totals, streaks, daily explored-hex counts by date, and total distance on foot
- Your display name and avatar choice, if you set them, and your chosen home neighborhood
- Weekly neighborhood hex counts that enter your home neighborhood in the weekly race (on by default once you pick a home neighborhood; opt out anytime in Settings)
- While you are on an outing, coarse "walking now" pings (borough and neighborhood only, never coordinates) that update shared live counters, plus a per-account rate-limit timestamp that clears within minutes
- Anonymous community coverage rows: H3 hex ID, neighborhood, borough, and first-lit time, stored without a user ID, plus an hourly count of how many hexes your account uploaded (an anti-abuse measure that stores no location)
- Optional bug reports you submit (your category choice, the text you enter, your app version, and your iOS version) and hex-removal requests (the hex ID being reported, a reason, and any note you add)
We do not intentionally receive your raw GPS coordinates, movement route, or per-outing timeline.
Motion and pedometer data
Gridlock uses iOS Core Motion (CMMotionActivity and CMPedometer) to verify that progress comes from real on-foot movement. This data is processed entirely on-device for anti-cheat validation and is never transmitted to any server, sold, shared with third parties, or used for advertising, marketing, analytics, or tracking.
Location permission
Gridlock uses location during active outings to light up hexes. If you grant background location, tracking can continue while your iPhone is locked or in your pocket. You can revoke location access at any time in iOS Settings. Some account and community features use derived counts from explored hexes and coarse presence pings (borough and neighborhood), but never raw GPS routes.
Third-party services
- Supabase — authentication, account storage, aggregate stats, community coverage, bug reports, and moderation requests. See supabase.com/privacy.
- Apple Sign-In — optional account authentication. We receive only the information Apple shares per your Apple ID settings.
- Apple system services — local notifications and Live Activities when you enable those features.
- Gridlock map tiles — map rendering. Tile requests contain standard HTTP headers such as IP address and user agent, and the requested tile coordinates indicate the general map area you are viewing. Map data uses OpenMapTiles-compatible tiles derived from © OpenStreetMap contributors, licensed under ODbL. Full license at openstreetmap.org/copyright
- OpenFreeMap — map glyph (font) resources. Glyph requests contain standard HTTP headers such as IP address and user agent and include no location data.
Data retention
On-device data persists until you delete it in Settings or uninstall the app. Account-linked server data is retained while your account exists and is removed when account deletion completes. Anonymous community coverage and feed rollups may remain after account deletion because they are not tied to your account. Short-lived live-presence counters expire automatically.
Children
Gridlock is not directed at children under 13. We do not knowingly collect data from children under 13.
Your rights
You can:
- Delete local data at any time from Settings
- Request account and account-linked server data deletion from Settings
- Revoke location permission at any time in iOS Settings
- Opt out of the weekly neighborhood race in Settings
- Avoid optional submissions such as bug reports or hex-removal notes
For questions or data requests, contact privacy@gridlock-nyc.com.
Changes
We may update this policy. Material changes will be communicated through the app. Continued use after changes constitutes acceptance.