RevForge — Privacy Policy
Last updated: 6 September 2026
Last updated: 6 September 2026 (text version; the in-app copy under Settings → Legal carries the same date) Applies to: the RevForge application for Android, package dev.huszak.revforge.
The short version
RevForge runs on your phone. It has no account, no login, no advertising and no analytics. It uses the internet for exactly one thing: the Minimap fetches the streets around your car from OpenStreetMap, one small square of map at a time, and keeps them on the phone. That request says which square of the world to send back and which app is asking, and nothing about you; it is the only thing the app ever sends anywhere, and you can switch it off in Settings → Real streets on the minimap, after which the app makes no network request at all. Nothing else is transmitted. If you press Share on a saved result, RevForge creates an image and gives it only to the other app you select in Android's share sheet.
It does use your precise location, but only if you switch that on, and only for recording Trip, quick trip, Circuit and GPS performance results. What it records stays in the app's own storage on your phone until you delete it or explicitly share a generated result image.
Who is responsible
Huszák Richárd János e.v. Egyéni vállalkozó (sole trader), Hungary Registered seat: 8200 Veszprém, Takácskert utca 14. 1/1., Hungary Nyilvántartási szám (registration number): 61171811 — register kept by the National Tax and Customs Administration of Hungary (NAV) Adószám (tax number): 91452155-1-39 · EU VAT number: HU91452155 E-mail: hi@huszak.dev Web: https://huszak.dev/en
If you have a question about this policy, or about data the app holds, write to the e-mail address above. There is no Data Protection Officer; the address above reaches the developer directly.
In practice, the developer never receives your data and has no way to reach it — it stays on your phone. That means requests about the data itself are things you carry out inside the app, not things anyone can do on your behalf. This policy tells you how.
What the app uses, and what for
Precise location — only if you turn it on
Off by default. The app does not touch your position until you have (a) read the explanation the app shows you, (b) tapped "Allow location" — or "Accept and continue" on the welcome the app shows on its first start, which explains what each permission is for and then asks Android for location, Bluetooth and notifications together — and (c) granted the Android permission. Decline any of those and the app reads nothing — the minimap and the trip module simply say they cannot draw or record, rather than measuring something else instead, and a tap on either asks again.
When it is on, the app reads from your phone's GNSS (GPS) receiver, several times a second:
- latitude and longitude
- speed over the ground
- direction of travel
- how accurate the fix is
- the time of the fix
It is used for these recording features:
Trip recording. This is a separate switch in Settings, off until you turn it on. With it on, the trip module asks whether to carry on your last drive or start a new one, and from then on notices by itself when the drive begins and ends. It keeps the route, the speed along it and the time taken, so you can read the drive back afterwards.
Quick trip recording. Pressing QUICK TRIP on the Trip instrument creates a new dated point-to-point session. A quick trip is never resumed and never reuses an earlier route. It stores the same position, speed and time trace as a trip in a separate quick trip history, which opens from the same instrument.
Circuit and lap timing. Pressing Start creates a new dated Circuit session and places the current fix as its start/finish line. It stores that line and the laps timed against it. A Circuit is never resumed or used as a reusable route. Nothing extra is read from the receiver; the lap results are worked out from the same positions used to draw the trace.
GPS performance runs. When explicitly armed, a performance run uses receiver speed to create a short time/speed curve. The stored performance result does not include a route or coordinates.
No background tracking. The app records only while it is open on the screen and being fed position. It does not hold Android's background-location permission, it does not ask for one, and it does not run a location service. Put the app aside or lock the screen and the recording stops. This is a deliberate limit, not an oversight.
Vehicle data from your OBD-II adapter
If you connect a Bluetooth ELM327 adapter, the app reads live engine data to drive the sound: engine speed, road speed, driver demand (throttle), manifold pressure/boost, coolant temperature, and the list of which readings your car supports.
This is used live, to make the sound and the gauges, and none of it is stored. The engine's on/off state is the one reading that reaches trip recording at all, and only as a signal that a stopped car's journey has ended sooner than a timer would have decided; it is never written to a trip.
The app does not read your VIN, and does not read anything else that identifies your vehicle or you. It uses standard OBD-II mode 01 live-data requests only.
The Bluetooth address of your adapter is remembered so the app can reconnect to it automatically. It stays in the app's settings on your phone.
Motion and orientation sensors
The g-meter uses your phone's accelerometer. Those readings are used to draw the dial and to estimate braking, and are never written to storage.
The Minimap uses the phone's orientation sensors — the rotation vector Android builds from the magnetometer, gyroscope and accelerometer — to know which way the car is facing, so the map can turn with it, and corrects that compass reading to true north using the position. These readings are used live to turn the map and are never written to storage.
Your settings
The app saves what you would expect it to save: which engine you selected, your sound tuning, your dashboard layout, theme, units, your car's rev range, and whether the two location switches are on. All in the app's own private settings storage.
What the app does NOT touch
No account or login. No name, e-mail address or phone number. No contacts, calendar, messages or call log. No photos or files on your phone at all. No microphone, no camera. No advertising identifier. No list of your other apps. No health or fitness data. No payment information. No analytics of any kind, no crash reporting, no usage statistics, no third-party SDKs.
Where it goes: nowhere unless you choose Share
Everything described above is processed and stored on your device. The app does not send it to the developer or to any server. The one request it makes on its own — the Minimap's street squares, described below — carries none of it.
The exception is an action you take yourself: Share on a Trip, quick trip, Circuit or performance detail creates a PNG result card in the app's temporary cache and opens Android's share sheet. The card may contain the session date, route shape, speed curve, lap or run values, and a RevForge recorded/internally-validated label. It contains no latitude/longitude values, location names or embedded location metadata. Only the app you select receives temporary read access. What that receiving app then does is governed by its own privacy policy and permissions. RevForge does not automatically post, upload or save the card to the photo library.
The minimap, and the streets it fetches
The Minimap module draws a map of the streets around you, heading-up, the way a navigation minimap does. The streets come from three places, and only one of them involves the network.
Fetched squares. With Real streets on the minimap → Fetch the streets around the car switched on — it is on by default — the app asks OpenStreetMap's public Overpass server for the roads in the square of map your car is in and the eight squares around it, each about 2 km by 1.5 km, one square at a time, nearest first, and keeps the answers on the phone. A square you have once been near is drawn with the radio off from then on. Each request says which square of the world to send back (its four corners, rounded to the square's grid, so never a position finer than the square) and which app and version is asking, and nothing else — no account, no key, no identifier, no location history, no drive. The server sees the request come from your phone's internet connection the way any website you open does, and it is operated by the OpenStreetMap community under its own privacy policy, not by the developer. The squares are stored in the app's private files directory, at most 64 MB of them, the oldest dropped first; Settings shows how many are there and lets you forget them. Switch the fetch off and the app makes no network request at all — the permission stays in the manifest, the code that uses it is behind that switch, and the squares already on the phone are still drawn.
An imported map. You can also give it a whole town at once, in the same Settings card. The app writes an OpenStreetMap query for a square around where you are and hands the whole link to your browser; your browser downloads the file the way it downloads any other; and you then pick that file with Android's own document picker, which needs no permission because the system does the choosing. The file is converted once into the app's own compact street format and stored in the app's files directory. Where an imported map covers, nothing is fetched. Removing the imported map (same screen) deletes that file and nothing else.
Your own drives. Where neither of the above reaches, the streets are read from the drives already saved on this phone — the same records the Trip and Circuit history is made of — and delete a recorded drive and the roads it drew go with it.
Map data is © OpenStreetMap contributors, under the Open Database Licence.
The map itself carries no buttons and hands nothing to any other app. A tap on the module changes its shape between a panel and a circle, and that is all a tap does. It reads nothing from any navigation app: the car and the trail it draws behind itself come from the location fix and from nothing else.
The media control, and notification access
The Media control module shows what the phone is playing and offers the three keys a steering wheel has — previous, play/pause, next. How much it can see depends on one grant that is yours to give or not.
Without notification access the module is blind: it sends the same media-button press a steering-wheel key sends, addressed to the one player you pick, and nothing comes back. It cannot see what is playing, who is playing it, or anything else about the app it is pressing. It needs to be able to SEE that such a player is installed, which Android calls package visibility; the manifest declares exactly one such thing, apps that accept a media button, which is a visibility declaration and not a permission.
With notification access — an optional grant you give on Android's own settings screen, which the module offers to open and never asks for anywhere else — the module reads the phone's active media sessions: which app is playing, whether it is playing or paused, and the title and artist it publishes. Its keys then press that app's own transport, so play becomes pause and the module shows which. Notification access is a broad grant, and this is exactly what RevForge does with it and all it does with it:
- It reads the list of active media sessions and their published state and metadata.
- Of notifications, it reads nothing at all. The listener component exists because Android hands other apps' media sessions only to a notification listener; it does not receive the notifications themselves, and no notification's content ever reaches the app.
- It stores none of it. Nothing read this way is written to disk, kept beyond the moment it is shown, or sent anywhere. It cannot be: the only network request in the app is the street fetch above, and that carries a square of map and nothing else.
- It never reads the content of any app's notifications — messages, mail, codes, navigation — and the code that would have to is not in the app.
You can take the grant back at any time in Android Settings → Notifications → Notification access (or Special app access), and the module goes back to being blind at once.
The one purchase, and why it does not change that
RevForge sells one thing: a single permanent unlock, through Google Play. The purchase happens inside the Google Play app, which is a separate app with its own permissions and its own privacy policy; RevForge talks to it through an on-device channel and asks one question — does this Play account own the unlock? What comes back is a yes or a no. Nothing about the purchase goes over the app's own network use, which is the street fetch above and nothing else.
RevForge never sees your name, your card, your address or your order. It stores one boolean. If you ask Play for a refund, the answer to that question changes and the app follows it.
Google Play's own handling of the payment is covered by Google's privacy policy, not by this one. The permission list in Android's app info is where you can check all of it: the purchase adds com.android.vending.BILLING — permission to ask the Play Store — and nothing else. The whole list is Bluetooth, location, the foreground service, its notification, the internet for the street squares, and that one.
What is stored, where, and for how long
Everything below lives in the app's private storage, which other apps cannot read.
| What | How long it is kept |
|---|---|
| Recorded sessions — separately dated Trip, quick trip and Circuit records containing route, speed and time; Circuit also stores its start/finish line and lap times. Older pre-split records remain in Trip history and are not silently converted. | The most recent 200 records, or 25 MB, whichever limit is reached first. Older ones are deleted automatically to make room. Records you mark "keep" are never deleted automatically — they stay until you delete them. |
| Performance runs — a dated result, selected speed source, reached timing milestones and a time/speed curve; no route or coordinates | The most recent 100 runs, until you delete them, clear app data or uninstall. |
| Generated result images — a result card created only after you press Share | Temporary cache only. The two result-card caches retain at most 8 images each, 16 total; Android or the app may clear them sooner. They are not a durable history. |
| Settings — selected engine, tuning, theme, layout, units, your adapter's Bluetooth address | Until you change them, or clear the app's data. |
| Street squares — the roads of the map squares fetched around the car, and nothing else: no time, no position, no drive | Until they are the oldest of more than 64 MB, until you press Forget the fetched squares in Settings, or until you clear the app's data. |
| Imported street map — the file you chose, converted | Until you remove it in Settings, or clear the app's data. |
Ordinary Trips shorter than 300 metres or one minute are discarded as parking manoeuvres. Explicit quick trip and Circuit sessions use smaller minimums so a completed short measurement is not lost: 10 metres and one second for a quick trip, 50 metres and five seconds for Circuit.
Everything the app stores is removed when you uninstall the app.
Your choices, and how to exercise them
This notice is also readable inside the app, without a network connection, under Settings → Legal, next to the terms of use and the open-source licences.
Turning location off
In the app: Settings → Location & your data → Use my location, switched off. The app stops reading position immediately — the subscription to the receiver is closed, not merely ignored — and it discards the position it was holding, including the live trail on the map.
In Android: Settings → Apps → RevForge → Permissions → Location → Don't allow. This has the same effect and also revokes the permission itself.
Either way, the drives already recorded remain until you delete them.
Turning trip recording off
Settings → Trip recording → Record my drives, switched off. New Trip, quick trip and Circuit sessions stop being recorded, including lap timing.
Note: switching this off while you are driving ends the drive in progress and keeps what was recorded up to that moment. If you would rather not keep it, delete it from the trip list.
Deleting one recorded session
Open Trip, quick trip or Circuit history, open the record, press DELETE and confirm. The record, its route and its whole trace are removed from the device permanently — every file that carries it, including the half-written temporary of an interrupted save. If the record being deleted is the one currently recording, the recorder stops rather than writing it back.
Deleting everything at once
Settings → Location & your data → Delete every drive. It says how many records there are and asks you to confirm; Yes, delete everything then removes every Trip, quick trip and Circuit record and its route, including records marked to keep and the one being recorded at that moment. It cannot be undone.
Saved performance runs have their own independent control at Settings → Performance runs → Delete saved runs. Confirming Delete all removes the stored run times and speed curves; it does not change Trip, quick trip or Circuit history.
Deleting absolutely everything
Android Settings → Apps → RevForge → Storage → Clear data, or uninstall the app. This removes drives, your saved engines and every setting. It cannot be undone.
Your rights under the GDPR
Because the data never reaches the developer, the rights you have under the GDPR — access, rectification, erasure, restriction, portability, objection — are things you exercise directly on your own device, using the controls above, without asking anyone's permission and without waiting for a response. Nobody else holds a copy to hand over or to delete.
The legal basis for using your location is your consent (GDPR Art. 6(1)(a)), given in the dialog the app shows before it asks Android for the permission. You may withdraw it at any time, as described above; withdrawal does not affect what was lawfully recorded before you withdrew it, which you can then delete.
If you believe something here is wrong, write to hi@huszak.dev. You also have the right to complain to a supervisory authority — in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), https://naih.hu — or to the authority in your own EU country.
Children
RevForge is a driving app and is intended for adults. It is not directed at children, and it does not knowingly collect anything from them.
Changes to this policy
If a future version of the app changes what it does with your data, this policy is updated before that version is released, and the "Last updated" date at the top changes with it. A change that widens what is collected — for example, anything that would send data off the device — would be introduced with a fresh, explicit request for your consent, not with a silent update to this page.
Contact
Huszák Richárd János e.v. 8200 Veszprém, Takácskert utca 14. 1/1., Hungary hi@huszak.dev https://huszak.dev/en