English (TraceHero · Google Maps)  |  中文版(寻踪侠 · 高德地图)

TraceHero Privacy Policy

Effective date: December 16, 2025
Last updated: July 9, 2026
Applies to: Google Play build (Google Maps Platform)

Welcome to TraceHero (the “App”). The App is operated by Nanjing Ruichuangte Information Technology Co., Ltd. (“we”, “us”, or “our”).

We take your privacy seriously. This Privacy Policy explains how we process information to provide TraceHero features. Core business data in the App—such as device locations, track history, geofences, profiles, and device bindings—is processed on your device. We do not upload that business data to our own servers. No account registration is required to use the App.

Please read this policy carefully before using the App. By using the App, you acknowledge that you have read and understood this Privacy Policy.

1. Information We Collect and How We Use It

We follow a minimum-necessary approach and request system permissions only when needed for App features. Data handled directly by our App logic is processed primarily on your device.

1.1 Information Processed Directly by the App

For App functionality, we may process the following information locally on your device:

  1. Location information
    • Your GPS location (to show “My Location” on the map and calculate distance and direction to tracked devices)
    • Location coordinates (latitude/longitude) received from Bluetooth broadcasts of trackers, mobile relays, beacons, and other RCT hardware
  2. Device and UI information
    • Platform type (iOS/Android) and OS version
    • Status bar height and screen size (for layout adaptation)
  3. Sensor information
    • Device heading (compass direction, 0–360°) to orient the “My Location” marker on the map
    • Sensor capabilities reported by the system (e.g. GPS, accelerometer) for location, map, and Bluetooth features only—not for advertising or profiling
  4. Bluetooth device information
    • Scanned BLE device names, device IDs, and signal strength (RSSI)
    • Location and other data in device broadcasts (for map display, alerts, and parsing)
    • Data sent over Bluetooth when configuring devices or performing over-the-air (OTA) firmware updates
    • On supported helmet/card devices: device identifiers such as IMEI read over Bluetooth for display and configuration (not uploaded to our servers)
  5. Helmet Wi‑Fi configuration (when you use that feature)
    • Wi‑Fi SSID and password you enter, or read from a connected device over Bluetooth, to send configuration to the device
    • Used only for Bluetooth parameter transfer; we do not upload Wi‑Fi credentials to our servers. Avoid configuring sensitive networks on untrusted devices
  6. Camera and QR scanning
    • When you use “Scan to bind device”, the camera reads a device QR code; the parsed device ID is used locally for binding. We do not upload scan images or photo library content
  7. Information you voluntarily enter in profiles
    • In Profile Management you may enter names, notes, emergency contacts, phone numbers, and other optional fields for livestock, team members, or tour participants
    • This content is stored only in the on-device database for map and list display
  8. Locally stored data (on device only)
    • SQLite database rct_app.db: track history, geofences, alerts, device aliases, scene settings, profiles and bindings, missions, OTA records, and related data
    • App settings: privacy consent status, data retention days, permission guidance records, etc.
    • OTA firmware cache (downloaded to the device only when you use network-based OTA)
    • Import/export backup files (created or restored by you)
Information we do not actively collect or upload to our servers: contacts, SMS, call logs; government ID numbers (except what you voluntarily store in local profiles); and IDFA for cross-app advertising (IDFA is disabled in our build configuration; we do not request iOS App Tracking Transparency for ad tracking).

Note: Third-party SDKs (especially Google Maps Platform) may process device identifiers, location, and network information on the device or with their service providers, as described in Section 1.5. That is separate from us collecting and storing your business data.

1.1.1 Network features (device OTA)

The App is local-first by default. When you open Device OTA or related network features, the App may contact location.rctiot.com, for example:

Requests mainly include device-type and firmware metadata needed for upgrades. They do not include your tracks, geofences, profiles, or other business data. Device IDs shown on the OTA screen are used locally for Bluetooth transfer and local OTA logs; they are not uploaded to the firmware server. Downloaded firmware is stored on the device and transferred to hardware over Bluetooth.

1.1.2 DCloud uni-app framework

The App is built with DCloud uni-app (5+ App).

Current build configuration:

Framework components may still be used for runtime and UI rendering. For DCloud’s general compliance information, see https://dcloud.io/license/appprivacy.html

1.1.3 uni-app runtime components

The packaged App may include default framework components (e.g. for nvue rendering and images), such as:

These support UI and basic capabilities. We do not use them for ad tracking, and we do not upload your business data to our servers through them.

1.2 System permissions and purposes

To provide core features, the App and integrated map services may request the permissions below. Prompts generally appear when you first use the related feature.

When permissions are requested (summary):

Note: Our Android manifest explicitly excludes several sensitive permissions (e.g. contacts, phone calls, microphone, READ_PHONE_STATE, broad external storage read/write). Merged dependencies may still declare additional permissions; refer to your device’s Settings → Apps → TraceHero → Permissions for the installed build.

Location (GPS)

Network (Internet)

Bluetooth (scan and connect)

Camera (QR codes)

Orientation sensor

Write system settings (Android only)

Wi‑Fi state (Android only)

Storage permissions

Our Android main configuration excludes broad external storage read/write. OTA firmware, the SQLite database, and backups are stored in app-specific directories. If your installed package still lists storage-related permissions, they may come from merged libraries; we do not use them to read unrelated photos or videos.

Camera vs. photo library

Device binding uses the camera for QR scanning only (uni.scanCode). We do not access your photo library for this feature. Settings may label “Camera/Album” for clarity on some devices; album access is not required for core binding flows.

Background location and notifications (if present in your build)

Map or system components may declare background location or notification permissions. Our product focus is foreground map use and Bluetooth scanning. Background location may occur only when you use related features and the OS allows it. You can revoke permissions in system settings.

1.3 System information

For UI layout we read platform (iOS/Android), OS version, status bar height, and screen size. This is not uploaded to our servers.

1.4 Local storage

Business data is stored primarily in SQLite at _doc/rct_app.db. Upgrades from older versions may have migrated legacy keys (e.g. histrackdata, saved_fences_list) into the database once.

Data type Storage Purpose Retention
Track history device_track_points History screen Auto-deleted per Storage settings (default 3 days; options 1/3/7/14 days)
Geofences geo_fences Geofence configuration Until you delete or uninstall
Alerts (geofence, offline, etc.) alert_records Alert list Expired records cleaned per retention policy
Device aliases device_aliases Custom display names Until uninstall
Profiles and bindings object_profiles, device_bindings Profiles and device links Until you delete or uninstall
Scenes and alert settings scenes, app_settings Scene mode, retention, privacy consent, etc. Until uninstall
Missions / activities missions Hiking or tour group activities Until you delete or uninstall
Last seen (device status) device_last_seen Last location, battery, RSSI Cleaned per retention policy
OTA records ota_records Upgrade history and status Until you delete or uninstall
Device config summary device_config_summary Bluetooth configuration summary (when used) Until you delete or uninstall
Permission guidance app_settings, _permissionStatus, etc. Avoid repeated permission prompts Until uninstall
Backup files JSON you export or save via share Backup and restore (all 12 business tables) Managed by you

Online maps: The current version uses Google Maps Platform for online map tiles. There is no in-app offline map pack download (unlike legacy Amap-based builds). Without network access, map tiles may not load; local Bluetooth and stored data features may still work.

All business data above stays on your device. We do not read or upload it to our servers. Uninstalling the App removes data in the app directories.

1.5 Third-party SDKs

The App integrates third-party SDKs for maps, firmware transfer, and framework/runtime support. They may process data under their own policies.

SDK Provider Types of information Purpose Privacy policy
Google Maps Platform Google LLC Location; device and network information (model, OS, IP, connectivity—see Google’s policy) Map display, tiles, positioning Google Privacy Policy
Maps Terms
Nordic DFU Nordic Semiconductor (via embedded library) Bluetooth connection data during Secure DFU BLE firmware upgrade to supported devices nordicsemi.com (library terms apply to the embedded component)
DCloud uni-app runtime DCloud Device and runtime information as needed for the framework App runtime and UI DCloud App Privacy

Notes specific to this App:

2. Storage and Security

Runtime data: Live map display and Bluetooth parsing are handled mainly in memory while the App runs.

Persistent data: See Section 1.4; stored in SQLite or app-specific folders on device.

Security measures:

  1. Local data resides in app-protected storage
  2. OTA and policy pages are accessed over HTTPS where supported
  3. We do not maintain a cloud copy of your business data on our servers

No security measure can guarantee absolute protection.

3. Sharing, Transfer, and Disclosure

We do not sell or share your local business data (tracks, geofences, alerts, profiles, etc.) with third parties for their marketing.

Exceptions include:

4. Your Rights and Choices

  1. Access: View tracks in History, geofences and alerts in their screens, and profiles in Profile Management
  2. Correction: Edit geofences, device display names, and profile fields in the App
  3. Deletion:
    • Delete individual geofences in the geofence screen
    • Track history and some alerts: automatic cleanup by retention days, or manual cleanup in Storage
    • Profiles and bindings: delete in the relevant screens
    • All local data: uninstall the App
  4. Backup and restore: Use Import/Export to export or restore on-device data; you are responsible for backup files you create
  5. Withdraw consent: Revoke location, Bluetooth, camera, etc. in system settings (Android: Settings → Apps → TraceHero → Permissions; iOS: Settings → Privacy & Security → Location Services / Bluetooth / Camera → TraceHero)
  6. Account deletion: There is no account system; uninstalling the App stops use and removes local business data from app storage

5. Sensitive and Voluntary Information

You may optionally enter emergency contacts, phone numbers, blood type, or similar fields in profiles. This is voluntary and stored locally. Exported backups include these fields if present. Please store backups securely and avoid entering information you do not wish to keep on device or in backup files.

6. Children

We do not knowingly target children. If you are a minor, use the App only with a parent or guardian’s consent and supervision. If you believe we have processed a minor’s information without appropriate consent, contact us and we will address it as required by law.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through in-app notice or announcements on our website. Continued use after an update means you accept the revised policy.

Online versions:

8. Contact Us

If you have questions, comments, or requests regarding this policy, contact us:

We aim to respond within 15 business days of receiving your message.