Privacy Policy
Summary
Pothole Reporter has no project-operated server, advertising network, or app account system. Reports, recordings you choose to create, and a saved dashcam RTSP address stay on your device.
It is not fully offline: selected pothole images are sent directly to OpenAI for analysis. Precise coordinates are sent to OpenStreetMap Nominatim; Karnataka locations also query Karnataka GIS, and exact Hyderabad CURE checks query Telangana GIS. Downloaded state-boundary containment, including Uttar Pradesh, Chhattisgarh, and Rajasthan, is checked locally.
Routing/contact and optional National Highway, PMGSY, official State/UT procurement-notice, and Karnataka KPPP candidate data is downloaded only when needed as a versioned State/UT pack or 2° National Highway tile from this project's GitHub Pages site and then cached locally. That request contains no report, photo, or exact coordinates, but GitHub can receive an IP address, standard connection metadata, and the requested URL, which identifies the selected state, the top-50 city pack, or an approximate 2° tile. Downloaded bytes are checked against a checksum pinned in the app before use. Remote candidate packs do not enter the APK; the three catalog manifests add about 100 KB to a future build. These repository changes do not alter the already-submitted Play closed-test binary.
Reports are not filed automatically. Only when you choose a handoff does the app open an official app or portal, place prefilled text in WhatsApp, open the dialler, share compressed evidence, or hand an editable draft to your email app. You must review and complete the complaint in that external service.
Scope and controller
This policy applies to the Pothole Reporter Android app and its project pages. “The project” below means the Pothole Reporter open-source project identified by that name in its store listing and source repository.
The project does not receive a central copy of your reports because it operates no collection backend. The external services listed below receive data directly from your device for the features you request.
Data the app handles
| Data | What happens | Purpose |
|---|---|---|
| Pothole photos and video frames | A pothole photo, or selected complete still frames sampled during Drive Mode or from saved drive evidence, is resized and sent to the OpenAI API. Drive can use either the phone camera or a user-configured H.264 RTSP dashcam stream. The RTSP address, including any credentials, is saved only in app storage on the device; audio is disabled. The whole dashcam stream is neither saved nor uploaded. When optional phone-camera recording is enabled, Android stores local video and a 720p evidence frame at most every two seconds; an explicit post-drive pass can send an unfinished evidence frame with nearby frames from just before and after it. On a precise later live-drive revisit, the saved earlier damage photo and current views may be sent together for a separate before/after repair check. Images are not blurred first and may contain faces, number plates, people, vehicles, or shopfronts. The complete saved video file is not uploaded by the app. | Assess visible potholes and create an editable local report. |
| Legacy garbage and manhole reports | Current versions do not offer these Photo categories. Reports created by an older version remain readable and deletable on the device; their photo leaves the app only if you choose an external handoff, email, or share destination. | Preserve access to existing on-device reports after an update. |
| Precise location and drive motion data | The app reads latitude and longitude and may retain a local drive track with accuracy, speed, heading, and timestamps. Coordinates are sent to OpenStreetMap Nominatim. Its structured city/municipality and state fields are also required for the remaining city-specific top-50 routes. Karnataka locations query Karnataka GIS endpoints. For Hyderabad-area reports, a small envelope representing the GPS accuracy is sent to the official Telangana GIS service to check the 2,053 km² Core Urban Region and exclude Secunderabad Cantonment before selecting My Cure. An unavailable or ambiguous response, or a Cantonment intersection, cannot select My Cure but can use neutral Prajavani after local state containment. The app requests the 2° National Highway tile containing the point and checks mapped NH/NE geometry locally. After the required verified routing pack has been downloaded, all 28 States and all 8 Union Territories are checked locally against cached checksum-pinned geometry; more-specific reviewed municipal routes retain precedence. Viewing the in-app map requests OpenStreetMap tiles for the displayed area. | Find an address, check supported coverage, suggest a complaint route, identify a supported Karnataka body, classify Karnataka roads, display report locations, and suppress repeated Drive Mode observations. |
| Downloaded routing, highway, contact, and optional project/procurement data | When needed, the app requests a versioned routing, National Highway project, PMGSY road-agreement, official State/UT procurement-notice, Karnataka KPPP, or 2° highway-geometry pack from coding-parrot.github.io. The URL identifies the selected state, the shared top-50 city pack, or an approximate tile but contains no report, photo, or exact coordinates. GitHub can receive the device's IP address and standard connection metadata. If an optional candidate pack is unavailable or cannot be verified, the report continues without contract context. Verified packs are stored in the app's local cache. |
Keep the APK smaller while providing locally processed highway geometry, boundaries, published contacts, and optional road candidates. |
| OpenAI API key | The key you enter is stored in the app's local WebView storage and sent to OpenAI in the authorization header for API requests. It is never built into the app or sent to a project-operated server. | Authenticate usage billed to your own OpenAI account. |
| Road address and procurement candidates | For an eligible Karnataka route only, the reverse-geocoded road address and a shortlist of public KPPP records may be sent to OpenAI for a probable match. National Highway, PMGSY, and official State/UT notice candidates outside this flow are matched locally on the device. | Offer an optional, reviewable road reference. A match is not proof of the exact segment, award, contractor responsibility, warranty, or DLP. |
| Name, settings, reports, labels, photos, footage, and drive summaries | These are stored on the device. A verified or review-needed repair revisit also stores its current evidence photo and physical-condition status locally, separately from complaint-submission status. Your name is placed in the complaint signature. An official grievance/reference ID is stored locally only if you enter it to mark an official-channel report submitted. Settings include language, model, image detail, Drive video source, the optional RTSP address, recording, Drive battery limit, frame-saving, and debug choices. | Run the app, preserve history, allow review, and prepare complaint drafts. |
| Official handoff text and evidence | The offered app or portal opens only after you choose it. A Google Play fallback receives no report attachment. A WhatsApp action places complaint text in a link but does not press Send. Share creates compressed image copies and report text in app cache and invokes Android's share sheet. Call opens the dialler. Email hands an editable draft and attachment to your email app. | Let you review and complete a complaint yourself in an external official channel. Opening any channel is not treated as a submission. |
| Email draft and attachment | When you choose Email, the recipient, subject, complaint body, and road photo are handed to your email app. The email provider may sync a draft under its own terms. Pothole Reporter does not press Send. | Let you review, edit, and choose whether to send a complaint. |
| Saved or exported evaluation files | If you enable frame saving, analysed frames and a model-verdict manifest are written to the device's Documents area. If you export labelled data, a ZIP is handed to Android's share sheet and goes only to the destination you choose. | Let you inspect model output and build a human-labelled evaluation set. |
External recipients
- OpenAI: API credentials, selected pothole images, prompts, and—for eligible Karnataka contract matching only—a road address and procurement shortlist. Requests set
store: false, which prevents Responses API application-state retention but does not override OpenAI's security, abuse-monitoring, or legal retention. See OpenAI's privacy policy. - OpenStreetMap services: coordinates sent to Nominatim for reverse geocoding—including the structured city/state fields required by remaining city-specific routes—and map-area requests sent to the tile service. Downloaded ODbL boundary copies cover all 28 States and all 8 Union Territories, with more-specific reviewed municipal polygons where available; those polygon checks run locally and do not themselves send the coordinate to OpenStreetMap. See the OpenStreetMap Foundation privacy policy and Nominatim policy.
- Karnataka GIS/KSRSAC: for Karnataka locations only, coordinates are sent to government map endpoints to check municipal, gram-panchayat, and national-highway layers.
- Telangana GIS/TGRAC: for Hyderabad-area routing only, the report coordinates and GPS-accuracy envelope are sent to official government map endpoints to check the Core Urban Region and Secunderabad Cantonment. No report text or photo is included.
- GitHub Pages: hosts this project's versioned routing, National Highway, PMGSY, official State/UT procurement-notice, Karnataka KPPP, and 2° highway packs. A request can disclose the device's IP address, standard connection metadata, and the requested URL, which identifies the selected state or approximate tile. It contains no report, road photo, or exact coordinates. GitHub handles its logs and metadata under the GitHub General Privacy Statement.
- Google Play: when an offered official Android app is absent, its store page may open. The app does not attach report content to that link, although Google receives ordinary connection and device metadata under its privacy policy.
- WhatsApp/Meta: after a separate confirmation, choosing an offered published WhatsApp route—including PMC CARE and supported BMC, VVCMC, KMC, Delhi PWD Sewa, GCC Chennai, or AMC CCRS routes where applicable—passes prefilled complaint text, including the exact location, to WhatsApp. It is not sent as a chat until you choose Send there. See WhatsApp's privacy policy.
- Official complaint recipients: opening a plain app or portal link sends ordinary connection or launch metadata; report content reaches that recipient only when you complete a message, email, upload, call, or submission in its external service. Available routes include Rajmargyatra/1033 for mapped National Highways; reviewed municipal channels where available; State/UT grievance systems; and CPGRAMS as the conservative State/UT handoff where no safer specific online intake was verified. Every neutral handoff requires the user to select and verify the district, department, local body, category, and road owner. No handoff proves ownership or automatic submission, and the app has no public complaint-write API integration. See BMC's published website policy and KMC's website disclaimer and privacy terms.
- Your email and sharing providers: data is transferred only when you open a complaint draft or choose a destination in Android's share sheet. Their own policies and retention rules apply.
Like other internet services, these recipients can receive an IP address and standard connection metadata. They may process data outside your state or country, including outside India. The project does not control their independent retention or legal obligations.
Permissions
- Camera captures a manual pothole photo or Phone camera Drive frames. Dashcam Drive does not request or use the phone camera. While Phone camera Drive is active, the camera remains in use in the background—even when this app is not visible or in use and another app, such as Google Maps or the phone-call screen, is visible—under a persistent foreground-service notification.
- Precise or approximate location locates and routes a report and records a drive track. With either Drive source, location remains in use in the background under the same persistent foreground-service notification, including when this app is not visible or in use.
- Internet and network access reach the external services described above and the RTSP endpoint on a dashcam network selected by the user.
The app does not request Android's separate background-location permission. Android Drive Mode nevertheless uses location and the selected video source in the background while its visible foreground service is active, including when this app is not visible or in use and Google Maps or the phone-call screen is visible. It can be paused or stopped from the app or persistent notification. A video call or another higher-priority camera user can temporarily interrupt Phone camera sampling; a dashcam or Wi-Fi interruption triggers bounded reconnection attempts. RTSP does not expose the dashcam sensor's true capture time, so an uncalibrated dashcam detection keeps its evidence and observed coordinate but does not automatically select an authority, tender, or repair match; Phone camera is required for that automatic routing until the exact dashcam/phone pair is calibrated. Mount the phone or dashcam before moving and do not interact with it while driving.
Retention and deletion
- Phone camera Drive recording is off by default. If you enable it, silent 60-second clips and sparse 720p evidence frames are written to app-private storage; the live screen and persistent notification state when video is being saved. Recording stops instead of deleting older clips when total footage reaches 4 GB or free space approaches 500 MB. Dashcam Drive stores selected evidence frames but does not save the whole RTSP stream.
- Drive has a selectable 15, 30, 60, or 90-minute active-time battery limit and defaults to 30 minutes. When the active-time limit expires, camera, location, recording, inference, and the foreground service stop through the normal Drive shutdown; paused time does not consume the limit.
- Reports, original and repair-evidence photos, sparse Drive frames, physical-condition history, drive summaries, and recorded footage remain in app-private storage until the app deletes them automatically or you delete them.
- An official grievance/reference ID you enter remains in the local report until that report or all app data is deleted.
- Sharing report evidence or an exported dataset creates temporary files in the app's dedicated cache folder. Android may clear cache automatically, and Delete all app data removes that folder. Copies already handed to another app are controlled by that destination.
- For browser fallback recording, successfully analysed footage is deleted when analysis completes without failed frame requests and Debug is off. Native Android clips and sparse frames remain until you delete that drive's footage from History or delete all app data.
- Verified routing, project/procurement, and highway packs are cached locally after download. On a subsequent pack use, entries past their unused limits or above the shared cache-size limit are pruned automatically and can be downloaded again when needed.
- Delete all app data clears local reports, photos, drive summaries, app-held footage, downloaded packs and highway tiles, the API key, sender name, RTSP address, settings, and the app's
Documents/pothole-framesfolder. - Files already exported, shared, attached, copied elsewhere, or sent are outside the app's control and must be deleted from their destination separately.
- Data already processed by OpenAI, OpenStreetMap services, Karnataka GIS, Telangana GIS, GitHub Pages, Google Play, WhatsApp, an email or sharing provider, or an official complaint service is subject to that recipient's retention and deletion process.
The app creates no Pothole Reporter account, so there is no project account to delete. Android backup is disabled for the app.
Security and your choices
Internet calls in the current app use HTTPS. A dashcam's local rtsp:// stream is commonly unencrypted, so use the dashcam's own trusted Wi-Fi and a camera password where supported; the app never places that address or password in Drive status or logs. Each downloaded pack has a version, expected byte length, and SHA-256 checksum pinned in a local manifest. The complete download is verified before parsing or caching. If required routing data is unavailable, malformed, or different from the pinned checksum, authority routing stops; failure of optional project/procurement data only omits candidate context. Highway matching also refuses weak GPS, ambiguous parallel references, and conflicting driving direction. State/UT and exact municipal polygon routes never fall back to a place name; enclave territories retain their own pinned boundaries. The specific My Cure route requires a successful official Telangana GIS check and excludes an accuracy envelope intersecting Secunderabad Cantonment. Detection, geocoding, Karnataka GIS, and exact CURE checks still require their own network services.
Local app data is protected by Android's device and application storage controls, but the app does not add separate at-rest encryption to the OpenAI key or dashcam RTSP address and credentials stored in WebView storage. Local RTSP is also normally unencrypted in transit, so use only a trusted dashcam Wi-Fi. Protect your device, use revocable credentials with appropriate limits, and revoke them if the device or a credential may be compromised.
- You can deny camera or location permission, but the corresponding capture or routing feature will not work.
- You can choose whether to enable drive recording, Debug retention, or saved analysis frames in Settings.
- You decide whether to edit, share, export, open an official channel, or send any draft or dataset. No complaint is submitted automatically.
- Review every AI verdict, recipient, and probable contract match before acting on it.
Children, changes, and contact
Pothole Reporter is a civic-reporting tool and is not designed for children. It does not create user profiles or knowingly operate a child-directed service.
If this policy or the app's data flows change, this page will be updated and its effective date will change. Material new collection should be disclosed in the app before it begins.
For a private privacy question or request, email contact@aiengg.dev. For a non-sensitive public bug, you may instead open a GitHub issue. Do not put an API key, precise location, unredacted report photo, or other sensitive information in a public issue.