Privacy Policy
wanderer is self-hosted software. That changes who holds your data, so this policy starts by saying who is responsible for what. The rest follows from it.
Last updated: 5 September 2026
1. Who is responsible for what
Three separate parties can be involved when you use wanderer, and they hold different data. Confusing them is the most common misunderstanding about this project, so they are named first.
- The wanderer project
- Publishes this website, the documentation, and the wanderer mobile apps in the App Store and Google Play. We operate no account system for the app and receive none of your trails, recordings, photos or account details.
- Your instance operator
- The app connects to a wanderer instance that you choose: one you host yourself, one run by a community member, or a company's. That operator stores your account and your content, and is the data controller for it. Their privacy policy governs that data, not this one.
- Other instances, through federation
- If your instance is connected to others, content you have marked public can be copied to those instances and stored by their operators. See section 8.
Everything below distinguishes between data that stays on your device, data that goes to your chosen instance, and the small number of cases where something reaches a third party.
2. This website
openwanderer.com serves documentation and information about the project. It has no user accounts, no login, and no comment system.
- No analytics or tracking. The site runs no analytics, no tracking pixels and no advertising, and sets no tracking cookies.
- No third-party fonts or embeds. Fonts are served from this site, not from a font CDN, so visiting a page does not disclose your IP address to a third party.
- Server logs. Our hosting provider records standard request data (IP address, timestamp, requested URL, referrer and user agent) to deliver the site and defend against abuse. These logs are not combined with anything else and are not used to profile visitors.
- Links leave us. Pages link to GitHub, Discord and other sites. Once you follow such a link, that site's own policy applies.
3. The app: data on your device
Most of what the app holds never leaves your phone unless you send it. Stored locally are:
- Trails you have saved or downloaded, including their route geometry, waypoints and photos.
- Map regions you download for offline use, and the map tiles inside them.
- Recordings in progress, including the track recorded so far, so a recording survives the app being closed.
- Your session with your chosen instance, and app settings such as theme and units.
Uninstalling the app deletes all of it. Clearing the app's storage in Android or iOS settings has the same effect.
4. The app: data sent to your instance
The app is a client for the instance you sign in to. What it sends there is what you ask it to send: your account details and profile, trails you create or save, recorded tracks you choose to save, photos you attach, comments, lists and summit logs.
That instance stores this data under its own operator's control and its own policy. If you host your instance yourself, that operator is you. We have no access to it, cannot retrieve it, and cannot delete it on your behalf.
5. The app: location data
Location is the most sensitive thing the app handles, so it is set out in full.
- When it is collected. Only while you are actively recording a trail or navigating one. Both start on an explicit action by you, and both run with a persistent notification that stays visible for as long as they are running. The app does not collect location at other times.
- Background collection. Recording and navigation continue when the screen is off, when another app is in front, and when the app has been cleared from recent apps. This is why the app asks for background location access. Without it, recording and navigation stop as soon as the app is closed and the rest of the trail is lost. Before that permission is requested, the app shows an in-app explanation of what it is for.
- Where it goes. The recorded track is written to your device as you walk. It is transmitted to your instance only when you choose to save the trail. If you discard a recording, it never leaves the device.
- What it is used for. Drawing your position on the map, turn-by-turn guidance, and building the saved trail: its track, distance, elevation gain and duration. Location is not used for advertising, profiling or analytics, and is not sold or shared with data brokers.
6. The app: permissions
- Location (while using the app)
- Shows where you are on the map, and records or navigates a trail.
- Location (all the time / background)
- Keeps a recording or navigation session running when the app is not in front. Optional: declining leaves the app working, but a session ends when you close the app.
- Notifications
- Shows the persistent notification for a running recording or navigation, and progress while a map region downloads. Without it a session can run without being visible to you, which is why the app asks.
- Photos and files
- Only when you attach a photo to a trail or import a GPX, KML or similar file. The app reads what you pick and nothing else.
7. The app: third parties
Besides the instance you choose, the app contacts very little. In full:
- Avatar images (api.dicebear.com). When an account has no profile picture, the app requests a generated placeholder from DiceBear, sending the display name or username so the initials match. No other account data is sent. Requests carry your IP address to that service, as any web request does.
- Map data and routing. Map tiles, search and route calculation are served by your instance, using whichever providers its operator has configured. Your instance operator's policy covers that.
- External map apps. If you tap to open a location in another app such as Google Maps, Apple Maps or Organic Maps, the coordinates are handed to that app. This only happens when you tap it.
- App stores. Downloads and updates go through Apple and Google, who record their own data about installs. We receive only aggregate statistics, never anything identifying you.
The app contains no analytics SDK, no crash-reporting SDK, no advertising SDK and no social-media SDK. There is nothing in it that reports your behaviour back to us, because there is nowhere for it to report to.
8. Federation: how public content travels
wanderer instances can connect to one another using ActivityPub, the same protocol Mastodon uses. If your instance operator has connected it to others, this affects where your content ends up, so it is worth understanding before you post publicly.
- Only public content federates. Trails, comments, lists and summit logs you have marked public can be copied to connected instances. Content that is private or shared with specific people is never sent.
- Copies live on other servers. A federated copy is stored by the operator of the receiving instance, under their control and their policy. You remain the author, and editing rights stay with your own instance.
- Deletion is a request, not a guarantee. Deleting or unpublishing content sends a delete out to instances that received it. Well-behaved instances honour it. An instance that is offline, misconfigured or hostile may not. Treat anything published publicly to a federated network as difficult to fully retract.
- Who you federate with is your operator's choice. If you run your own instance, it is yours.
9. Demo instance
A public demo instance is linked from this site so people can try wanderer without installing it. It is for evaluation only: accounts and content on it may be reset or deleted at any time, without notice and without backup. Do not put anything there you would mind losing or anything you would mind others seeing.
10. Legal bases
Where the GDPR applies, we rely on the following legal bases for the limited processing we carry out:
- Art. 6(1)(f), legitimate interests for serving this website securely and keeping server logs to defend against abuse.
- Art. 6(1)(a), consent for device permissions such as location, background location and notifications, each of which you grant and can withdraw in your device settings at any time.
Processing carried out by your instance operator has its own legal basis, which they are responsible for stating.
11. Retention and deletion
- On your device: kept until you delete the content or uninstall the app.
- On your instance: governed by your instance operator's retention policy. Deleting your account there is the way to remove it.
- Federated copies: see section 8.
- Website server logs: kept only as long as needed for security and troubleshooting, then deleted.
12. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, to object to processing, and to complain to a supervisory authority.
Direct these to whoever holds the data. For your account, trails, photos and recordings, that is your instance operator. We cannot act on data we do not hold. For this website, use the contact details below.
13. Children
The app and this site are not directed at children and we do not knowingly collect data from them. Age requirements for an account are set by the instance you sign up to.
14. Changes
This policy may change as the software does. The date at the top reflects the current version, and material changes will be noted in the project changelog.
15. Contact
For questions about this policy or about data held by the project:
info@openwanderer.comFor data held on a wanderer instance you use, contact that instance's operator instead. We have no access to it.