App Privacy Policy
Last updated 27 September 2026
English · Deutsch · Français · Norsk · Svenska · 한국어 · עברית · العربية
The short version
Global Adventurer records where you walk. By default that record stays on your iPhone, iPad and Apple Watch, and in your own iCloud if you turn that on. There is no account, no advertising, no analytics and no tracking.
Some things you can choose to do send data beyond your devices, and this policy describes each of them:
- Ordinary online requests. Showing a map, planning a route, fetching the weather or checking for summits means asking a server for something, and every server that is asked sees the request and the address it came from. The section Services the app talks to lists them, what each one receives and how long we keep anything.
- Sharing you switch on. Live location sharing puts your position on our server for up to 24 hours, and deletes it after.
- Accounts you connect. Garmin Connect and Strava pass activities through our server, which holds the permission you granted until you disconnect.
Nothing we hold is sold, used for advertising or given to anyone except the processors named here, and the only people who can see a shared position are the people you send the link to.
Who we are
Global Adventurer is operated by eplatforms ltd, a company registered in England and Wales (number 03954521), registered office 9 Donnington Park, 85 Birdham Road, Chichester, West Sussex, PO20 7AJ, United Kingdom. For anything in this policy: [email protected].
What stays on your devices
The following is held in the app's own storage on your iPhone, iPad or Apple Watch, and reaches us only in the specific cases described later in this policy.
- Your hikes — the GPS trace, distance, ascent, timings, waypoints and stops, whether recorded on the phone or on the watch or imported from a file.
- Photos and notes you attach to a hike or a saved place.
- Collections, favourites and the order you keep your hikes in.
- Saved places, parking spots and your personal heatmap, which is worked out on the device from your own hikes.
- Your gear and packing lists, including anything imported from LighterPack.
- Summits and hill-list progress, once a hike has been checked (see Summits below).
- Health data, if you turn on Apple Health syncing. Hikes are written to Health as workouts, and the app reads resting and walking heart rate and body weight to show the Health dashboard and estimate calories. On the watch, heart rate is read during a recording and saved with the workout. All of this is between the app and Apple Health on your device.
- Motion and barometer readings, used only to notice that a hike has finished and to show air pressure while you walk.
- Downloaded map areas, so the map works with no signal.
iCloud
If you turn on Settings → Backup in the app, your hikes, photos, places and collections are copied to your own iCloud account, so they appear on your other devices and survive a new phone. That is between you and Apple, under Apple's terms. We have no access to it. Turning the switch off stops the copying; what is already there stays until you delete it (see Your rights and your choices).
Live location sharing
This happens only when you start a share, and stops when you stop it.
- What is stored on our server: latitude, longitude, altitude, GPS accuracy and a timestamp for each position, plus a label you type yourself and, for a group, the group name.
- What is not stored: your name, your email, your device, or anything connecting one share to another. The link contains a random 128-bit token and is the only way in. Anyone you send it to can pass it on.
- How long: until you stop the share or its time limit runs out, and never more than 24 hours. Then it is deleted. There is no archive.
Legal basis: your consent, given by starting the share and withdrawn by stopping it.
Garmin Connect
Connecting a Garmin account is optional (and part of Pro). Garmin, not us, asks you to approve exactly what you are sharing.
- Bringing activities in. When you finish an activity on a Garmin device and it syncs, Garmin notifies our server, which collects the activity — its GPS track, timings, distance, elevation and the sensor data your device recorded, such as heart rate — and holds it until your phone picks it up, then deletes it. If you ask the app to import older activities, our server asks Garmin for that period and the same relay applies. Anything not collected within 30 days is deleted.
- Sending routes out. If you send a planned route to your Garmin device, its line, waypoints and name go to Garmin so they can reach the device.
- What we keep: the access tokens Garmin issues and the identifier Garmin uses for your account, against a random token the app made up for itself. We never see your Garmin password. A connection the app has not used for a year is deleted.
- What we do not do: read the activities for any other purpose, aggregate them, profile you with them, or pass them to anyone.
Disconnecting: Settings → Garmin Connect → Disconnect deletes the tokens and anything waiting to be collected. Revoking the app in your Garmin account does the same: Garmin tells us and we delete the connection. Activities already on your phone stay there, because they are yours.
Garmin is an independent controller for everything in your Garmin account, under Garmin's privacy policy. No third party ever receives or processes your Garmin data on our behalf: it is not shared with anyone, and no AI or other automated analysis service is applied to it. The only processors that touch our server at all are the hosting providers named under Our server, logs and processors. Legal basis: your consent, given when you connect.
Strava
Connecting a Strava account is optional (and part of Pro). Strava, not us, asks you which permissions to grant.
- What we keep: the access and refresh tokens Strava issues, your Strava athlete number, your first name and last initial as Strava reports them (shown on the settings screen so you can see which account is connected), and which permissions you granted. We never see your Strava password.
- Bringing activities in. When you open the list of your Strava activities or choose one to import, our server asks Strava on your behalf and passes the reply straight to the app. Nothing about the activities is written on our server. Strava also notifies our server when you record a new activity; that notification is the activity's number only, and it is deleted when your phone has collected the activity or after 30 days.
- Sending hikes out. If you send a hike to Strava, its GPS trace, name and notes go to Strava as a GPX file, and Strava's activity number is kept with the hike on your phone so it can link back.
- How long: until you disconnect. A connection the app has not used for a year is deleted.
Disconnecting: Settings → Strava → Disconnect revokes the app at Strava and deletes everything above from our server. Revoking it under My Apps on Strava does the same: Strava tells us and we delete the connection.
Strava is an independent controller for everything in your Strava account, under Strava's privacy policy. Legal basis: your consent, given when you connect.
Summits and hill lists
Pro can tell you which named summits a hike reached, and how far through the Wainwrights, the Munros and other lists you are. To do that, the app sends our server the rectangle around a hike — its bounding box, a few hundred metres larger than the walk — and receives the summits inside it. The rectangle says roughly where you walked; it does not carry the walk itself, and the deciding is done on your device. Our server may in turn ask OpenStreetMap's Overpass service for the summits in that rectangle, which then sees the same rectangle and our server's address, not yours. The rectangle is not stored beyond the request logs described below. Hill lists are downloaded in full and say nothing about you.
Purchases
Global Adventurer Pro is a one-off in-app purchase handled by Apple. Apple tells the app whether your Apple Account owns Pro; we never see your name, your payment details or your Apple Account. Apple also sends our server notices of purchase events — a purchase, a refund, a revocation — carrying Apple's transaction and product identifiers and dates, and nothing that names you. We keep those notices for up to six years as accounting records. Legal basis: performance of the purchase contract, and our legal obligations.
Routes bought on this website
The app can list the GPX routes sold on this website and download the ones you have bought. To unlock a purchase, the app sends the order reference and access key from your order email to our server, which answers with the download links. Nothing else about you is sent.
Services the app talks to
Every request to a server carries the address it came from (your IP address) and, for the services below, the specific information listed. None carries your name, an account or an advertising identifier, because the app has none. Where the service belongs to another company, that company processes the request under its own privacy policy, as an independent controller.
- Maps (MapTiler, and, when you choose one of the national layers, Ordnance Survey, the USGS, IGN, swisstopo, BKG, Kadaster or OpenTopoMap; trail overlays and trail lines from Waymarked Trails). Receives: the coordinates of the map squares you look at, which reveal roughly where you are looking. Elevation for planned routes and for the climb warnings comes from MapTiler in the same way. Downloaded areas ask nobody anything.
- Route planning (the BRouter routing service). Receives: the points you tapped, any areas or paths you chose to avoid, and the route type.
- Spoken directions (our own server). Receives: the points of a route you follow in Great Britain, once, so the junctions along it can be found. The route is not stored; the directions are then kept in the app.
- Summits (our own server, and OpenStreetMap's Overpass service). Receives: the rectangle around a hike, as described above.
- Slope angle and aspect shading (our own server). Receives: the coordinates of the map tiles you look at while a Winter shading is on, as a map server does. Nothing is kept beyond the request logs below.
- Avalanche danger (our own server, which asks the forecasting service for the area: the Scottish Avalanche Information Service, varsom.no, SLF, the European Avalanche Warning Services' archive at avalanche.report for the Alps, the Pyrenees, Sweden and the rest of Europe, the National Avalanche Center for the US, or Avalanche Canada). Receives: the coordinates of the place you asked about and your language. Bulletins are cached for twenty minutes for everyone; nothing about you is kept beyond the request logs below.
- Hill lists and the update check (our own server). Receive: nothing about you. The update check asks about once a day which version is current.
- Weather (Apple WeatherKit). Receives: the location whose forecast you asked for.
- Place search, directions to a start point, and the 3D Flyover (Apple Maps). Receives: what you searched for, or the area of the hike being flown over, under Apple's privacy policy.
- Siri. Apple processes what you said; the app receives only the request.
- Google Earth. Open in Google Earth hands a file to the share sheet on your device; nothing is sent by us.
Our server, logs and processors
Our server runs on Amazon Web Services in London, behind Cloudflare, which carries every request and keeps its own logs under its privacy policy. Our server logs each request — the IP address, what was asked for, when, and the app's description of itself — for security and troubleshooting, and deletes those logs after 14 days. Automatic backups of our database are kept for 7 days, so something deleted from the live database may persist in a backup for up to a week. Cloudflare and Amazon Web Services act as our processors; some processing takes place outside the UK under appropriate safeguards such as the UK Addendum to the Standard Contractual Clauses. Legal basis for logging: legitimate interests in keeping the service secure and working.
What we do not do
- No analytics or crash-reporting SDKs, and no advertising or advertising identifiers.
- No selling of data, and no sharing of it for anyone's marketing.
- No accounts, so no password to lose.
Children
The app is not directed at children under 13, and we do not knowingly collect anything from them.
Your rights and your choices
Under UK GDPR you have the right to access, correct, erase and port your personal data, to object to or restrict its processing, and to complain to the Information Commissioner's Office (ico.org.uk). Email [email protected] and we will answer within a month.
In practice, because almost everything is on your devices, you already hold it:
- A hike: delete it in the app. With iCloud sync on, the deletion reaches your other devices.
- Everything on one device: delete the app. That removes the app's data from that device only.
- Your iCloud copy: delete the hikes in the app first, or remove the whole store under iOS Settings → your name → iCloud → Manage Account Storage → Global Adventurer.
- Apple Health: workouts the app saved are deleted in the Health app, under your profile → Apps → Global Adventurer.
- A live share: stop it, or wait; it is gone within 24 hours either way.
- Garmin and Strava: disconnect in Settings before deleting the app, or revoke access at Garmin or Strava. Unused connections are deleted after a year.
Changes
If this policy changes in a way that affects what happens to your data, the app will tell you before the change applies to you. The date at the top of the page is the date of the current version.