English translation · Les den norske versjonen (gjeldende)
Privacy Policy for TrackNavigator
TrackNavigator is a trip and map app for iPhone and Apple Watch with a companion web page. This is what is stored, where, for how long and who sees it – without an account, with an account and on the web pages.
In short
- Without an account, everything you make stays on your phone. The app fetches maps, weather and lookups directly from the services in section 5, which then see your IP address and what you ask for.
- With an account, your projects are stored on our server in Germany so you can use them in the app and on the web page and share them with members you invite. Recordings stay private until you share them.
- Heart rate from Apple Watch is not sent to the server unless you turn on «Lagre puls i kontoen» (Store heart rate in the account).
- No ads, no tracking, no analytics. We do not know your e-mail address.
1. Controller
The controller is Marius Arnesen, private individual, Norway. TrackNavigator is developed and run by him alone, with no employees, so no data protection officer has been appointed.
Privacy contact: support@tracknavigator.app. We answer within one month.
2. What the app does without an account
Everything you make – routes, points, drawings, recordings, photos and documents – is stored only on your phone, and during a recording also on your Apple Watch. None of it is sent to us. The content follows your phone's ordinary backup (iCloud or a computer), which Apple handles according to your settings.
The app does fetch data from other services while you use it, directly from the phone. The service then sees your IP address and what the app asks for:
- Map tiles: which map area you look at, and which areas you download for offline use (Kartverket, Esri, OpenTopoMap, the Norwegian Polar Institute; Swedish maps via our server).
- Weather: the position of the place you view a forecast for, rounded to three decimals (about 100 m), to MET/Yr. The app states its name and version, as MET requires.
- Elevation: points you place and routes you draw or save are sent to Kartverket's elevation service to get heights. Outside Kartverket's coverage, when the service does not answer, in elevation profiles and in the 3D view, terrain tiles from Amazon Web Services (USA) are used, see section 5. On Svalbard, heights come from our own server (the Norwegian Polar Institute's terrain model).
- Point lookups: when you open a point, its coordinate is sent automatically to Kartverket (property and municipality), NVE (avalanche terrain) and Artsdatabanken (red-listed species). When you create a route analysis or an analysis of a recording, the coordinates of the start, the end, the highest point and your points along the route or track – at most 24 places – are sent to the same services in the same way. Zones, mobile and emergency-network coverage are looked up in data bundled with the app, without network, along the whole route or track as well. None of this is stored by us.
- Place search: the text you type, directly to stadnamn.no (Norwegian place names). When you are signed in, the text and the map centre and zoom level go to our server instead, so that places near where you are looking rank first. Our server searches stadnamn.no and our own place index from OpenStreetMap. Searches are not stored: our logs leave out the search text and the position, and an answer is only kept in memory for up to five minutes to make the next search faster. If our server does not answer, the app asks stadnamn.no directly (see section 5).
- Avalanche bulletins: the region you tap, to NVE.
- Map layers: the map area, to Geonorge/Kartverket, NVE, the Norwegian Environment Agency, DSB and the Norwegian Polar Institute while the layer is on.
- Air traffic (off by default): the map centre rounded to 0.1° (about 10 km), to adsb.fi or adsb.lol.
- Drone zones and NOTAMs: the whole dataset is fetched from dronesoner.no; no position is sent.
- Sea charts, contour lines and Swedish maps are fetched from our own server, which fetches them from Kartverket, the Norwegian Coastal Administration, the Norwegian Polar Institute and Lantmäteriet. They see only our server, not you. The server keeps a technical log with a masked IP address for 14 days (section 4).
Apple Watch: during a recording the watch app reads heart rate, active energy and distance from Health (HealthKit) and saves the workout to the Health app. The samples are sent to the phone and stay in the recording there. Heart rate leaves the phone only in the cases listed in sections 4 and 5.
Location: the app asks for location access «while using the app». During a recording, and when you have turned on live sharing «also in the background», location updates continue after you put the app away and iOS shows the blue location indicator. Otherwise all location use stops when the app is in the background.
Mobile coverage in recordings: if you turn on «Registrer mobildekning» (record mobile coverage) when you start a recording (off by default), the phone notes which type of mobile network it is on – 5G, 4G, 3G, 2G, none or flight mode – and when that changes, and stores it in the recording with the track. iOS gives apps no access to signal strength or the operator, and the app reads no IP address, cell ID or other identifier. The data follows the recording: without an account it stays on the phone, with an account it is stored in your account (section 3), it is private like the recording, and it never appears on share pages.
Camera in «Sol og måne» (sun and moon): the camera view draws the paths of the sun and the moon over the camera image. The image is used on the phone only and is neither stored nor sent. A picture is saved only when you press «Ta bilde» (take picture) and then choose to save it to Photos or share it; it carries no location.
3. Account and sync
You sign in with Sign in with Apple. We receive a technical Apple identifier (not your e-mail address) and a display name you can change yourself – Apple suggests your name, and we store up to 40 characters. You choose a colour and can add a profile photo.
While you are signed in, all your projects are stored in your account on our server at Hetzner in Falkenstein, Germany, so you can use them in the app and on the web page: routes, points, drawings, recordings (GPS tracks with timestamps, speed and elevation, and the type of mobile network along the track if you turned on «Registrer mobildekning»), photos, documents, folder structure and account settings. Before the projects already on your phone are uploaded the first time, the app asks you. If you answer «Ikke nå» (Not now), you stay signed in and the question returns next time.
Projects can be shared with others («Sammen») using an invite code. Invitation codes are valid for as long as the owner chooses – 30 days by default, one year at most – and can be extended. An expired code is kept until it is extended or the project is deleted; a code replaced by a new one is deleted at once. Members see your name, colour and profile photo, the items shared in the project, and the change log – who changed what, when, and the name the item had at the time. Recordings are private until you share them, and you can keep routes, points, drawings, photos and documents private. Private items are stored on the server but visible only to you. If you share a recording with the members, they also see the timestamps in the track – and the heart rate, if «Lagre puls i kontoen» is on. Members who are removed from a project keep what is already on their phone.
Live position: if you turn on «Del min posisjon live» (Share my position live), your last position is sent to the members of the project. Only the last position is shared. It is visible to the members until you turn sharing off or pause it, and is deleted from the server after 24 hours regardless. New members do not see positions sent before they joined.
Share pages: any member can create a public, read-only page for selected items in a project. The page lives at an unguessable address that works for anyone with the link, is marked not to be indexed by search engines, and never contains heart rate, per-point timestamps, mobile network data from recordings, private items or documents. Photos are shown downscaled and without metadata. If you delete an item or make it private, it is removed from every share page in the project.
Road weather and webcams from the Norwegian Public Roads Administration are fetched via our server and require an account. They see only our server.
4. Purposes, data, legal basis and retention
«Contract» refers to Article 6(1)(b) of the GDPR: the processing is necessary to provide the service you asked for by using the app and the account.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account and sign-in | Apple identifier, display name, colour, profile photo, creation time | Contract, Art. 6(1)(b) | Until the account is deleted |
| Sign-in keys | Random sign-in keys for the app and the browser, stored hashed | Contract | Deleted when you sign out; otherwise after 90 days at the latest (used keys after 30) |
| Projects, sync and sharing with members | Routes, points, drawings, recordings with timestamps (and the mobile network type if you chose it), photos, documents, folders, account settings, and who added or changed what | Contract | Until you delete the item, the project or the account |
| Heart rate in the account | Heart-rate samples from Apple Watch in recordings (health data) | Explicit consent, Art. 9(2)(a), given with the switch «Lagre puls i kontoen» (off by default) in the app or on the web page. Withdrawn in the same place; heart rate is then deleted from the server and from share pages | Until consent is withdrawn or the account is deleted |
| Live position | Last position (coordinate, elevation, course, speed, time) | Consent given with the switch «Del min posisjon live», Art. 6(1)(a) | Until you turn it off or pause it; deleted from the server after 24 hours regardless |
| Share pages | A frozen copy of the items you select, without heart rate and without per-point timestamps; photos downscaled and without metadata; the page title | Contract (you create the page) | Until a member deletes the page, or its creator is removed from the project or deletes the account |
| Photos and documents | Image files – metadata such as position, time and camera is removed on the server at upload; PDFs and documents are stored unchanged and shown only behind sign-in | Contract | Until you delete them or the account |
| Invite codes | Code, project, who created it | Contract | Invitation codes are valid for as long as the owner chooses – 30 days by default, one year at most – and can be extended. An expired code is kept until it is extended or the project is deleted; a code replaced by a new one is deleted at once |
| Change log in projects | Who changed what, when, and the name the item had | Legitimate interest, Art. 6(1)(f): members must be able to see what happened in a shared project | The name of deleted items is removed after 30 days; rows older than 365 days are deleted; anonymised when the account is deleted |
| Technical logs | Time, method and path without query string, status code, IP address with the last part masked (IPv4 /24, IPv6 /48), and in the web server log the browser or app version (User-Agent) | Legitimate interest, Art. 6(1)(f): operations and security | 14 days (web server and API) |
| Backups | Nightly copy of the database and the files | Legitimate interest, Art. 6(1)(f): recovery after failure | 14 days on the server, 30 days with the controller in Norway. What you delete is therefore gone from every copy within 30 days |
If you delete an item in the app or on the web page, its content is removed from the server immediately and from the members' devices at their next sync. Only the item's id and the time of deletion remain, so the deletion reaches everyone.
5. Recipients and services the app and the web page contact
One processor handles data on our behalf: Hetzner Online GmbH, Gunzenhausen/Falkenstein, Germany, which operates the server. Every other service below is an independent controller with its own privacy policy. They receive only what the table says, and only when you use the feature in question. The web page and the share pages fetch maps, heights and point lookups from the same services directly from your browser, see section 9.
| Recipient | Country | What they receive | When |
|---|---|---|---|
| Hetzner Online GmbH (processor) | Germany | Operates the server where your account lives; data processing agreement with us | Always while you have an account |
| Apple – Sign in with Apple (appleid.apple.com) | USA (DPF) | That you sign in to TrackNavigator with your Apple ID | Sign-in, and a new sign-in when you delete the account |
| Strava, Inc. (www.strava.com) | USA | The recording's name, the track with timestamps, and heart rate only if you choose «Med puls» (With heart rate). Your Strava sign-in is kept in the phone's keychain | Only when you tap «Last opp til Strava» (Upload to Strava) |
| Kartverket / Geonorge (cache.kartverket.no, wms.geonorge.no, ws.geonorge.no, status.kartverket.no) | Norway | IP address and map area; coordinates of points and routes you want heights for; the coordinates for property lookups (one point, or up to 24 stops in a route or track analysis) | Maps, offline downloads, elevation, point lookups, route and track analysis, service status |
| Esri / ArcGIS (ibasemaps-api.arcgis.com, server.arcgisonline.com) | USA (DPF) | IP address and map area | The «Satellitt» map layer, the 3D view and offline downloads of satellite imagery |
| Amazon Web Services (s3.amazonaws.com – Mapzen/Terrarium terrain tiles) | USA (DPF) | IP address and which terrain tiles the app needs, which reveals the area you look at or the route you analyse | The 3D view, elevation profiles, heights where Kartverket has no coverage or does not answer |
| OpenTopoMap (a.tile.opentopomap.org) | Germany | IP address and map area | The «OpenTopoMap» layer and offline downloads of it |
| Norwegian Polar Institute (geodata.npolar.no) | Norway | IP address and map area | Maps and layers for Svalbard and Jan Mayen |
| Norwegian Meteorological Institute / Yr (api.met.no) | Norway | IP address, position rounded to three decimals, the app's name and version | Forecasts, precipitation nowcasts and weather warnings for the place you choose |
| NVE (gis3.nve.no) | Norway | IP address and map area; the coordinates for point lookups and the stops of a route or track analysis; the region for avalanche bulletins | Slope, avalanche and power-grid layers, point lookups, route and track analysis, avalanche bulletins |
| DSB (ogc.dsb.no) | Norway | IP address and map area | The emergency-network coverage layer |
| Norwegian Environment Agency (kart.miljodirektoratet.no) | Norway | IP address and map area | Protected-area layers |
| Artsdatabanken (artskart.artsdatabanken.no) | Norway | IP address and the coordinate with a search radius | Automatically when you open a point or create a route or track analysis, and when you open the species list |
| iNaturalist (api.inaturalist.org) | USA | IP address and the species' scientific name – no position | Only when you open the species list for a point (species photos) |
| stadnamn.no (Språksamlingane, University of Bergen) | Norway | IP address and the search text | Place search in the app when you are not signed in, or when the app gets no answer from our server |
| adsb.fi / adsb.lol (volunteer ADS-B networks) | Not stated by the services | IP address and the map centre rounded to 0.1° | The air-traffic layer, which is off by default |
| Civil Aviation Authority of Norway / dronesoner.no | Norway | IP address; no position | The drone-zone and NOTAM layers |
| Via our server – the recipient sees only our server: the Norwegian Public Roads Administration (road weather and webcams, account required), Lantmäteriet (Swedish maps), the Norwegian Coastal Administration and Kartverket (sea-chart layers), Kartverket and the Norwegian Polar Institute (contour lines), the Norwegian Polar Institute (heights for Svalbard), stadnamn.no (place search), and for the web page also dronesoner.no, MET and adsb.fi/adsb.lol | Norway, Sweden | The server's IP address and the map area or lookup – never your address | While the layer or feature is in use |
| Telia and Telenor (mobile coverage) | – | Nothing: the coverage maps are bundled with the app and hosted on our server | – |
| Fontshare (api.fontshare.com and cdn.fontshare.com, Indian Type Foundry) | Global CDN | IP address | This page and the product page load their typeface there. The app and the web page do not |
| Apple (appleid.cdn-apple.com) | USA (DPF) | IP address | The sign-in card on the web page while you are signed out, and when you delete the account there |
Links you tap yourself – Apple Maps, Google Maps, Norgeskart, Toposvalbard, Varsom, Se eiendom, globe.adsb.fi and status.kartverket.no – open in another app or in the browser and are not part of TrackNavigator. The web page and the share pages load code only from our own server, with the two exceptions in the table: Apple's sign-in script when the sign-in card is shown and when you delete the account, and jsPDF when you export a PDF. Share pages never load Apple's script.
We do not sell data, use no advertising or analytics services, and do not share data with anyone not listed here – unless the law requires it.
6. Transfers outside the EEA
Your account, the backups and everything we store ourselves is in the EEA (Germany and Norway). Some services the app and the web page contact directly are in the USA:
- Apple, Esri and Amazon Web Services are certified under the EU–US Data Privacy Framework, which the European Commission has approved (Art. 45). They receive your IP address and map areas, or – for Apple – the fact that you sign in.
- Strava receives a recording only when you tap «Last opp til Strava» yourself after being told that it is sent to the USA (Art. 49(1)(a)). Strava processes it further under its own privacy policy.
- iNaturalist and adsb.fi/adsb.lol receive your IP address and a scientific name or a rounded map centre when you use the feature (Art. 49(1)(b)). We cannot vouch for where these services keep their logs. You can avoid both features: the air-traffic layer is off by default, and species photos are shown only when you open the species list.
7. Your choices and rights
Access
Everything you have stored in the account is visible in the app and on the web page. For a complete export, including what is not shown there (for example log rows concerning you), ask via support@tracknavigator.app. We answer within one month and may ask you to confirm your identity with a sign-in.
Rectification
You edit your own content. Name, colour and profile photo are changed under Innstillinger › Konto (Settings › Account) in the app or in the account settings on the web page.
Deleting individual items
If you delete a route, a point, a recording, a photo or a document, its content is removed from the server immediately, from share pages, and from the members' devices at their next sync. The change log shows the deleted item's name for another 30 days; the log row itself is deleted after 365 days.
Deleting the account
Choose Innstillinger › Konto › Slett konto (Settings › Account › Delete account) in the app, or Delete account in the account settings on the web page. You confirm with your Apple ID. This is deleted from the server:
- the account and profile photo, sign-in keys, folder structure, account settings and last position
- projects where you are the only member, with all files
- all your recordings, shared or not, with files
- everything you kept private, with files
- share pages and invite codes you created
Routes, points, drawings, photos and documents you added to projects shared with other members remain for the members, without your name: they are attributed to «Slettet bruker» (Deleted user), as are your entries in the change log. The members' projects thus do not lose content they used together with you. If you want that gone too, delete the items in the app before deleting the account.
At the same time we ask Apple to revoke the access the app was given with your Apple ID, so TrackNavigator disappears from the list of apps under your Apple ID. Your projects remain on your phone after deletion. Backups are deleted within 30 days.
Data portability
Every route, point and recording can be exported as GPX from the app. A complete export of the whole account in a machine-readable format is available on request.
Withdrawing consent
- Heart rate: turn off «Lagre puls i kontoen» under Innstillinger › Opptak (Settings › Recording) in the app or in the account settings on the web page. Heart rate already on the server is then deleted, also from share pages. It stays in the recordings on your phone.
- Live position: turn off «Del min posisjon live» or pause it. The last position is deleted from the server immediately.
- Strava: «Koble fra Strava» (Disconnect Strava) in the app removes the access on the phone and asks Strava to revoke it. What you have already uploaded you delete at Strava.
Objection
You can object to the processing based on legitimate interest – technical logs, the change log and backups – via support@tracknavigator.app. We then assess whether the interest still outweighs yours in your case.
Complaints
If you disagree with how we handle your data, you can complain to the Norwegian Data Protection Authority, datatilsynet.no. We would appreciate hearing from you first.
8. Children
TrackNavigator is for people aged 13 and over. We do not collect age, but delete the account of a younger child when we learn of it. Parents and guardians can contact us via support@tracknavigator.app.
9. The web page and browser storage
The web page tracknavigator.app shows the same projects as the app. You sign in with the same Apple ID; new accounts are created in the app. The web page uses no cookies and no analytics. It stores the following in the browser's local storage (localStorage), which only the web page itself can read:
| Keys | Content | Purpose and duration |
|---|---|---|
tnAccessToken, tnRefreshToken |
Your sign-in keys | Keeps you signed in in this browser until you sign out. Deleted at sign-out |
tnUser |
Your user id, display name and colour | Shows who is signed in. Deleted at sign-out |
tnAccountPrefs, tnAccountCoordFormat |
Account settings, including the heart-rate choice and coordinate format | Mirrors the settings in the account. Deleted at sign-out |
tnBaseLayer, tnOverlays, tnKoter, tnCollapsedOverlayGroups |
Map choices | Remembers which map and layers you had on. Kept until you clear browser data |
tnProjectsSort, tnSectionSorts, tnExpandedProjects, tnCollapsedGroups, tnCollapsedFolders |
How the lists are sorted, and which projects, groups and folders are unfolded | Display preferences for this browser. Kept until you clear browser data |
tnVisibleProjects, tnEyeOn, tnActiveProjects, tnLocalHidden, tnViewStamps, tnProjectLastUsed |
Which projects are drawn on the map, active or hidden, and when you last viewed and used them | View state for the account. Deleted or emptied at sign-out |
At sign-out every other key the web page has stored under the tn prefix is removed as well; only the map and display preferences in the two rows above remain.
Share pages (?share=…) require no sign-in, store nothing beyond the map choices, do not load Apple's script, and are marked «noindex» so search engines should not index them. Our server logs page views with a masked IP address for 14 days.
When you are not signed in and not on a share page, the web page shows only the sign-in card. It creates no map and fetches no map tiles, heights, weather, searches or other data – only Apple's sign-in script (section 5). Place search and the weather forecast on the web page go through our server and answer signed-in users only; on share pages place search works with the share link, and no forecast is shown.
Signed in, and on share pages, the web page fetches maps, heights and point lookups directly from your browser, from the same services as the app (section 5): map tiles from Kartverket, Esri, OpenTopoMap, NVE, DSB, the Norwegian Environment Agency and the Norwegian Polar Institute, heights from Kartverket and Amazon Web Services (on Svalbard from our server), and – when you open a point or create a route or track analysis (signed-in web app only; share pages offer no analysis) – the coordinate to Kartverket, NVE and Artsdatabanken. Those services then see your IP address and what is asked for. This also applies to visitors of share pages without an account.
This page and the product page tracknavigator.app/om/ run no scripts, but load the Cabinet Grotesk typeface from Fontshare, which then sees your IP address.
10. Changes
If we change what is stored, for how long, or who receives it, we update this page and the date at the top before the change takes effect. Changes that require new consent are asked for in the app. The Norwegian text is the authoritative version; this English version is a translation.
- 27 September 2026 – first version, together with app version 2.0.
- 28 September 2026 – Invite codes: validity is chosen by the owner (30 days by default, one year at most) and can be extended; an expired code is kept until it is extended or the project is deleted, and a code replaced by a new one is deleted at once (sections 3 and 5). Together with app version 2.0.2.
- 28 September 2026 – Route analysis: point lookups also run for up to 24 stops along a route when you ask for it (sections 2, 5 and 9). Together with app version 2.0.2.
- 29 September 2026 – Place search outside Norway: the search text and the map centre go to our server, which searches stadnamn.no and our own place index from OpenStreetMap; nothing is stored (sections 2 and 5). Applies to the web page now and to the app from the version after 2.0.4. Section 1 no longer describes TrackNavigator as a hobby project.
- 29 September 2026 – The web page requires sign-in for everything except share pages: signed out, it shows only the sign-in card and fetches no maps or data. Place search and the weather forecast through our server answer signed-in users and share pages only. The app searches through our server only when you are signed in, otherwise directly at stadnamn.no (sections 2, 5 and 9).
- 29 September 2026 – Mobile coverage in recordings: with «Registrer mobildekning» on, a recording stores the type of mobile network the phone had along the track (5G, 4G, 3G, 2G, none or flight mode) – never signal strength, operator, IP address or cell ID. It follows the recording, is private like it and never appears on share pages. The analysis routes had now exists for recordings too, with the same lookups (sections 2, 3, 4, 5 and 9). Applies to the app from the version after 2.0.6 and to the web page.
- 29 September 2026 – «Sol og måne» with the camera: the camera image is used locally on the phone only, and a picture is saved only when you ask for it (section 2). Applies to the app from the version after 2.0.6.
- 29 September 2026 – New address: the web page, share links and these pages move to tracknavigator.app. The server and where data is stored are unchanged (sections 2 and 4); the old addresses forward you.
- 29 September 2026 – New contact address: support@tracknavigator.app. The old address still works.