1. Introduction
TPASS.calc (hereinafter referred to as "the Application") is developed by Cheng Ruei Hsu (hereinafter referred to as "we" or "us"). We are deeply committed to protecting your privacy and data security. This Privacy Policy explains how the Application handles your data and your privacy rights.
2. Core Data Storage and Collection Methods
The Application's core functionality uses a "Local-First" architecture, and your trips and settings stay on your device by default. The following are exceptions where necessary data leaves your device: "Route Planning / Map Queries" in Section 4, voice parsing logs shared with your explicit consent in Section 5, and "Issue Reports and Pro Support" actively submitted by you in Section 6. Each section explains the content, purpose, identity linkage, and available controls:
- Local Storage: All trip records, favorite routes, TPASS cycle settings, and user preferences you create within the app are stored exclusively on your personal device (via SwiftData and UserDefaults).
- NFC and Web Import: All reading, parsing, and filtering operations for NFC card scanning and official website data import are performed locally on your device. We do not upload your card numbers, verification codes, or transaction details to any third-party servers.
3. Location Data and Automatic Trip Detection
"Automatic Trip Detection" is an optional feature that is off by default. It only works after you enable it and grant location permission:
- Detection Modes: Three levels are offered — "Off (default, no location activity)", "Only While Using the App (one-time foreground sampling)", and "Automatic Background Detection (requires 'Always' location permission; uses low-power Visit and Significant-Location-Change monitoring, not continuous precise tracking)".
- Processed Entirely On-Device: All waypoint matching and trip inference happen locally on your device. We do not upload your location or movement history to any server.
- Suggestions Only: Each detected trip is merely a suggestion pending your review, and is written into your records only after you confirm or edit it.
- Turn Off Anytime: You can disable it in the Automatic Detection settings within the app's "Advanced" tab, or adjust/revoke location permission in iOS Settings.
4. Route Planning and Map Queries (Third-Party Services)
"Route Planning" is an optional feature. When you use it, the Application sends the necessary queries to the following third-party services to obtain places and multi-modal routes:
- Apple Maps (MapKit): When you search for origin/destination places, your typed text and preferred region are sent to Apple for place search, subject to Apple's Privacy Policy.
- Taiwan's Transport Data eXchange (TDX): To plan multi-modal routes, the coordinates of your selected origin/destination are sent to the TDX API (tdx.transportdata.tw) to retrieve routes and schedules, subject to TDX's terms of service.
These queries contain only the place text or coordinates needed to complete the planning, and do not include your name, Apple ID, or other identifying information. We also do not retain your query history on our own external servers.
5. Voice Recognition and Optional Parsing-Log Sharing
"Voice Quick Record" works without sharing data. On a new install, its Info sheet initially recommends sharing as enabled, but the Application uploads nothing until you explicitly tap "Agree and Continue":
- Permission Requests: This feature requires your "Microphone" and "Speech Recognition" permissions to function. Your voice audio is processed by Apple's native speech recognition technology (SFSpeechRecognizer).
- Consent Before Sharing: The initially enabled preference is a recommendation, not consent. It takes effect only after you tap "Agree and Continue." To decline sharing, close the sheet from the top-left; Voice Quick Record remains available.
- What Is Shared: After consent, successful, failed, and abandoned voice-parsing attempts may be uploaded to improve the natural-language parser. Records may contain the original transcript, parsed and final results, correction fields, failure reason, confidence data, app or rules versions, and technical details of the parsing process: device model code (e.g. iPhone17,1, not a device identifier), iOS version, the TPASS region of your active plan, the recognition engine used and the time each step took, your editing activity on the result screen (time spent and which fields you changed), and a code generated at random each time the voice screen opens to link retries within the same session (not linked to your identity or device). Shared content does not include audio recordings.
- Private Cloud Compute (Pro, iOS 27 or later): If you use Pro "Enhanced Recognition" or choose Private Cloud Compute as the recognition engine, the transcribed text (not audio) is sent to Apple's Private Cloud Compute for parsing. This processing is performed by Apple and is separate from parsing-log sharing; you can turn it off from the engine menu on the voice screen.
- Identity and Sensitive Content: We do not add custom Apple ID, device ID, or email fields. However, dictated text can itself contain names, addresses, or other personal information, and CloudKit may retain system creator metadata. We therefore do not claim that every sample is fully anonymous. Please do not dictate sensitive information.
- Access, Retention, and Deletion: Logs are available only to authorized developers for parsing-quality analysis and are retained only as long as needed for model improvement and quality validation, after which they are deleted or de-identified. To request access to or deletion of a previously shared log, email tpass.calc@gmail.com with an approximate upload time and a transcript fragment that can identify it.
- Turn Off Anytime: Disable future sharing under "Voice Quick Record → Info → Privacy."
6. Issue Reports and Pro Support
The following support content is uploaded only when you actively submit it and is read and processed by us (the developer):
- Report an Issue (all users): the description you submit, an optional contact email, and your app and iOS versions attached automatically.
- Pro Support (subscribers): the case subject, the full conversation, an optional contact email, optional screenshot attachments, and your app and iOS versions attached automatically.
- Screenshot attachments (optional): in a Pro Support conversation you may attach screenshots, and we may reply with screenshots to explain a step. Images are always re-encoded on your device before upload, which strips capture location (GPS), device model and other metadata. Note that the screenshot itself may still show your trip history, stops and times, so please review it before sending. We receive an image only when you attach it yourself; the app uses the system photo picker and does not need or request access to your photo library.
- Where it is stored: in our Apple CloudKit public database. We do not transfer it to any other third-party server, and never use it for advertising or cross-app tracking.
- Link to your identity: so that you see only your own cases and we can reply to the right person, each case carries a hash derived from your iCloud user identifier; CloudKit itself also records a creator identifier. Support content is therefore data linked to your identity, and we do not claim it is anonymous.
- Who can access it: other users cannot read your cases. Only developers holding support-admin permission can read and reply.
- Your control: open any case under "Settings → Pro Support" in the app and choose Delete this case from the top-right menu. The entire conversation, including any screenshots in it, is deleted permanently and becomes unreadable to us as well.
- Retention: case content is kept until you delete it, or until we have confirmed the case is resolved and no longer needs to be retained.
- Please do not share sensitive information: support conversations are free text and may include screenshots. Please do not include passwords, credit card numbers, or national ID numbers in either. We will never ask you for such information.
7. Subscriptions and In-App Purchases (TPASS Pro)
Certain advanced features (such as Route Planning and Automatic Trip Detection) require a "TPASS Pro" subscription:
- Payment Handled by Apple: Subscriptions are purchased and charged through the Apple App Store (StoreKit). We do not access or store your credit card or other payment information.
- Subscription Status: The Application determines whether your subscription is active on your device using verified StoreKit transactions and entitlements provided by Apple. We do not create TPASS.calc member accounts, nor do we access your complete payment details or payment method.
- Pro Support Eligibility and Diagnostics: When you actively create a Pro Support case, the case includes the current subscription status, entitlement source, and app installation channel so that we can confirm support eligibility and diagnose TestFlight, Sandbox, or production App Store transaction issues. This diagnostic information is stored with the support case in Apple CloudKit and is retained and deleted as described in Section 6.
- Manage and Cancel: You can manage or cancel anytime via iOS "Settings → Apple ID → Subscriptions". See the Terms of Use for details.
8. Cloud Backup (Apple iCloud)
The Application does not use any third-party authentication services that require account registration (no login mechanism). We only provide backup services supported by Apple's native platform:
- Apple iCloud (CloudKit): If you choose to enable cloud backup, your data will be encrypted and synchronized to your personal iCloud Private Database. We (the developer) have absolutely no ability to access, read, or modify any data stored in your personal iCloud space.
- Service Configuration Read: The Application reads necessary service configuration (such as the service key required for Route Planning) from our CloudKit public database. This particular operation is read-only and does not involve or upload any of your personal data.
- Writes to the public database: When you choose to use "Report an Issue" or "Pro Support," or consent to voice parsing-log sharing in Section 5, the relevant content is written to our CloudKit public database and is readable by us.
9. Purposes of Data Use
All your trip and operation records are used exclusively for functionality within the Application, including:
- Calculating the actual payment and discount amounts for TPASS plans.
- Generating personal commute data dashboards (monthly pass ROI, route rankings, etc.).
- Providing daily reminders and periodic push notifications (all triggered and sent locally on your device).
We will never sell, rent, or share your data with any third party for commercial or marketing purposes.
10. Data Security
To protect your privacy, we implement the following security measures:
- Local Encryption: All data stored locally on your device is protected by iOS's built-in encryption mechanisms.
- Transmission Encryption: When data is synchronized to iCloud, it is protected using TLS/SSL encryption protocols to ensure transmission security.
- Data Minimization: Voice parsing logs do not include audio recordings or custom Apple ID, device ID, or email fields, but transcripts may contain dictated information as explained in Section 5.
11. Data Deletion and User Control
You can manage local data, private iCloud data, and the public-database content described in this policy through in-app controls or by contacting us:
- Clear Local Data: You can delete all trip records and settings stored locally by using the one-click clear option in the app's Settings page.
- Delete Cloud Backup: You can directly delete your CloudKit backup data stored in your iCloud space through the app's Settings page.
- Export Data: You can export your data as a CSV file anytime for offline backup or cross-device migration purposes.
- Access Your Data: You can view all personal data stored in the application at any time.
- Stop or Delete Voice Sharing: Stop new sharing under "Voice Quick Record → Info → Privacy." Request access to or deletion of previously shared samples as described in Section 5.
12. Cookies and Tracking
The Application does not use cookies or any similar tracking mechanisms. We do not use third-party tracking tools, advertising technologies, or analytics platforms (such as Google Analytics) to monitor your behavior.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal changes or updates to our practices. Any significant changes will be notified through the Application or announced on our official website. Your continued use of the Application signifies your acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions or suggestions regarding this Privacy Policy, please feel free to contact us:
Email: tpass.calc@gmail.com