privacy policy · iOS, android & web

privacy, in plain english.

last updated · 30 september 2026
plus1 is built with the same data minimum as a paper noticeboard at the trail centre. we store only what's needed for the app to work, we never sell or share it for advertising, and you can wipe it all by deleting your account. the rest of this page is the long-form version of that sentence — written so a normal human can read it.

who we are.

plus1 is an independent iOS and android app made by moss davis, a sole developer based in the forest of dean, gloucestershire, united kingdom. we're the data controller for everything described on this page. you can reach us any time at hello@plus1app.uk.

what data we collect.

we only collect what we genuinely need to make the app work. nothing about your device fingerprint, ad ID, contacts, or anything you didn't actively give us.

email address
required to sign you in. if you use sign in with apple (iOS) and choose to hide your email, we receive only the relay address apple gives us — never your real one. sign in with google (android) shares your google account email.
name (optional)
the name you give us. other riders see your first name and the initial of your surname — "chris m." — next to rides you post, comments, messages and in active now; if two riders would look the same we add your home riding area, like "chris (wye valley)". your surname is never shown in full. you can leave the surname off, but then riders may not be able to tell you apart.
home riding area (optional)
a free-text region you ride in (e.g. "forest of dean"). it's part of your profile, which other riders can see, and it defaults your feed to nearby rides. never required.
rides you post
title, description, photo, location (lat/lng + optional what3words address), date/time, duration, discipline, vibe, skill level, capacity, optional whatsapp link, "how to find us" notes.
attendance
when you tap "attend" on a ride, we record that you're going so the host and other attendees can see headcount.
maybes
if you say maybe to a ride, only its host (and, for a group's ride, the group's leaders) can see your display name there. a maybe doesn't count as going, isn't in any attendance list or export, and is deleted when the ride starts, or with your account.
emergency contact (optional)
an emergency contact's name and phone number, if you add one. see "emergency contact and no photos" below.
comments and questions
anything you write in a ride's comments and questions, with a timestamp and your display name. comments and questions on a ride can be read by anyone signed in to plus1, but not on the public web, and not by riders you've blocked or who've blocked you. a ride's host, its group's leaders and plus1's moderators can remove a comment; a removed comment is kept for 90 days in case it's reported, then deleted.
rough location (only in "active now")
if you flag yourself as out for a ride in the active now tab, your phone takes a location fix and rounds it to roughly a square kilometre before anything is sent. we receive that square, never your actual position — everyone in the same square looks identical to us and to other riders. we also store the area name it falls in (e.g. "forest of dean") — your phone asks apple's or google's geocoder for that name using the centre of the square, not your position. while your session runs the square keeps up with you, even with the phone in your pocket (see "active now" below). your precise coordinates never leave your phone.
what you're riding (optional)
the trail or meeting spot you type in when you go active (e.g. "fetter hill"), plus any ping you send another rider. you choose this text, and it's shown exactly as you wrote it.
trail reports, epic trails and places (only while out)
while you're out you can say how a trail is riding (a condition plus up to 60 characters of your own words), call a trail "epic" (its name, 2–40 characters), or suggest a place — a café, bike shop, trail centre, or an area where unofficial trails are reported. each is stored against your rough square, never a point on a map. riders nearby see the report, not who made it. a moderator checking a place you suggested sees your first name; only moss can see who posted a trail report or an epic trail.
been there squares (opt-in)
off until you turn it on in active now. once on, every rough square you're out in is kept as part of your scratch map, with the first and last time you were there. only you can see your squares. if you choose the leaderboard, other riders see your first name and how many squares or riding areas you've ridden — never the squares themselves, and never anything from today. turn it off and every square is deleted straight away.
pop-up rides
when you join a pop-up ride we record that you joined, and when. other riders see only how many are in. if you host it, it becomes your ride and the people in it become its attendees, like any other ride.
your bikes (garage, optional)
the bikes you add — make, model, year, an optional nickname, the parts on them, the miles or hours you log and your service history. only you can see your garage. you can choose to show a bike's make, model and nickname on your profile; nothing else about it is ever shown. we publish anonymised averages of how long a part lasts, and only once at least ten riders have replaced that part.
roll call, kudos and reliability
after a ride you can say who turned up and who didn't, and give kudos. you see only your own answers; the rider you mark never learns who marked them, and only moss can see the full roll call. no-show marks from the other riders on the ride become a strike — two of them on a bigger ride, one if it was just the two of you. strikes stop counting after 90 days, and three live strikes stop you hosting for a month. other riders can see your kudos, how many rides you've hosted and joined, and your no-show count.
feedback you send us
if you tell us how a ride went or send feedback from settings, we keep what you wrote, which platform and app version you were on, and the ride it was about, so we can read it and act on it. only moss reads it. if you delete your account it's kept without your name attached.
ride recaps (photos)
after a ride, the host can post a group photo and a caption to it. a recap is visible to everyone in the app. if you're in the photo and would rather not be, you can take yourself off the recap from the ride, and we'll remove it entirely if you email us.
host reward claims
if you claim a host reward we keep the uk postal address you give us, and which rides qualified, until it's been sent. only moss sees it.
moderation
some riders are local moderators: they can hide a ride, suspend a rider, review suggested places and trail reports, and post pop-ups for their area. if you ask to be one we keep your note. every moderation action is logged (see "how long we keep it").
riding mates, messages, blocks
who you've asked to be mates with (and their answer), the messages you exchange with other riders, and anyone you've blocked. only you and the other rider in each case can see these — never third parties, and blocks are visible only to you.
reports
if you report a rider, we store who was reported and any note, so we can review it and keep people safe. reports are private to moderation — moss, and for your area a local moderator, a rider we've appointed. the person you report is never told who reported them, and no other rider can see reports. reporting someone also blocks them.
push token
a push token for your device — via apple's push service (apns) on iOS, or google firebase cloud messaging (fcm) on android — so we can send you ride reminders and notify you when someone joins your ride or comments on it, or when the host answers on a ride you've asked about or said maybe to.

what we do not collect: analytics, advertising identifiers, your precise location — ever, any location at all outside an active now session you started, your contacts, your photo library beyond the single image you pick when posting a ride, device fingerprints (we note only which platform and app version feedback came from), crash reports tied to your identity, behavioural profiles (we keep a daily tally of how often each feature is used across everyone — a number per feature per day, with nothing that says who), third-party cookies, or behavioural data of any kind.

the women only filter is kept on your phone. we don't know who uses it — we only count how many times a day it's switched on, with no names.

finding riding mates: the mates search shows only riders you've shared a ride with or who ride in your area, by the name they show as. there is no directory of everyone on plus1, and a rider you've blocked, or who has blocked you, never appears.

on your phone: the app may ask for the camera or your photo library (only to pick a photo for a ride or a recap — the one photo you choose is the only thing that leaves your phone), for your calendar (only if you tap "add to calendar", and it only writes the ride), for notifications, and for location as described below. nothing else.

how we use it.

we do not use your data for advertising, profiling, or training machine-learning models.

"active now" and your location.

"active now" lets you say you're out for a ride so other riders nearby can find you. it is entirely optional — the rest of plus1 works without ever granting location access. here is exactly what happens:

plus1 does not offer live location sharing between riders, and we have no plans to store precise location. if you want to share exactly where you are with someone you've arranged to meet, use whatsapp or your phone's own location sharing — those are built for it, time-limited, and revocable.

riding mates, messages and blocking.

you can ask another rider to be riding mates. it is mutual and approval-gated: nothing happens until they accept, and either of you can end it at any time. being mates changes exactly two things:

messages between riders are stored so the other person can read them, and either of you can delete your side. a conversation can only be started between two riders who are both out right now, or who are already mates — there is no way to cold-message someone from the feed. we cap how many new conversations one account can open in an hour.

blocking is available from any conversation or rider. it is immediate and symmetric: neither of you can message, request, or see the other's active status. we do not tell the other person they've been blocked.

reporting is available anywhere you can act on a rider — a conversation, an attendee, a comment author. reporting someone also blocks them, so you're protected the moment you report. the report goes only to us to review; the other person is never told, and no other rider can see it.

when you go out we keep the rough square you started in, and when — only you can read it, it's overwritten each time you go out, and it goes with your account. it's used for two things: to nudge you when someone goes out nearby if you turn on "riders near me" in settings (off by default, at most one nudge every two hours, switch it off and the nudges stop), and to tell you about pop-up rides posted near you.

near you: places, trail reports and epic trails.

while you're out on active now, the tab also shows what's around your rough square — within about five kilometres: how the trails are riding today, according to riders who were just there; trails other riders have called "epic"; and places — trail centres, cafés, bike shops, bike washes and the like. it only opens up while you're out, and every report is tied to a rider's rough square, never to a point.

been there: your scratch map.

been there colours in the rough squares you've been out in, and rolls them up into "12 of 57 riding areas" and "68% of the forest of dean". it's off until you turn it on, because an active now session is normally deleted the moment you tap "i'm done" — the scratch map is you asking us to keep the square.

pop-up rides.

plus1 reads each riding area's forecast and shows the slots that look good for a ride. tap keen on one and we record that; other riders see how many are keen, never who. when three riders are keen a pop-up appears on its own, with the keen riders in it; a local moderator can also post one. the forecast comes from open-meteo, which is sent only the riding area's centre — never anything about you.

when a pop-up is posted we may tell riders whose last go-out square was nearby (if they've kept "new rides" notifications on). joining stores that you joined and when; everyone in gets a nudge when it needs a host, when someone hosts it, and if it closes. once a rider hosts it, it's their ride under the normal rules.

groups.

anyone can start a group — a club, a shop's rides, a guide, a regular crew. a group is run by its leaders, who organise its rides under the group leader terms or, for a group that hosts social rides, the host terms. a group that guides or leads rides looks after the riders on them; on a social ride, everyone rides at their own risk.

emergency contact and no photos.

emergency contact. you can add the name and phone number of someone to call if you're hurt on a ride — nothing else, and never medical details. it's optional, unless a group asks for one before you join its rides. only the host of a group ride you're going on, and that group's leaders, can see it, in the app, from 24 hours before the ride starts until 24 hours after it ends. it isn't shown to other riders, isn't in any download or on the web, and we don't use it for anything else. we keep a record of who opened it, for which ride and when, for 90 days, and you can see that record in the app. please only add someone who's happy to be contacted. you can change or remove it any time, and it's deleted with your account.

no photos of me. if you turn on "no photos of me, please", the hosts and group leaders of rides you join see it next to your name on their list of riders. it's a request: we can't stop anyone taking a photo.

group emails: keep me posted.

sharing rides.

when a host shares a ride, the app uploads a card image to our storage; it's public at its link so facebook, whatsapp and imessage can show a preview. link previews show the ride's title, time, place and how many are going. they never show riders' names; a card a host shares shows the host's own display name, or the group's name.

secret spots.

as well as naming an epic trail, you can pin a secret spot — an exact point where you're standing, tagged fresh first, loam, brand new trail, running well or must ride. this is the one place plus1 shares an exact location, and only because you choose to: the pin is stored and shown to riders out nearby, or only to your mates if you pick that, with the date to the day. it fades after four months unless riders keep it alive. trail builders and landowners can ask us to take a pin down; that request stores the requester's account and reason.

apple watch.

if you use the watch app, we note whether you went out from the watch or the phone, and store the watch's own push token so notifications can reach it directly. the phone hands the watch its own sign-in; the two never share one.

new notifications.

group updates, join requests, a weekly "share your ride" reminder for hosts, and "your group is approved / verified" — each has its own switch in settings, or follows the one for the feature it belongs to.

the web app.

there's also a web app at rideplus1.netlify.app for riders without the apps. it does the same job with a few different helpers: onesignal delivers browser push notifications if you turn them on (they hold a push subscription for your browser, not your email); openstreetmap and carto serve its map tiles, and openstreetmap's nominatim does its place search — those servers see your ip address and what you look at or search; and the what3words api turns an address into a spot on the map.

the web app also has an sos and companion-ride form. if you use it, your browser reads your exact position once, turns it into a what3words address, and sends that address, your name and what you typed to us so we can act on it. apart from secret spots you choose to pin (below), that is the one place plus1 handles your precise location — only when you press the button, and it's stored no longer than it takes to deal with.

signing in with apple or google.

plus1 supports sign in with apple (on iOS) and sign in with google (on android), alongside plain email and password. when you use one of them:

where the data lives.

plus1's backend runs on supabase, a managed postgres + auth + storage service. supabase processes data on our behalf in eu-west data centres. they don't use your data for their own purposes.

push notifications are delivered via apple push notification service (apns) on iOS, and google firebase cloud messaging (fcm) on android. we send the relevant service a push token and a short message; they deliver it to your device.

if you tap a what3words address on a ride, the app opens what3words.com in your browser — nothing is sent from the app itself. the web app does use the what3words api (see "the web app" below).

third parties, full list: supabase (backend hosting, eu-west); apple (sign in with apple, push notifications, maps and the geocoder that names your square's area, the address of a ride pin you drop and any place you search for when dropping one, iOS); google (sign in with google, firebase cloud messaging push and the geocoder that names your square's area, the address of a ride pin you drop and any place you search for when dropping one, android); openstreetmap (map tiles on android — the tile server sees your device's ip address and the map area you're looking at — and place data, © openstreetmap contributors); open-meteo (weather for pop-up rides — receives a meeting point, nothing about you); what3words (optional location autosuggest); netlify (hosts this website). that's it. no facebook sdk, no google analytics, no ad networks, no segment, no mixpanel, no anything else.

some of these providers process data outside the uk — supabase in ireland, apple and google in the united states, open-meteo in germany. each is covered by the uk's international-transfer rules (an adequacy decision or standard contractual clauses), and none of them uses your data for their own purposes.

how long we keep it.

we keep your data for as long as your account exists. when you delete your account (which you can do from the in-app profile screen, or by emailing us), we delete:

if you'd like everything wiped — including any anonymised ride records — email hello@plus1app.uk and we'll do it within 30 days.

"active now" sessions are the shortest-lived data we hold. a session lasts at most four hours, is deleted the moment you tap "i'm done", and an expired one is cleared within about a day. trail reports last up to four days and are deleted a week after they expire; epic trails last up to a year and are deleted a week after they expire; a report a moderator hides is kept for 180 days. been there squares are kept until you turn the scratch map off, when they're deleted immediately. your bikes, place suggestions, pop-up joins, roll-call marks, kudos and feedback are kept with your account. messages are kept so the other rider can read them; deleting your account removes every message you sent and every mate link and block that involves you.

groups and rides. your emergency contact, your no-photos setting and your keep me posted choices are kept with your account and deleted with it. who opened your emergency contact is kept for 90 days, and so is a keep me posted choice you've stopped. a note each time a leader downloads their keep me posted list is kept for 12 months, and your daily count of links read for 7 days. a maybe goes when the ride starts, and a removed comment after 90 days.

we also keep a log of moderation actions — what was hidden or approved, by whom and why, and place suggestions — so we can answer complaints. it holds account ids, not names, and no rider can see it.

your rights.

under the uk gdpr you have the right to:

email hello@plus1app.uk for any of the above.

cookies and tracking.

the app (iOS and android) uses no cookies and no third-party tracking sdks of any kind — on android, google's firebase sdk is used only for push message delivery, not analytics or advertising. the marketing website you came from (plus1app.uk) is a static html page with no analytics or trackers either.

children.

plus1 is for adults. you must be 18 or over to use it — it's in the terms. if you're under 18, please don't sign up. if you're a parent or guardian and discover that your child has, email us and we'll delete the account.

security.

we take reasonable steps to protect your data:

no system is perfectly secure. if you ever spot something concerning, please email us first — we'd rather hear from you than from the news.

changes to this policy.

if we ever change anything material, we'll update the "last updated" date at the top and — if it actually affects you — let you know in the app. the historical version will stay archived on request.

contact.

any privacy question, request, or complaint:

moss davis
email · hello@plus1app.uk
forest of dean, gloucestershire, united kingdom