Privacy Policy
This policy was rewritten from the database schema, table by table. An earlier version said Waypath collected nothing and had no servers. That was true of the first release and stopped being true when accounts, the social feed and live sharing were added. If you read that version, this one replaces it.
Who is responsible
Waypath is operated by Hugo Moriceau, the data controller for the purposes of the UK GDPR and EU Regulation 2016/679. For any question about this policy, or to exercise any right described below, write to hugo@oshi-messenger.com.
The short version
- You need an account to use the social and sharing features. Recording an activity for yourself does not require one. The only way to create an account is Sign in with Apple; there is no password.
- We sell nothing, we run no advertising, and we load no third-party analytics or tracking scripts in the app or on this site.
- Your direct messages are end-to-end encrypted. We hold the ciphertext and cannot read them.
- The community heatmap is opt-in. Until you turn it on, nothing about where you run or ride leaves your phone for it.
- Live sharing transmits your position while it is switched on, and only then. The link stops working the moment the activity ends.
What we collect, why, and on what legal basis
Account
An account is created with Sign in with Apple, and that is the only way to create one. There is no password, so there is nothing to reset: signing in again, or on another device, means authorising with Apple again. Apple is the identity provider. Apple checks who you are and hands the app a signed token; our authentication service verifies that token against Apple's public keys and then issues the session the app uses. That authentication service is one we run ourselves, on the same server in France as the rest of the database — it is not a third-party sign-in service, and no password of yours exists for it to hold.
What we end up holding is an account identifier Apple issues for you, the email address Apple returns, and the name Apple returns, which pre-fills your profile name and which you can change. That identifier is not your Apple ID: Apple issues one per developer account, so it means nothing to anyone but us, and it is the same identifier in any other app we publish. Apple hands the app the name only on the very first authorisation — the app stores it at that moment and cannot ask Apple for it again. The address reaches us inside the signed token, which is how our authentication service comes to hold it; the copy on your device is the one captured at that same first authorisation. Neither the address nor the Apple identifier is written into your profile row, so neither is ever visible to another user.
If you chose Hide My Email, the address we hold is Apple's relay address, ending in @privaterelay.appleid.com, and not your real one. It is generated for Waypath alone, mail sent to it reaches you through Apple, and we never see the address behind it. If you later turn on contact matching, that relay address is one of the identifiers hashed — and because it is in nobody's address book, the app says so rather than letting you believe it makes you findable. Legal basis: performance of a contract.
Profile
Display name, handle, and anything you choose to add: biography, location text, avatar image, sports, gear, website and social handles. All of it is optional except the display name and handle, and all of it is visible to other users. Legal basis: performance of a contract.
Activities you record
The route as an encoded polyline, distance, duration, elevation gain, activity type, and your chosen title and visibility. Legal basis: performance of a contract.
Two deliberate reductions apply to anything published:
- Both ends of the route are trimmed by a random 200 to 600 metres, so a shared activity reveals neither the doorstep you set off from nor the one you came back to. The amount is derived from the activity itself rather than drawn afresh, so republishing the same run cannot be used to narrow down where it really began.
- The start time is stored bucketed to the hour, not to the minute, so a public activity cannot be used to work out your daily routine.
Live sharing
While live sharing is on, the app sends position points, distance, duration, elevation gain and temperature to our server so that people holding your link can follow you. Legal basis: your consent, given by starting a live session, and withdrawn by ending it.
Anyone with the link can see the session while it is running. When the activity ends, is set to private, or goes silent, the link returns nothing. A paused session is shown as paused rather than as finished.
Social activity
Follows and follow requests, comments, reactions, reposts, group membership and messages within groups, challenge entries, and photos or videos you attach to an activity or a trail. Legal basis: performance of a contract.
Direct messages
Encrypted on your device before they are sent. Our database stores the ciphertext and the sender, recipient and timestamp needed to deliver it. There is no plaintext column and no key on our servers, so we cannot read your messages and cannot produce their contents to anyone. Legal basis: performance of a contract.
We can still see that two people exchanged a message and when. That is metadata we need in order to deliver it, and encryption does not hide it.
Finding people you know
If you turn on contact matching, contact identifiers are hashed on your device and only the hashes are sent. We never receive your address book. Three further protections apply: the server re-hashes what it receives with a secret pepper, so a database leak does not expose a reversible list of phone numbers; the hashes you upload to search are discarded immediately after matching; and turning the feature off deletes the hashes you published. It is off until you switch it on. Legal basis: your consent.
Community heatmap contributions
Off unless you switch it on, in Map layers ▸ Community or Settings ▸ Map. While it is on, a finished activity contributes the coarse shape of where it went: the ~75-metre grid squares you passed through and the ISO week, as integers. No coordinates, no time of day, no activity, no device identifier and no account — contributions are sent without a signed-in session and are never joined to your profile. The first and last 300 metres of every activity are dropped before anything is built, so neither end of a route is ever in it. That is a fixed reduction rather than the randomised 200-to-600-metre trim applied to a published route, because a heat tile is built from many activities at once. The only label on a contribution rotates every Monday, so two weeks of the same person's activity cannot be linked together. Legal basis: your consent, given by turning the switch on and withdrawn by turning it off.
A path is published on the map only once at least three different people used it in the same week. Below three it does not appear at all, which is what stops one person's route from being visible to anyone.
Turning it off stops any further contribution, and that is all it can do. Contributions already sent hold nothing that points back to you — that is the point of them — and the same property means we cannot find them to show you, correct them or delete them on request, and neither can anyone else. Under Article 11 GDPR the access, correction, erasure and portability rights do not apply to data a controller cannot link to a person, and we are telling you that plainly rather than implying a control we do not have. They are deleted automatically within 26 weeks either way.
Notifications
A device token so Apple can deliver push notifications to your phone or watch. Legal basis: your consent, given in the system permission prompt.
Safety and moderation
Reports you file, blocks you set, and the content reported. Legal basis: legitimate interest in keeping the service usable and safe.
Health and fitness data
With your permission, Waypath reads and writes workouts, heart rate and related metrics through Apple HealthKit. HealthKit data is not sent to our servers and is never used for advertising or sold, as Apple's rules require. It stays on your device except where it forms part of an activity you choose to publish.
Purchases
Subscriptions and any one-off purchase are processed by Apple. We receive confirmation that a subscription is active. We never see your card details.
What we do not do
- We do not sell or rent personal data, to anyone, ever.
- We do not run advertising and we do not build advertising profiles.
- We do not embed third-party analytics, tag managers, social pixels or external fonts, in the app or on this website.
- We do not track you across other apps or websites.
Who else processes your data
We keep this list short on purpose.
- Apple, sign-in — Apple is the identity provider for Sign in with Apple, authenticates you, issues the token our server verifies, and operates the Hide My Email relay if you use one — as well as the App Store, in-app purchases, push notification delivery, and HealthKit on your device.
- A hosting provider, supplies the dedicated server, located in Lauterbourg, France, inside the EEA, that holds the database, the authentication service and stored images. They process data on our instructions only, under a data processing agreement.
- Apple WeatherKit, receives an approximate location to return conditions for an activity. It does not receive your identity.
Map and trail data comes from OpenStreetMap. Displaying a map does not send OpenStreetMap anything that identifies you.
Where your data is held
Our server sits in Lauterbourg, France, inside the European Economic Area, so your account, activities, photos and messages do not leave it in the ordinary course of using Waypath. Apple's services may process data outside the EEA under the safeguards described in Apple's own privacy documentation.
Our European data protection page sets out the same arrangement at length: the server, what is encrypted and what is not, and the reductions applied before anything is published.
How long we keep it
- Account, profile, activities and social content, until you delete them or delete your account.
- Live position points, retained with the session; a session stops being readable through its public link as soon as it ends.
- Direct messages, kept as ciphertext until the sender deletes them or either account is deleted. Deleting a message you sent removes the single stored copy, so it disappears for the recipient too.
- Community heatmap contributions, deleted automatically after 26 weeks. The aggregated map built from them is kept, and holds no personal data: it exists only where at least three different people passed in the same week.
- Push tokens, until the device is removed or notifications are turned off.
- Reports, kept while the report is open and for a reasonable period afterwards, so repeated abuse can be recognised.
Your rights
Under the GDPR you may: access the data we hold about you, correct it, delete it, export it in a portable format, restrict or object to certain processing, and withdraw consent at any time without affecting what happened before you withdrew it.
You can delete individual activities, photos, comments and messages in the app at any time. To delete your entire account and everything attached to it, use the account deletion control in Settings, or write to hugo@oshi-messenger.com and we will do it. We answer within one month. The one exception is community heatmap contributions, which carry no identifier of any kind and therefore cannot be located, exported or erased on request; see that section above.
If you think we have handled your data badly, you can complain to your national supervisory authority. In France that is the CNIL.
Cookies and this website
This website sets no advertising or analytics cookies, because it runs no advertising and no analytics. The only thing stored in your browser is a record that you dismissed the privacy notice, so it does not reappear on every page. That is a strictly necessary preference and needs no consent. See the cookie notice for the detail.
Children
Waypath is not intended for children under 16. We do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
Changes
If we change how we handle your data, we will update this page and change the date at the top. Where a change is significant, we will say so in the app rather than rely on you noticing.
Contact
Hugo Moriceau · hugo@oshi-messenger.com · contact form