Train Kid (“we,” “us,” or “our”) is a transit trip-planning app for the MBTA (Boston-area public transit), operated at https://trainkid.boston.
The Android app (boston.trainkid.wv) is a wrapper around the same web app hosted at that address.
Data controller / contact for privacy questions:
Email: dev@trainkid.boston
If you have questions about this policy or want to exercise your privacy rights, contact us at the email above.
Train Kid needs your location to plan trips and show nearby transit. When you plan a route, we send origin/destination coordinates to our routing server only to compute that request; we do not keep those coordinates in a user profile after the request is handled.
We collect limited analytics (what routes get planned, tied to a random install ID) and delete that analytics data after 90 days. We do not sell your data or use it for advertising.
If you grant location permission, the app collects precise GPS coordinates using high-accuracy device location.
How we collect it
How we use it
Where it goes
| Recipient | What is sent | Retained? |
|---|---|---|
Our server (trainkid.boston / OpenTripPlanner) |
Origin and destination coordinates for the specific trip you request | No — used only to answer that routing request (ephemeral processing) |
| MBTA (third party) | Coordinates when looking up nearby stops and live predictions | Governed by MBTA’s policies |
| Our analytics (see below) | Origin/destination name and coordinates when you tap “See Trips” | Yes, up to 90 days |
Location is optional in the sense that you can type addresses instead of using “Current location,” but trip planning requires some origin and destination (which may be coordinates after geocoding).
When you search for a place by name or address, the app sends your search text to Nominatim (OpenStreetMap’s geocoding service at nominatim.openstreetmap.org) to convert it to coordinates.
We send a User-Agent header identifying the app as “Train Kid.” Nominatim’s use of that data is governed by the OpenStreetMap Foundation privacy policy and Nominatim usage policy.
Each time you plan a route (when both origin and destination are set), the app sends an analytics event to our server at https://trainkid.boston/telemetry containing:
plan)token)Purpose: To understand how the app is used (e.g. which kinds of trips are planned) and to help with support.
Retention: We delete analytics records older than 90 days.
We do not sell analytics data or use it for advertising.
On first launch, the app generates:
token)first-use)These are stored in your browser/app local storage and are sent with analytics and optional feedback. They are not tied to your name, email, or a login account unless you voluntarily include identifying information in feedback.
If you submit feedback through the in-app form, we collect:
Feedback is stored on our servers so we can read and respond to it. We keep feedback until it is no longer needed for support or product improvement, or until you ask us to delete it (see Your choices and rights).
The following stays on your device and is not sent to our servers except as part of trip planning, analytics, or feedback as described above:
| Data | Purpose | Retention on device |
|---|---|---|
Saved locations (locations-v1) |
Quick re-selection of places you’ve used | Until you clear app/site data or uninstall |
Route plan cache (plan-cache-v1) |
Faster display of recent trip plans | Entries older than ~30 days are removed automatically |
| Install ID and first-use time | Analytics and feedback correlation | Until you clear app/site data or uninstall |
On Android, app backup may be enabled, which can include local storage in device backups managed by Google. See your device backup settings for details.
When your device contacts our servers, standard web server logs may temporarily record technical information such as:
We use this only for security, debugging, and operating the service. We do not use server logs for advertising.
We use the information above to:
Legal bases (where applicable, e.g. GDPR):
We share data only as needed to run the app:
| Third party | Data shared | Purpose |
|---|---|---|
MBTA (api-v3.mbta.com) |
Coordinates (nearby stops), stop/route IDs, schedules and predictions | Live transit data |
| OpenStreetMap Nominatim | Address/search text | Geocoding |
| Our hosting providers | Data processed on trainkid.boston |
Hosting and operation |
We do not sell or rent your personal information. We may disclose information if required by law or to protect rights, safety, or security.
| Data type | Retention |
|---|---|
| Trip-planning analytics | 90 days, then deleted |
| Routing coordinates (OTP) | Not stored after the request is processed |
| Feedback | Until no longer needed, or upon your deletion request |
| Server logs | Short operational retention (typically up to 90 days) |
| On-device saved locations & cache | Until you clear data or uninstall |
Data sent between the app and our servers is encrypted in transit using HTTPS (TLS).
No method of transmission or storage is 100% secure. We take reasonable measures to protect your information but cannot guarantee absolute security.
You can deny or revoke location permission in your device settings. Without location, you can still plan trips by typing places, but “Current location” and nearby-route features will not work fully.
You can clear saved locations, cached plans, and your install ID by clearing the app’s storage (Android: Settings → Apps → Train Kid → Storage → Clear data) or clearing site data in your browser for the PWA.
Because we do not operate user accounts, deletion is by install identifier or other details you provide.
To request deletion of analytics and/or feedback associated with your install, use the in-app feedback form with the text "Please delete my data." You can also email us at dev@trainkid.boston for assistance.
We will delete matching server-side analytics (within any remaining 90-day window) and feedback within a reasonable time (typically within 30 days).
Residents of certain regions (e.g. EEA/UK, California) may have additional rights to access, correct, delete, or restrict processing of personal data. Contact us to exercise those rights.
Train Kid is not directed at children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Train Kid is operated from the United States. If you use the app from outside the U.S., your information may be processed in the U.S. and in jurisdictions where our service providers operate.
We may update this policy from time to time. We will post the revised policy at https://trainkid.boston/privacy.html and update the “Last updated” date. Continued use after changes means you accept the updated policy.
Email: dev@trainkid.boston