What Haremoto processes, why, and the choices you have. Last updated: 28 July 2026.
Who is responsible
Haremoto is operated by Alexandru Radu, a private individual based in Romania, under the name Lazy. Postal contact: Romania. For privacy requests, account help, objections, or complaints, email [email protected].
Data we process
Accounts: Google/Firebase user ID, email, display name, account dates, linked device IDs, preferences, and entitlement status.
Active Ride Mode: precise foreground/background GPS track, timestamps, accuracy, speed, direction, altitude, battery/thermal tracking mode, route adherence and detours. For Pro riders, the Android app also records phone-sensor estimates such as lean angle and acceleration/braking/cornering G-force after mount calibration.
Billing: Stripe customer/subscription IDs and Pro status. Card details are entered on Stripe-hosted Checkout and are not stored by Haremoto.
Temporary sharing and Telegram: random share links, tracking/monitor records, route data, and—after you connect the bot—your Telegram chat ID and live location updates.
Security and operations: short-lived server/proxy logs, rate-limit information, error logs, and map/weather lookup caches.
Android stability diagnostics: app/build version, phone manufacturer/model, Android and WebView versions, coarse app phase, crash/ANR/app-exit reason, renderer/network errors, memory pressure, and counts/timing for keyboard or focus loops. A random app-install ID is pseudonymous and hashed again on the server. These reports never include typed text, field values, GPS coordinates, route history, sensor values, email, or account identity.
Why we process it
To provide plans, accounts, synchronization, alerts, logbook, EV profiles, and Pro features: performance of the service contract.
To secure, debug, rate-limit, and maintain Haremoto: legitimate interests in operating a reliable service.
Essential Android stability reports are processed for the same reliability interest and do not depend on optional Umami analytics consent.
To process subscriptions and retain required billing evidence: contract and legal obligations.
To measure site use with Umami: consent only. Analytics does not load before you accept.
Cookies and device storage
hs: Secure, HttpOnly sign-in session cookie; up to 90 days. Essential.
hl: language choice; up to one year. Essential preference.
Local/session storage: device ID, planner preferences, consent choice, and temporary form/plan state. Required for app features and continuity.
Umami: self-hosted, loaded only after “Accept analytics”. With consent it records page views and aggregate product events such as plan generated, ride started/ended/recovered, weather alert shown, reroute, offline pack, ride check, or Pro-interest actions. Events use coarse categories and never include coordinates, origin/destination, route names, email, or sensor/telemetry values. It is not loaded when you choose “Essential only”.
You can change the analytics choice at any time using . Browser controls can also clear cookies and local storage; clearing them may sign you out or make this browser appear as a new device.
Sharing, processors, and international transfers
Haremoto does not sell personal data. Data is sent only as needed to service providers: Google Firebase (sign-in and push), Stripe (billing), Geoapify/OpenStreetMap/OSRM/Open-Meteo/MET Norway/RainViewer/Open Charge Map/TomTom (route, map, weather, and EV results), Telegram when you activate its bot, Cloudflare for delivery and protection, and self-hosted Umami if you consent. Some providers may process data outside the EEA under their published safeguards.
Retention
Account, linked-device, preferences, Garage, maintenance, and completed Logbook data: until you delete the relevant record or the account. Losing or cancelling Pro does not delete accumulated Logbook data; the service has an abuse ceiling of 1,000 completed rides per device.
Upcoming saved planned rides: until you delete them or normally 24 hours after their planned departure.
Active/interrupted Ride Mode records and their rotating recovery checkpoints: up to 7 days after the newest real sample so you can resume, save a partial ride, discard it, or decide later. Future/ended operational ride records are normally removed one day after departure.
If you choose End and save, the completed ride is copied to the permanent logbook; End without saving removes the active record instead. Offline native samples remain in private app storage until the requested action can be acknowledged/finalized or the local lifecycle removes them.
On-device data: the native ride queue is capped at 50,000 samples (about 69 hours at a five-second rate) and is cleared as samples/actions are acknowledged, finalized, or discarded. Offline Ride Packs and private Logbook photos have no automatic expiry; they remain until removed, app/site data is cleared, or the app is uninstalled. Deleting the online ride/account does not currently erase those device-only copies.
Account sessions: up to 90 days. The language cookie lasts one year; local app/browser preferences remain until app/site storage is cleared or the app is uninstalled.
Public shared-plan links: 48 hours. A public live-watch link works only while its ride is active and closes immediately when the ride ends; an abandoned active ride expires under the seven-day rule above.
Telegram live-tracking sessions: up to 24 hours; /stop ends a linked session.
Telegram ride monitors: until the ride date or you send /stopmonitor.
Privacy-filtered Android stability diagnostics: up to 30 days; the offline device queue is capped at 50 events and is removed after successful delivery.
Consent-based Umami analytics currently has no automatic time expiry and remains until the operator deletes it or introduces a retention job. It contains aggregate/coarse product events, not ride coordinates or sensor telemetry.
Backups: the newest 14 local and 14 offsite daily archives are retained (normally about 14 days). A storage provider's recycle-bin/version-recovery policy may retain a deleted archive longer. Backups are restored only for disaster recovery.
Stripe invoices and transaction records: retained by Stripe and/or the operator as required for accounting, fraud prevention, and law.
Export, deletion, and your rights
From the account menu, Download my data exports the account record, linked-device records, session timestamps, saved/active rides, permanent logbook trips, and account-linked Telegram tracks/monitors. Login secrets are intentionally omitted. Delete account & data cancels a known Pro subscription immediately, then removes server-held linked records and push tokens. Device-only Offline Ride Packs, photos, and preferences must be removed separately or by clearing app/site data or uninstalling the app.
Anonymous capability links or Telegram sessions created while signed out cannot be reliably matched to an account. Let them expire, use the relevant stop command, or send the random link/token to support. Stripe may retain billing records required by law.
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing; you may withdraw analytics consent at any time. You may complain to Romania’s data-protection authority (ANSPDCP) or your local supervisory authority. Identity verification may be required before a request is completed.
Security, children, and changes
Haremoto uses encrypted HTTPS transport, scoped authentication, Secure cookies, request rate limits, and restricted access to stored data. No internet service is risk-free. Haremoto is not directed to children under 16. Material policy changes will be dated here and, where appropriate, shown in the app.