YOUR DATA AND YOUR CHOICES
Privacy Policy.
This policy covers the FirstLogbook Android app, listed as AU Logbook during internal testing, and firstlogbook.com. It explains the data we handle, its purposes, retention and deletion, and your choices.
Last updated 7 October 2026. The currently distributed Android internal test is version 0.22.5. The updated release candidate described below has not yet been distributed.
Developer and privacy contact
For FirstLogbook privacy questions, data requests or complaints, email support@firstlogbook.com. Identify FirstLogbook and describe your request. Do not send passwords, authentication tokens, full payment details or precise route exports unless necessary and specifically requested.
Journey records and permissions
The app stores journey records on your phone: route coordinates, timestamps, observed speed and location accuracy where available, distance estimates, classifications, business purposes, notes, vehicle details, manually entered dashboard readings and edited places. These enable recording, review, summaries and exports.
Location recording requires Android permission and a manual recording action or enabled automatic-recording setup. Automatic recording additionally uses background location and companion-device approval so a configured vehicle connection can start a trip while the app is closed. Selected Bluetooth device information is stored in private app preferences. You can decline permissions, disable automatic recording and stop a recording.
Address and place lookup
Address lookup sends completed trips' endpoint coordinates to the Android geocoding provider and, when needed, the public OpenStreetMap Overpass service to obtain place labels. Providers may receive your IP address. Full routes, classifications, purposes and notes are not sent for lookup. Provider handling is subject to the provider's privacy practices.
In the currently distributed 0.22.5 internal test, lookup is on by default unless disabled in Settings. The updated release candidate keeps new lookups off until an affirmative address-lookup choice after disclosure, including for existing history. Check your installed version and Settings; older installations do not yet have this new control. Disabling lookup prevents new requests; requests already sent cannot be recalled. Previously cached place labels may remain on the phone.
Installation identity and purchases
Firebase Authentication creates an anonymous installation identity without a FirstLogbook registration form, email address or password. Its SDK handles IP addresses, user-agent information and app identifiers, and generates Firebase user IDs to authenticate the installation. Our entitlement service stores installation and random journey identifiers, qualifying-recording and allowance activity, and verified Google Play purchase records for recording access, restoration and refund handling. Routes, coordinates, purposes and notes are not sent to that service.
Google Play manages subscriptions. Clearing data, removing an installation identity or uninstalling does not cancel a subscription; manage it in Google Play. The Google account used for optional Drive access is separate from the anonymous installation identity. See Firebase privacy information and Google's privacy policy for provider handling.
Authorised review access in the release candidate
The updated, undistributed release candidate supports a reusable review code validated by the entitlement service to enable Pro features without a purchase. The code is sent over HTTPS for validation and is not saved by the app or logged by the entitlement service. The server stores a credential hash, the grant linked to the installation and device, its activation time, and hashed installation and shared attempt counters for access control and abuse prevention. This does not authorise Google Drive or give access to another installation's records.
Review credentials have no automatic expiry and can be revoked by an authorised operator. Successfully refreshed access reflects revocation; previously issued offline recording access may remain valid for up to 72 hours. New Drive uploads require a fresh server check and separate Google authorisation.
Optional Google Drive backup
Connecting alone uploads nothing. If you explicitly select an account and enable backups, snapshots of journeys, routes, classifications, purposes, notes, vehicles, dashboard readings, edited places and the recording journal, including diagnostics, go directly to its private app data folder over HTTPS. The app requests access to that folder, not general Drive file access. Automatic daily backup is initially off and requires a separate choice. New uploads in the currently distributed app require an active subscription. The updated release candidate also accepts authorised review access.
Drive protects these copies; the app adds no separate FirstLogbook encryption or password to Drive backups. The selected Drive identity stays locally to prevent accidental account changes. Drive access tokens are not saved by the app or sent to the entitlement service. Existing versions can be read, restored, exported or deleted after subscription expiry, subject to Google authorisation.
Exports and encrypted file backups
You choose where to save or share exports. CSV can include dates, vehicle details, places, classification, purposes, notes, distance sources and review status. Diagnostic JSON includes precise route coordinates and technical events. Anyone with access to an unencrypted export may read it.
Manual file backups are password encrypted and saved to your chosen Android document provider. A lost password cannot be recovered. Restoring creates another local copy; deleting one copy does not delete exports or backups elsewhere.
Diagnostics and security
Recording diagnostics can include location quality, service events, battery readings and app CPU or network counters. They explain recording interruptions. Diagnostics remain on the phone unless included in an export, file backup or an optional Drive snapshot. If you enable automatic daily Drive backup, its snapshots also include the recording journal. Diagnostics are not sent to the entitlement service.
Requests to the entitlement service, Drive and the app's Overpass endpoint use HTTPS. Local records use private app storage and Android app backup is disabled. You control exported files and their recipients. FirstLogbook does not sell personal or sensitive data or use journey data for advertising.
Retention and deletion requests
Local journey history remains until you remove app data or uninstall; it is not automatically trimmed by age. Keep independent copies first. Local-data controls can clear cached places and journey history: read the confirmation carefully. They do not delete Drive copies or exports. Disabling lookup alone does not erase cached labels.
Drive keeps the latest and previous snapshots from each phone; older versions from that phone are replaced after successful uploads. Other phones' versions remain until deleted. Use the app's Drive backup controls to delete versions, and your chosen provider's controls for exported files. Disconnecting Drive does not delete existing backups.
For server-side installation-data removal, email support@firstlogbook.com with the subject “FirstLogbook data deletion request”. Describe the installation and data concerned. We may need information to verify ownership before removal: an anonymous installation cannot always be identified by email alone. The current app has no user-facing installation-identity deletion button. Uninstalling does not itself delete server data.
Server installation and allowance records have no scheduled automatic expiry. On verified deletion, installation account data and direct identity links can be removed. Purchase/refund records and hashed deletion markers can remain for restoration, refund processing, fraud prevention and preventing deleted identities from being reused; they currently have no configured automatic expiry. For the release candidate's review-access records, verified installation deletion removes the installation grant and its hashed attempt counter. Credential hashes and fixed shared counters have no scheduled expiry and remain until operator cleanup for revocation and abuse prevention; individual attempts and raw codes are not stored. Applicable legal retention obligations and non-excludable privacy rights still apply. Deletion requests do not cancel subscriptions.
This website and external services
This site does not request location access, run third-party analytics, register accounts or collect signup details. Its illustrative classification demo sends no demo data to a server. Vercel serves the site and may process technical requests, including IP address and browser information, under its privacy policy and retention practices. Email provides the information you include so we can handle your request. External services and storage providers have their own terms and privacy practices.
Your choices and updates
FirstLogbook is intended for adults aged 18 and older. Manage location, notifications, address lookup, recording and backups in Android and the app's Settings. See the user guide and Terms of use. We update this policy when described practices change and show the updated date here. Contact support@firstlogbook.com for privacy help.