Skip to content

Privacy policy

Last updated: 11 October 2026.

TROME needs to know which station you are near, not who you are. By Apple’s definition, TROME collects no data about you: what reaches the server is used to answer, then not kept. This page says what the TROME iPhone app does with your data, what the server stores, who receives it, and what your rights are.

  • TROME has no account and shows no ads.
  • The app does not measure what you do: the server only counts how many requests it receives, never who makes them.
  • Your position stays on your iPhone: the app sends it to nobody.
  • To show the train times, the app sends the server the identifier of the station you are near, but not your position, and nothing that the app adds to identify you.
  • The server keeps no history of the stations asked for, or of who asks for them. Cloudflare, which runs the server, sees each request while it passes, as explained below.
  • The App Store page says the same: Data Not Collected. What Apple provides, such as the number of downloads, or your data if you test TROME with TestFlight, is explained below.

TROME uses your position, on the iPhone, to find the nearest station, and to show or remove the Live Activity when you come near a station or move away from it. With Always access, iOS tells TROME when you come near a station, even when the app is closed.

The app sends your position to nobody, not even to the server. You can change this access at any time in Settings > Apps > TROME > Location. Without your position, TROME cannot find the nearest station.

To show the next trains, the app asks TROME’s server for the times. It sends the identifier of the station (for example the one of Châtelet) and a code that every copy of the app shares, which says nothing about you. It sends neither your position, nor an identifier of your iPhone, nor anything that the app adds to identify you. So the request shows which station you are near at that moment.

Like any internet connection, the request arrives with the IP address of your iPhone and technical details, such as the versions of the app and iOS. The server does not read them and does not store them.

Section titled “Why this data is used, and on what legal basis”

The legal basis is the same for each use below: legitimate interest (GDPR, article 6(1)(f)). Here is what each piece of data is for:

  • The identifier of the station, and the IP address that comes with it: to give you the times that you ask for, and nothing else. Under the GDPR, using data for the length of one request already counts as processing, even if nothing is stored. The interest is legitimate here because TROME cannot work without this data, the processing is very short, and nothing that identifies you is stored.
  • The server’s totals, and their copy: to watch the daily limit of calls to the source of the times, and to follow how much TROME is used. They have no station and no IP address.
  • The server’s list of errors: to see why it did not get the times from the source, and to fix what is wrong.
  • Your messages: to answer you and to fix TROME.
  • TestFlight data and the numbers that Apple provides: to fix TROME, to improve it and to follow how much it is used.

The server writes no station that was asked for in its totals, its errors or its logs. It stores only:

  • totals: how many requests it receives each hour and each day, how many calls it makes to the source of the times, and how many errors. These totals have no station and no person. A copy goes to a private monitoring tool that no third party hosts, and nobody else receives it. The totals and their copy are kept for as long as they serve the purposes given above;
  • a list of errors: the time, the kind of error and its code. It has no station either. It is kept only while it helps to find and fix the cause of an error;
  • the latest answer of the source of the times for each station, as the source gave it, to give it to everyone who asks. It stays in the memory of the server, never written down, and the server erases it at its next request after 10 minutes. It does not say who asked for the station;
  • the station for which the source just failed, with the time of the failure, in the same memory, until the server’s next request after one minute: the server does not call the source again at once;
  • the time until which the server waits, after the source refuses a call: it does not call the source before then.

The server stores no IP address, no identifier of you or of your iPhone, and no position. No request log is turned on at its host.

The server runs on Cloudflare. Cloudflare gets each request before the server does, so it sees the address that was requested, which holds the identifier of the station, and the network details that come with any web request, such as your IP address and the approximate location that it works out from it. Every log that Cloudflare could keep for TROME is turned off. Cloudflare handles this request on behalf of TROME, as its processor, under its data processing addendum and its privacy policy. Cloudflare is a US company, so it may handle a request outside the European Union, in particular in the United States. To protect your data there, it relies on the EU-US Data Privacy Framework and on the standard contractual clauses of the European Commission, which its addendum includes.

The server asks Île-de-France Mobilités (PRIM) for the times with the identifier of the station and TROME’s key only. PRIM gets nothing that comes from you.

TROME keeps your settings (the automatic mode, the snooze and the pauses), the last station shown, and the latest times it got, on your iPhone. The app sends them nowhere, but they are part of the backups of your iPhone, like the data of every app. Deleting the app deletes them.

For TROME on the App Store, Apple reports how many times TROME was shown, how many times its page was opened and how many times the app was downloaded, but never by whom.

If you share analytics with app developers (Settings > Privacy & Security > Analytics & Improvements > Share With App Developers), Apple provides crash reports and usage statistics, with nothing that says who you are. Apple explains it in Share analytics, diagnostics, and usage information with Apple. These usage statistics come only from people who share: the others do not count in them.

If you test TROME with TestFlight, Apple provides your crash reports, usage data, and the feedback that you send. If you were invited by email, they come with your name and email address, but not if you joined the test through a public link. Apple explains it in TestFlight & Privacy.

This information is used only to fix TROME, to improve it and to follow how much it is used, and it is shared with nobody.

Your rights: see, correct or delete your data

Section titled “Your rights: see, correct or delete your data”

The server stores nothing that could lead back to you, so there is nothing to see or delete on it. The only personal data that reaches me is what Apple provides if you test TROME with TestFlight, and the messages you write. A message is kept for as long as it takes to answer and fix the problem, then deleted, and sooner if you ask. The name and email address of a tester are kept for the length of the test, then removed from the list of testers.

You can ask to see this data, to delete it, to correct it, or to limit how it is used, and you can object to its use. I answer within one month at most.

To ask a question, or to make one of these requests, write to contact@trome.valfur.fr. If you were invited to TestFlight by email and you want your data deleted or your name removed from the testers, write from the address that received the invitation: it is what lets me find your name. An issue on GitHub with the question form works too for a question, but an issue is public and GitHub keeps it under its own privacy policy: do not write your name, your email address, or anything personal in it. You can also complain to the CNIL, the French data protection authority, or to the one in your own country.

I am Valentin Furmanek, and I make TROME on my own. I am the person responsible for the data that this page describes (the “controller”, in the GDPR). To reach me, write to contact@trome.valfur.fr.

This page is hosted by GitHub Pages. GitHub logs the IP address of whoever opens it, for its own security, under its privacy statement. This site has no visit statistics and no cookies.

Each time this page changes, the date at the top of the page changes too.