Gipfelbuch — Alpine Companion
Version 1.0, effective 26.07.2026
The German version of this document is authoritative. In case of discrepancies, the German text prevails, unless mandatory consumer protection provisions require otherwise.
Summary in five sentences. Gipfelbuch stores what you enter or record yourself: your account, your tours, your contributions. We use your location only while you are using a feature that needs it — recording, weather warnings, avalanche check — and we deliberately round coordinates before sending them to weather services. We do not sell data, show advertising, or track you across other apps and websites. Everything not required for operation — crash reports, usage statistics, background location, connections to Strava or Garmin — is off until you explicitly turn it on, and you can withdraw consent at any time. You can delete your account and all its content directly in the app.
>
This summary does not replace the text below. The full text is authoritative.
Niklas Eder
Dornauberg 11a, 6295 Ginzling, Austria
Email: gipfelbuchalpin@gmail.com
Controller within the meaning of Art. 4(7) GDPR. No data protection officer has been appointed; the conditions of Art. 37(1) GDPR are currently not met. This assessment is reviewed annually.
| Data | Email address, password (hashed only — we never see it in plain text), display name, registration and last login timestamps, optionally profile picture and bio |
| Purpose | Providing the account, associating your tours and contributions, sign-in, password reset |
| Legal basis | Art. 6(1)(b) GDPR — performance of the user agreement |
| Retention | Until account deletion; see section 6 |
Whether provision is required (Art. 13(2)(e) GDPR): email address, password and display name are necessary to conclude and perform the user agreement — without them no account can be created. Providing your age is a legal requirement. All other details, in particular profile picture and bio, are optional; if you do not provide them, only the respective feature is unavailable and there are no other consequences.
Location data is the most sensitive category we handle. Four distinct cases:
a) Map display and current position (foreground). Art. 6(1)(b) GDPR. Your position is processed on your device and is not transmitted to us unless you start a recording.
b) Recording a tour. Precise location trace with timestamps, altitude, speed and accuracy values. Art. 6(1)(b) GDPR — the recording is the service you explicitly requested. Recording starts and stops only through your action.
c) Background location access. Required so that recording continues when the screen is off, and so that thunderstorm and weather alerts can be triggered for your actual position. Legal basis: Art. 6(1)(a) GDPR — your consent, additionally § 165(3) of the Austrian Telecommunications Act 2021. Off by default; consent is given separately and can be withdrawn at any time in the app settings and in your device settings.
d) Transmission to external weather, warning and avalanche services. To retrieve information for your position, a coordinate must be sent to the relevant service (see section 4). We round the coordinate to two or three decimal places before transmission (roughly 100 to 1,000 metres of imprecision). The service learns your weather region, not your exact position. Legal basis: Art. 6(1)(a) GDPR.
Retention: recorded tours are stored until you delete them individually or delete your account. There is no automatic time-based deletion, so that year-on-year route comparison keeps working.
Important: Location traces can indirectly reveal home address, workplace, habits and health status. We therefore treat them with particular care: recorded tours are private by default. When you publish a tour, we automatically trim the start and end points by a configurable radius (500 m by default) so that your home address does not become public.
| Data | Condition reports, route and summit information, launch sites, comments, photos (including embedded metadata, see below), timestamp, display name, verification status where applicable |
| Purpose | Building and maintaining the shared alpine database; display to other users |
| Legal basis | Art. 6(1)(b) GDPR for storage and display; you decide for each contribution individually whether to make it public |
| Retention | Until you delete it, or until removal under the Community Guidelines; for account deletion see section 6 |
Photo metadata: On upload we strip all EXIF data except the capture timestamp by default. A photo's location is only retained if you confirm this in the individual case.
Persons in photos (Art. 14 GDPR): where a contribution exceptionally shows identifiable third parties, we process their data solely to display the contribution, on the basis of Art. 6(1)(f) GDPR. Those affected may at any time request access, blurring or deletion at gipfelbuchalpin@gmail.com; we act on such requests without substantive review. Contributors are obliged under the Terms of Use to upload such images only with the consent of the persons depicted.
Please note: Contributions you publish are visible to all users and may be indexed by search engines. Do not publish personal data of third parties, in particular do not publish identifiable persons in photos without their consent.
| Data | The fact and category of verification, date, reviewing person |
| Purpose | Making qualified contributions identifiable — for safety-critical information this is a legitimate interest of the entire user community |
| Legal basis | Art. 6(1)(f) GDPR |
| Supporting documents | We inspect proof of qualification for review purposes only and do not store it permanently. Only the outcome is stored. Submitted documents are deleted within 30 days. |
| Objection | You may object to the display of your verification status at any time under Art. 21 GDPR; the verification is then removed |
| Data | Device push token (APNs on iOS, FCM on Android), device type, language, subscribed warning regions |
| Purpose | Delivering weather, thunderstorm and avalanche alerts, and replies to your own contributions |
| Legal basis | Art. 6(1)(a) GDPR; additionally § 165(3) TKG 2021 |
| Content | Push messages contain no personal content. A generic notice is delivered; details are loaded once you open the app. |
| Retention | Until push is disabled, the app is uninstalled, or the operating system reports the token as invalid |
We do not send promotional notifications.
a) Manual file import (GPX, TCX, FIT). You select the file yourself. Art. 6(1)(b) GDPR.
b) Connecting Strava or Garmin via OAuth (where offered). After your explicit authorisation we store an access token and import the activities you select. Legal basis: Art. 6(1)(a) GDPR. Strava and Garmin are independent controllers for their own processing; their privacy policies apply. You can disconnect at any time in the app — the token is deleted immediately and revoked with the provider.
c) Health and vital data. Heart rate, training metrics and comparable values are health data under Art. 9 GDPR. We import and store them only if you give separate, explicit consent under Art. 9(2)(a) GDPR. Without that consent, such fields are discarded on import. The feature is off by default.
Disabled by default. No corresponding module is initialised without your consent.
| Data | Crash reports (error message, stack trace, app version, OS version, device model), anonymous event counters |
| Purpose | Finding and fixing errors, particularly those affecting safety-critical features |
| Legal basis | Art. 6(1)(a) GDPR and § 165(3) TKG 2021 |
| Not included | No location data, no advertising identifiers, no cross-device tracking, no transfer to ad networks |
| Retention | 90 days |
| Withdrawal | Settings → Privacy → Diagnostics. No further data is collected from that point. |
IP address, timestamp, endpoint, HTTP status and user agent are logged. Legal basis Art. 6(1)(f) GDPR — legitimate interest in operational security and abuse prevention. Retention 14 days, then automatic deletion.
Reports of illegal content under Art. 16 DSA, related correspondence and decisions taken are stored. Legal basis Art. 6(1)(c) GDPR (legal obligation under the DSA) and Art. 6(1)(f) GDPR; the legitimate interest lies in demonstrating compliance to authorities and in defending or bringing legal claims. Retention: three years after conclusion.
Storing information on your device and accessing it is governed by § 165(3) of the Austrian Telecommunications Act 2021 — which applies to apps, not only to cookies on websites.
Without consent, because strictly necessary: authentication tokens in secure storage, your app settings, your consent status, offline map tiles, the local database of your tours, the cache for avalanche and weather data.
Only with consent: diagnostics and usage statistics (2.7), background location (2.2c), transmission of the rounded coordinate to external weather, warning and avalanche services (2.2d), push token (2.5), Strava or Garmin connection (2.6b). The local cache of weather and avalanche data already retrieved is by contrast strictly necessary, as it is what makes display without a network connection possible at all.
Consent can be withdrawn at any time under Settings → Privacy with immediate effect. The lawfulness of processing carried out before withdrawal is unaffected.
We do not sell data and do not disclose it for advertising purposes.
| Provider | Purpose | Data transferred | Place of processing | Transfer safeguard |
|---|---|---|---|---|
| Supabase, Inc., USA | Database, authentication, file storage | All account data, tours, contributions, photos | Region eu-west-1 (Irland) (EU). Access by support and individual sub-processors from the USA possible | Standard Contractual Clauses (Implementing Decision (EU) 2021/914); data processing agreement in place |
[Sentry / Functional Software, Inc.], EU instance de.sentry.io, Frankfurt | Crash reports — only with consent | Error messages, app and device version | Frankfurt (EU). Account and organisation management in the USA | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Recipient | Purpose | Data transferred | Safeguard |
|---|---|---|---|
| Apple Inc. (APNs) / Google Ireland Ltd, Google LLC (FCM) | Push delivery | Push token, message text without personal reference | Apple: Standard Contractual Clauses. Google: EU-US Data Privacy Framework (Decision (EU) 2023/1795) and SCCs |
| Mapbox, Inc., USA (where used) | Map rendering | Requested map tiles, IP address | EU-US Data Privacy Framework, plus SCCs under the Mapbox DPA |
| Open-Meteo, GeoSphere Austria, Deutscher Wetterdienst, MeteoAlarm/EUMETNET, avalanche.report | Weather, warning and avalanche data | Rounded coordinate, no identifier, no account reference | Art. 6(1)(a) GDPR. GeoSphere, DWD, MeteoAlarm and avalanche.report process within the EU |
| Strava, Inc. / Garmin (only with an active connection) | Activity import | OAuth token, requested activities | Independent controllers; transfers under the providers' SCCs |
| National Weather Service (USA) (only for tours outside Europe) | Official weather warnings | Rounded coordinate | Art. 6(1)(a) GDPR; retrieved via our proxy, no identifier |
| Law enforcement, judicial and emergency authorities | Notifications under Art. 18 DSA; alerting rescue services in acute emergencies | Only the information required in the individual case | Art. 6(1)(c) GDPR (legal obligation) or Art. 6(1)(d) GDPR (vital interests) |
Where data is transferred to the USA, we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023 (Decision (EU) 2023/1795) where the recipient is certified, and additionally on Standard Contractual Clauses under Art. 46(2)(c) GDPR. A copy of the Standard Contractual Clauses is available on request to gipfelbuchalpin@gmail.com.
A residual risk remains: authorities in the USA may under certain conditions access data stored there, and the level of legal protection does not in every respect correspond to that of the EU. We minimise this risk by keeping the main database within the EU and sending only the minimum necessary to US services.
| Right | Article |
|---|---|
| Access | Art. 15 |
| Rectification | Art. 16 |
| Erasure | Art. 17 |
| Restriction | Art. 18 |
| Data portability | Art. 20 |
| Objection | Art. 21 |
| Withdrawal of consent, at any time and without disadvantage | Art. 7(3) |
How to exercise them: fastest in the app under Settings → Privacy:
Alternatively by email to gipfelbuchalpin@gmail.com. We respond without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR). For particularly complex requests this period may be extended by up to two further months; we will inform you within the first month. Processing is free of charge.
Complaints: you may lodge a complaint with a supervisory authority at any time; in Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.
You can delete your account at any time: in the app under Settings → Account → Delete account, or via the web form at https://gipfelbuch-alpin.com/konto-loeschen, without needing the app installed.
| Data category | Treatment on account deletion |
|---|---|
| Account data, email, profile, profile picture | Deleted immediately and permanently |
| Recorded tours and tracks | Deleted immediately and permanently |
| Private contributions, drafts, photos | Deleted immediately and permanently |
| Push token, Strava/Garmin OAuth tokens | Deleted immediately and revoked with the provider |
| Public community contributions | You choose in the deletion dialog: full deletion, or anonymisation (the contribution remains available to the community, the link to you is irreversibly removed). Deletion is the default. |
| Moderation and reporting records | Retained pseudonymised for 3 years (legal obligation under the DSA) |
| Server logs | Expire automatically after 14 days |
| Accounts with no sign-in for 36 months | Deleted. We warn you by email 30 and 7 days beforehand; a single sign-in prevents deletion. |
| Backups | Overwritten after no more than 30 days |
Deletion is final and cannot be reversed.
For content that has been made public, we additionally take reasonable steps under Art. 17(2) GDPR to inform other controllers of an erasure request.
Measures under Art. 32 GDPR include: encrypted transmission (TLS 1.2 or higher); encrypted database storage; passwords stored only as salted hashes; row level security on every database table, binding each record to its owner; two-factor authentication for all administrative access; authentication tokens in the device's secure storage (Keychain / Keystore); least-privilege role and permission model; regular dependency updates and automated security scanning.
Despite all measures, no transmission over the internet is entirely secure.
In the event of a personal data breach we notify the Austrian Data Protection Authority within 72 hours of becoming aware of it (Art. 33 GDPR) where there is a risk to you. Where the risk is likely to be high — which, for location data, is effectively always the case — we will also inform you directly and in plain language (Art. 34 GDPR).
Using Gipfelbuch requires a minimum age of 16. The reason is twofold: the age of digital consent varies between 13 and 16 across EU Member States (in Austria, 14 under § 4(4) DSG) — 16 is safe EU-wide. And the app is aimed at people making their own decisions in alpine terrain.
We ask for your year of birth at registration and create no record if the minimum age is not met. If we learn that an account was created contrary to this rule, we delete it without delay. Guardians may contact gipfelbuchalpin@gmail.com at any time.
There is no automated decision-making, including profiling, producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR.
The avalanche slope analysis and the wind and launch window analysis are purely technical calculations from terrain models and weather data. They assess terrain and weather, not you as a person. What these calculations can and — more importantly — cannot do is set out in the Disclaimer at https://gipfelbuch-alpin.com/haftung.
We update this policy when the app or the legal situation changes. The current version is always available at https://gipfelbuch-alpin.com/datenschutz and in the app. For material changes — in particular new processing purposes or new recipients — we inform you in advance in the app and obtain fresh consent where required.