Privacy Policy

For Late Again. Last updated 25 September 2026.

This policy explains what Late Again does with your information. It describes this app specifically, not a category of apps. If anything here is unclear, ask us at harfredlabs@gmail.com.

The short version

Late Again has no accounts and no sign-in. It asks you for nothing about yourself. No name and no email address, and nothing about where you are ever reaches us. The lines you watch and your settings live on your device. The one exception is alerts: if you turn them on in the iPhone or Android app, a copy of your notification token, the lines and stations you watch, your quiet windows, your commute rules, any mute you have set, which city you chose and your timezone offset is kept on our server, because a phone that is closed cannot alert itself. Alerts are a subscription, so the store's transaction id or purchase token and the date it runs until are kept with it. Turning alerts off deletes it. The app carries no analytics, no advertising and no tracking of any kind. This website counts its visits with Google Analytics, which the section below explains, and we have nothing to sell even if we wanted to.

What stays on your device

Everything you choose in the app is held in your device's own storage:

Deleting the app deletes all of it. We cannot read it, and we cannot recover it for you.

What the app sends to our server

Late Again gets its train information from the operator of whichever city you chose, and one source answers for one city:

Nothing is asked of a city you are not in. PTV requires every request to be signed with a developer key, and a key shipped inside an app is a published key, so the app never talks to a source directly. It asks our own server, our server signs the request where signing is required, and it asks the source. Every request the app makes carries which city it is about, and that is the only thing about you in any of them. Four requests exist, and they are the only ones the app makes:

A station name and a stop identifier say where you are looking at trains from, so treat them as we do: they are used to answer that one request and are not stored against you, because there is no account to store them against. Answers are cached briefly on the server so that everyone asking in the same minute costs the source one request rather than hundreds, and the cache holds the answer, not the asker.

The app also checks whether a newer version of itself has been published. That request carries the release channel of your build, and nothing else.

What our server records automatically

Like any web server, ours records the technical details of a request it receives: IP address, the type of device and operating system, and the time. We use these to serve the app, diagnose faults and prevent abuse. We do not use them to build a profile of you, and we do not combine them with anything else.

Notifications

The point of this app is the 6:40am you have not looked at your phone yet, and a closed app cannot notice anything. So on the iPhone and Android apps, turning alerts on registers your phone with our server. Until you do, nothing in this section applies to you.

What is sent. Seven things, and nothing else (plus, if you subscribe, the purchase record described under Subscription):

Why. Our server checks your city's source every couple of minutes and pushes an alert when a disruption starts, or gets worse, on a line you watch, while the app is closed. It needs the token to reach your phone, the city and the lines to know which disruptions are yours, the rules to narrow that to the trips you actually make, and the quiet windows, the mute and the offset to know when not to reach you at all.

Where it is kept. In Google Cloud Firestore, in Google's us-east1 region, as one record per device. There is no name, email address, account or location on it: a city is not a location, it is which of five timetables to read. Nothing on it says who you are. It is a delivery address and a filter, not a profile. We do not sell it, share it or use it for anything else.

How it is deleted. The record, the rules and the mute on it included, is kept for exactly as long as alerts are on. Turning alerts off in Settings tells the server to delete it, and it does. It is also deleted without you doing anything the first time Apple or Google tells us the token is dead, which is what they report after the app is uninstalled or notifications are turned off in the phone's own settings. Deleting the record deletes everything on it.

On the web there is no server push at all. The page in your browser checks while it is open, raises its own alert, and registers nothing with us. Everything stays in the browser.

If you never grant the notification permission, or turn it off, the rest of the app works unchanged.

Follow and the station alarm

Following a trip on iPhone or Android is a second, shorter registration. The server needs a way to rewrite the lock-screen card (and to move or cancel a station alarm) while the phone is locked. Until you tap Follow, nothing in this section applies.

What is sent. The push token for that follow, the trip it belongs to as stop and run ids, when the trip should end, and, if you turned the station alarm on, the phone’s ordinary device token so an alarm can be moved or cancelled. Station names on the card are not stored as a profile: they travel with the trip while it is running.

Why. A closed app cannot update a Live Activity or an Android shade card, and cannot reschedule an alarm when the train runs late. The server watches that run and pushes only while the follow is on.

How it is deleted. Stopping the follow, or the trip ending, drops the registration. It is also dropped when Apple or Google reports the token dead. There is no follow record without a live trip.

Subscription

Alerts and Follow are a paid subscription, bought through the App Store or Google Play. Everything else in the app is free and needs no purchase. We never see your name, your Apple Account or Google account, or any payment details: Apple or Google takes the payment, under their own privacy policies.

What is stored. When the app registers for alerts or a follow, it sends the store's proof of your subscription: on iPhone, the signed transaction Apple issued; on Android, Google Play's purchase token. Our server checks it with Apple or Google and keeps two things against your push token: the store's transaction id or purchase token, and the date the subscription runs until. Nothing else.

Your free Follow. Your first Follow is free. So that it is only one, the app sends a random id made for this install (and your push token, if you have turned alerts on), and our server keeps a one-way hash of each — never the id or the token itself — with when the free Follow was used, which follow it was, and when that trip ends.

Why. So the server only sends alerts to a phone that has subscribed, and stops when a subscription ends, is refunded or is not renewed. Apple and Google tell the server about renewals and cancellations against the same id.

How it is deleted. With the alert or follow record it sits on, in the same ways described above. Your phone also keeps a note of whether it is subscribed, so the app works offline; removing the app removes it.

Analytics on this website

The public pages of this website, meaning this page and the home, about, support and terms pages, load Google Analytics so we can see how many people visit and which pages they read. In practice that means Google receives your IP address, which page you are on, roughly where in the world you are, and what browser and device you are using, and it sets a cookie in your browser so a second page view in the same visit is counted as the same visit rather than two. We look at the totals. We do not try to work out who anyone is, we have no way to connect a visit to a person, and nothing from the analytics is combined with anything else here.

The app itself sends no analytics. Not the iPhone app, not the Android app, and not the version that runs in a browser at /app or /demo. Those pages do not load the tag at all, so nothing about how you use the app reaches Google or us.

If your browser sends a Do Not Track or a Global Privacy Control signal, these pages do not load Google Analytics at all: no script is fetched and no visit is counted. Blocking it yourself, with a content blocker or by refusing cookies, works too and breaks nothing on the site.

What we do not do

Who else is involved

Late Again is not affiliated with, endorsed by or associated with Public Transport Victoria, the Victorian Department of Transport and Planning, Metro Trains Melbourne, Transport for NSW, Sydney Trains, Translink, the Queensland Department of Transport and Main Roads, Queensland Rail, Adelaide Metro, the South Australian Department for Infrastructure and Transport, Transport Canberra, the ACT Government or Canberra Metro.

Children

Late Again is not directed at children under 13, and collects nothing from anyone, of any age, that would identify them.

How long we keep things

Data on your device lasts until you delete it or remove the app. We hold no account records, because there are no accounts. An alert record is held for as long as alerts are on: it is deleted when you turn them off, and otherwise when Apple or Google reports the token as dead. Server logs are kept for a short period for security and diagnostics and then discarded. A support email is kept for as long as it takes to help you, and no longer.

Your rights

Depending on where you live you may have the right to see the personal information we hold about you, correct it, or have it deleted. In this app's case there is almost nothing to exercise those rights over. If alerts are off, we hold nothing about you at all. If they are on, we hold the one record described under Notifications, and you delete it yourself by turning alerts off or by uninstalling the app. We cannot look it up for you by name or email, because it carries neither. If you have written to us and want that correspondence deleted, ask at harfredlabs@gmail.com and we will do it within 30 days.

Security

Everything between the app and our server travels over HTTPS, as does everything between our server and each transport source. The PTV credentials, every other source's keys, and the keys that let us push to Apple and Google, live in Google Secret Manager and are never included in the app. A notification token is treated as a credential: it is never written to a log in full. No system is perfectly secure, so we do not claim otherwise, but the most effective protection available is holding almost nothing, which is what this app does.

Changes to this policy

If we change this policy we will update this page and the date at the top. If a change materially affects how we use your information, we will tell you in the app before it takes effect.

Contact

Late Again is published by Harfred Labs. For any privacy question, write to harfredlabs@gmail.com.

← Back to Late Again