Contact
Trail Tunes is provided by G&K Studios LLC. For privacy or support questions, email support@gandkstudiosllc.com.
Data we handle
Trail Tunes is an account-first app. Users sign in before using public app features, browsing, playback, profile, pass, Journey, announcement, or account surfaces.
Account and profile data
Trail Tunes uses Firebase Auth for Google sign-in and email/password accounts. Firebase Auth may process your email address, sign-in provider, account identifier, and authentication state. Trail Tunes does not store your password.
The app stores account profile records in Firebase Firestore, including your Trail Tunes user ID, email address, display name, profile photo URL when provided by your sign-in provider, created and updated timestamps, and announcement state.
Paid pass and subscription data
Trail Tunes uses Google Play Billing for Overlook Pass and Trail Pass subscriptions. The app and backend process subscription product IDs, plan period, package name, purchase status, purchase and expiry timestamps, purchase tokens, linked purchase tokens, and related billing state so Trail Tunes can verify and sync access. For a signed-in purchase or restore, the app sends an obfuscated Trail Tunes account ID to Google Play. Google Play can return that value to the Trail Tunes backend to help associate the purchase; it is not the account's raw Trail Tunes user ID.
Separately, to help prevent one Google Play purchase from being attached to multiple Trail Tunes accounts, the backend stores a server-only one-way hash of the purchase token in an ownership index rather than storing the raw token in that index. The ownership index is not sent back to the app. After account deletion, a retained ownership record may keep the obfuscated account marker but removes the raw Trail Tunes user ID. Trail Tunes does not automatically transfer a purchase between accounts when ownership is missing, deleted, or disputed.
Trail Tunes also uses server-only recovery records when Google Play billing work is delayed or cannot be completed immediately. A private recovery record may contain current and linked raw purchase tokens only while the recovery is active, scheduled, retrying, verifying, or blocked and still needs correctness work. App clients cannot read these records. When verified recovery reaches a terminal state, Trail Tunes removes the raw purchase tokens and keeps only hash-based recovery metadata for the limited retention period described below. Hash-only records of processed real-time billing notifications are also stored to make retries idempotent. Google Cloud Pub/Sub uses separate configured 31-day retention windows for unacknowledged recovery messages and dead-letter copies.
Playback, catalog, and Cloudflare delivery
Audio and catalog requests are served through Cloudflare Workers and Cloudflare R2. Playback requests may include Firebase App Check tokens, Firebase ID token claims, requested trail/song identifiers, and request metadata needed to authorize and deliver audio. Cloudflare and other internet infrastructure may process IP address and request metadata as part of delivering the service.
Your Journey listening stats
Journey stats are local-first in the app. For signed-in users with an active Trail Pass, Trail Tunes may sync Journey summaries and listening-day records through Firebase Cloud Functions and Firestore so the account-backed Journey view can be restored.
Rewards, ads, and activity recognition
Trail Tunes uses Google Mobile Ads / AdMob for rewarded video ads. Depending on the ad request, device or app settings, and applicable consent choices, the Google Mobile Ads SDK may collect and share ad interactions, device or advertising identifiers, diagnostics, and IP address or approximate location information with Google and participating advertising partners for advertising, analytics, and fraud-prevention purposes.
The production app also includes Unity Ads as an AdMob mediation partner. Depending on which partner handles an ad request, advertising partner SDKs may collect and share ad interactions, device or advertising identifiers, diagnostics, IP address or approximate location, and related request metadata with Unity Ads and participating advertising partners to provide advertising, analytics, security, and fraud prevention according to their own policies and the user's applicable consent choices.
Trail Tunes may request Android activity recognition permission. If granted, the app uses activity signals to avoid showing a visual rewarded-ad gate while the app detects driving. Trail Tunes does not use this permission for GPS location.
Notifications and announcements
Trail Tunes uses Firebase Cloud Messaging for catalog and announcement updates. The app may process messaging tokens, notification delivery state, and announcement seen state so updates can be delivered and not repeatedly shown.
Analytics, diagnostics, and crash reporting
Trail Tunes uses Firebase Analytics and Firebase Crashlytics for app reliability, launch readiness, playback health, billing health, and support debugging. Telemetry is designed to avoid raw email addresses, user IDs, purchase tokens, raw URLs, and raw exception messages.
Local-only app data
Account-scoped local data includes Day Pass and rewarded playback state, Trail Streak progress, announcement-seen state, local Journey rows, and per-account Journey sync markers. In-app account deletion automatically removes that data for the deleted account and retries safely if cleanup is interrupted.
Device-scoped recent driving signal state and rebuildable catalog cache data are not tied to a Trail Tunes account. Clearing app data or uninstalling the app removes that device-only data.
Service providers and advertising partners
Trail Tunes uses Firebase, Google Play, and Cloudflare to provide authentication, storage, billing, messaging, diagnostics, security, catalog delivery, and audio playback. Trail Tunes also uses Google Mobile Ads / AdMob and the packaged Unity Ads mediation SDK as an advertising and mediation partner. Their data collection and sharing depends on the ad request, configuration, device or app settings, and applicable consent choices as described above and in each partner's privacy policy.
Trail Tunes does not sell personal information. Data may be processed by service providers, collected or shared with advertising partners as described above, when you ask us to provide app functionality, or when required for legal, security, fraud-prevention, or compliance reasons.
Retention and deletion
Trail Tunes keeps account and entitlement records while needed to provide account, pass, support, security, and app functionality. Deleting your Trail Tunes account removes your Firebase Auth account and triggers retry-enabled backend cleanup of Trail Tunes Firestore profile, entitlement, entitlement-claim sync, announcement-seen, and Journey sync records tied to that account. Cleanup also removes the account's private paid-access recovery record and every hash-only real-time billing recovery event associated with that account.
A temporary one-way deletion marker receives a purge date 24 hours after successful backend cleanup. To prevent a deleted account's Google Play purchase from being silently reused by another Trail Tunes account, the one-way purchase and account markers receive a purge date 15 months after the later of account deletion or the latest subscription expiry verified by Trail Tunes. Later verified subscription activity may extend that date. Configured retention controls remove eligible records after their purge date; removal is not instantaneous. Records with unresolved or conflicting ownership evidence are kept until the evidence is explicitly resolved. These retained records do not provide app access and do not contain the deleted account's raw Trail Tunes user ID.
Outside account deletion, a terminal private recovery record contains no raw purchase token and receives a purge date 32 days after its final verification. Hash-only real-time billing recovery-event records receive a purge date 32 days after receipt. The extra day covers the 31-day Pub/Sub replay window plus one operational day. Active, scheduled, retrying, verifying, or blocked nonterminal recovery records do not receive a purge date and are kept until the recovery work is resolved because they still own correctness work. Configured retention controls remove eligible terminal and hash-only records after their purge date; removal is not instantaneous.
Some records may remain with service providers such as Google Play, Firebase, Cloudflare, or AdMob according to their own retention rules or where needed for security, fraud prevention, accounting, dispute handling, or legal compliance.
To delete your account or request deletion without using the app, visit Account deletion.
Security
Trail Tunes uses HTTPS and service-provider security controls for data in transit. The app uses Firebase App Check and authenticated backend calls for protected app flows. No method of transmission or storage is perfect, but Trail Tunes limits data handling to app functionality, support, security, analytics, billing, ads, and service operation.
Children
Trail Tunes is not designed or marketed as a child-directed app. If you believe a child has provided account data without appropriate permission, contact support@gandkstudiosllc.com.