Noricho

Privacy Policy

Last updated 22 August 2026 · Effective 22 August 2026

Noricho records train rides. That means it handles location data, which is about as personal as app data gets. This page describes what the app actually does with it — not what a template says a policy should claim.

The short version. Noricho reads your location only while a hunt is running and when you check in at a station. It never asks for “Always” location. A ride uploads a sampled trail of at most 300 points along with the stations and segments it resolved; the full trail stays on your phone. Your profile is private by default. There are no ads and nothing is sold or shared for advertising. Noricho does use one analytics service, PostHog, to find bugs — it never receives your coordinates. You can delete your account, and everything attached to it, from inside the app.

Who is responsible

Noricho is an independent project run by an individual developer, not a company, and it is not affiliated with, endorsed by or connected to any railway operator. For anything in this policy, write to privacy@noricho.com.

What Noricho collects

Location, while you are hunting

The whole app rests on one idea: a station stamp means you were actually there. That only works with real location data.

What a completed ride uploads

When you confirm a hunt while signed in, the app sends the ride to the Noricho server so it can be credited and so your collection survives losing your phone. That upload contains:

Rides you never confirm are not uploaded. If you use Noricho without signing in, nothing is uploaded at all — your collection lives only on your phone, and is lost if you delete the app.

Account

Signing in is optional and uses Sign in with Apple or Sign in with Google. Noricho never sees or stores your password. From the provider it receives an account identifier, an email address and, where the provider supplies one, your name. If you use Apple’s Hide My Email, Noricho only ever sees the relay address.

Your account also holds a display name and an optional handle, your XP, level and unlocked achievements, and a switch controlling whether your profile is public.

Diagnostics, so bugs can be found at all

Worth being straight about why this exists. Noricho only works on Greater Tokyo track, and it is built by one person in Argentina who cannot ride those trains. Nobody on this project can watch a hunt go wrong on the Ginza line and read the logs. Without diagnostics, a bug that mis-credits your ride is invisible to us — and the only person who ever finds out is you.

So the app sends anonymised diagnostic events to PostHog, a product-analytics service, hosted in its US region. What goes in one of those events:

What deliberately does not go into a diagnostic event:

If you are signed in, these events are tagged with your account identifier, so a recurring fault reads as one rider hitting it five times rather than five separate strangers. Signed out, they carry only a random device identifier. Deleting your account does not automatically erase past diagnostic events — write to privacy@noricho.com and they will be removed.

Support messages

If you report a problem or a data error from inside the app, Noricho sends the message you wrote, what it was about (a station, a line, a ride), the dataset version and the app version. Reports made while signed in are attached to your account so a reply is possible.

Reporting another rider

If you report a handle, Noricho sends the handle you reported, the reason you picked, and — if you write one — up to 1,000 characters of your own text. It is held for handling abuse, and it is not shown to the person you reported. Reporting also blocks them for you straight away, so you do not have to keep looking at them while it is dealt with. Blocking on its own sends only the pair of accounts, and no message.

What Noricho does not collect

Why Noricho holds it

DataPurposeBasis
Location during a hunt Working out which segments and stations you actually rode Performing the service you asked for
Sampled ride trail Letting you review a ride, correct a mis-credited one, and letting the developer diagnose a ride you report as wrong Performing the service; legitimate interest in the app working
Collection and progress Keeping your collection across devices and reinstalls Performing the service you asked for
Account identifiers Signing you in and attaching your collection to you Performing the service you asked for
Handle and display name Showing you on leaderboards — only if you turn the public profile switch on Your consent, withdrawable at any time
Support messages Answering you and fixing rail data Legitimate interest in supporting the app
Diagnostic events Finding bugs in an app whose developer cannot ride the trains it is about Legitimate interest in the app working correctly

Who can see your data

Your profile is private by default. While it is private, other riders cannot see your name, your handle, your rides or your collection, and you appear on leaderboards only in anonymised form.

If you switch your profile to public, other signed-in riders can see your handle or display name, your level and XP, your rank on the leaderboards, and summary counts of what you have collected. They never see your GPS trails, the individual rides behind those counts, or your email address. Turning the switch back off removes your identity from those boards again.

Your display name is filled in from your Apple or Google account when you first sign in, so it may be your real name. Check it before you make your profile public — you can change it in the app.

Where it is stored, and who processes it

Ride and account data is stored on Supabase (Postgres and authentication), hosted in the Tokyo region (ap-northeast-1) — the same country as the railways the app is about. Supabase acts as a processor on the developer’s instructions.

Sign-in is handled by Apple and Google, each under their own privacy policy. Realtime train information comes from the Open Data Challenge for Public Transportation through a server-side proxy that asks about a railway line and never sends your location or any identifier to it.

Diagnostic events go to PostHog Inc., hosted in its US region, as a processor on the developer’s instructions. Note this is a different country to your ride data, which stays in Tokyo — the two are separate systems and PostHog never receives ride contents.

This site is served by Vercel and Cloudflare, which process the usual web-server request logs. The site itself sets no cookies and runs no analytics — the diagnostics described here are in the app, not on this page. It loads a webfont from Google Fonts, which means Google receives the request for that font file.

Noricho does not sell your data, does not share it for advertising, and does not use it to train machine-learning models.

How long it is kept

Your choices and your rights

Children

Noricho is not directed at children. It is rated 12+ and should not be used by anyone under 13. The developer does not knowingly collect data from children under 13; if you believe a child has an account, write to privacy@noricho.com and it will be deleted.

Changes

If this policy changes in a way that affects what is collected or who can see it, the date at the top changes and the app will tell you before the change takes effect. Older versions are in the site’s git history.

Contact

privacy@noricho.com for anything on this page, or the support page for everything else.