1. Introduction
Route Companion ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use our mobile application.
2. Data We Collect
Route Companion ("we", "us") is operated from Switzerland. The data controller for the purposes of applicable data protection law can be reached at [email protected].
Route Companion is designed to be privacy-first. Your personal data and content (routes, location, preferences) stay on your device. The only data that reaches our servers is the minimum required to fulfill features you invoke, a small set of anonymous operational counters described in section 7, and the stop reports and confirmations you choose to send, described below.
- Route Data: Routes you import (GPX, TCX and FIT files, including GPX exports from Komoot; Strava; Ride with GPS) or create with the route planner are processed and stored locally on your device. A route you imported stays until you delete it, also after you disconnect the service it came from.
- Shared Plans: If you explicitly create a plan link ("Share the plan"), a copy of that route (simplified to at most 1,500 points), the stops you marked with their OpenStreetMap opening hours, the start time, average speed, the name and note you typed, and a preview image are stored on our Cloudflare-hosted gateway so that anyone with the unguessable link can view them, download them as a GPX file, or open them in the app. The forecast shown on a plan page is fetched from Open-Meteo when the page is opened and is not stored. Your location, other stops, and your ride history are never part of a plan. A plan is deleted 7 days after its start time (30 days after creation when it has no start time), or immediately when you stop sharing it.
- Follow links: If you explicitly share a follow link for a ride, the route you are navigating (if any), its name and the display name you typed are stored the same way, together with your latest position while you navigate, as described for the live layer below. Your position is deleted two hours after you finish, and the link itself, including the route, is deleted one day after you shared it, or immediately when you delete it in the app. If you turn on "Hide start and finish", your phone removes the parts of the route near its start and finish before uploading it, and while you are near either end, and when you finish, it sends only your status and no coordinates.
- Riding a plan together (the live layer): A shared plan can carry a live layer. Nothing about you is published until you explicitly join it in the app by typing a display name; joining one plan enables nothing on the next. While you then navigate that plan's route, the app sends your latest position, accuracy, heading, speed, how far along the route you are, your estimated arrival time and the update time to our Cloudflare-hosted gateway, about every 30 seconds. Anyone with the plan link can see the display names, latest positions and arrival times of everyone who joined, on the plan page and in the app. We store only the latest position per rider, never a location trail, and at most eight riders per plan. Your position is deleted at once when you leave, when the person who shared the plan removes you or switches the live layer off, two hours after the last update from anyone, or twelve hours after the first person joined — whichever comes first.
- Stop Data: Stops are fetched from our servers (sourced from OpenStreetMap data) and cached locally on your device.
- Stop reports and confirmations: If you report a problem with a stop, we store which stop, what you said, when, the id of the route you had open and how far the stop was from that route’s start and from the route. If you confirm that a stop is still as listed, we store the stop, the kind of confirmation and when. Both come with a key derived from your app installation’s id, the same for every report and confirmation from that installation, so one person cannot count twice. We do not link it to your name, and neither stores coordinates of yours. When more than one rider independently reports the same stop as gone, we may send an aggregated correction to OpenStreetMap as a public note on that stop. We have not started doing this. The note names the stop and the problem, not the riders.
- Weather Data: Weather forecasts are fetched from third-party weather services based on coordinates along your route. No personal data is sent with these requests.
- Authentication Tokens: If you connect third-party services (Strava, Ride with GPS, Garmin, Wahoo, Hammerhead, Suunto, COROS), OAuth access tokens are stored securely on your device using OS-provided secure storage (Keychain on iOS and Android's secure credential storage where available).
- Location Data: Your device location is used to show where you are on the route, record your activities, check the weather and find stops ahead, give proximity alerts, and show the Live Activity or Android navigation notification. On Android, location is also collected while the app is closed or not in use, but only while you navigate or record, and it stops when you end it. Location leaves your phone only when a feature needs it: route planning and rerouting send your position to our routing server, and weather and place-name lookups send the coordinates to our gateway, which passes them to the weather and place-name services in section 4. The app may also send them to those services directly. Your position is published only when you share a follow link or join the live layer of a shared ride plan, both described above. We never sell your location or use it for ads.
- Preferences: App settings such as unit system, map type, route appearance, and fuel plan parameters are stored locally on your device.
3. How We Use Data
Most data processing happens on your device. When you invoke a network feature, we process only the data needed to provide it. We use data solely to:
- Display your routes, stops, and weather forecasts on the map.
- Calculate fuel and hydration estimates based on route parameters.
- Provide navigation and proximity alerts.
- Display Live Activity information on your iOS Lock Screen or persistent navigation status on Android.
- Show the group where each rider is, when you explicitly join the live layer of a shared ride plan.
- Provide a time-limited plan page with the route, stops, start time, and a fresh forecast when you explicitly share a plan.
- Export routes with course points to FIT, TCX, and GPX formats for use with GPS devices.
- Import routes, and past activities from Strava, from connected third-party services, and use those activities to show where you have ridden, your explored tiles, weekly goal, and the speed and stops the app learns for arrival times.
- Upload a finished ride to Strava as an activity, only when you choose to.
- Show on a stop what other riders last reported or confirmed about it, hide a stop that many riders report as gone, and, when more than one rider reports the same stop as gone, send an aggregated correction to OpenStreetMap as a public note. That last step is not switched on yet.
4. Third-Party Services
Route Companion integrates with the following services. When you use these integrations, your data is also subject to their respective privacy policies:
- Cloudflare: Our API gateway, shared ride plans and their live layer, and aggregate analytics run on Cloudflare Workers. Cloudflare acts as our data processor and may temporarily log request metadata (including IP addresses) at the network edge for security and abuse prevention. Subject to Cloudflare's Privacy Policy.
- Apple: Apple WeatherKit provides weather data, Apple Maps provides map tiles on iOS, and App Store Connect gives us aggregate installation metrics for our developer account. Subject to Apple's Privacy Policy.
- Google Play: Google Play processes Android in-app purchases and subscriptions and gives us aggregate installation, subscription, and store performance metrics for our developer account. Subject to Google's Privacy Policy.
- OpenStreetMap: Stop data displayed in the app is sourced from OpenStreetMap. We query our own servers using geographic coordinates along your route to retrieve nearby stops. No personal data is sent with these requests. We may also post public notes to OpenStreetMap from our own server, under a Route Companion account, when more than one rider agrees that a stop is gone (see Stop reports and confirmations above). This is planned and not switched on yet. Subject to the OpenStreetMap Foundation's Privacy Policy.
- Terrain Tiles (elevation data): Route elevation, the outdoor map's contour lines and its 3D terrain come from the Terrain Tiles open dataset (Mapzen, hosted on Amazon Web Services). Route elevation is looked up on our own servers. While you navigate on the tilted outdoor map, the app downloads terrain tiles for the area on screen directly from Amazon Web Services; no personal data is sent with these requests. The dataset is built from these sources, credited as its licence asks: ArcticDEM terrain data DEM(s) were created from DigitalGlobe, Inc., imagery and funded under National Science Foundation awards 1043681, 1559691, and 1542736; Australia terrain data © Commonwealth of Australia (Geoscience Australia) 2017; Austria terrain data © offene Daten Österreichs – Digitales Geländemodell (DGM) Österreich; Canada terrain data contains information licensed under the Open Government Licence – Canada; Europe terrain data produced using Copernicus data and information funded by the European Union - EU-DEM layers; Global ETOPO1 terrain data U.S. National Oceanic and Atmospheric Administration; Mexico terrain data source: INEGI, Continental relief, 2016; New Zealand terrain data Copyright 2011 Crown copyright (c) Land Information New Zealand and the New Zealand Government (All rights reserved); Norway terrain data © Kartverket; United Kingdom terrain data © Environment Agency copyright and/or database right 2015. All rights reserved; United States 3DEP (formerly NED) and global GMTED2010 and SRTM terrain data courtesy of the U.S. Geological Survey.
- Weather Services: For fetching weather forecasts along your route. We send geographic coordinates to retrieve forecast data. No personal information is included in these requests.
- Place names: To name the place you are at or a point on your route, the app sends its coordinates to Photon (komoot's OpenStreetMap search), either through our gateway or directly. When Photon is unavailable, our gateway asks GraphHopper's geocoder instead. The app may also use your phone's built-in geocoder (Apple's on iPhone, Google's on Android). No personal information is included in these requests.
- Strava API (optional): When you connect Strava, the app asks for three permissions: to read your profile, routes and segments including private ones (
read_all); to read your activities including private ones (activity:read_all); and to upload activities (activity:write). Your routes and past activities are read so you can open them as routes and see your own riding history in the app. The app uploads a finished ride to Strava only when you choose to. Requests go directly between your device and Strava; what the app reads is kept on your device, and our servers only take part in the sign-in exchange. Activities from the last month are refreshed while you use the app. Older activities are kept for up to six months after they were first downloaded; after that the app deletes them the next time it reads them and downloads them again. You can disconnect in the app or revoke access in your Strava settings at any time. Disconnecting in the app revokes its access at Strava, erases the sign-in tokens, and deletes the downloaded routes and activities from your device. It does not delete what the app worked out from them: your explored tiles with the date you first reached each one, the speed and stops it learned from your activities, and the recent weeks' activities behind your weekly goal, which stay until you next finish a ride in the app. Routes you imported from Strava stay in your saved routes until you delete them. No setting in the app deletes the rest; deleting the app removes it from your device, although a backup of your phone may still hold a copy. Disconnect before you delete the app so its access at Strava is revoked and the tokens are erased. Subject to Strava's Privacy Policy. - Komoot: You can import Komoot routes by sharing them to Route Companion via your device's share sheet. We do not use Komoot's API or connect to Komoot on your behalf. Subject to Komoot's Privacy Policy.
- Ride with GPS API: For importing your routes (optional). Subject to RWGPS Privacy Policy.
- Garmin Connect: For exporting routes to your Garmin device (optional). Subject to Garmin's Privacy Policy.
- Hammerhead: For exporting routes to Hammerhead Dashboard and Karoo devices (optional). Subject to Hammerhead's Privacy Policy.
- Suunto: For sending routes to your Suunto account and watch (optional). The route file, with the stops you added, passes through our servers on its way to Suunto so our Suunto API key stays off your device; we do not store it. Subject to Suunto's Privacy Policy.
- COROS: For sending routes to your COROS account, watch or Dura (optional). Requests go directly between your device and COROS; our servers only take part in the sign-in exchange. Subject to COROS's Privacy Policy.
- Apple Maps / Google Maps: For map tiles, base map display, and Street View/Look Around previews where available. Subject to Apple's and Google's respective privacy policies.
5. Data Storage & Security
Route data, preferences, and history are stored locally on your device using encrypted storage where available. Requests to our servers contain only the minimum needed to fulfill the feature. Shared ride plans are the narrow exception to immediate-response processing: a plan you create, and the latest position of each rider who joined its live layer, are stored in isolated, time-limited records. The live layer is deleted when the sharer switches it off, two hours after the last update, or after an absolute maximum of twelve hours. We do not maintain a database of user accounts, personal profiles, or historical location trails on our servers.
6. Data Sharing
We do not sell or rent your personal data. Network requests are made to our servers and to the third-party services listed above only when needed for a feature you invoke. When you share a ride plan, anyone who has that link can view the route, the stops and — if you and others join its live layer — everyone's display names and latest positions, until you remove it or it expires. The link is unguessable, but you should send it only to people you trust.
7. Analytics & Operational Data
We do not use advertising SDKs, tracking pixels, third-party product analytics SDKs, or cross-app tracking. We do record a small set of aggregate, allowlisted feature counters so we can understand which Route Companion features are useful and worth improving. These counters do not include route names, search terms, coordinates, connected account names, or stable user identifiers. Stop reports and confirmations (section 2) are separate: they carry a stable key derived from your app installation’s id.
To keep the service running reliably, the following narrow operational data reaches our API gateway. All of it is anonymous by construction:
- Rate-limit counters: short-lived request counters keyed to a hashed install identifier, used only to prevent abuse. Automatically deleted within at most one hour.
- Aggregate usage data: for each request, we record the endpoint name, HTTP status code, response time, and period-salted hashed user keys derived from an install identifier: one key salted per UTC day, one per ISO week, and one per calendar month. Each key is only meaningful inside its own period, so the same install hashes to unrelated values on the next day, in the next week, and in the next month. This lets us count distinct daily, weekly, and monthly users and measure endpoint popularity, but we cannot follow any individual device beyond a calendar month or reconstruct a usage history. Under GDPR Recital 26 this qualifies as anonymous data.
- Aggregate feature counters: the app periodically reports allowlisted feature names, open/action counts, and foreground duration totals (for example, that the Discover screen was open for a number of seconds). Each report carries the UTC day the usage happened on (so a delayed upload is counted on the right day), uses the same period-salted anonymous keys, and never includes route content, location, search text, or identifiers from third-party integrations.
- How long you have had the app: because the keys above deliberately rotate, our servers cannot tell that someone using the app this week is someone who installed it last week — so we cannot otherwise answer whether people come back. The app therefore works this out on your own device and sends the answer as one of a few coarse labels alongside a feature report: roughly how many weeks ago it was installed (for example “week 1”, or “weeks 5-7”) and how many weeks in a row it has been opened (for example “4-7 weeks”). Your install date and the record of which weeks you opened the app stay on your device and are never sent. The labels are shared by everyone of the same vintage, so they are not identifiers and cannot be used to link your activity across weeks.
- Crash reports: when the app runs into an error and has to show an error screen, your phone turns the error into a one-way SHA-256 fingerprint of the error type and where in the app's code it happened. Only that fingerprint is sent, together with which part of the app it happened in (for example the planner or a ride) and whether the error took down the whole app or only that part. The error message, stack trace, screen contents, route data and coordinates never leave your device. The report carries the same app version, platform and period-salted anonymous keys as the usage data above, so we can tell how many installs a crash affects without knowing whose they are.
- Third-party service quota counters: the app periodically reports aggregate counts of calls to providers that have monthly quotas (e.g. WeatherKit) so we can monitor our provider budgets. No content, coordinates, or individual request data is reported, only a count.
This data is stored on Cloudflare Workers Analytics Engine for up to 90 days and is used exclusively for operating and troubleshooting the service. Processing is based on legitimate interest under Art. 6(1)(f) GDPR and Art. 31 of the revised Swiss Federal Act on Data Protection.
8. Children's Privacy
Route Companion does not knowingly collect data from children under the age of 13. The app does not require account creation or personal information to function.
9. Your Rights
Under GDPR and the revised Swiss FADP, you have the right to access, rectify, erase, restrict, or object to the processing of personal data about you, and the right to data portability. Because almost all Route Companion data is stored on your device, these rights are primarily satisfied by deleting the app or clearing its storage. For the narrow operational data in section 7, individual access and erasure cannot be technically fulfilled for the anonymous categories because we have no identifier to look up. Stop reports and confirmations (section 2) are stored under a key we do not link to your name, so we cannot find them from your name or email address. To exercise your rights or ask questions about your data, contact us at [email protected]
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at [email protected].