Guides
A GDPR running app, in concrete terms
Waypath is a GPS running, trail and live-tracking app for iPhone and Apple Watch, built in Europe, that lets anyone follow a run live from a browser link without installing an app.
Every app with European users says it complies with the GDPR, because it has to. The useful questions are narrower: where is the server, who else gets a copy, what is public by default, and how do you leave. This page answers those four for Waypath, with the parts that are not covered stated as plainly as the parts that are.
Question one
Where is the data?
On one machine in Lauterbourg, France, inside the European Economic Area. That server holds the database, authentication and the images you upload. There is no second region, no mirror outside the EEA, and no content delivery network in front of the images. The data controller is Hugo Moriceau, the independent developer who builds and operates Waypath, and the address for data requests is on the privacy page.
Apple sits alongside this in the ordinary way: the App Store handles the purchase, and if you use Sign in with Apple, Apple handles that. Neither sees your activities.
Question two
Who else gets a copy? Nobody
Waypath contains no advertising SDK and no analytics SDK. Specifically, the project contains no Firebase, Amplitude, Mixpanel, Sentry, AppsFlyer, Adjust, Facebook or Google Analytics SDK. No data broker receives anything, because there is no advertising business to feed. The website you are reading is built the same way: no third-party scripts, no external fonts, no analytics.
Direct and group messages are encrypted on your device and the server stores only ciphertext; it holds no key. Attachments are refused unless they arrive encrypted. This is a stronger claim than “we do not read your messages”: the server cannot.
Question three
What is public by default? Nothing
An activity is private until you publish it, and you choose the audience each time. When you do publish, Waypath removes any privacy zone you declared, trims a random 200 to 600 metres from each end of the route so it never starts at your door, and stores the start time bucketed to the hour, so a public history cannot be read back as a daily routine.
The heat map follows the same rule. Your own heat map is drawn on your phone from your own activities. The community layer is opt-in, and a path appears on it only once at least three different people have crossed it in the same week, so nobody's individual route is ever what you are looking at.
Live sharing is by link: whoever holds the link can watch, and the page is served with no third-party script and marked not to be indexed. When the run ends, the view ends.
Question four
How do you leave? With a file
Every activity exports as a GPX 1.1 track, with elevation and a timestamp on every point, on the free plan. Deletion is in the app. Under the GDPR you also have the rights of access, rectification, erasure, portability and objection, and the privacy page says how to exercise them and how long each kind of data is kept.
Elsewhere
Where the other apps keep your data
Strava's privacy policy states that information is transferred to, processed and stored in the United States, under Standard Contractual Clauses. Komoot, incorporated in Germany, processes location data on EU servers in Luxembourg and Germany. For Nike Run Club, Runkeeper, AllTrails, Runna and Garmin Connect we could not verify the storage region from the vendor's own material on the date below, so this page says not verified rather than guessing. Storage in the United States under SCCs is lawful; the difference is that Waypath does not need the clauses because the data does not leave the EEA.
Not covered
What this page does not claim
- Not a certification. Waypath has not been audited by a third party. These are the facts of how it is built, which you can check against the privacy policy and the app's own network behaviour.
- One server is one server. A single machine is easier to reason about and easier to lose. Backups are described on the privacy page; an outage is an outage.
- Apple is still Apple. Health data you allow Waypath to read is governed by Apple's rules as well as ours; nothing from Health is uploaded unless it is part of an activity you publish.
Written on 4 September 2026 and correct to the best of our knowledge on that day. Competitor apps and prices change often; where a competitor detail is marked "not verified" we could not confirm it from the vendor's own material and you should check theirs. Waypath is not affiliated with, endorsed by or sponsored by any company named here, and all trademarks belong to their owners.
Questions
Questions people ask
The full reasoning is on the European data protection page.
Where does Waypath store my runs?
On one server in Lauterbourg, France, inside the EEA. There is no mirror outside the EEA and no CDN in front of uploaded images.
Does Waypath use analytics or advertising SDKs?
No. The project contains no Firebase, Amplitude, Mixpanel, Sentry, AppsFlyer, Adjust, Facebook or Google Analytics SDK, and no data broker receives anything.
Are my activities public by default?
No. Each activity is private until you publish it and you choose the audience each time. Published routes have a random 200 to 600 metres trimmed from each end and their start time bucketed to the hour.
Can I export and delete my data?
Yes. Every activity exports as GPX 1.1 on the free plan, deletion is in the app, and the privacy page explains how to exercise your GDPR rights.
Who is the data controller?
Hugo Moriceau, the independent developer who builds and operates Waypath. Contact details are on the privacy page.
One server, in France. No one else in the room.
Private by default, no analytics or ad SDK, and a GPX export of everything on the free plan.
Requires iPhone. There is no Android app today; one is planned for January 2027.