TachoClear — privacy policy
Last updated: 20 September 2026
The short version
TachoClear keeps your driver record on your phone. It has no account or adverts. From version 1.1.1, product analytics, crash reports and privacy-preserving advertising measurement are on by default and can be switched off separately in Settings. They never include your activity log, hours, dates, rules, compliance results, GPS location used by Drive Detection, motion activity, notes or exports. Measurement providers may derive a coarse region from network/IP information and receive product interaction, purchase and technical diagnostic data. Nobody — including us — can see your hours. If you choose to send feedback, the message goes anonymously to TachoClear's shared feedback database. No email or account is required, and that system has no individual reply channel.
Versions covered
Version 1.1.0 build 9 has no third-party measurement SDKs or measurement switches. It sends no product analytics, crash reports or advertising-measurement events. Pro product, purchase, verification and restore requests still connect to Apple's StoreKit. The provider collection and switch behaviour described below starts with version 1.1.1.
What TachoClear stores, and where
Everything you enter stays in the app's own storage on your device:
- your activity log — driving, other work, availability, breaks and rest, with the times
- your settings, including which rules you drive under
- weeks you have told the app about but not logged
- your own notes about Driver CPC training and your card's expiry date
Apple may include app data in your iPhone's normal encrypted backups if you use them, whether to iCloud or to a computer. TachoClear has not independently verified a cross-device restore, so export PDF or CSV before replacing or erasing a phone. Those backups are covered by Apple's terms, not ours, and we have no access to them.
What TachoClear sends
TachoClear sends none of your activity log, settings, GPS location used by Drive Detection, motion activity, driver notes or exports to us. There is no account or driver-record sync.
The app uses Apple's StoreKit framework to ask the App Store for TachoClear Pro product information and to purchase, verify or restore Pro access. Apple processes those App Store requests under Apple's terms and privacy policy. They contain the App Store transaction information Apple needs, not your driver record. This does not prevent the shift tracker, saved records or rules guide from working without a signal.
From version 1.1.1, TachoClear also uses:
- PostHog for a small set of pseudonymous product milestones such as completed setup, first completed shift, paywall views, purchase outcomes and export format. The app sends these events explicitly. It disables automatic lifecycle, screen, UI-interaction, feature-flag, push, survey, replay and error capture; it does not create person profiles. Before an event is queued or sent, the app strips SDK-added device, locale, screen, time-zone and session details. PostHog is also instructed not to derive GeoIP location fields from the event's network address. PostHog retains a generic anonymous installation identifier to group product journeys while analytics is enabled. That persistent identifier makes the product events pseudonymously linked to the app installation under Apple's App Privacy definition. TachoClear never supplies a name, contact detail or TachoClear account identity.
- Firebase Crashlytics for crash reports and technical diagnostics needed to find stability problems. Firebase associates reports with app-installation identifiers; TachoClear does not add your name, contact details, account identity or your own text to them.
- AppsFlyer to measure which advertising campaigns lead to an install, first completed shift, paywall view or Pro purchase. A purchase event contains the product identifier, value and currency, but never an App Store transaction identifier or receipt. AppsFlyer generates an identifier for the app installation even though TachoClear disables Apple's IDFA and IDFV.
PostHog retains its anonymous installation identifier. PostHog, Crashlytics and AppsFlyer can therefore associate their respective events or reports with an app installation over time while its measurement is enabled. This is installation-level linkage, not a claim that a provider knows the driver's real-world identity. Each provider can receive the network/IP information involved in a request; AppsFlyer and Crashlytics can also receive ordinary technical information needed to provide their services, such as app version, device model, operating-system version and event time. Purchase events may include the product, price/value and currency. TachoClear does not request Apple's permission to track you across other companies' apps or websites, does not access the advertising identifier, and limits AppsFlyer to privacy-preserving attribution such as SKAdNetwork.
In version 1.1.1, product analytics, advertising measurement and crash reports have separate switches in Settings and all start on. On a cold launch with Product analytics off, TachoClear does not initialise PostHog. If analytics is turned off during an enabled session, it stops new collection and queued sending. It does not delete data already sent or file-backed events captured while analytics was previously on: if you later re-enable analytics, PostHog may send those offline events. A request already in progress cannot be recalled. Turning off Crash reports stops new Firebase Crashlytics reports. Turning off advertising measurement also configures AppsFlyer's SKAdNetwork attribution as disabled. TachoClear does not ask Apple to send AppsFlyer copies of SKAdNetwork postbacks. Data sent before a switch is turned off remains subject to the relevant provider's retention and deletion rules. PostHog, Google and AppsFlyer act as service providers for these purposes under their own privacy and security terms.
Optional feedback
Today and Settings include an optional way to share an idea, feature request, suggestion or problem. Nothing is sent merely because the invitation or form appears. When you tap Send, TachoClear sends:
- the message and whether you labelled it as an idea, problem or other feedback
- the place in the app where you opened the form
- the app version and build, platform, operating-system version and locale
- a random submission UUID used to acknowledge the exact message and make a retry duplicate-safe
The shared feedback service uses Neon Auth to issue a short-lived anonymous token and Neon to process and store the submission. The feedback tables store no name, email, account ID, advertising or device identifier, or IP address. Neon necessarily receives network information while processing the request, but TachoClear does not put it into the feedback record. There is no individual reply channel, so do not include personal information or anything that needs a response.
An unfinished draft stays in TachoClear's own storage on your iPhone. Closing the form keeps the draft so you can return to it; Discard draft removes it. A successful send clears the local draft only after the service acknowledges the matching UUID. Failed sends keep the draft and offer a retry. Submitted feedback is kept until Tom deletes it from the shared feedback database. Provider backups may retain deleted records within their restore window.
This feedback transport is separate from product analytics. It remains available if Product analytics is switched off. TachoClear may record content-free events such as opening the form or whether a send succeeded while Product analytics is enabled, but it never puts the message, submission UUID, token or error detail into PostHog.
Location and motion
Drive Detection is off by default. While it is off, the app never asks the system for your location or your motion activity.
If you turn it on:
- it reads high-confidence motion activity as the required automatic-switch signal and may use location speed as corroborating evidence while the app is open
- both are processed on your device, in the moment, to decide whether to log a switch between driving and other work
- neither is stored as a track, a route or a history. The only thing that survives is the activity entry it created, which is the same entry you would have made by tapping
- no GPS location or motion data used by Drive Detection is transmitted by TachoClear or included in StoreKit requests; measurement providers may still derive a coarse region from network/IP data
- you can turn it off at any time in Settings, or revoke the permission in iOS Settings, and the app remains fully usable by tapping to switch
Exports and sharing
When you create a PDF or a CSV, the file is written to your device and handed to the iOS share sheet. Where it goes after that is your choice. TachoClear does not upload it, keep a copy, or see where you send it.
Notifications
Break, finish and other reminders are scheduled locally by your phone from times the app has worked out. No notification goes through a server, and nothing about them leaves the device.
Analytics provided by Apple
Apple gives every developer aggregate, anonymised statistics about downloads and crashes through App Store Connect. That is Apple's measurement of the App Store, not ours of you, and it contains nothing about your hours. This is separate from the PostHog and AppsFlyer measurement described above.
Children
TachoClear is a tool for professional drivers. It is not directed at children.
Your rights
Your driver record is yours: export it whenever you like, and delete it from Settings → Your data, where a full wipe asks you to type a confirmation first and offers an export before it happens. Because TachoClear has no account and provider metrics use pseudonymous installation identifiers rather than your name or contact details, we generally cannot connect a particular provider-side event to you from a support request alone. You can stop future collection at any time in Settings. Contact us with a privacy request or question and we will explain what can be actioned directly and what requires the relevant provider.
Changes
If a future version of TachoClear ever needs to transmit your app data, this policy will say so before that version ships, and the App Store privacy answers will change with it.
Contact
Tom Murton — support@weevolve.app
TachoClear is a planning aid, not the legal record — your tachograph is. Not legal advice.
Contains public sector information licensed under the Open Government Licence v3.0.