Privacy
Amble privacy
Amble is a free, read-only guide to the Pioneer Valley made by Kairos Studios. This page says what the app stores and where.
What Amble is
Amble gathers public listings for local events, walks, farmers markets, and places to play, and shows them on your phone. It reads from our server; it never invents listings and it never writes anything back to the sources. There is no advertising. We don’t sell data and we don’t run analytics inside the app. Our server keeps a few running totals, described below, so we can tell the local organizations that support Amble how many people use it. Nothing in them could identify you or your phone.
What the app sends to our server
- Listings. Ordinary HTTPS requests to our server on Cloudflare to fetch events, walks, markets, places, weather, and map tiles. Like any web request these carry your IP address; Cloudflare keeps short-lived request logs and we keep none of our own. Each listings request also says which kind of device it comes from (iPhone, Android or Mac); our server adds one to that day’s count for that kind and keeps nothing else about the request.
- Usage totals, unless you turn them off. The first time you open Amble each day, the app tells our server that it’s a new day (and a new week or month, when it is), which kind of phone it is, roughly which town your chosen area is near (a town name only, and only within three miles of one), the week the app was installed, and how many times the Home screen was shown since the last time. It sends no ID and nothing else that could tell your phone apart from another. Our server adds each piece to running totals and keeps nothing else; a town with fewer than 20 phones is never reported as a number. The totals are used to improve Amble and to show local supporters how many people use it, never for ads, and they are never sold. Turn them off in Settings, under About, and the app sends none of this and stops saying which kind of device it is.
- Coarse location, only when you choose it. The app never asks for your location on first launch. If you pick “near me” or the locate button on a map, it reads your position once, rounds it to about one kilometer, and sends the rounded point to our server to filter nearby listings and fetch local weather and air quality. Our server forwards that rounded point to the National Weather Service and to AirNow for air quality, and asks Google’s Weather API for the UV index of the surrounding area, about seven by five miles, never a finer point. Your phone never contacts any of them directly. Nothing runs in the background and the app never tracks where you go.
- Household sharing, only if you join one. If you create or join a household, the app stores shared favorites, an optional household name, optional member nicknames typed in the household editor, the private trail notes you write (visible to everyone in the household), the events you mark Not for us (the listing’s title, venue and a key that groups its dates, so everyone in the household stops seeing it; never shown to guests), a chosen avatar number, and kid birth years on our server, keyed by a random household id and a random token for each device. The kid names you type under “For your crew” are a different field and never leave the phone. There are two codes: a family code, which makes a full member who sees everything and shares the kids’ ages, and a guest code, which shows only the picks you choose to share and the household’s name, nothing about the kids or the other members. A guest code works once, within seven days. Anyone with the family code can join until you rotate it, so treat it like a house key.
- Drive times, only when you open a listing. Opening a place or event asks our server for a drive time from the rounded point your trip starts from (about a kilometer wide): your current location when you’re using it, otherwise your saved home, and never a town you picked. With neither, there’s no drive time. Our server asks openrouteservice for the route and MassDOT for road events along it, caches the answer, and sends back minutes and any construction or incidents on the way. Our server never receives your exact home point; cards use an on-device estimate and make no request at all. On iPhone and Mac the drive time comes from Apple Maps instead: your phone asks Apple’s routing service directly, with your exact home point (or your current location, when you use your location), the way the Maps app does.
What stays on your phone
In solo mode your favorites, lens choices, and chosen area stay on the device only. The app keeps a cached copy of listings so it still works offline. There’s no crash reporting or analytics software built into the app, and nothing that follows what you do; the only counting is the totals above. If you install a test build through TestFlight, TestFlight’s own feedback is the only diagnostic channel, and it’s Apple’s to run.
Home. A saved home is optional. As you type, Amble suggests addresses from a list of valley street addresses built into the app (public MassGIS address points), matched on your phone, so nothing you type is sent anywhere while you pick. You see the address on a map and save it yourself. If your address isn’t on the list you can ask your phone’s own map service (Apple or Google) to look it up, which sends that one address to them the way the Maps app would, or drop a pin. The address and the map point stay on the device and never sync through a household; the one place the point goes is Apple Maps, for drive times on iPhone and Mac. Our server still receives only the rounded coordinate it already receives for near-me.
Not in backups. Your home, its address, kid names, and household membership are kept out of iCloud and Mac backups on iPhone and Mac, and out of Google’s app backup on Android. The trade-off: a new or restored phone starts without them, and you set Home and the kids up again and rejoin your household with its code.
Kid names. Names you give your kids stay on this phone and shape on-device wording (who is coming along, kid-fit labels, the Home suggestions). They are never synced and never written into a share card, a notification, or the Friday digest. Household sync carries kid birth years only.
Third parties
Our server runs on Cloudflare. Map tiles come from CARTO through our server, so CARTO sees our server’s requests rather than your phone’s. Weather, air quality and UV come from the National Weather Service, AirNow and Google’s Weather API, as described above, and only for a rounded point you chose to send. Home addresses are matched on your phone; only if you ask your phone to look up an address the built-in list doesn’t have does your phone’s own map service (Apple on iPhone, Google’s on Android) see it, the way it does for any app. Our server never does. On iPhone and Mac the drive time comes from Apple Maps, which your phone asks directly with your exact home point; on Android, drive routes come from openrouteservice (HeiGIT) requested by our server. Road events come from MassDOT, requested by our server, never by your phone. The listings themselves come from public calendars, town sites, libraries, and open state data, credited inside the app. To find more local events, our server subscribes one address to local organisations’ public newsletters and reads them; it keeps no personal data from them, and nothing about you is ever sent to those organisations.
Removing your data
Delete the app to remove everything on the device. Leaving a household removes your device token from our server; when the last member leaves, the household record and its favorites go with it. To have anything removed by hand, including a household’s shared data, write to [email protected] and we’ll do it.
Questions
Write to [email protected].
Last updated October 9, 2026.