Legal

Privacy Policy

Effective May 1, 2026 · Last updated August 20, 2026
The short version. Blocks is a walking app. We collect the location data we need to draw your map, the account info you give us to log in, and a small amount of diagnostic data so we can fix bugs. We don't sell your data, we don't share it with advertisers, and you can delete everything any time.

1. About this policy

This Privacy Policy describes how Blocks by Traversal Labs, Inc. ("we", "us") collects, uses, and shares information when you use the Blocks by Traversal Labs, Inc. mobile application and the website at nycblocks.com (together, the "Service"). By using the Service, you agree to the practices described here.

2. Information we collect

2.1 Information you give us

  • Account info. When you sign up, we ask for your email address, a display name, a username, and an optional home neighborhood. If you sign in with Apple, we receive a privacy-relay email and your chosen name. If you sign in with Google, we receive your email and basic profile.
  • Profile content. Anything you choose to add or generate — profile photo, bio, friend list, blocked accounts, venue ratings (1–5 stars + optional notes), tastemaker picks — is stored against your account.
  • What other people can see. Some of this is visible beyond your friends, so it is worth being precise:
    • Reviews are public by default. When you rate a venue, that rating, any note you write, and your display name and username are visible to anyone using Blocks — not only to friends. You can set any individual review to private when you write it, change it afterwards, and change the default for new reviews.
    • Your profile is private unless you make it public. A public profile lets anyone see your stats and appear on public leaderboards. Public leaderboards are opt-in.
    • Tastemaker picks are visible to the person picked. If you add someone as a tastemaker, they can see that you did, and their total count of who picked them. Only people with public profiles can be picked.
    • Your precise location is never shown to anyone. Friends see completed blocks and stats — never a live position or a raw GPS trace.
  • Communications. If you email support, we keep that thread so we can help you.

2.2 Information collected automatically

  • Location data. When you start a walk (manually or via auto-track), we collect GPS coordinates from your device. We use these to determine which NYC street segments and blocks you have walked. iOS's Core Motion classifier filters non-walking activity (driving, cycling, riding the subway) on-device before any sample is sent to us. You control location access via iOS Location permissions and can revoke it at any time.
  • Device and diagnostic data. We collect crash reports, performance metrics, and basic device info (model, OS version, app version) to keep the app stable. Crash reports and product-analytics events are tagged with your account ID so we can tell one person's twenty crashes from twenty people's one crash, and so we can delete your diagnostic history if you ask. They do not carry your name or email, and our analytics is configured not to derive any location from your IP address.
  • Usage data. Which screens you open, which features you use, how often you open the app. Used only to make the app better.

2.3 Apple Health (optional)

Blocks can fill in your map from walks and runs you recorded somewhere else — an Apple Watch you wore without your phone, or an app like Strava or Nike Run Club that saves workouts to Apple Health. This is off unless you turn it on, and you can turn it off again at any time in iOS Settings → Health → Data Access & Devices → Blocks.

  • What we read. With your permission, Blocks reads walking and running workouts from the last 30 days and the GPS route saved with each one. We read only these. We never write anything to Apple Health.
  • What leaves your device. The workouts and routes themselves stay on your phone. Blocks matches a route against the NYC street map on your device, and only the result — which streets you covered and when — is saved to your account, exactly as it would be for a walk tracked in the app.
  • What we never do with it. We never use Apple Health data for advertising, marketing, or data mining. We never sell or share it. We never store it in iCloud or any other cloud service.
  • Undoing it. The one-time import of your last 30 days can be reversed from the Apple Health screen in the app, which removes the streets it added. Turning the connection off stops future imports; streets already credited stay on your map unless you undo the import or delete your account.

2.4 What we do not collect

  • We do not access your contacts, photos, microphone, or camera unless you explicitly grant permission for a specific feature (e.g. profile photo upload, contact-import to find friends). When you import contacts to find friends, we HMAC-hash each phone number on-device and only send the hashes — raw numbers never leave your phone.
  • We do not use third-party advertising SDKs, and we do not load tracking pixels.
  • We do not collect biometric data or financial data. The only health data we ever read is described in section 2.3, and only if you turn it on.

3. How we use information

We use the information we collect to:

  • Provide the core Service — drawing your map, counting blocks, calculating tiers and streaks.
  • Sync your data across your devices so you can switch phones without losing your walks.
  • Show your map and tier to friends you have approved (and only to those friends).
  • Send transactional messages (account verification, password reset, security alerts).
  • Improve the app — diagnose crashes, prioritize features, fix bugs.
  • Comply with legal obligations and enforce our Terms of Service.

4. Who we share information with

We share information only in these limited cases:

  • With other users. Your map, tier, and stats are visible to friends you have accepted, and to anyone if you turn on a public profile. Reviews you write are public by default. Section 2.1 lists exactly what is visible to whom.
  • With service providers. We use a small number of vendors to run the Service — backend & database (Supabase, hosted on AWS in us-east-1), maps and street geometry (Mapbox), crash reporting (Sentry), product analytics (PostHog, configured without IP collection and with autocapture disabled), authentication (Apple Sign-In, Sign in with Google), push notifications (Expo Push Service, which relays to Apple Push Notification service), and email delivery (Loops). The website uses Cloudflare (hosting and cookieless traffic analytics), Formspree (waitlist sign-ups), and Google Fonts (which receives your IP address when a page loads a font). Each vendor is bound by a Data Processing Agreement and may only use your data to provide their service to us.
  • For legal reasons. If we receive a valid legal request (subpoena, court order), we may disclose information to the extent required by law. We will push back on overbroad requests and notify you where legally permitted.
  • In a corporate transaction. If Blocks by Traversal Labs, Inc. is acquired or merged, your data will transfer to the new entity under this same policy. You will be notified in advance.

We do not sell your personal information. We do not share your location data with advertisers, data brokers, or analytics networks.

5. How long we keep information

  • Account & walks. Walked segments, completed blocks, sessions, venue ratings, visits, friends, and tastemaker picks are kept until you delete your account.
  • Diagnostic data. Retained for 90 days, then deleted.
  • Support emails. Retained for two years from your last reply.
  • Deleted accounts. When you delete your account, your walks and map data are removed from your account view immediately; your profile, venue ratings, visits, and social connections are purged from production databases within 7 days. Backups containing your data are overwritten on a rolling 30-day cycle. See Delete your account for the full breakdown.

6. Your rights

Wherever you live, you can:

  • Access a copy of the personal data we hold about you — request via [email protected].
  • Correct inaccurate information from your account screen.
  • Delete your account and all associated data at any time. See Delete your account.
  • Export your walking data — email [email protected] and we will send you a machine-readable copy. There is no self-serve export in the app yet.
  • Object to or restrict certain processing.

If you are in the EEA, UK, or Switzerland, you have additional rights under the GDPR including the right to lodge a complaint with your local data protection authority. If you are a California resident, you have additional rights under the CCPA/CPRA — including the right to opt out of sales of personal information, which we do not engage in regardless.

7. Children

Blocks by Traversal Labs, Inc. is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact [email protected] and we will delete it.

8. Security

We protect your data with industry-standard practices — TLS in transit, AES-256 at rest, hardware-backed key storage, and least-privilege access controls. No system is perfectly secure, but we work hard to keep yours protected. If we ever experience a breach affecting your data, we will notify you within 72 hours.

9. Changes to this policy

When we make material changes, we will notify you in-app and by email at least 30 days before they take effect. Minor changes (typo fixes, clarifications) are made without notice but always reflected in the "Last updated" date at the top of this page.

10. Contact us

Email us at [email protected] for any privacy question. For general support, use [email protected].

Blocks by Traversal Labs, Inc.
New York, NY
United States