Privacy Policy
Paxi, by Passenger Labs, LLC · Effective August 5, 2026 · Last updated August 5, 2026
The short version
- Paxi has no user accounts and no Paxi server holding your rides. Your linked ride-service credentials stay on your iPhone.
- Your location and trip addresses go from your phone to the ride services you asked Paxi to check — that is how a fare gets quoted.
- We collect anonymous product analytics (which screens and actions, which service won a fare) with no addresses, coordinates, names, or emails.
- During the beta, Paxi can upload diagnostic copies of ride-service API responses, which may contain trip addresses. It is a one-tap toggle in Settings.
- We do not sell your data, do not run ads, and do not track you across other apps or websites.
1. Who this covers
This policy explains how Passenger Labs, LLC ("Passenger Labs", "we", "us") handles information in connection with the Paxi iOS app and the paxi.fyi website. Passenger Labs is a California limited liability company based in San Francisco.
Paxi is a fare comparison and booking app: it asks several ride services — such as Uber, Lyft, Waymo, Tesla, Zoox, and Curb — for a live price on the trip you entered, shows them side by side, and books the one you pick using your own account with that service. Paxi is independent and is not affiliated with, sponsored by, or endorsed by any of those companies.
2. How Paxi is built, and why it matters here
Paxi does not proxy your rides through our servers. When you request fares, your iPhone talks directly to each ride service using the account you linked. We do not operate a database of Paxi users, trips, or fares, and we cannot look up your ride history.
The practical consequence: for anything to do with your actual rides — pricing, payment, driver or vehicle information, receipts, support — the ride service is the party holding that data, under its own privacy policy and its own agreement with you. Paxi is the app on your phone that asks the question.
3. Information Paxi handles
Location
With your permission, Paxi uses your device location ("While Using the App" only — Paxi never requests background or always-on location) to set your pickup point and to center the map. Your pickup and drop-off coordinates are sent to the ride services you are comparing so they can quote and book the trip. Passenger Labs does not receive or store your location, except as described under Diagnostic captures below.
You can deny or revoke location access in iOS Settings; Paxi still works if you set the pickup manually.
Addresses and trip details
Addresses you type or pick are sent to Apple's Maps services for search and geocoding (handled under Apple's privacy policy) and to the ride services for quoting and booking. Recently used destinations are stored on your device so they can be offered again; deleting the app removes them.
Ride-service accounts and credentials
To show live, bookable fares, Paxi needs you to sign in to each ride service you want to compare. You sign in through that service's own login flow. The resulting session tokens are stored in Paxi's private app sandbox on your iPhone, protected by iOS app sandboxing and file protection. They are used only to talk to that service on your behalf.
Passenger Labs never receives your ride-service passwords or tokens. They are not transmitted to us and not backed up to any Passenger Labs system. Unlinking a service in Paxi's Settings deletes its stored credentials from your device.
Payment information
Paxi does not collect, process, or store payment card details. Rides are charged to the payment method already on file with the ride service, by that service. Some bookings hand off to the provider's own app or web checkout to complete payment.
Product analytics
Paxi sends anonymous usage analytics to Amplitude, our analytics provider, so we can see what works and what breaks. The events are a fixed, reviewed list — for example: the app launched; fares were requested; a given service returned a price, was busy, or failed; a ride was booked, canceled, or completed; an onboarding step was shown; which services you have linked; and which other ride apps are installed on your device (a signal for what to integrate next). Alongside these, Amplitude records standard technical context such as a randomly generated device identifier, app version, OS version, device model, and coarse region derived from IP address.
These events do not include your name, email address, phone number, street addresses, GPS coordinates, or ride-service credentials. Where a trip involves an airport, the airport's name may be included so we can debug airport pickup and drop-off rules.
Paxi does not use the iOS advertising identifier, does not present App Tracking Transparency prompts, and does not participate in any advertising or cross-app tracking network.
Diagnostic captures (beta)
Paxi talks to ride-service APIs that are undocumented and change without notice. When a response is unreadable or clearly wrong, Paxi can upload a copy of that response to a private, encrypted Passenger Labs storage bucket so we can fix the parser.
Diagnostic capture is on by default in the beta and can be turned off at any time with a single toggle in Paxi → Settings. Turning it off stops all such uploads immediately.
Website
paxi.fyi is a static page served through Amazon CloudFront. It sets no cookies and runs no analytics or advertising trackers. Standard web-server request logs (including IP address) may be generated by our hosting provider for security and operational purposes. Fonts are loaded from Google Fonts, which receives the request as part of serving them.
4. How we use information
- To quote and book the ride you asked for.
- To keep you signed in to the services you linked.
- To understand aggregate product usage and prioritize what to build.
- To diagnose crashes, failed quotes, and broken integrations.
- To meet legal obligations and to protect Paxi and its users from abuse.
We do not use your information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
5. What we never do
- We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we have not in the preceding 12 months.
- We do not share your information with advertisers, data brokers, or ad networks.
- We do not track you across other apps or websites.
6. Who else is involved
Paxi relies on a small number of third parties:
- The ride services you link (Uber, Lyft, Waymo, Tesla, Zoox, Curb and others we add) — they receive your trip request and handle the ride itself under their own privacy policies and terms.
- Apple — the App Store and TestFlight distribute Paxi; MapKit provides address search and maps. Apple may provide us with aggregate, anonymized TestFlight and App Store metrics.
- Amplitude — product analytics, as described above.
- Amazon Web Services — hosts the website and the diagnostic capture storage.
- Google — serves the web fonts on this site, and provides the sign-in flow for services that authenticate through a Google account.
We may also disclose information if legally required to do so, or if necessary to investigate fraud, security incidents, or violations of our terms. If Passenger Labs is ever acquired or merged, information may transfer as part of that transaction; we will note it in this policy.
7. How long we keep things
- On-device data (credentials, recent destinations, settings) — until you unlink the service or delete the app.
- Diagnostic captures — automatically deleted 90 days after upload.
- Analytics events — retained by Amplitude under our account's retention settings, in anonymous form.
8. Your choices and rights
Because Paxi has no accounts and no server-side record of you, the most direct controls are the ones on your phone:
- Location — grant, limit, or revoke in iOS Settings → Privacy & Security → Location Services.
- Linked services — unlink any service in Paxi → Settings to delete its credentials from your device.
- Diagnostic captures — turn the toggle off in Paxi → Settings.
- Everything — delete the app; the sandbox and all on-device data go with it.
Depending on where you live, you may have rights to access, correct, delete, or port personal information we hold, to opt out of sale or sharing (we do neither), and to be free from discrimination for exercising those rights. California residents have these rights under the CCPA/CPRA; residents of the EEA and UK have comparable rights under the GDPR, for which Passenger Labs, LLC is the controller of the limited data described above. To exercise any of them, email hi@paxi.fyi and we will respond within the time the applicable law allows. We may need to ask for information to verify your request. For data held by a ride service about your rides, please contact that service directly — we cannot access or delete it for you.
9. Security
Credentials stay in Paxi's iOS app sandbox rather than on our servers, which removes the single most attractive target. Traffic between the app and every service is encrypted in transit with TLS. Diagnostic captures are stored in a private, encrypted, non-public bucket with a hard 90-day expiry. No system is perfectly secure, and Paxi is beta software — please tell us about anything that looks wrong at hi@paxi.fyi.
10. Children
Paxi is not directed to children. It is intended for people old enough to hold an account with a ride service in their jurisdiction, and we do not knowingly collect personal information from children under 13 (or under 16 where that is the applicable threshold). If you believe a child has provided us information, contact us and we will delete it.
11. International users
Paxi is operated from the United States, and the analytics and diagnostic infrastructure described above is hosted in the United States. If you use Paxi from outside the U.S., the limited information described here will be processed there, under laws that may differ from your own.
12. Changes to this policy
We will update this page when Paxi's data practices change, and we will move the "Last updated" date at the top. The beta-era diagnostic capture behavior in particular is expected to narrow before general release. Material changes will also be surfaced in the app.
13. Contact
Passenger Labs, LLC
San Francisco, California, United States
Privacy: hi@paxi.fyi · General: hi@paxi.fyi