Privacy Policy

Gipfelbuch — Alpine Companion

Version 1.0, effective 26.07.2026

The German version of this document is authoritative. In case of discrepancies, the German text prevails, unless mandatory consumer protection provisions require otherwise.

Summary in five sentences. Gipfelbuch stores what you enter or record yourself: your account, your tours, your contributions. We use your location only while you are using a feature that needs it — recording, weather warnings, avalanche check — and we deliberately round coordinates before sending them to weather services. We do not sell data, show advertising, or track you across other apps and websites. Everything not required for operation — crash reports, usage statistics, background location, connections to Strava or Garmin — is off until you explicitly turn it on, and you can withdraw consent at any time. You can delete your account and all its content directly in the app.

>

This summary does not replace the text below. The full text is authoritative.

1. Controller

Niklas Eder

Dornauberg 11a, 6295 Ginzling, Austria

Email: gipfelbuchalpin@gmail.com

Controller within the meaning of Art. 4(7) GDPR. No data protection officer has been appointed; the conditions of Art. 37(1) GDPR are currently not met. This assessment is reviewed annually.


2. What we process, why, and on what legal basis

2.1 User account

DataEmail address, password (hashed only — we never see it in plain text), display name, registration and last login timestamps, optionally profile picture and bio
PurposeProviding the account, associating your tours and contributions, sign-in, password reset
Legal basisArt. 6(1)(b) GDPR — performance of the user agreement
RetentionUntil account deletion; see section 6

Whether provision is required (Art. 13(2)(e) GDPR): email address, password and display name are necessary to conclude and perform the user agreement — without them no account can be created. Providing your age is a legal requirement. All other details, in particular profile picture and bio, are optional; if you do not provide them, only the respective feature is unavailable and there are no other consequences.

2.2 Location data

Location data is the most sensitive category we handle. Four distinct cases:

a) Map display and current position (foreground). Art. 6(1)(b) GDPR. Your position is processed on your device and is not transmitted to us unless you start a recording.

b) Recording a tour. Precise location trace with timestamps, altitude, speed and accuracy values. Art. 6(1)(b) GDPR — the recording is the service you explicitly requested. Recording starts and stops only through your action.

c) Background location access. Required so that recording continues when the screen is off, and so that thunderstorm and weather alerts can be triggered for your actual position. Legal basis: Art. 6(1)(a) GDPR — your consent, additionally § 165(3) of the Austrian Telecommunications Act 2021. Off by default; consent is given separately and can be withdrawn at any time in the app settings and in your device settings.

d) Transmission to external weather, warning and avalanche services. To retrieve information for your position, a coordinate must be sent to the relevant service (see section 4). We round the coordinate to two or three decimal places before transmission (roughly 100 to 1,000 metres of imprecision). The service learns your weather region, not your exact position. Legal basis: Art. 6(1)(a) GDPR.

Retention: recorded tours are stored until you delete them individually or delete your account. There is no automatic time-based deletion, so that year-on-year route comparison keeps working.

Important: Location traces can indirectly reveal home address, workplace, habits and health status. We therefore treat them with particular care: recorded tours are private by default. When you publish a tour, we automatically trim the start and end points by a configurable radius (500 m by default) so that your home address does not become public.

2.3 Community contributions

DataCondition reports, route and summit information, launch sites, comments, photos (including embedded metadata, see below), timestamp, display name, verification status where applicable
PurposeBuilding and maintaining the shared alpine database; display to other users
Legal basisArt. 6(1)(b) GDPR for storage and display; you decide for each contribution individually whether to make it public
RetentionUntil you delete it, or until removal under the Community Guidelines; for account deletion see section 6

Photo metadata: On upload we strip all EXIF data except the capture timestamp by default. A photo's location is only retained if you confirm this in the individual case.

Persons in photos (Art. 14 GDPR): where a contribution exceptionally shows identifiable third parties, we process their data solely to display the contribution, on the basis of Art. 6(1)(f) GDPR. Those affected may at any time request access, blurring or deletion at gipfelbuchalpin@gmail.com; we act on such requests without substantive review. Contributors are obliged under the Terms of Use to upload such images only with the consent of the persons depicted.

Please note: Contributions you publish are visible to all users and may be indexed by search engines. Do not publish personal data of third parties, in particular do not publish identifiable persons in photos without their consent.

2.4 Verification status (pilot, mountain guide, admin)

DataThe fact and category of verification, date, reviewing person
PurposeMaking qualified contributions identifiable — for safety-critical information this is a legitimate interest of the entire user community
Legal basisArt. 6(1)(f) GDPR
Supporting documentsWe inspect proof of qualification for review purposes only and do not store it permanently. Only the outcome is stored. Submitted documents are deleted within 30 days.
ObjectionYou may object to the display of your verification status at any time under Art. 21 GDPR; the verification is then removed

2.5 Push notifications

DataDevice push token (APNs on iOS, FCM on Android), device type, language, subscribed warning regions
PurposeDelivering weather, thunderstorm and avalanche alerts, and replies to your own contributions
Legal basisArt. 6(1)(a) GDPR; additionally § 165(3) TKG 2021
ContentPush messages contain no personal content. A generic notice is delivered; details are loaded once you open the app.
RetentionUntil push is disabled, the app is uninstalled, or the operating system reports the token as invalid

We do not send promotional notifications.

2.6 Importing activities

a) Manual file import (GPX, TCX, FIT). You select the file yourself. Art. 6(1)(b) GDPR.

b) Connecting Strava or Garmin via OAuth (where offered). After your explicit authorisation we store an access token and import the activities you select. Legal basis: Art. 6(1)(a) GDPR. Strava and Garmin are independent controllers for their own processing; their privacy policies apply. You can disconnect at any time in the app — the token is deleted immediately and revoked with the provider.

c) Health and vital data. Heart rate, training metrics and comparable values are health data under Art. 9 GDPR. We import and store them only if you give separate, explicit consent under Art. 9(2)(a) GDPR. Without that consent, such fields are discarded on import. The feature is off by default.

2.7 Diagnostics and usage statistics

Disabled by default. No corresponding module is initialised without your consent.

DataCrash reports (error message, stack trace, app version, OS version, device model), anonymous event counters
PurposeFinding and fixing errors, particularly those affecting safety-critical features
Legal basisArt. 6(1)(a) GDPR and § 165(3) TKG 2021
Not includedNo location data, no advertising identifiers, no cross-device tracking, no transfer to ad networks
Retention90 days
WithdrawalSettings → Privacy → Diagnostics. No further data is collected from that point.

2.8 Server logs

IP address, timestamp, endpoint, HTTP status and user agent are logged. Legal basis Art. 6(1)(f) GDPR — legitimate interest in operational security and abuse prevention. Retention 14 days, then automatic deletion.

2.9 Reports and moderation

Reports of illegal content under Art. 16 DSA, related correspondence and decisions taken are stored. Legal basis Art. 6(1)(c) GDPR (legal obligation under the DSA) and Art. 6(1)(f) GDPR; the legitimate interest lies in demonstrating compliance to authorities and in defending or bringing legal claims. Retention: three years after conclusion.


3. Access to your device (§ 165(3) TKG 2021)

Storing information on your device and accessing it is governed by § 165(3) of the Austrian Telecommunications Act 2021 — which applies to apps, not only to cookies on websites.

Without consent, because strictly necessary: authentication tokens in secure storage, your app settings, your consent status, offline map tiles, the local database of your tours, the cache for avalanche and weather data.

Only with consent: diagnostics and usage statistics (2.7), background location (2.2c), transmission of the rounded coordinate to external weather, warning and avalanche services (2.2d), push token (2.5), Strava or Garmin connection (2.6b). The local cache of weather and avalanche data already retrieved is by contrast strictly necessary, as it is what makes display without a network connection possible at all.

Consent can be withdrawn at any time under Settings → Privacy with immediate effect. The lawfulness of processing carried out before withdrawal is unaffected.


4. Recipients and processors

We do not sell data and do not disclose it for advertising purposes.

4.1 Processors under Art. 28 GDPR

ProviderPurposeData transferredPlace of processingTransfer safeguard
Supabase, Inc., USADatabase, authentication, file storageAll account data, tours, contributions, photosRegion eu-west-1 (Irland) (EU). Access by support and individual sub-processors from the USA possibleStandard Contractual Clauses (Implementing Decision (EU) 2021/914); data processing agreement in place
[Sentry / Functional Software, Inc.], EU instance de.sentry.io, FrankfurtCrash reports — only with consentError messages, app and device versionFrankfurt (EU). Account and organisation management in the USAEU-US Data Privacy Framework and Standard Contractual Clauses

4.2 Other recipients

RecipientPurposeData transferredSafeguard
Apple Inc. (APNs) / Google Ireland Ltd, Google LLC (FCM)Push deliveryPush token, message text without personal referenceApple: Standard Contractual Clauses. Google: EU-US Data Privacy Framework (Decision (EU) 2023/1795) and SCCs
Mapbox, Inc., USA (where used)Map renderingRequested map tiles, IP addressEU-US Data Privacy Framework, plus SCCs under the Mapbox DPA
Open-Meteo, GeoSphere Austria, Deutscher Wetterdienst, MeteoAlarm/EUMETNET, avalanche.reportWeather, warning and avalanche dataRounded coordinate, no identifier, no account referenceArt. 6(1)(a) GDPR. GeoSphere, DWD, MeteoAlarm and avalanche.report process within the EU
Strava, Inc. / Garmin (only with an active connection)Activity importOAuth token, requested activitiesIndependent controllers; transfers under the providers' SCCs
National Weather Service (USA) (only for tours outside Europe)Official weather warningsRounded coordinateArt. 6(1)(a) GDPR; retrieved via our proxy, no identifier
Law enforcement, judicial and emergency authoritiesNotifications under Art. 18 DSA; alerting rescue services in acute emergenciesOnly the information required in the individual caseArt. 6(1)(c) GDPR (legal obligation) or Art. 6(1)(d) GDPR (vital interests)

4.3 Transfers to third countries

Where data is transferred to the USA, we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023 (Decision (EU) 2023/1795) where the recipient is certified, and additionally on Standard Contractual Clauses under Art. 46(2)(c) GDPR. A copy of the Standard Contractual Clauses is available on request to gipfelbuchalpin@gmail.com.

A residual risk remains: authorities in the USA may under certain conditions access data stored there, and the level of legal protection does not in every respect correspond to that of the EU. We minimise this risk by keeping the main database within the EU and sending only the minimum necessary to US services.


5. Your rights

RightArticle
AccessArt. 15
RectificationArt. 16
ErasureArt. 17
RestrictionArt. 18
Data portabilityArt. 20
ObjectionArt. 21
Withdrawal of consent, at any time and without disadvantageArt. 7(3)

How to exercise them: fastest in the app under Settings → Privacy:

Alternatively by email to gipfelbuchalpin@gmail.com. We respond without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR). For particularly complex requests this period may be extended by up to two further months; we will inform you within the first month. Processing is free of charge.

Complaints: you may lodge a complaint with a supervisory authority at any time; in Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.


6. Account deletion and retention

You can delete your account at any time: in the app under Settings → Account → Delete account, or via the web form at https://gipfelbuch-alpin.com/konto-loeschen, without needing the app installed.

Data categoryTreatment on account deletion
Account data, email, profile, profile pictureDeleted immediately and permanently
Recorded tours and tracksDeleted immediately and permanently
Private contributions, drafts, photosDeleted immediately and permanently
Push token, Strava/Garmin OAuth tokensDeleted immediately and revoked with the provider
Public community contributionsYou choose in the deletion dialog: full deletion, or anonymisation (the contribution remains available to the community, the link to you is irreversibly removed). Deletion is the default.
Moderation and reporting recordsRetained pseudonymised for 3 years (legal obligation under the DSA)
Server logsExpire automatically after 14 days
Accounts with no sign-in for 36 monthsDeleted. We warn you by email 30 and 7 days beforehand; a single sign-in prevents deletion.
BackupsOverwritten after no more than 30 days

Deletion is final and cannot be reversed.

For content that has been made public, we additionally take reasonable steps under Art. 17(2) GDPR to inform other controllers of an erasure request.


7. Security

Measures under Art. 32 GDPR include: encrypted transmission (TLS 1.2 or higher); encrypted database storage; passwords stored only as salted hashes; row level security on every database table, binding each record to its owner; two-factor authentication for all administrative access; authentication tokens in the device's secure storage (Keychain / Keystore); least-privilege role and permission model; regular dependency updates and automated security scanning.

Despite all measures, no transmission over the internet is entirely secure.


8. Personal data breaches

In the event of a personal data breach we notify the Austrian Data Protection Authority within 72 hours of becoming aware of it (Art. 33 GDPR) where there is a risk to you. Where the risk is likely to be high — which, for location data, is effectively always the case — we will also inform you directly and in plain language (Art. 34 GDPR).


9. Minimum age

Using Gipfelbuch requires a minimum age of 16. The reason is twofold: the age of digital consent varies between 13 and 16 across EU Member States (in Austria, 14 under § 4(4) DSG) — 16 is safe EU-wide. And the app is aimed at people making their own decisions in alpine terrain.

We ask for your year of birth at registration and create no record if the minimum age is not met. If we learn that an account was created contrary to this rule, we delete it without delay. Guardians may contact gipfelbuchalpin@gmail.com at any time.


10. No automated decision-making

There is no automated decision-making, including profiling, producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR.

The avalanche slope analysis and the wind and launch window analysis are purely technical calculations from terrain models and weather data. They assess terrain and weather, not you as a person. What these calculations can and — more importantly — cannot do is set out in the Disclaimer at https://gipfelbuch-alpin.com/haftung.


11. Changes

We update this policy when the app or the legal situation changes. The current version is always available at https://gipfelbuch-alpin.com/datenschutz and in the app. For material changes — in particular new processing purposes or new recipients — we inform you in advance in the app and obtain fresh consent where required.