Privacy Policy
Last updated: 2 September 2026
DailyDash shows you live NSW public-transport departures for your regular trips. It's built to need as little of your data as possible.
The short version
- No account, no login — your saved routes and settings live only on your phone.
- We add no analytics, tracking, or crash-reporting SDKs of our own, and send no push notifications. (On Android, the Google Maps component reports its own diagnostic and crash data to Google — see below.)
- Your location stays on your device. From version 1.1.0 there is one exception you choose: planning a door-to-door “Anywhere” trip sends that trip's start and end points (as coordinates) to compute your journeys. We keep them out of our logs; they pass through short-lived serving caches, never a database. In version 1.0 your location never left your device at all.
- The app talks to one server we run, which relays public timetable and live-running data from Transport for NSW. It sends the stop, route, or place you're asking about — never your name or contacts.
What's stored on your device (only)
Your saved routes and trips (including any custom names you give them), your pinned journey, your app settings, and your theme choice are stored only in the app's local storage. We never upload them. A copy of the public NSW timetable database is also downloaded and cached on your device so the app works quickly and with less network use — public data, not personal data. Uninstalling the app removes all of it.
What the app sends to our server
To answer a query, the app contacts one server we operate — api.dailydash.today — which relays data from Transport for NSW Open Data. Each request includes only what's needed to answer it: public transit identifiers (stop IDs, route IDs and labels, trip IDs, and travel mode), and — from version 1.1.0, and only for door-to-door "Anywhere" trips — the trip's start and end coordinates. We do not send your name, email, contacts, or account details. Custom route names stay on your device. We hold the Transport for NSW API key on our server, so the app never handles it.
A per-install identifier
Each request also includes a random identifier the app generates on your device the first time it runs. It is not derived from any hardware, device, or advertising identifier, and it resets if you reinstall the app. It appears in our server logs; its intended purpose is to help us protect the service from abuse (for example a per-install rate limit). It does not identify you personally. Because it is stable for the life of an install, repeated requests from the same install can be associated with one another in our logs — we don't build user profiles, but in the interest of honesty we note your queries are correlatable at the log level (for instance, a stop you look up every morning could imply a regular boarding location).
Location
If you enable location, the app uses your device's location on the device for "Near me" stop search and the live "you are here" dot while you're tracking a service you've boarded. It's used only while the app is open (when-in-use), controlled by a "Use my location" switch in Settings. For these features your coordinates are never sent anywhere, and the map is not given your location dot — it's drawn by the app as an overlay, so the map provider (Apple or Google) never receives your position, only the area you're viewing.
From version 1.1.0: door-to-door “Anywhere” trips are the one place location leaves your device, because computing a journey from an address requires it. If you type an address, that search text goes to our server, which asks Transport for NSW's trip planner to match it; if you tap "Use my current location", your position is read once, while you're setting the trip up, and saved on your device as that trip's fixed starting point. Each time the app shows that trip's journeys, its start and end coordinates are sent to our server and on to Transport for NSW — exactly as if you had typed them into the official trip planner. We keep these coordinates and address searches out of our server's logs. Like any answer we serve, the responses pass through short-lived serving caches (up to 24 hours for an address search, minutes for journeys) so repeated requests don't have to re-ask Transport for NSW; they are never written to a database, never used for anything except answering the request, and expire on their own. Transport for NSW processes the queries it receives under its own privacy policy.
Version 1.0 of the app had no “Anywhere” feature: in that version location was used only on your device, for the two purposes in the paragraph above, and was never transmitted. This page describes both versions so it stays accurate whichever you are running; the App Store and Google Play listings show your installed version.
No analytics or tracking
DailyDash contains no analytics, tracking, or crash-reporting SDKs of our own, and sends no push notifications. On Android, the Google Maps component used for the tracking map reports its own diagnostic and crash data to Google (see "Infrastructure and third parties" below); we don't operate or receive it.
Infrastructure and third parties
- Transport for NSW Open Data — the upstream source of the data our server relays, used under CC BY 4.0.
- Cloudflare — hosts our server and serves the timetable database. As with any internet service, our hosting provider may process standard request metadata — such as your IP address and the requested URL — and keep it in logs under its own retention policy. We do not use your IP address to identify you.
- Apple Maps (iOS) — when you open the tracking map on iOS, iOS fetches map tiles from Apple under Apple's terms. We don't hand your location to the map.
- Google Maps (Android) — when you open the tracking map on Android, the Google Maps SDK fetches map tiles from Google. Google receives your device's IP address and the on-screen map area (which is centred on the service you're tracking, so it's near you), plus standard SDK data — a pseudonymous Maps identifier, device and request metadata, map interaction events such as panning and zooming, and diagnostic and crash metrics — under Google's terms, to provide and improve its services. We don't hand Google your location: the "you are here" dot is drawn by the app from your on-device GPS, so the map provider receives only the area you're viewing, not your position.
Retention and deletion
Because there are no accounts, there's nothing for us to delete on your behalf. Removing the app deletes everything stored locally and resets the per-install identifier. Request logs held by our hosting provider are retained under Cloudflare's log-retention policy.
Children
DailyDash is a general-audience transit app, is not directed at children, and we do not knowingly collect information from children.
Changes
If we change this policy, we'll update the date above and post the new version at this address.
Contact
Questions? Email mark@dailydash.today.