Privacy Policy
Effective date: July 27, 2026
TrailTime (“the app”, “we”, “us”) maps how far you can hike in the time you have, records your hikes, and — if you choose — lets you share them with other TrailTime users. There is no advertising and no third-party analytics or tracking of any kind.
In short: Planning, recording, saved routes, offline maps and Apple Health all work with no account, and that data stays on your device. Sharing a hike is the one feature that needs an account — creating one means giving us an email address and a username, and anything you post is stored on our servers until you delete it.
What stays on your device
Saved routes, recorded hikes and their GPS tracks, your preferences, downloaded trail tiles, and a short-lived crash-recovery snapshot of an in-progress hike are stored only on your device. We never receive them. You can delete any saved route or hike in the app, and deleting the app removes all of it.
Reachability — the “how far can I get?” calculation the app is built around — runs entirely on your device. Your position is never sent to a server to compute it.
Location
The app uses your device’s location to:
- centre the map and work out which trails you can reach; and
- record a hike with live distance, pace and elevation — including while the screen is locked (background location) — only while you are actively recording.
Your precise location is processed on your device. It is not sent to us or stored on any server we operate, with the narrow exceptions described under Third-party services and Sharing a hike.
Health data (Apple Health)
If you turn on “save to Apple Health,” the app writes each recorded hike to Apple Health as a workout (distance, elevation ascended, and the GPS route). If you use the Apple Watch app, it reads your heart rate during an activity so it can be shown live and saved with that workout. Health data is never sent to us, never used for advertising, and never sold. It stays in Apple Health under your control, governed by Apple’s privacy policy.
Your account
An account is required only to view or post in the shared feed. If you create one, we store:
- your email address (used to sign in, confirm your account, and reset your password);
- your password, stored only as a salted hash — we never see or store the password itself;
- a username, and optionally a display name, which appear on anything you post.
Your sign-in tokens are kept in your device’s Keychain, are never synced to iCloud, and are removed when you sign out.
Sharing a hike
Posting is always a deliberate act — nothing is shared automatically. A post contains a title, an optional note, the hike’s distance, duration and elevation gain, the activity type, an area name, and a single approximate location.
Location in a shared hike is coarse by default. The one coordinate a post carries is rounded to roughly a kilometre, because an exact position paired with a timestamp says where a person was. You can opt into sharing the exact area on a per-post basis. Your recorded route is never shared in either case.
Each post is either visible only to you, or to any signed-in TrailTime user. Posts are not published to the open web, are not crawlable, and have no public URL. You can delete any post you have made at any time.
Safety and moderation
You can hide individual posts, block another user, or report a post or person. Hides and blocks are private to you — a blocked user is not told. A report records what you reported, the reason, any detail you add, and who filed it, so that we can act on it. Reports are retained after the reported account is deleted, with the deleted person’s identifier removed, so that a pattern of abuse cannot be erased by deleting and re-registering.
Purchases
Premium (“Summit”) subscriptions are sold and processed by Apple through the App Store. We never receive your payment-card details. Purchase verification is handled on your device by Apple’s StoreKit.
Third-party services
These are all of the third parties involved, and what each receives:
- Apple — MapKit renders the map and provides place search; HealthKit stores workouts; StoreKit handles purchases. WeatherKit receives your approximate location while an activity is recording, in order to return current conditions. Subject to Apple’s privacy policy.
- Supabase — hosts the database behind accounts and shared hikes. If you create an account, your email address, username, display name and posts are stored there on our behalf. See Supabase’s privacy policy.
- Resend — delivers account emails (confirmation and password reset). It receives your email address for that purpose only. See Resend’s privacy policy.
- Cloudflare — hosts this website and the static trail-map files the app downloads. Tile requests indicate the general map area you are viewing (a region roughly 55 km across) and, like any web request, include your IP address in standard server logs. We do not use those logs to identify you.
- Open-Meteo — when you open a route’s elevation profile, the app sends that route’s starting coordinate to its public elevation API. No identifier is attached. See Open-Meteo’s terms.
We do not sell your personal information, and we do not share it with anyone for advertising.
Retention and deletion
On-device data is kept until you delete it or remove the app. Account data is kept until you delete your account.
You can delete your account from inside the app — Feed → Account, or Settings → Account & Sharing → Delete account. This permanently removes your profile, your posts, your blocks and your hidden-post list. It cannot be undone. Hikes you recorded stay on your phone, because they were never in your account. Abuse reports are anonymised rather than deleted, as described above.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to or restrict its processing. Account deletion in the app satisfies the deletion right immediately; for anything else, email us and we will respond within 30 days. If you are in the EEA or UK, our lawful basis is performance of a contract (running the account and feed you asked for) and legitimate interests (keeping the service safe from abuse).
Children
The app is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, email us and we will remove it.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new effective date.
Contact
Questions about this policy, your privacy, or a data request? Email [email protected].