We Are RPV — Privacy Policy
About this policy
We Are RPV is an independent community app operated by Michael LaNovara. It is not an official City of Rancho Palos Verdes or Palos Verdes Peninsula Land Conservancy app. This policy explains information handled by the app, its account service, and the backup and sharing options you choose. Contact michael.lanovara@gmail.com with privacy questions or requests. Updated September 22, 2026.
Email accounts and access
The account service uses Supabase to store your email address, first name, account identifier, membership status, administrator role, and an optional profile photo you choose. Profile photos are stored in a private bucket and are available only to the signed-in owner through authenticated requests. These details provide sign-in, personalization, access control, and account support. If a password has been set for your account, you may instead use Sign In With Password. The password is sent securely to Supabase for authentication; the app does not save the password. Sign-in session tokens are stored in the device Keychain. Verification messages are delivered through the operator’s email provider, currently Gmail SMTP. Supabase and the email provider process the requests needed to deliver this service, including technical connection and delivery information.
Any email address may register. Every verified, active account can use all sections included in the installed app, regardless of email domain. We Are RPV includes the full set of sections; Explore RPV includes Explore RPV, Clean RPV, and Documents. Administrators can manage account access; this does not give them access to your phone’s saved notes, routes, recordings, or documents through the account service.
Account service diagnostics
Supabase automatically records authentication events. These technical records can include your account identifier, IP address, user-agent information, event timestamps, and sign-in, verification, or service-error details. Supabase and the operator use this information to operate and secure sign-in, detect abuse, and diagnose service or email-delivery failures. The app does not use these logs for advertising, cross-company tracking, or deriving your trail location. Provider log retention depends on the service and its configuration; see the retention section below.
Apple Health
With your permission, the app reads workouts and their recorded routes from Apple Health. This can include activity type, dates, duration, distance, source information, GPS coordinates, and available elevation and accuracy data. Workout import on iPhone is read-only. With your separate permission, the Apple Watch companion saves Explore RPV workouts and their GPS routes to Apple Health, including workout duration, distance, and available active-energy measurements. New Clean RPV recordings use Core Location only and do not start or save Health workouts. Older Watch cleanups that used workout sessions remain stored locally and are excluded from new app cloud backups and community sharing. Existing Apple Health workouts are not deleted. You may revoke access in iPhone Settings or Health.
Health information is used to display your activity maps and the individual workout routes you select. The app does not upload Health information to Supabase. All Explore RPV workouts and routes are excluded from iCloud Drive Backup, including direct GPS recordings. Read available Health workouts on supported devices; the Mac does not provide Apple Health workout access. You can separately choose to export and share your own routes; the chosen recipients or services then receive the exported information.
Location and trail recording
The app uses location when you request map centering, a note location suggestion, or GPS recording. A trail recording can save precise coordinates, timestamps, elevation, accuracy, activity permissions, trail names, and associated media locations. Recording can continue while the screen is locked or another app is open when iOS permissions allow it. Use Pause or Finish and Save to end active collection. A Lock Screen activity may display recording information, including altitude.
Apple Maps and Apple location/place-search services provide map content and place suggestions. Your use of these Apple services is also governed by Apple’s privacy information. Note locations and private trail recordings are not uploaded to the account service. If you explicitly share a Clean RPV cleanup, its GPS coordinates and cleanup date are stored in Supabase for the community map.
Notes, documents, photos, video, and audio
Text you enter, categories, dates, location names, imported PDFs, photos, videos, and meeting recordings are stored in the app’s local library. Camera and microphone access occurs when you choose the relevant capture or recording function. Files selected from Photos, Files, iCloud Drive, Google Drive, email, or another document provider are copied into the app when you import them. The originating provider remains responsible for its own copy.
Media can contain original metadata, including time and location. Trail photos may also be linked to a recorded trail location. Review what you are sharing: exports can reveal location, recording details, and people or conversations captured in the media.
Transcription and summaries
Meeting transcription uses Apple’s on-device speech tools, and summaries use Apple’s on-device Foundation Models framework on supported devices. The app may ask Apple to download the required language or model assets. The app does not send your recording, transcript, or summary to Supabase or a separate online AI service for processing. The transcript and summary are saved with your note and may be included in a backup you enable. Check generated text for mistakes before relying on or sharing it.
Landslide data shared with app members
The Landslide Districts section receives district boundaries and historical survey observations from the We Are RPV Supabase master. This includes monitoring-point identifiers, survey dates, coordinates, elevations, and calculated movement values. Every signed-in, active app member can view this shared dataset. It is not published to anonymous website visitors or added to the City's public ArcGIS layers. The shared master may also contain source archives supplied by the operator. These reference datasets are distinct from your private notes, recordings, and Apple Health imports. A local copy of data received from Supabase supports offline viewing after the first successful sync. The designated master account can update the shared City boundary snapshot; other devices read the Supabase copy.
Optional backups and sharing
iCloud Drive Backup is off until you enable it. Once enabled, We Are RPV creates and manages its own iCloud Drive Documents container. Saved changes can trigger automatic backup and the app can reload saved content from that container on another signed-in device. Depending on access, backups include notes, documents, media, eligible direct-GPS Map RPV or Clean RPV recordings, including new GPS-only Clean RPV routes recorded on Apple Watch, and trees added with Drop Pin in RPV One For One Plan. Explore RPV workouts and routes are excluded. Health-derived and unreviewed-source routes in other map sections are also excluded. When older backups contain excluded routes, the app verifies a protected local recovery copy and a replacement backup before archiving the older snapshot. Backup status reports incomplete cleanup. Local Health and unreviewed-route recovery copies are excluded from device backups.
The app does not apply its own password encryption to backup or export files. iCloud and device protections depend on your Apple Account and settings. Backups can contain prior versions, recovery copies, and history even after an item changes or is removed from the current list. Turning backup off does not delete existing iCloud files. A Rev 4 selected-folder backup can be imported and moved into the app-managed container.
AirDrop, Mail, Files, and other sharing destinations receive only the exports you choose to send or save through the sharing interface. When sharing is enabled, Clean RPV offers a separate Submit For Review choice after a cleanup is saved. Submitting sends its exact GPS coordinates and cleanup date to Supabase for administrator review. Approved submissions are visible to other active app members, subject to sharing preferences, contributor blocks, and moderation. Your first name is included only when you choose Share As with your name in Community settings; otherwise members see Anonymous. Emails, precise sample times, elevation, photos, videos, and Apple Health imports are not included. A route can still reveal private places even without a name. Repeated cleanups are retained. Use Community → My Shared Cleanups → Stop Sharing to remove a shared copy; private edits and deletions do not change that copy. Use Community → Sharing & Safety to turn your sharing off, hide your existing shares, and stop automatic sharing prompts without deleting private recordings. Administrators can disable community sharing for everyone. Other members’ maps update when refreshed. Your account remains privately linked to your contributions so you can withdraw them and administrators can moderate access. Supabase also stores sharing preferences, contributor blocks, report reasons and optional report text, timestamps, and moderation actions. Reports are visible to administrators, not the reported contributor. Submissions and shared-name changes require review before publication. Account deletion removes its sharing preferences, blocks, contributions, and reports; moderation action records may remain with deleted account and cleanup references removed. Reports linked to a removed contribution are deleted. Provider backups and operational logs follow the retention limits described below.
Security and local ownership
The app uses HTTPS for its account requests and stores sign-in credentials in the device Keychain. Its local library is linked to one account identity. A restored library requires a fresh online check of the original account identity before it is reopened. Merely using the same email with a different account identifier does not unlock another account’s files. These measures do not make every export or iCloud Drive backup private; protect access to your devices and Apple Account.
Retention, deletion, and recovery
Your account details remain in the account service while the account exists. Use Account → Delete Account to delete the online account, profile photo, membership, its community cleanup contributions, and its explicit full-access email grant. Service-provider operational logs and backups may persist according to the provider’s retention processes; the app does not promise immediate erasure of every infrastructure copy. Contact support for related privacy requests.
Deleting the account does not erase files saved on your device, copies you have shared, or files and historical backups in folders you control. Delete those copies separately if you want them removed. Before deleting the account, export anything you need. Confirming deletion of the library’s owning account also authorizes a recovery permission in this device’s Keychain for 30 days. During that period, you can verify the same email on a newly registered account and explicitly recover the saved library on this same device. That permission is not a substitute for your backups and does not transfer to another device. Re-registration does not restore administrator or manual full-access privileges.
If the last administrator chooses deletion, a second confirmation explains that app administration will be unavailable until the Supabase project owner appoints another administrator. Other accounts are not deleted. Offline access can continue temporarily after a permission change, and an already-started recording can be finished to preserve it.
Your choices and contact
You can add, change, or remove your profile photo, edit your first name, sign out, delete your account, change device permissions, turn iCloud Drive Backup on or off, import an older folder backup, and choose what to export. Turning backup off stops future automatic use of the app’s iCloud container; it does not delete existing files. Ask Michael LaNovara at michael.lanovara@gmail.com about account information, correction, access, deletion, or other privacy concerns. Identity verification may be needed to protect another person’s information. Do not email passwords, sign-in codes, or private recordings unless you choose to provide that content for a specific support request.
Other services and changes
The app does not include advertising, sell your Health or location information, or track you across other companies’ apps or websites. Calendar links and other external destinations have their own privacy practices. Apple distribution or TestFlight services may handle testing and diagnostic information under Apple’s terms and your settings. This policy may be updated when the app’s data practices change; the updated date identifies the version. The in-app copy is available without signing in or connecting to a website.