Arrivo Privacy Policy
Last updated: 2026-05-22
Release note: replace the developer name, support contact, and `geo-time-recorder.example` host before public launch. Google Play requires an active, non-editable HTTPS web page for the privacy policy.
App and developer
- App: Arrivo
- Developer/entity: Replace with the exact Google Play developer name before release.
- Support contact: hello@example.com — replace before release.
What the app does
Arrivo lets users save places with a latitude, longitude, and radius. When the user enables automatic recording, the app can record the time the device enters or exits the saved geofence.
Data collected or created
- Saved place data: place name, latitude, longitude, radius, active status, and creation/update timestamps.
- Report preference data: the selected all-visible/recent-7-day/current-month/custom-range report preset and saved custom report dates, stored locally to keep the reporting view consistent.
- Location-derived time records: saved place name, enter/exit transition, event timestamp, and whether the event was automatic or manual. Users may edit a record timestamp/transition as a manual correction.
- Import/export files: registered-place CSV files are read only when the user chooses an import file, and history, stay-summary, or premium monthly report package CSV/PDF export files are generated only when the user taps an export/share action.
- Local beta conversion counters: counts for place creation, background-permission completion, free-limit upsell, first time event, report view, CSV export, CSV import completion, and premium-screen opens. These counters stay on the device in the MVP, are shown in the beta metrics card, and are used only for beta product validation unless the user explicitly shares the beta metrics CSV.
- Advertising SDK technical data: AdMob may process device, app, or network data needed to load ads. Development/default builds use test ad IDs; production IDs must be configured only after consent, UMP/Privacy & messaging QA, and Play disclosure review.
Background location use
Arrivo uses background location only for the core feature: automatic entry/exit time recording for places the user configured. If the user grants background location, the app may monitor saved geofence boundaries when the app is closed or not in use — 앱이 닫혀 있거나 사용 중이 아닐 때도 자동 입장/이탈 시간 기록을 위해 위치를 사용할 수 있습니다.
The app does not use background location for advertising or analytics targeting. 위치 데이터는 광고 타게팅에 사용하지 않습니다.
Storage and sharing
- Saved places and time records are stored locally on the device — 기기 내 저장소에 보관됩니다.
- Local beta conversion counters are stored locally on the device, Android Auto Backup is disabled for the MVP, and counters are not transmitted automatically; users can explicitly share a beta metrics CSV from the app.
- Saved-place settings and records remain on the device unless the user deletes them, explicitly imports a registered-place CSV, or explicitly shares a CSV/PDF export.
- Registered-place CSV import uses the system file picker and validates rows locally before saving; CSV export for registered-place settings, time history, and stay summaries plus CSV/PDF export for premium monthly report packages use Android's share sheet, and after the user chooses a share target, that target's privacy practices apply.
- The MVP does not provide cloud backup or account sync.
Retention and deletion
Free users see recent 30-day history in the app; older local records may remain on the device as an extended-history premium candidate until deleted.
Users can edit a single event as a manual correction, delete a single event, delete older-than-30-day history while keeping saved places/recent records, delete records older than the recent-90-day or recent-1-year retention presets, delete all history, or delete all saved places and history in the app. When active places and permissions remain, deleting history also re-syncs automatic recording so future enter/exit records can continue. Deleting all saved places/history also removes automatic geofence registrations and clears local beta conversion counters. 사용자는 앱에서 기록과 위치 데이터를 수정하거나 삭제할 수 있습니다.
Ads and monetization
The MVP includes AdMob banner integration that defaults to test IDs and can be configured with production IDs for release after consent review. When the production build enables the UMP consent gate, banners are blocked until Google's UMP SDK reports that ads can be requested, and the app can show an ad privacy choices entry point when required. Banners are hidden before the first saved place, during background-location disclosure, and for future premium users. Location data is not used for ad targeting.
Premium billing scaffolding and local entitlement storage are present, but paid purchases must not be enabled until Play Console products, purchase verification, acknowledgement, restore, and live entitlement refresh are complete.
Children's data
The app is not designed specifically for children. If the target audience changes, Google Play Families and child-safety requirements must be reviewed before release.
Contact
For privacy questions, contact hello@example.com. Replace this with a monitored production support address before release.