Last updated:
The short version.
This policy covers the Trailtold mobile app and this website. Trailtold is currently in closed beta and is operated by a small independent team, not a large company. If something below changes, we'll change this page and update the date at the top.
When you create an account you give us an email address and a password. These are held by our authentication service, which we run ourselves; passwords are stored hashed and we never see them in readable form. Your account is identified internally by a random user ID, and that ID — not your email — is what's attached to everything else below.
A display name that you choose. This is public: it appears next to anything you post. Your email address is never shown to other people.
Notes and other contributions you write about places, ratings and reviews you leave on tours, and the moderation actions you take (following someone, blocking someone, reporting a post). Contributions are reviewed before anyone else can see them.
If you subscribe or buy a park pack, the payment itself is handled entirely by Apple or Google. We never see your card number. We useRevenueCat, a third-party service, to keep track of what you're entitled to; RevenueCat receives your random user ID and the purchase and receipt data from the app store. RevenueCat publishes its own privacy documentation for the data its SDK handles.
This is the important one, so here is precisely how it works. While a tour is running, the app asks the operating system for your position so it can tell when you've reached a stop and start the right audio. That position is handed straight to the part of the app that plays narration, on your device, and is never transmitted. There is no field in any request the app makes to our servers that carries a latitude or longitude, and the location library in the app is configured with no upload address, so there is no destination for coordinates to be sent to. Location access is requested only as "while using the app", and only while a tour is actually active — nothing tracks you between tours or after you close the app.
To be complete about it: the location library keeps its own history of the position fixes it recorded, in a database on your phone. That history stays on your device — we never fetch it, and nothing in the app uploads it — and it goes away when you uninstall the app.
Because no coordinates leave the device, we declare location as not collected on the App Store and Google Play data forms, which define "collected" as transmitted off the device. The map tile requests described below do leave your device. They are framed by the tour you're viewing rather than by your GPS position, so they never carry your coordinates — but we won't pretend they reveal nothing: if you're walking that tour, the area they show is roughly where you are.
The app contains no analytics SDK, no advertising SDK, and no crash-reporting SDK. We don't build a profile of your behavior, we don't sell or rent data to anyone, and we don't participate in any ad network. We do not track you across other companies' apps or websites, so Apple's App Tracking Transparency prompt does not apply to Trailtold.
We don't ask for or collect your contacts, photos, microphone, calendar, health data, or advertising identifier.
Audio. When you play a tour or download an offline pack, your device fetches the audio files from our content storage. Those requests carry no account information — they're anonymous, and they are not linked to your profile. As with any request to any server on the internet, the receiving server can see the IP address it came from and which file was asked for. We don't use those requests to identify you or to reconstruct where you've been.
Map tiles are different, and you should know about it. The map in the app currently draws its tiles from MapLibre's public demo tile server, which is run by the MapLibre project and is not ours. That means that whenever a map is on screen, your device makes requests directly to a third-party server, and that server can see your IP address and — from the tiles you request — roughly which area you are looking at. Those requests carry no account information and are not linked to your profile, but they do leave your device, and they go to someone other than us. This is a beta shortcut, not our intended setup; when the app switches to serving tiles from our own storage we will update this page.
Offline packs currently include a map-tile file that the app stores but does not yet use for drawing — offline map rendering isn't built. Downloading a pack therefore makes the audio available offline, but a map still fetches tiles as described above.
Map data comes from OpenStreetMap contributors under the Open Database License. Park information comes from the National Park Service and is in the public domain.
We keep the list of third parties as short as we can. Today it is:
| Who | What they handle |
|---|---|
| Apple / Google | App distribution and all payment processing for purchases. |
| RevenueCat | Purchase and subscription status, keyed to your random user ID. |
| Amazon Web Services | Hosting for our servers and database. |
| Cloudflare | Hosting for this website, and storage/delivery for audio and pack files. |
| MapLibre | Serves the map tiles the app draws. Receives your device's IP address and the tile coordinates it asks for, which indicate the area you're viewing. No account information is sent. |
Apple, Google, RevenueCat, AWS and Cloudflare are service providers acting on our behalf. MapLibre is not — it's a public service the app currently draws tiles from, as described above. We don't sell your personal information, and we don't share it for advertising.
Public inside the app: your display name, your published contributions, and your reviews. Not public: your email address, your password, and your purchase history.
Your account data stays until you delete it — see below. Our servers keep ordinary operational logs (things like IP address, request path and timestamp) so we can debug problems and detect abuse. Those log files are size-capped and rotate, so the oldest entries are overwritten as new ones arrive rather than being kept indefinitely.
Some log lines do include your account's random user ID — for example when a purchase message from the app store can't be processed, or when part of an account operation fails. So while we don't use logs to build a profile of your behavior, we won't claim log entries are anonymous: until they rotate away, some of them can be associated with an account.
One identifier deliberately survives deletion, in order to enforce it. When you delete your account we keep your random user ID and the date it was deleted — one opaque identifier and a timestamp, nothing else. No email address, no display name, no content, nothing that ID was ever attached to.
We keep it because a store subscription outlives the account that bought it. Deleting your Trailtold account doesn't cancel an App Store or Google Play subscription — only the store can do that — so the store keeps sending us renewal messages carrying your old ID, every billing period, for as long as the subscription lives. With no record that the account is gone, each of those messages would create a fresh entitlement keyed to that ID, putting back the identifier we told you we had erased. Keeping the bare ID is what makes the erasure stick — the same principle as an unsubscribe list. The only read we ever perform against it is "has this ID been deleted?", so the message can be dropped. It is never used to serve, profile, re-identify, or contact anyone, and it is never joined back to user data.
You can delete your account from inside the app: Profile → Delete account. It's immediate and permanent, and it removes your profile, your contributions, your reviews, your follows and blocks, and your login itself.
Cancel a subscription before you delete. Deleting your Trailtold account does not cancel an App Store or Google Play subscription — only the store can do that — so if you delete first, the store keeps charging you for an account that no longer exists. Deleting also forfeits your purchases: they cannot be restored onto a new account. The full list of what is and isn't removed is on theaccount deletion page.
Trailtold isn't directed to children under 13, and we don't knowingly collect personal information from them. If you believe a child has created an account, contact us and we'll remove it.
Traffic between the app and our servers is encrypted with HTTPS. Sign-in tokens are stored in your device's secure storage (the iOS Keychain or the Android Keystore). No system is perfectly secure, and we won't pretend otherwise — but we keep the amount of data we hold small on purpose, which is the most effective protection available to us.
Trailtold is in closed testing and runs on test infrastructure. Features and data handling may change during the beta; material changes will be reflected here with a new date at the top of the page.
Questions about privacy, or a request about your data:[email protected]. For anything else, see support.