Privacy Policy
For Late Again. Last updated 25 September 2026.
This policy explains what Late Again does with your information. It describes this app specifically, not a category of apps. If anything here is unclear, ask us at harfredlabs@gmail.com.
The short version
Late Again has no accounts and no sign-in. It asks you for nothing about yourself. No name and no email address, and nothing about where you are ever reaches us. The lines you watch and your settings live on your device. The one exception is alerts: if you turn them on in the iPhone or Android app, a copy of your notification token, the lines and stations you watch, your quiet windows, your commute rules, any mute you have set, which city you chose and your timezone offset is kept on our server, because a phone that is closed cannot alert itself. Alerts are a subscription, so the store's transaction id or purchase token and the date it runs until are kept with it. Turning alerts off deletes it. The app carries no analytics, no advertising and no tracking of any kind. This website counts its visits with Google Analytics, which the section below explains, and we have nothing to sell even if we wanted to.
What stays on your device
Everything you choose in the app is held in your device's own storage:
- which of the five cities you are in: Melbourne, Sydney, Brisbane, Adelaide or Canberra. It is stored on the device like everything else here, and it is also sent with a push subscription, because the server has to know which network to watch on your behalf. If you let the app use your location it picks the nearest city for you on a fresh install; the coordinate it compares is not kept and not sent;
- the lines you watch, and whether each is active;
- your quiet windows: the hours of each and the days it runs on;
- your commute rules: the stations each trip runs between, the times and days it runs, and the stops and routes those stations resolved to;
- any mute you set from a notification, and when it lifts;
- the stations you have saved for the departures board;
- the disruptions the app has already told you about, so it does not tell you twice;
- a record of this device: whether you allowed notifications, and when, together with either an identifier the device made up for itself (on the web, and before any push service has answered) or the notification token the push service issued. Neither is derived from anything about you. The made-up one never leaves the device; the push token does, and the next section says where it goes.
Deleting the app deletes all of it. We cannot read it, and we cannot recover it for you.
What the app sends to our server
Late Again gets its train information from the operator of whichever city you chose, and one source answers for one city:
- Melbourne: Public Transport Victoria's Timetable API;
- Sydney: Transport for NSW;
- Brisbane: Translink;
- Adelaide: Adelaide Metro;
- Canberra: Transport Canberra.
Nothing is asked of a city you are not in. PTV requires every request to be signed with a developer key, and a key shipped inside an app is a published key, so the app never talks to a source directly. It asks our own server, our server signs the request where signing is required, and it asks the source. Every request the app makes carries which city it is about, and that is the only thing about you in any of them. Four requests exist, and they are the only ones the app makes:
- Disruptions. A request for the current disruption list for your city. It carries nothing about you but the city, not even which lines you watch. Your line choices are applied on your device, to the full list.
- Station search. When you search for a station, the text you typed is sent so the source can be asked for matches.
- Departures. When you open the board, the source's own identifier for the station you picked is sent so it can be asked for its next trains.
- Alerts, if you turn them on. Covered in its own section below, because it is the only request that leaves something behind.
A station name and a stop identifier say where you are looking at trains from, so treat them as we do: they are used to answer that one request and are not stored against you, because there is no account to store them against. Answers are cached briefly on the server so that everyone asking in the same minute costs the source one request rather than hundreds, and the cache holds the answer, not the asker.
The app also checks whether a newer version of itself has been published. That request carries the release channel of your build, and nothing else.
What our server records automatically
Like any web server, ours records the technical details of a request it receives: IP address, the type of device and operating system, and the time. We use these to serve the app, diagnose faults and prevent abuse. We do not use them to build a profile of you, and we do not combine them with anything else.
Notifications
The point of this app is the 6:40am you have not looked at your phone yet, and a closed app cannot notice anything. So on the iPhone and Android apps, turning alerts on registers your phone with our server. Until you do, nothing in this section applies to you.
What is sent. Seven things, and nothing else (plus, if you subscribe, the purchase record described under Subscription):
- the notification token Apple or Google issued for this installation of this app, and which of the two it is;
- which city you chose. The server watches one network per device and cannot know which one without being told;
- the route ids of the lines you watch, and the stop ids of the stations you have saved, as your city's source numbers them;
- your quiet windows: the hours of each and the days it runs on;
- your commute rules, as ids: for each trip, the stop ids of its two ends and the stop and route ids of the path between them, together with its times, its days, the lead time before it starts, whether it is switched on and any mute on the rule itself. The station NAMES are not sent: the server decides with the ids and never prints a rule, so a name would be your home station in a database for no purpose;
- a mute you set from a notification: which of the two buttons you pressed, nothing about the alert itself. The server works out the instant it lifts at and holds that against this device, because the button is pressed with the app closed and the phone is not there to remember it;
- your timezone as a number of minutes ahead of UTC. Without it a Melbourne 8pm to 6am quiet window would silence the middle of your day, because the server runs in UTC.
Why. Our server checks your city's source every couple of minutes and pushes an alert when a disruption starts, or gets worse, on a line you watch, while the app is closed. It needs the token to reach your phone, the city and the lines to know which disruptions are yours, the rules to narrow that to the trips you actually make, and the quiet windows, the mute and the offset to know when not to reach you at all.
Where it is kept. In Google Cloud Firestore, in Google's us-east1 region, as one record per device. There is no name, email address, account or location on it: a city is not a location, it is which of five timetables to read. Nothing on it says who you are. It is a delivery address and a filter, not a profile. We do not sell it, share it or use it for anything else.
How it is deleted. The record, the rules and the mute on it included, is kept for exactly as long as alerts are on. Turning alerts off in Settings tells the server to delete it, and it does. It is also deleted without you doing anything the first time Apple or Google tells us the token is dead, which is what they report after the app is uninstalled or notifications are turned off in the phone's own settings. Deleting the record deletes everything on it.
On the web there is no server push at all. The page in your browser checks while it is open, raises its own alert, and registers nothing with us. Everything stays in the browser.
If you never grant the notification permission, or turn it off, the rest of the app works unchanged.
Follow and the station alarm
Following a trip on iPhone or Android is a second, shorter registration. The server needs a way to rewrite the lock-screen card (and to move or cancel a station alarm) while the phone is locked. Until you tap Follow, nothing in this section applies.
What is sent. The push token for that follow, the trip it belongs to as stop and run ids, when the trip should end, and, if you turned the station alarm on, the phone’s ordinary device token so an alarm can be moved or cancelled. Station names on the card are not stored as a profile: they travel with the trip while it is running.
Why. A closed app cannot update a Live Activity or an Android shade card, and cannot reschedule an alarm when the train runs late. The server watches that run and pushes only while the follow is on.
How it is deleted. Stopping the follow, or the trip ending, drops the registration. It is also dropped when Apple or Google reports the token dead. There is no follow record without a live trip.
Subscription
Alerts and Follow are a paid subscription, bought through the App Store or Google Play. Everything else in the app is free and needs no purchase. We never see your name, your Apple Account or Google account, or any payment details: Apple or Google takes the payment, under their own privacy policies.
What is stored. When the app registers for alerts or a follow, it sends the store's proof of your subscription: on iPhone, the signed transaction Apple issued; on Android, Google Play's purchase token. Our server checks it with Apple or Google and keeps two things against your push token: the store's transaction id or purchase token, and the date the subscription runs until. Nothing else.
Your free Follow. Your first Follow is free. So that it is only one, the app sends a random id made for this install (and your push token, if you have turned alerts on), and our server keeps a one-way hash of each — never the id or the token itself — with when the free Follow was used, which follow it was, and when that trip ends.
Why. So the server only sends alerts to a phone that has subscribed, and stops when a subscription ends, is refunded or is not renewed. Apple and Google tell the server about renewals and cancellations against the same id.
How it is deleted. With the alert or follow record it sits on, in the same ways described above. Your phone also keeps a note of whether it is subscribed, so the app works offline; removing the app removes it.
Analytics on this website
The public pages of this website, meaning this page and the home, about, support and terms pages, load Google Analytics so we can see how many people visit and which pages they read. In practice that means Google receives your IP address, which page you are on, roughly where in the world you are, and what browser and device you are using, and it sets a cookie in your browser so a second page view in the same visit is counted as the same visit rather than two. We look at the totals. We do not try to work out who anyone is, we have no way to connect a visit to a person, and nothing from the analytics is combined with anything else here.
The app itself sends no analytics. Not the iPhone app, not the Android app, and not the version that runs in a browser at /app or /demo. Those pages do not load the tag at all, so nothing about how you use the app reaches Google or us.
If your browser sends a Do Not Track or a Global Privacy Control signal, these pages do not load Google Analytics at all: no script is fetched and no visit is counted. Blocking it yourself, with a content blocker or by refusing cookies, works too and breaks nothing on the site.
What we do not do
- No accounts, no sign-in, no passwords.
- No analytics or crash-reporting SDK in the app, no advertising, no third-party trackers. The website has Google Analytics on its public pages; the app does not, and neither does the version of the app running on this website at /app.
- No purchases: the app is free and does not handle payments.
- No location leaves your device. The app can ask your phone for your position, but only if you tap Use my location. It is used on the device to pick the nearest stations out of the network map bundled inside the app, and on a fresh install to work out which of the five cities you are nearest to; it is never stored, and is never sent to us, to any transport operator or to anyone else. Decline it and you choose a city and a station by name instead.
- No sync and no cloud backup: the alert record is not a copy of your app, and nothing is restored from it to a new phone.
- No selling or sharing of personal information, with anyone, for any purpose.
Who else is involved
-
The five transport sources. Each receives the requests our
server makes for its own city, never a request from your phone, so none of
them is ever told which device is asking.
- Public Transport Victoria: Melbourne disruption, station and departure data, through the PTV Timetable API. Licensed from Public Transport Victoria under a Creative Commons Attribution 4.0 International Licence.
- Transport for NSW: Sydney. Sydney train information is data from Transport for NSW, used under a Creative Commons Attribution 4.0 International Licence.
- Translink: Brisbane. Brisbane train information is data © Translink and the Queensland Government, used under a Creative Commons Attribution 4.0 International Licence.
- Adelaide Metro: Adelaide. Adelaide train and tram information is data from Adelaide Metro, Department for Infrastructure and Transport (South Australia), used under a Creative Commons Attribution 4.0 International Licence.
- Transport Canberra: Canberra. Canberra light rail information is data © Transport Canberra, ACT Government, used under a Creative Commons Attribution 4.0 International Licence.
- Google Cloud: hosting for the server and the website, and Firestore (us-east1) for the alert records described above.
- Google Analytics: visit counting on the public pages of this website only, as described above. Google's handling of what it receives is covered by its own privacy policy.
- Apple Push Notification service and Firebase Cloud Messaging is the only way an alert can reach a closed app. If you turn alerts on, your token and the text of the alert pass through Apple's or Google's service to your phone.
- Apple and Google: distribution of the app through their stores. They apply their own privacy policies to what they collect about an installation, which we neither control nor receive.
Late Again is not affiliated with, endorsed by or associated with Public Transport Victoria, the Victorian Department of Transport and Planning, Metro Trains Melbourne, Transport for NSW, Sydney Trains, Translink, the Queensland Department of Transport and Main Roads, Queensland Rail, Adelaide Metro, the South Australian Department for Infrastructure and Transport, Transport Canberra, the ACT Government or Canberra Metro.
Children
Late Again is not directed at children under 13, and collects nothing from anyone, of any age, that would identify them.
How long we keep things
Data on your device lasts until you delete it or remove the app. We hold no account records, because there are no accounts. An alert record is held for as long as alerts are on: it is deleted when you turn them off, and otherwise when Apple or Google reports the token as dead. Server logs are kept for a short period for security and diagnostics and then discarded. A support email is kept for as long as it takes to help you, and no longer.
Your rights
Depending on where you live you may have the right to see the personal information we hold about you, correct it, or have it deleted. In this app's case there is almost nothing to exercise those rights over. If alerts are off, we hold nothing about you at all. If they are on, we hold the one record described under Notifications, and you delete it yourself by turning alerts off or by uninstalling the app. We cannot look it up for you by name or email, because it carries neither. If you have written to us and want that correspondence deleted, ask at harfredlabs@gmail.com and we will do it within 30 days.
Security
Everything between the app and our server travels over HTTPS, as does everything between our server and each transport source. The PTV credentials, every other source's keys, and the keys that let us push to Apple and Google, live in Google Secret Manager and are never included in the app. A notification token is treated as a credential: it is never written to a log in full. No system is perfectly secure, so we do not claim otherwise, but the most effective protection available is holding almost nothing, which is what this app does.
Changes to this policy
If we change this policy we will update this page and the date at the top. If a change materially affects how we use your information, we will tell you in the app before it takes effect.
Contact
Late Again is published by Harfred Labs. For any privacy question, write to harfredlabs@gmail.com.