privacy, in plain english.
who we are.
plus1 is an independent iOS and android app made by moss davis, a sole developer based in the forest of dean, gloucestershire, united kingdom. we're the data controller for everything described on this page. you can reach us any time at hello@plus1app.uk.
what data we collect.
we only collect what we genuinely need to make the app work. nothing about your device fingerprint, ad ID, contacts, or anything you didn't actively give us.
what we do not collect: analytics, advertising identifiers, your precise location — ever, any location at all outside an active now session you started, your contacts, your photo library beyond the single image you pick when posting a ride, device fingerprints (we note only which platform and app version feedback came from), crash reports tied to your identity, behavioural profiles (we keep a daily tally of how often each feature is used across everyone — a number per feature per day, with nothing that says who), third-party cookies, or behavioural data of any kind.
the women only filter is kept on your phone. we don't know who uses it — we only count how many times a day it's switched on, with no names.
finding riding mates: the mates search shows only riders you've shared a ride with or who ride in your area, by the name they show as. there is no directory of everyone on plus1, and a rider you've blocked, or who has blocked you, never appears.
on your phone: the app may ask for the camera or your photo library (only to pick a photo for a ride or a recap — the one photo you choose is the only thing that leaves your phone), for your calendar (only if you tap "add to calendar", and it only writes the ride), for notifications, and for location as described below. nothing else.
how we use it.
- to show you rides — your feed needs ride data; ride data needs hosts.
- to send you notifications — a reminder the day before and an hour before a ride you're attending; a ping when someone joins your ride or comments on it, or when the host answers on a ride you've asked about or said maybe to. you can turn these off in your iOS or android settings any time.
- to schedule local reminders — these are scheduled on your device, by your device, and never leave it.
- to keep the app secure — basic abuse prevention (e.g. spotting spam patterns server-side).
we do not use your data for advertising, profiling, or training machine-learning models.
"active now" and your location.
"active now" lets you say you're out for a ride so other riders nearby can find you. it is entirely optional — the rest of plus1 works without ever granting location access. here is exactly what happens:
- we ask for coarse location only. the app never requests precise location permission.
- your position is rounded on your phone, before it is sent. we snap it to a grid of roughly one square kilometre and send only the grid square. we never receive, store or log your real coordinates.
- while you're out, even in your pocket. during an active now session your square keeps updating as you ride — on iphone using apple's low-power "significant location change" updates if you allow "always" (with "while using" it updates only while the app is open), on android using a foreground service that shows a notification the whole time, with "i'm done" on it. it's still only the rough square, never your position, and it stops the moment you tap "i'm done" or the session ends (at most four hours). outside a session plus1 never reads your location.
- we watch for impossible jumps. to stop anyone faking their square, the server keeps, for the length of your session, when your square last changed and how many times — no coordinates. a jump too fast to be real quietly pauses near you and been there until it settles. it goes when the session does.
- only other active riders can see you — plus your riding mates. this is enforced by our database, not just hidden in the app: if you are not currently out yourself, the server returns nothing, unless you are riding mates with the person who is. riders who haven't gone active see a count of how many people are nearby, and no identities.
- riders who can see you also see how long. alongside your rough area and what you typed, they see how long you've been out and roughly how long you've got left ("about 40 min left"), so nobody sets off to meet someone who's about to pack up.
- you're shown as an area, never a pin. the map draws a soft circle wider than the grid square. there is no point on it that represents you.
- it ends on its own. you pick 1, 2 or 4 hours; four is the maximum and the server enforces it. tapping "i'm done" deletes the record immediately; an expired session stops being visible to anyone and the record is cleared within about a day.
plus1 does not offer live location sharing between riders, and we have no plans to store precise location. if you want to share exactly where you are with someone you've arranged to meet, use whatsapp or your phone's own location sharing — those are built for it, time-limited, and revocable.
riding mates, messages and blocking.
you can ask another rider to be riding mates. it is mutual and approval-gated: nothing happens until they accept, and either of you can end it at any time. being mates changes exactly two things:
- you can see each other's "active now" status even when you're not out yourself. this is the one exception to the rule above, and you chose the person. your "you're active" card always shows how many mates can currently see you.
- you can message each other any time, not only while you're both out.
messages between riders are stored so the other person can read them, and either of you can delete your side. a conversation can only be started between two riders who are both out right now, or who are already mates — there is no way to cold-message someone from the feed. we cap how many new conversations one account can open in an hour.
blocking is available from any conversation or rider. it is immediate and symmetric: neither of you can message, request, or see the other's active status. we do not tell the other person they've been blocked.
reporting is available anywhere you can act on a rider — a conversation, an attendee, a comment author. reporting someone also blocks them, so you're protected the moment you report. the report goes only to us to review; the other person is never told, and no other rider can see it.
when you go out we keep the rough square you started in, and when — only you can read it, it's overwritten each time you go out, and it goes with your account. it's used for two things: to nudge you when someone goes out nearby if you turn on "riders near me" in settings (off by default, at most one nudge every two hours, switch it off and the nudges stop), and to tell you about pop-up rides posted near you.
near you: places, trail reports and epic trails.
while you're out on active now, the tab also shows what's around your rough square — within about five kilometres: how the trails are riding today, according to riders who were just there; trails other riders have called "epic"; and places — trail centres, cafés, bike shops, bike washes and the like. it only opens up while you're out, and every report is tied to a rider's rough square, never to a point.
- where it comes from. trail reports and epic trails come from riders who are out. places come from riders, from our own research, and from openstreetmap (© openstreetmap contributors, open database licence) — we show that credit wherever their data appears. a moderator checks every suggested place before it's shown.
- how long they last. a trail report lasts 48 hours; a confirmation from another rider nearby adds time, up to four days at most, and it's deleted a week after it expires. an epic trail lasts four months from the last "still epic", a year at the outside, and is deleted a week after that. places stay until we remove them. a report a moderator hides is kept for 180 days so we can deal with complaints, then deleted.
- who sees who. other riders see the report, its square and how many riders agreed — not who made it. local moderators see the text and the square so they can hide anything abusive; only moss can see the reporter's name. a place you suggest shows your first name to the moderator who reviews it, and never to other riders.
- unofficial trails. some areas are marked "unofficial trails reported around here". we store and show these only as a rough area — no name, no line, no point — with the reminder that they may not be legal to ride. if you own or manage land and want an area removed, email hello@plus1app.uk and we'll take it down.
been there: your scratch map.
been there colours in the rough squares you've been out in, and rolls them up into "12 of 57 riding areas" and "68% of the forest of dean". it's off until you turn it on, because an active now session is normally deleted the moment you tap "i'm done" — the scratch map is you asking us to keep the square.
- what's kept. for every session while it's on: the rough square you started in and any square you moved into, with the first and last time you were there and how many sessions started there. no route, no track, no times in between. a ride you were on (host or joined, and not marked absent) adds its meeting-point square too.
- who sees it. only you can see your squares. you choose: keep it private; share a card of your totals when you want to; or appear on a leaderboard, where other riders see your first name and your square or area count — never the squares, and never anything from today, so nobody can tell you're out from it.
- turning it off deletes every square immediately. deleting your account does too.
pop-up rides.
plus1 reads each riding area's forecast and shows the slots that look good for a ride. tap keen on one and we record that; other riders see how many are keen, never who. when three riders are keen a pop-up appears on its own, with the keen riders in it; a local moderator can also post one. the forecast comes from open-meteo, which is sent only the riding area's centre — never anything about you.
when a pop-up is posted we may tell riders whose last go-out square was nearby (if they've kept "new rides" notifications on). joining stores that you joined and when; everyone in gets a nudge when it needs a host, when someone hosts it, and if it closes. once a rider hosts it, it's their ride under the normal rules.
- pop-ups near where you are. if you've already let plus1 use your location, each time the feed loads the app sends your position rounded to about a square kilometre, so we can show pop-up rides and riding windows within 50 km of it. the server rounds it again, uses it for that answer and doesn't store it. we never ask for location just for this; without it we use your home area. pop-up notifications still use your home area.
- busy times and places. we keep anonymous counts of when and where riders go out, join rides and say they're keen — riding area, weekday and hour only, no names — to suggest better pop-up times and places. the counts fade week by week and are gone after about seven months. a usual time is only suggested once at least two different hosts have ridden then, and a pop-up only ever meets at a start that three different hosts or five different riders have set off from. so that each rider counts once, the server privately notes that you've been counted — until that ride or window starts, or for a day — then forgets it.
groups.
anyone can start a group — a club, a shop's rides, a guide, a regular crew. a group is run by its leaders, who organise its rides under the group leader terms or, for a group that hosts social rides, the host terms. a group that guides or leads rides looks after the riders on them; on a social ride, everyone rides at their own risk.
- starting, leading or hosting for a group. we keep the group's details, which terms you accepted (group leader terms or host terms), the version and the time, and our approval decision. your acceptance of the host terms is private. every new group is checked by hand before it goes live; the people who approve it see your display name, how long you've been on plus1 and how many rides you've hosted. we may mark a group "verified" once we've checked it's the club, shop or guide it says it is.
- members. who's in a group is visible to its leaders — display names, when you joined, and rides with the group in the last 90 days. the public group page shows only a member count. a group can be open, or ask-to-join, where a leader sees your request and your display name.
- ride hosts. a group's leaders can make a member a ride host. a ride host sees who's going and waiting on their own rides and when each rider accepted the waiver, and can export that list; they don't see the group's members or anyone else's rides. leaders see all of the group's rides.
- group areas. a group can list the areas it rides in. they're public on its page, to about a kilometre.
- reminders. if a group rides in more than one area, we use your home area (the rough square you usually go out from, or the riding area you chose) to send its day-before reminders only for rides within about 50 km of you. the group never sees it.
- rides, waiting lists and waivers. leaders and hosts see who's going, who's waiting and when you accepted a waiver, and can export that as a spreadsheet — once exported, the leader is responsible for it. we keep your place in a waiting list, the waiver text you accepted and the time.
- updates. updates and photos posted to a group, and the group page itself, are public.
- group websites and calendars. a group's leaders can show the group's upcoming rides on their own website and share a calendar link. these show only what the group's public page already shows (each ride's title, time, place, description and whether places are left), never who's going. when the rides are shown on a website we count it, once per day per group, with no names and no cookies; nothing is stored on the visitor's device.
- reading an event page. if you paste a link into quick post, plus1's server fetches that one public page, reads the event's title, date, time, place and summary, and sends them back to your phone to check. we don't keep the page or the link. we keep a count of how many links you've read each day, to stop misuse; it's deleted after a week, or with your account.
emergency contact and no photos.
emergency contact. you can add the name and phone number of someone to call if you're hurt on a ride — nothing else, and never medical details. it's optional, unless a group asks for one before you join its rides. only the host of a group ride you're going on, and that group's leaders, can see it, in the app, from 24 hours before the ride starts until 24 hours after it ends. it isn't shown to other riders, isn't in any download or on the web, and we don't use it for anything else. we keep a record of who opened it, for which ride and when, for 90 days, and you can see that record in the app. please only add someone who's happy to be contacted. you can change or remove it any time, and it's deleted with your account.
no photos of me. if you turn on "no photos of me, please", the hosts and group leaders of rides you join see it next to your name on their list of riders. it's a request: we can't stop anyone taking a photo.
group emails: keep me posted.
- some groups let you tick "keep me posted" when you join, so they can email you about their rides and news. it's never ticked for you. we record that you said yes, which wording you saw and when, and any email address you gave for that group.
- the group's leaders can then download your display name and email address. once they have it, the group is responsible for it under data-protection law, as its own controller, not plus1.
- you can stop any time on the group's page or in settings → group emails, and leaving the group stops it too. for 90 days afterwards the leaders' list shows that you've stopped, so they can take you off their own list; then we delete the record. if you said yes while asking to join and never became a member, the leaders never see it, and we delete it once you stop or your request ends.
- if a group has already added you to its own mailing list, use the unsubscribe link in its emails. deleting your plus1 account deletes our record, but we can't take back an address a group has already downloaded.
- if you signed in with apple and hid your email, a group's emails may not reach your hidden address. you can give that group a different address when you tick the box. we only give it to that group.
sharing rides.
when a host shares a ride, the app uploads a card image to our storage; it's public at its link so facebook, whatsapp and imessage can show a preview. link previews show the ride's title, time, place and how many are going. they never show riders' names; a card a host shares shows the host's own display name, or the group's name.
secret spots.
as well as naming an epic trail, you can pin a secret spot — an exact point where you're standing, tagged fresh first, loam, brand new trail, running well or must ride. this is the one place plus1 shares an exact location, and only because you choose to: the pin is stored and shown to riders out nearby, or only to your mates if you pick that, with the date to the day. it fades after four months unless riders keep it alive. trail builders and landowners can ask us to take a pin down; that request stores the requester's account and reason.
apple watch.
if you use the watch app, we note whether you went out from the watch or the phone, and store the watch's own push token so notifications can reach it directly. the phone hands the watch its own sign-in; the two never share one.
new notifications.
group updates, join requests, a weekly "share your ride" reminder for hosts, and "your group is approved / verified" — each has its own switch in settings, or follows the one for the feature it belongs to.
the web app.
there's also a web app at rideplus1.netlify.app for riders without the apps. it does the same job with a few different helpers: onesignal delivers browser push notifications if you turn them on (they hold a push subscription for your browser, not your email); openstreetmap and carto serve its map tiles, and openstreetmap's nominatim does its place search — those servers see your ip address and what you look at or search; and the what3words api turns an address into a spot on the map.
the web app also has an sos and companion-ride form. if you use it, your browser reads your exact position once, turns it into a what3words address, and sends that address, your name and what you typed to us so we can act on it. apart from secret spots you choose to pin (below), that is the one place plus1 handles your precise location — only when you press the button, and it's stored no longer than it takes to deal with.
signing in with apple or google.
plus1 supports sign in with apple (on iOS) and sign in with google (on android), alongside plain email and password. when you use one of them:
- apple or google sends us a verified user identifier and your email address (with apple you can choose a private relay address; with google it's your account email). your name is shared the first time only, if you choose to.
- we never receive your apple id or google password, your devices, your purchases, or anything else from your apple or google account.
- if you use apple's "hide my email," messages we send you (e.g. password reset) go through apple's relay and only apple knows your real address. we're fine with that.
where the data lives.
plus1's backend runs on supabase, a managed postgres + auth + storage service. supabase processes data on our behalf in eu-west data centres. they don't use your data for their own purposes.
push notifications are delivered via apple push notification service (apns) on iOS, and google firebase cloud messaging (fcm) on android. we send the relevant service a push token and a short message; they deliver it to your device.
if you tap a what3words address on a ride, the app opens what3words.com in your browser — nothing is sent from the app itself. the web app does use the what3words api (see "the web app" below).
third parties, full list: supabase (backend hosting, eu-west); apple (sign in with apple, push notifications, maps and the geocoder that names your square's area, the address of a ride pin you drop and any place you search for when dropping one, iOS); google (sign in with google, firebase cloud messaging push and the geocoder that names your square's area, the address of a ride pin you drop and any place you search for when dropping one, android); openstreetmap (map tiles on android — the tile server sees your device's ip address and the map area you're looking at — and place data, © openstreetmap contributors); open-meteo (weather for pop-up rides — receives a meeting point, nothing about you); what3words (optional location autosuggest); netlify (hosts this website). that's it. no facebook sdk, no google analytics, no ad networks, no segment, no mixpanel, no anything else.
some of these providers process data outside the uk — supabase in ireland, apple and google in the united states, open-meteo in germany. each is covered by the uk's international-transfer rules (an adequacy decision or standard contractual clauses), and none of them uses your data for their own purposes.
how long we keep it.
we keep your data for as long as your account exists. when you delete your account (which you can do from the in-app profile screen, or by emailing us), we delete:
- your auth record and email
- your name, home riding area, and any other profile fields
- your push tokens
- rides you posted are anonymised — the ride content stays so attendees who joined still have a record, but it's no longer associated with you.
- your comments are deleted.
- uploaded photos are deleted from storage.
- your bikes and garage history, your scratch-map squares, your trail reports and epic trails, your roll-call marks, kudos and strikes, and any rides you joined or pop-ups you were in are deleted; places you suggested and feedback you sent stay, with your name removed.
if you'd like everything wiped — including any anonymised ride records — email hello@plus1app.uk and we'll do it within 30 days.
"active now" sessions are the shortest-lived data we hold. a session lasts at most four hours, is deleted the moment you tap "i'm done", and an expired one is cleared within about a day. trail reports last up to four days and are deleted a week after they expire; epic trails last up to a year and are deleted a week after they expire; a report a moderator hides is kept for 180 days. been there squares are kept until you turn the scratch map off, when they're deleted immediately. your bikes, place suggestions, pop-up joins, roll-call marks, kudos and feedback are kept with your account. messages are kept so the other rider can read them; deleting your account removes every message you sent and every mate link and block that involves you.
groups and rides. your emergency contact, your no-photos setting and your keep me posted choices are kept with your account and deleted with it. who opened your emergency contact is kept for 90 days, and so is a keep me posted choice you've stopped. a note each time a leader downloads their keep me posted list is kept for 12 months, and your daily count of links read for 7 days. a maybe goes when the ride starts, and a removed comment after 90 days.
we also keep a log of moderation actions — what was hidden or approved, by whom and why, and place suggestions — so we can answer complaints. it holds account ids, not names, and no rider can see it.
your rights.
under the uk gdpr you have the right to:
- access — ask us for a copy of everything we hold on you.
- correction — fix anything that's wrong (you can edit most of it yourself in the app).
- deletion — wipe your account, as described above.
- portability — get your data in a machine-readable format.
- object — to any processing you're not happy with.
- complain — to the uk information commissioner's office (ico.org.uk) if you think we've got something wrong.
email hello@plus1app.uk for any of the above.
cookies and tracking.
the app (iOS and android) uses no cookies and no third-party tracking sdks of any kind — on android, google's firebase sdk is used only for push message delivery, not analytics or advertising. the marketing website you came from (plus1app.uk) is a static html page with no analytics or trackers either.
children.
plus1 is for adults. you must be 18 or over to use it — it's in the terms. if you're under 18, please don't sign up. if you're a parent or guardian and discover that your child has, email us and we'll delete the account.
security.
we take reasonable steps to protect your data:
- all traffic to the backend is over https/tls.
- passwords are hashed with bcrypt by supabase auth — we never see your plaintext password.
- row-level security policies on the database mean users can only read/write their own rows where appropriate.
- the apns/fcm server keys, supabase service-role key, and other secrets live only on the server, never in the app binary.
no system is perfectly secure. if you ever spot something concerning, please email us first — we'd rather hear from you than from the news.
changes to this policy.
if we ever change anything material, we'll update the "last updated" date at the top and — if it actually affects you — let you know in the app. the historical version will stay archived on request.
contact.
any privacy question, request, or complaint:
moss davis
email · hello@plus1app.uk
forest of dean, gloucestershire, united kingdom