How Phare handles your data
Plain words, no legalese. Phare is a bookkeeping tool for rideshare and delivery drivers. Your records live on your phone. A small number of things leave it so the app keeps working and so drivers as a whole get a better picture of the market. This page says exactly what they are, and how to make it all go away.
Your records live on your phone
Your offers, earnings, trips, logbook, expenses, receipts and screenshots are stored on your device, not on our servers. If you make a backup it is encrypted on your phone before it is saved; we never hold a copy and cannot read one. Exports (tax documents, screenshot archives) are written to a folder you choose on your phone.
What leaves your phone, and why
- Your device's identity. A random device id and a public key your phone generates. It proves it is your phone at the door and rate-limits abuse. The app also periodically asks Google Play to confirm the phone is a genuine Android device; we keep the verdict, never the token.
- Detection health reports (always on). When the app detects a screenshot that contains a delivery offer, it reports whether the reading worked: counts and error types, tied to your device so we can fix what breaks. Never the content. If reading fails in a new way, the app may upload an image of the offer card as the platform drew it plus a small margin of screen around it, never the whole screen. Crash reports are scrubbed down to code locations. Hourly health gauges (uptime, memory, which permissions are granted) come with them.
- The observation pool (always on). Every captured offer and pickup visit becomes an observation in a shared pool: the quote as printed (amount, pickup, drop-off line, distance, time), what became of it, the pickup-venue location and the approximate offer location at that time. Pool rows carry no person key: no name, no email, no device identity. They carry a random stream tag minted on your phone that maps to nothing. De-identified is not the same as perfectly anonymous, and we will not pretend otherwise. What we control we commit to: no person key at rest, a 14-day window on the server, and long-term storage only as encrypted archives whose key never touches the server.
- Location. Phare records your location while you drive, including when the app is in the background, to build your trip log, particularly for tax logbook purposes, and to know where you received offers. Your journeys stay on your phone. Only the approximate offer location above, and your suburb while you are online with mates, ever leave it.
- Mates (only if you add one). Mates see the offer cards and the suburb you choose to share, never your exact location. Shares evaporate after 30 minutes. The server keeps a two-week log of when your mate connection comes and goes, used only to spot abuse.
- Recovery email (only if you give one). Used to verify you and to send a recovery code if you lose your phone. Nothing else is sent to it.
- Subscription. If you subscribe, Google Play handles the payment. We hold the purchase token and the subscription's state so the app knows what you have paid for.
- The beta list. An email you leave on this site is used to send you a beta invite and nothing else.
What we never do
- We do not sell or share your data with anyone for advertising. There are no ads and no trackers in the app or on this site.
- Phare cannot read your screen and does not scrape or interact with the delivery apps in any way. It only processes the screenshots you already take of offer cards and the gig app's online/offline notifications, on your phone.
- We do not read your earnings, your journeys or your receipts. They never reach us.
- We do not show fleet aggregates unless enough drivers stand behind them to keep any one driver invisible.
Who helps us run it
Servers are in Melbourne, Australia. Nightly server backups and pool archives are stored with Cloudflare, encrypted with a key the storage provider does not hold. Emails are sent through Resend. Payments and device checks go through Google Play. None of them receive your records.
How long we keep things
- Pool observations: 14 days on the server, then encrypted archive only.
- Mate shares: 30 minutes. Connection log: 14 days.
- Detection health reports: 90 days. Offer-card images from failed readings: 180 days. Health gauges: 14 days, then daily summaries.
- Your account (device identity, email, recovery code, subscription state): until you delete it.
Your choices
- Delete your account from inside the app: Menu → Account → Delete account. This removes everything the server holds that is keyed to you or your devices: identity, recovery email and code, mates, subscription state, health reports and any offer-card images. Pool observations carry no identity and cannot be matched to you, so they stay. Your records on the phone are untouched unless you tick the option to wipe them too. You can also ask us by email.
- Deleting an offer in the app retracts its observation from the pool.
- Blocking a mate ends the exchange both ways.
- Uninstalling stops everything. Your account stays on the server until you delete it, so a reinstall can recover it.
- Your data, your way. The app exports your records as tax documents (PDF and CSV), a screenshot archive with a manifest, and an encrypted backup you can restore on any phone.
Who this is for
Phare is for working drivers. It is not directed at anyone under 18 and we do not knowingly keep data about them.
Changes and contact
If this policy changes in a way that matters, the app will show you the new version and ask you to read it before it carries on. Questions or requests: privacy@pharego.com.