OnRoute Labs ("OnRoute," "we," "us," or "our") operates the OnRoute mobile application (the "App"). This Privacy Policy explains how we collect, use, share, and protect your information when you use the App. We are committed to transparency and to giving you meaningful control over your data.
This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 ("DPDPA"). For users in the European Economic Area (EEA), United Kingdom, and California, additional rights apply as described in the "Your Rights" section below.
If you do not agree with this Privacy Policy, please do not use the App.
1. Who We Are
OnRoute Labs is the operating name used by Aswin Madollathil, an individual operating a mobile application business based in India.
Contact for privacy questions: support@onroutelabs.com
Mailing address: Aswin Madollathil, 2145, DSR Sunrise Towers, Channasandra Main Road, Whitefield, Bangalore — 560067, Karnataka, India
For the purposes of the DPDPA, OnRoute Labs is the Data Fiduciary. For GDPR purposes, we are the Data Controller.
2. Information We Collect
We collect only the information necessary to provide and improve the App. We do not sell your personal information.
2.1 Information you provide directly
- Account-style preferences: your display name (used inside the App and on shared trips), preferred language, voice and vehicle preferences.
- Trip details: origin, destination, travel dates, traveler names and types (adult/kid), expenses you log, free-text checklist items, and any notes you add to a trip.
- Feedback you send us: the contents of any feedback or bug report you submit through the App's feedback form, along with your email address if you choose to provide it.
- Trip stories: if you turn a finished trip into a story and publish it, we keep what the story says on our servers so its page can be read: the title and introduction you wrote; a first name and a home city, only if you type them in; the month and year of the trip, never the dates; each day's start and end; the places you actually stopped at (their names, towns and map positions); the distance and time driven; a one-line summary of each day; and your own note, for the days you choose. A story never carries your photographs (the pictures on its page are Google's photographs of the places), your exact starting point, money in any form, or the people you travelled with.
2.2 Information collected automatically
- Location data: while you use the App, it uses your device's GPS location to plan routes, give turn-by-turn directions and find places near you (restaurants, fuel, restrooms). When a search needs our server, the App sends it the coordinates of the area being searched. Only when you turn it on does the App share your current position with the other members of your convoy or the people you shared a trip with. Our servers keep a position only where a feature you turned on needs it: your convoy's last positions, until 24 hours after the convoy's last activity, and a shared trip's last position, until the share expires (see section 5).
- Voice co-pilot: when you tap the co-pilot button and speak, your question is recorded for as long as you speak, sent to our server and forwarded to Google's Gemini, which works out what you asked and writes the answer. With the question, the App sends what the co-pilot needs to answer well: your first name (if you gave one), your convoy members' names, the place you're passing, your next stop, your speed and your approximate location (to about a kilometre, for questions about where you are). Newer versions of the App ask for your permission before they first send any of this; if yours doesn't, updating it adds the question. We do not keep voice recordings after the answer is generated.
- Wake-word listening ("Hey OnRoute"): this is off by default and you turn it on yourself. When it is on, the microphone stays open only while a trip is active so the App can hear the wake phrase. That listening happens entirely on your device, using your phone's built-in offline speech recogniser — OnRoute refuses to start the wake-word engine at all if your device cannot recognise speech offline. Audio captured before you say the wake phrase is never transmitted to us or to anyone else, is never written to storage, and exists only in a short rolling buffer in memory that is continuously overwritten. Only the words you speak after the wake phrase leave your device, and only as text.
- Motion data (crash detection and driving check-ins): if you enable crash detection, the App reads your device's accelerometer while you drive, about twenty times a second, to notice the signature of a sudden impact. This motion data never leaves your device and is never stored — it is evaluated in memory as it arrives and then discarded. If a possible crash is detected, or you do not answer a driving check-in, the App asks you first and waits thirty seconds. Only if you do not respond does it send an alert: a crash alert carries your current coordinates, an unanswered check-in carries no location at all. Those alerts go to the other members of your convoy through our servers and to nobody else. An optional feature that opens thirty seconds of live microphone to your convoy after a detected crash is also off by default.
- OnAir (trip radio): to write a radio segment for your drive, the App sends our server the car's current position and a point a little way ahead, the names of the places on your route and how far apart they are, the total distance and duration, your display name and the names of the people in your convoy. Our server looks up places near that position on Wikipedia, using the position rounded to about a kilometre, and passes the facts to Google's Gemini to write the script. We do not send your account or any device identifier — the request is unauthenticated. The spoken audio is produced by your phone's own text-to-speech; no audio file is created or uploaded anywhere. Nothing about the request is stored, apart from the nearby places we found, which are kept for a few hours so the next car passing gets them faster. As with the co-pilot, newer versions of the App ask for your permission first. Your device keeps only a small counter of how many segments have played on the current trip.
- Convoy voice (walkie-talkie): when you hold the convoy talk button (or use a hands-free voice send), your voice is streamed in real time to the other members of your convoy via LiveKit, our real-time voice infrastructure provider. Live voice is transient — it plays to convoy members as you speak and is not recorded or stored by us. If the live channel is unavailable, the App falls back to recording a short voice clip (up to 15 seconds) that is uploaded to our server solely for delivery to your convoy and deleted 24 hours after it is uploaded.
- Flight price alerts and push notifications: if you save an OnFlight price alert, we store the alert's route, dates, and target price together with your device's push notification token on our servers so we can check prices periodically and notify you when they drop. The token is used only to deliver OnRoute's notifications. When you delete an alert, we delete it and its token. When an alert's travel dates have passed, we keep its route, dates and prices for statistics, but delete the push token and the ID that linked it to your phone.
- Camera roll photos: the trip recap feature, if you enable it, reads photos from your device's camera roll that were taken within the geographic and time window of a completed trip. These photos are processed on your device and are not uploaded to our servers unless you explicitly choose to share the recap.
- Weather: to show the forecast at your stops, the App sends each stop's coordinates and the time you'll reach it to our server, which asks MET Norway (the Norwegian Meteorological Institute) for the forecast, using the position rounded to about a kilometre. MET Norway sees our server, not you. Older versions of the App asked Open-Meteo for the forecast directly from your phone, sending the stop's coordinates.
- Place search and routes: when you search for a place, the text you type goes either to our server, which asks Google Places, or from your phone to Photon, a search service run by komoot on OpenStreetMap data. When the App looks up the name of where you are, it sends your position to Photon. Routes are drawn by Google's Routes API, called from your phone; if Google can't answer, the App asks the public OSRM route server instead. These services receive the text or the coordinates, not your name.
- Crash reports and app health: we use Sentry. When the App crashes or hits an error, the report includes your device model, operating system and app version, and the last screens and taps before it, so we can reproduce the bug. Sentry also receives performance timings from about one in five uses of the App, and counts app sessions so we can see how often the App crashes. All of this is linked to a random ID created for this installation, not to your name or contact details. We don't use analytics or advertising tools.
- Server logs: our servers keep a short record of each request — your IP address, the part of the App asking, the time, whether it worked, and the app and system version your phone sends with every request — to keep the service secure and fix errors. The record can also include the web address the App asked for, which for some requests contains what was searched for (a place name, a flight route, or the area of a nearby search). It never includes what you say to the co-pilot or the messages you send.
2.3 Information collected through third parties
The App uses the following third-party services that may collect or process your information on our behalf or for their own purposes:
- Google (Maps SDK, Places API, Routes API, Gemini): map rendering, place search and route planning; and Google's Gemini, which receives your co-pilot questions (voice or text) with the details listed in section 2.2, OnAir's trip facts, your Trip Designer requests (the destination, dates, who is travelling and what you asked for), the names of places for restaurant descriptions and trip summaries, and up to three town names and a season to draw your year card's picture. We use Gemini as a paid service. Under Google's terms for it, Google does not use what we send, or Gemini's answers, to improve its products; it processes them as our data processor and keeps them for a limited time only, to detect misuse and for any disclosures the law requires. Google's privacy practices are described at policies.google.com/privacy.
- Google Cloud: runs our servers, database and logs, in Tokyo (see section 8).
- LiveKit: relays real-time convoy voice between convoy members. Voice passes through LiveKit's infrastructure for live delivery and is not stored there. LiveKit's privacy practices are described at livekit.io/legal/privacy-policy.
- Sentry: receives the crash reports, performance timings and session counts described in section 2.2 so we can fix bugs. See sentry.io/privacy.
- Expo (push notification delivery): delivers OnRoute's push notifications (for example, flight price-drop alerts) using your device's push token. See expo.dev/privacy.
- RevenueCat: manages Pro subscriptions for us. It receives an anonymous app user ID and your purchase records from Apple. See revenuecat.com/privacy.
- Apple (App Store): if you buy a Pro subscription, Apple processes the payment. We do not see your payment details.
- Travelpayouts / Aviasales and Ixigo: Travelpayouts receives the flight routes and dates you search in OnFlight (no personal identifiers) and returns fares. When you tap Book, Aviasales or Ixigo opens in your browser, and their privacy policy applies there.
- OpenStreetMap (Overpass API): receives anonymous queries for points of interest along your route, from our server. No personal information is sent.
- Photon (komoot): receives the place names you type and, when the App looks up where you are, your position, directly from your phone.
- OSRM: the public route server of the Project OSRM, asked only when Google's Routes API can't answer; it receives your route's coordinates from your phone.
- MET Norway: receives the stop positions our server asks forecasts for, rounded to about a kilometre. It never sees your phone.
- Open-Meteo: used by older versions of the App for forecasts; it received each stop's coordinates directly from your phone.
- Wikipedia (Wikimedia Foundation): receives a position rounded to about a kilometre when OnAir looks for places nearby, from our server; nothing about you.
- Resend: when you submit feedback through the App, or submit a trip story for review, we use Resend to deliver it to our team email. Resend may temporarily process the contents and your email address.
- Cloudflare: hosts our website, onroutelabs.com (see section 10).
- Affiliate networks (Amazon Associates, Awin and Commission Junction for Booking.com, GetYourGuide, Klook, and Indian travel partners such as MakeMyTrip, Goibibo, Cleartrip, Yatra and ixigo): when you tap an outbound shopping or booking link in the App, you are taken to the partner's website and an affiliate tracking parameter may accompany the link. Once you leave the App, the partner's privacy policy applies to your interactions on their site. We may receive aggregated commission reports identifying that a sale occurred via our link, but we do not receive identifying information about you from these partners.
2.4 What the App can see but deliberately does not send us
Some things are visible to the App on your device and stay there by design. We list them because "we could have, and chose not to" is worth stating plainly:
- What you are listening to. When you connect Apple Music or Spotify, the App reads the current track and artist so it can show them on the drive screen and duck the volume at the right moment. That information is never sent to our servers, and it is never included in the context we send to generate an OnAir segment.
- Audio before the wake phrase. See the wake-word entry above. It never leaves the device in any form.
- Accelerometer readings. Evaluated on the device and discarded. Only the conclusion — "a possible crash happened here" — is ever transmitted, and only to your convoy.
- Your trip recap photos. Selected, filtered, and rendered on your device. Nothing is uploaded to us; when you share a recap, your phone's own share sheet hands the finished image to whichever app you pick.
3. How We Use Your Information
We use your information for the following purposes:
- To provide the App's core features: route planning, navigation, meal and stop suggestions, voice co-pilot, OnAir trip radio, trip sharing, trip stories, convoy coordination, trip recaps, and the optional driving check-in and crash-detection safety features.
- To process and fulfil your Pro subscription, if purchased.
- To respond to your feedback or support requests.
- To improve the App, including by fixing bugs and analysing aggregate usage patterns.
- To comply with applicable law and to enforce our Terms of Service.
We process your information on the following legal bases:
- Performance of a contract: providing the App and its features.
- Consent: location sharing in convoys, voice co-pilot, wake-word listening, sending your co-pilot questions and OnAir's trip facts to Google's Gemini, crash detection and its optional hot microphone, and camera roll access for trip recaps. Each of these is off until you turn it on, and you can withdraw consent at any time in the App's Settings or in your device's system settings.
- Legitimate interests: crash reports and app health (section 2.2), security, and bug-fixing, balanced against your rights and freedoms.
- Legal obligation: complying with tax, accounting, and law enforcement requests.
4. How We Share Your Information
We share your information only as follows:
- With service providers (Google and Google Cloud, LiveKit, Sentry, Expo, RevenueCat, Resend, Apple, MET Norway, Cloudflare) that operate parts of the App on our behalf under contractual confidentiality obligations.
- With other users when you choose to share a trip or join a convoy. Recipients of a shared trip code can see the trip's destination, route, expenses, and (if you enable live location sharing) your real-time position. Convoy members can see each other's positions and exchange voice and text messages; live convoy voice is heard by all members of your convoy as you speak.
- With anyone who has a story's link when you publish a trip story: the link is how a story is read, and whoever you send it to can pass it on. Until then a story is kept out of search engines and listed nowhere. If you submit it to us and an editor accepts it, it becomes public: it can appear in the App under the drive it matches, and search engines may list it.
- With affiliate partners in the limited sense that an affiliate tag accompanies outbound links you tap, allowing the partner to credit OnRoute Labs with the referral.
- In response to legal process if compelled by a valid legal request (subpoena, court order) from an authority of competent jurisdiction.
- In connection with a business transfer if OnRoute Labs is sold, merged, or otherwise reorganised, your information may transfer to the successor entity subject to this Privacy Policy.
We do not sell your personal information. We do not share your information with advertising networks for cross-context behavioural advertising.
5. Data Retention
- On-device data (your trips, expenses, checklists, preferences) is stored on your device and remains there until you delete it or uninstall the App.
- Shared trip data (a trip you share with a share code, including its last position if you share live location) is kept on our servers until 30 days after it is created, then deleted.
- Convoy data (the members, their last positions and messages) is kept until 24 hours after the convoy's last activity, or until its last member leaves.
- Voice co-pilot recordings are not retained after the response is generated.
- Convoy voice is not recorded on the live channel. A fallback voice clip is deleted 24 hours after it is uploaded.
- Wake-word audio and accelerometer readings are never retained anywhere, on our servers or on your device.
- OnAir segments are not retained. The script is generated, spoken, and discarded; our OnAir endpoint keeps no record of the request.
- Saved price alerts (route, dates, target price, push token) are kept until you delete the alert in the App. When an alert's travel dates have passed, we keep its route, dates and prices for statistics and delete the push token and the ID that linked it to your phone.
- Trip stories stay on our servers until you delete them. Deleting a story in the App removes it from our servers at once, and its page stops working immediately. If you no longer have the phone that published it, email us and we will delete it for you. Copies other people have already made are outside our control.
- Feedback submissions, and the notice we receive when a story is submitted for review, are retained in our team email for as long as necessary to respond to and resolve the issue raised. A copy of feedback also stays on our server until the server next restarts.
- Server logs (IP address, the part of the App asking, time, result, app and system version, and for some requests what was searched for) are kept for 30 days.
You can delete all of your on-device data by uninstalling the App. To request deletion of any server-side data tied to your shared trips or your stories, contact us at the email above.
6. Data Security
We use industry-standard security measures including HTTPS encryption for all data in transit, restricted access controls on our servers, and minimal data collection by design. No method of electronic transmission or storage is one-hundred-percent secure; while we strive to protect your information, we cannot guarantee absolute security.
If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law.
7. Children's Privacy
The App is intended for users aged eighteen (18) and older. We do not knowingly collect personal information from anyone under eighteen (a "child" under the DPDPA). If you believe someone under eighteen has provided personal information to us, please contact us at support@onroutelabs.com and we will delete it.
8. International Data Transfers
OnRoute Labs is based in India. The App's backend services run on Google Cloud Platform in the asia-northeast1 region (Tokyo). Some of our service providers (Google, Resend, Apple) operate globally and may process your information outside your country of residence. Where required by law (for example, for transfers from the EEA), we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
9. Your Rights
Subject to applicable law, you have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — request that we correct inaccurate or incomplete information.
- Deletion — request that we delete your personal information, subject to legal retention obligations.
- Restriction or objection — request that we restrict or stop processing your information in certain situations.
- Data portability — receive a copy of your information in a structured, machine-readable format.
- Withdraw consent — where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Complaint — lodge a complaint with the Data Protection Board of India (under the DPDPA), your local supervisory authority (under GDPR), or the California Privacy Protection Agency (under CCPA/CPRA).
To exercise any of these rights, email support@onroutelabs.com. We will respond within the time frame required by applicable law (typically thirty days).
9.1 California residents (CCPA/CPRA)
California residents have the right to know what categories of personal information we collect, the right to delete personal information, the right to correct inaccurate information, and the right to opt out of "sale" or "sharing" for cross-context behavioural advertising. We do not sell or share personal information for cross-context behavioural advertising. To exercise these rights, contact us at the email above.
9.2 EEA / UK residents (GDPR)
In addition to the rights listed above, EEA and UK residents may lodge a complaint with their local data protection authority.
9.3 Do Not Track
We don't track you across other companies' apps or websites, and we don't let anyone else do so through OnRoute. So we treat every request the same way whether or not your browser or device sends a Do Not Track or Global Privacy Control signal.
10. Cookies and Similar Technologies
The App does not use cookies, and it doesn't use your device's advertising identifier. We do not use any tracking technologies that operate across third-party apps or websites.
Our website, onroutelabs.com, does not set cookies either, and it does not run any analytics script. It is served by Cloudflare, which receives your IP address in order to deliver the pages, as any web host does, and keeps aggregate traffic figures (such as how many requests arrived, and from which countries) from its own records. The details, including the one security cookie Cloudflare may set, are in our Cookie Policy.
11. Third-Party Links
The App contains affiliate and informational links to external websites (e.g. Amazon, Booking.com, GetYourGuide). When you tap such a link, you leave the App and the linked party's privacy policy governs your interactions with them. We are not responsible for the practices of third-party sites.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify you in the App and update the "Last updated" date at the top of this policy. Your continued use of the App after a change takes effect constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, contact us at:
Email: support@onroutelabs.com
Mailing address: Aswin Madollathil, 2145, DSR Sunrise Towers, Channasandra Main Road, Whitefield, Bangalore — 560067, Karnataka, India
For Grievance Officer matters under the DPDPA, contact:
Grievance Officer: Aswin Madollathil
Email: support@onroutelabs.com
We will acknowledge your communication within 24 hours and resolve it within 7 days.