Legal
Privacy Policy
Last updated: July 2026
MotoStar is a voice-first motorcycle navigation app with a conversational AI companion. Riding hands-free means trusting the app with sensitive signals — where you are and what you say. This policy explains, in plain terms, what we collect, why, who we share it with, and the lines we will not cross.
Not legal advice. This page describes product practices. Counsel should review before public store claims.
Two AI processing paths
MotoStar supports two ways AI and maps-stack calls can be billed and authenticated. Which path you use changes who is the customer of the underlying providers for those calls:
- Path 1 — Motostar-paid (default product path). MotoStar holds commercial API credentials (for example Anthropic Console / xAI API and maps/voice providers). MotoStar is the customer of those providers. Usage may be metered to you as part of the app plan (or estimated during closed testing without charge).
- Path 2 — Bring your own keys (optional power-user). You supply commercial API keys (Console / xAI API keys — not Claude Max or SuperGrok consumer logins). For those providers, you are the customer; MotoStar stores keys encrypted only to run your sessions on our servers. Surfaces still on Motostar-held keys remain under Path 1.
Consumer Claude Pro/Max OAuth and shared SuperGrok seats are not used as multi-tenant product backends for other riders. Operator/dev environments may still use Max or SuperGrok for internal development; that is not the multi-user product path.
What we collect
- Location data. While you are navigating, the app uses your device's GPS to calculate routes, give turn-by-turn guidance, detect off-route situations, find points of interest near you, and provide weather and traffic relevant to your ride. Location is processed for the duration of the ride; we do not build or sell a long-term profile of your movements for advertising.
- Voice and audio. When you speak to MotoStar, your microphone audio is captured and converted to text so the app can understand your request. Audio is used to fulfill that request and is not retained to build an advertising profile.
- Conversation content & ride journals. What you ask, companion answers, and ride context (routes, turns, memory the product needs for continuity) are processed to run navigation and the companion. We aim to keep only what is needed to operate, debug, and improve the service.
- Usage ledger. We record unit-level usage events (for example tokens, STT/TTS volume, maps/weather requests) and estimated cost for metering, soft caps, and (when billing is live) invoicing. During closed testing we may log estimated commercial costs without charging.
- Encrypted API keys (Path 2 only). If you connect bring-your-own keys, we store them encrypted server-side for session execution. Keys are hard-deleted when you disconnect; we never sell keys.
- Diagnostic data. Basic technical logs (errors, performance, app version) help us keep the app working and fix bugs.
Subprocessors
To deliver navigation and the companion, MotoStar sends the minimum data necessary to trusted providers, each under its own terms. Exact set depends on features and path:
- Anthropic (Claude) — conversational AI companion (commercial API under Path 1 or your Console key under Path 2).
- xAI (Grok) — alternate companion / agent backend when enabled (commercial API under Path 1 or your key under Path 2).
- OpenAI — speech-to-text and text-to-speech for the voice interface (and optionally your OpenAI key under Path 2 when supported).
- Google Maps Platform — routing, geocoding, and place search.
- TomTom — traffic incidents and flow where used.
- OpenWeather — weather and rain forecasts along your route.
- Microsoft Azure — hosting (containers, storage, logs) for the MotoStar backend.
- Stripe — subscription and metered billing when Path 1 charging is enabled (not used while only shadow-metering).
- Resend (or similar) — transactional email when account or billing mail is enabled.
We share only what a given feature requires — for example coordinates for routing, or spoken audio for transcription — and we do not authorize these providers to use your data to advertise to you.
Training and provider logs
- Commercial API paths we use generally default to no training on customer content under provider commercial terms. We do not claim Zero Data Retention unless we have a specific contractual ZDR arrangement for that surface.
- Providers may retain short-lived operational logs (often on the order of ~30 days for commercial APIs — check each provider). Deleting data from MotoStar does not guarantee immediate purge of those provider logs.
Retention
Product retention periods (transcripts, ride journals, memory, usage ledger) are tuned for continuity and support. As a working baseline pending final product settings: operational ride and transcript data may be retained for on the order of months unless you request earlier deletion; usage ledger aggregates used for billing may be kept as long as needed for accounting and dispute resolution. Exact periods may be refined before public launch — contact us for the current schedule or a deletion request.
What we never do
- We do not sell your personal data. Not your location, not your voice, not your conversations, not your API keys.
- We do not share your data with advertisers or data brokers.
- We do not track your location when you are not actively using the app for navigation.
- We do not use multi-tenant riders' Claude Max or SuperGrok consumer subscriptions as the product AI backend.
Data security
We use reasonable technical and organizational measures — including encrypted transport, access controls, and (for Path 2) envelope encryption of stored API keys — to protect your data. No method of transmission or storage is perfectly secure, but we work to keep the data we hold to a minimum and to isolate credentials per user.
Your choices
You can control location and microphone access at any time through your device's system permissions. Revoking microphone or location access will disable the features that depend on them. Path 2 users can disconnect keys (hard delete on our side). You may also contact us to request access to, correction of, or deletion of your personal data held by MotoStar.
Children
MotoStar is not directed to children, and we do not knowingly collect personal data from anyone under 13.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new “last updated” date.
Contact
Questions about this policy or your data? Email us at ajosephjohnson@gmail.com.