1. Who is responsible for what

Three separate parties can be involved when you use wanderer, and they hold different data. Confusing them is the most common misunderstanding about this project, so they are named first.

The wanderer project
Publishes this website, the documentation, and the wanderer mobile apps in the App Store and Google Play. We operate no account system for the app and receive none of your trails, recordings, photos or account details.
Your instance operator
The app connects to a wanderer instance that you choose: one you host yourself, one run by a community member, or a company's. That operator stores your account and your content, and is the data controller for it. Their privacy policy governs that data, not this one.
Other instances, through federation
If your instance is connected to others, content you have marked public can be copied to those instances and stored by their operators. See section 8.

Everything below distinguishes between data that stays on your device, data that goes to your chosen instance, and the small number of cases where something reaches a third party.

2. This website

openwanderer.com serves documentation and information about the project. It has no user accounts, no login, and no comment system.

3. The app: data on your device

Most of what the app holds never leaves your phone unless you send it. Stored locally are:

Uninstalling the app deletes all of it. Clearing the app's storage in Android or iOS settings has the same effect.

4. The app: data sent to your instance

The app is a client for the instance you sign in to. What it sends there is what you ask it to send: your account details and profile, trails you create or save, recorded tracks you choose to save, photos you attach, comments, lists and summit logs.

That instance stores this data under its own operator's control and its own policy. If you host your instance yourself, that operator is you. We have no access to it, cannot retrieve it, and cannot delete it on your behalf.

5. The app: location data

Location is the most sensitive thing the app handles, so it is set out in full.

6. The app: permissions

Location (while using the app)
Shows where you are on the map, and records or navigates a trail.
Location (all the time / background)
Keeps a recording or navigation session running when the app is not in front. Optional: declining leaves the app working, but a session ends when you close the app.
Notifications
Shows the persistent notification for a running recording or navigation, and progress while a map region downloads. Without it a session can run without being visible to you, which is why the app asks.
Photos and files
Only when you attach a photo to a trail or import a GPX, KML or similar file. The app reads what you pick and nothing else.

7. The app: third parties

Besides the instance you choose, the app contacts very little. In full:

The app contains no analytics SDK, no crash-reporting SDK, no advertising SDK and no social-media SDK. There is nothing in it that reports your behaviour back to us, because there is nowhere for it to report to.

8. Federation: how public content travels

wanderer instances can connect to one another using ActivityPub, the same protocol Mastodon uses. If your instance operator has connected it to others, this affects where your content ends up, so it is worth understanding before you post publicly.

9. Demo instance

A public demo instance is linked from this site so people can try wanderer without installing it. It is for evaluation only: accounts and content on it may be reset or deleted at any time, without notice and without backup. Do not put anything there you would mind losing or anything you would mind others seeing.

10. Legal bases

Where the GDPR applies, we rely on the following legal bases for the limited processing we carry out:

Processing carried out by your instance operator has its own legal basis, which they are responsible for stating.

11. Retention and deletion

12. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your data, to object to processing, and to complain to a supervisory authority.

Direct these to whoever holds the data. For your account, trails, photos and recordings, that is your instance operator. We cannot act on data we do not hold. For this website, use the contact details below.

13. Children

The app and this site are not directed at children and we do not knowingly collect data from them. Age requirements for an account are set by the instance you sign up to.

14. Changes

This policy may change as the software does. The date at the top reflects the current version, and material changes will be noted in the project changelog.

15. Contact

For questions about this policy or about data held by the project:

info@openwanderer.com

For data held on a wanderer instance you use, contact that instance's operator instead. We have no access to it.