European data protection

Last updated: 6 August 2026

Our ambition is to be the app European athletes and clubs reach for first. That is a goal and a standard we hold ourselves to, not a claim about our size. We are small and new. What we can already state as fact is where your data is kept, what is encrypted, and what is not, so this page does that first and argues afterwards.

Where the server is

Waypath runs on one server in Lauterbourg, France, inside the European Economic Area. It is a dedicated server rented from a hosting provider, which acts as our processor: it holds the machine, and it handles what is on it on our instructions only, under a data processing agreement. That single machine holds the database and the images people upload.

Your account, activities, photos and messages do not leave the EEA in the ordinary course of using Waypath. The exceptions are the Apple services the app depends on, and they are listed below rather than buried.

Where each kind of Waypath data is held
WhatWhere it is held
Account, profile, activities, photos, group and direct messages Our server in Lauterbourg, France, inside the EEA
Live sharing positions The same server, for as long as the session is running
Push notification delivery Apple, under the safeguards in Apple's own privacy documentation
Weather for an activity Apple WeatherKit, which receives an approximate location and not your identity
Subscriptions and purchases Apple. We are told a subscription is active; we never see card details
Health and fitness readings Apple HealthKit, on your device. Not sent to our server
Map and trail data OpenStreetMap, under the Open Database Licence. Displaying a map sends nothing that identifies you

What is encrypted, and what is not

Direct messages and group chat are end-to-end encrypted. The message is encrypted on your device before it is sent. Our database has a ciphertext column and no plaintext one, and no key sits on our servers, so we cannot read your messages and cannot produce their contents to anyone who asks. Attachments are refused unless they arrive already encrypted.

Three things are true alongside that, and they matter more than the headline:

  • Activities, photos and profiles are not end-to-end encrypted. They are stored on our server so the app can show them to the people you chose. Encryption protects what you write to someone, not what you publish.
  • We can see that two people exchanged a message, and when. Sender, recipient and timestamp are what delivery is made of, and encryption does not hide them. Anyone telling you otherwise is describing a different system.
  • A club's or event's own name, place and date are not encrypted, because people have to be able to find it.

Less data, by design

The cheapest way to protect information is not to hold it in the first place. Waypath applies these reductions before anything is published, and they are not settings you have to find:

  • A published route is trimmed by a random 200 to 600 metres at each end, so a shared activity reveals neither the doorstep somebody set off from nor the one they finished at. Any privacy zone you declared is removed on top of that.
  • Start times are stored bucketed to the hour, not to the minute, so a public activity cannot be read back as a daily routine.
  • A live position is held back until you are 250 metres past it, and the tail still being held when a session ends is discarded rather than released. A live link never shows anyone crossing the line.
  • Photographs are resized and stripped of their metadata, including location, on your device, before they are uploaded.
  • Contact matching is off until you turn it on. Identifiers are hashed on your device and only hashes are sent; the server re-hashes what it receives with a secret pepper, so a leak of the database does not yield a reversible list of phone numbers. Hashes uploaded to search are discarded straight after matching, and turning the feature off deletes the ones you published.

No advertising, no analytics, no brokers

Waypath makes its money from a subscription, so there is no reason for anybody else to be in the room. The app ships with no advertising SDK, no analytics SDK, no data brokers and no cross-app tracking. We have checked the project for the usual ones: there is no Firebase, Amplitude, Mixpanel, Sentry, Bugsnag, AppsFlyer, Adjust, Facebook or Google Analytics SDK in it. This website matches the app, loading no third-party scripts, no external fonts and no analytics.

We do not sell or rent personal data, we build no advertising profiles, and we do not track you across other apps or websites.

Your rights, and how to use them

Under the GDPR you may access the data we hold about you, correct it, delete it, export it in a portable format, restrict or object to certain processing, and withdraw consent at any time, without that affecting what happened before you withdrew it.

  • In the app, immediately. Individual activities, photos, comments and messages can be deleted whenever you like. Deleting a message you sent removes the single stored copy, so it goes for the recipient too.
  • Your whole account. The deletion control in Settings removes the account and everything attached to it, including the files you uploaded, not only the database rows that pointed at them.
  • By email. Write to hugo@oshi-messenger.com for access, a copy of your data, a correction or a deletion. We answer within one month.
  • If we get it wrong. You can complain to your national supervisory authority. In France that is the CNIL.

The data controller is Hugo Moriceau, an individual, and the person who reads that inbox is the person who writes the app. The full detail of what is collected, on what legal basis and for how long, is in the privacy policy.

What this page stands on

Everything above is a fact you can hold us to: where the server is, what is encrypted, what is cut before anything is published. Here is exactly what that is worth, and what it rests on.

  • Verifiable arrangements, not a badge. What this page offers is a described setup, in plain language, that you can check against how the app behaves. It is not a certification: there is no ISO 27001, no SOC 2, no external audit and no penetration test behind it — and no such thing as being “GDPR certified” in any case. We would rather give you the detail than a logo.
  • A clear ambition, stated as one. We want to be the app European athletes and clubs reach for first. Today we are a small independent app working towards that, not the largest or the leading one, and the comparison pages on this site say plainly where we are thinner than the alternatives.
  • Our own arrangements, on their own merits. This page is here so you can judge ours, not somebody else's. Plenty of apps built elsewhere are excellent; the case for Waypath is what is written above, not a complaint about anyone.
  • One accountable person. Waypath is operated by an individual, so the person who answers a data request is the person who writes the app and reads the inbox. That means no company, no separate EU establishment and no appointed data protection officer — none is required at this size, and inventing one would be worse than saying so.

The ambition

Endurance sport in Europe is organised around a club, a standing weekly session and races that go up rather than along. Waypath is built for that: clubs and events as first-class objects, a trail catalogue drawn from OpenStreetMap rather than from one country's mapping agency, elevation treated as the main story, and a spectator link anyone can open without an account.

The goal is to be the app European athletes and clubs reach for first. We are not there, and saying otherwise would be the kind of claim this page exists to avoid. What we can control today is the standard: your data in Europe, nothing sold, nothing tracked, and every limit written down where you can read it.

Contact

Hugo Moriceau · hugo@oshi-messenger.com · contact form · privacy policy