NavTrail — Privacy Policy
Effective date: 2026-09-21 (updated for v1.4 — badges and public profiles, comments and ratings, following; previously 2026-09-15, 2026-06-19 and 2026-05-19).
Public version hosted at: https://navtrail.app/privacy
This privacy policy explains what data the NavTrail app collects, how that data is used, who else processes it, and how long it is kept. It exists to comply with Romanian and EU data-protection law (Regulation (EU) 2016/679 — "GDPR") and applicable app-store publishing requirements.
If you have a question about your data or want to exercise any of the rights listed at the bottom of this document, email contact@navtrail.app.
1. Who is the data controller?
NavTrail is operated by Constantin, an individual developer based in Bucharest, Romania. This is a hobby / non-commercial project — there is no registered company behind it at the time of writing. Contact: contact@navtrail.app.
A Romanian version of this policy is available at https://navtrail.app/privacy-ro.
2. The short version
- No name, email, or phone is required to use the app. You sign in anonymously on first launch — the app generates a random user ID that lives on your device until you delete the app or wipe it.
- Creating an account is optional. If you want to back up your data and restore it on a new device, you can turn your anonymous identity into an account with an email + password — that is the only time we collect an email address. Without an account, nothing changes from before.
- Location data is collected only when you use a location-aware feature (recording a GPS track, sharing your position with convoy members, posting a hazard or SOS). Background location is requested only if you choose to broadcast to a convoy.
- No analytics, no advertising, no third-party SDKs beyond Firebase Cloud Messaging (for SOS notifications). The app has no Crashlytics, no Facebook SDK, no AppsFlyer, no anything-like-that.
- Map tiles, routing requests, and address searches are sent to third-party services (OpenStreetMap, OpenTopoMap, OSRM, Photon, Esri/ArcGIS, OpenFreeMap) — those providers can see the coordinates you query. See § 5 for the full list.
- You can delete all your data at any time — instantly and yourself, from inside the app (Settings → Personal data → Delete account and all my data, or the Account & backup screen). If you have already uninstalled the app, email
contact@navtrail.app instead. See our data-deletion page and § 9.
3. What data the app collects
3.1 Account
- A randomly-generated anonymous user ID (UUID), created by Supabase Auth on first launch. By default no email, password, phone, or name is required or collected.
- Optionally, an email address + password — only if you choose to create an account (to back up and sync your data across devices). Your existing anonymous user ID is preserved when you convert. Your password is never visible to us: it is sent to Supabase Auth, which stores only a salted hash. Email confirmation is required before an account becomes active.
- A Firebase Cloud Messaging (FCM) registration token — a long device-specific string Google issues to allow us to push you SOS notifications. Linked to your user ID in our database.
3.2 Location
The app collects precise location (GPS coordinates + altitude when available) only when:
- You record a GPS track — stored on your device. If you have an account, it is also backed up to your private cloud storage so you can restore it on another device (see § 3.3). Without an account, tracks stay on-device only.
- You post a POI (camping spot, water spring, etc.), hazard report, or SOS alert — the location of that single post is uploaded to Supabase so other users in the area can see it on the map.
- You join or create a convoy and enable position sharing — your live position is broadcast to the other convoy members (max 12 people who all share a 6-character convoy code). See § 6 for the convoy detail.
The app never collects location passively in the background unless you have explicitly joined a convoy and granted background-location permission. Even then, broadcasting auto-stops after 2 hours of foreground-screen-off use to limit battery and data drain.
3.3 Cloud backup of your tracks & lists (optional — requires an account)
If — and only if — you create an account (§ 3.1), the app backs up your personal data so you can restore it on a new device:
- Your recorded GPS tracks — summary stats plus the full track as a compressed GPX file stored in a private Supabase Storage bucket only you can read.
- Your packing inventory (item names, weights, checked state) and vehicle-maintenance records (category, odometer, date, free-text notes).
This data is private to your account (enforced by Row-Level Security) — it is never shown to other users. It is removed when you delete the record or your account (§ 9). Anonymous (no-account) users back up nothing.
3.4 User-generated content
- An optional public username (3–20 characters) — if you set one, it is shown on the POIs, hazards and SOS alerts you create, in place of your anonymous ID, and is readable by anyone using the app. You choose it when creating an account (or later, while it is still unset); leaving it blank shows "Anonim" instead.
- POI names + descriptions (≤ 800 chars)
- Hazard descriptions (≤ 280 chars, optional)
- SOS descriptions (≤ 280 chars, optional) and
contact_hint (≤ 80 chars, optional — typically your own phone number if you choose to share it)
- Convoy nicknames (≤ 8 chars, visible only to other members of your convoy)
- Travel partners (the trips board): the trip you post (title ≤ 80 chars, description ≤ 600 chars, start and destination place names with their coordinates, dates, difficulty, vehicle and sleeping style, how many vehicles or seats you look for, up to 3 photos, optionally one of your published routes), your requests to join other trips (a short message ≤ 300 chars), the messages you exchange inside a conversation (≤ 1000 chars each), an optional vehicle profile (type, make and model, modifications, winch, recovery gear, one photo), the ratings you give partners after a trip (1–5 stars, whether you would travel with them again, an optional private note ≤ 300 chars), and the reports you file. Listings never carry contact details — the server rejects phone numbers and e-mail addresses in a trip or a request. You may send your own phone number inside a conversation with one tap; it then goes only to the other person in that conversation. See § 6A.
- Comments and ratings: the comments you write on points of interest and published routes (≤ 500 chars, public, shown with your username and rank) and the 1–5-star ratings you give (only the average and the count are ever shown to others). See § 6B.
3.5 Map / routing / search queries
When you pan the map, search for a place by name, or ask for turn-by-turn navigation, the device sends the relevant coordinates or search text to third-party map providers (§ 5). These queries do not include your anonymous user ID. The providers can, however, see the IP address your device connects from.
3.6 What the app does NOT collect
- Your real name or phone number. Your email address is collected only if you voluntarily create an account (§ 3.1) — or if you put contact info in an SOS
contact_hint. The one exception is a phone number you choose to send inside a travel-partners conversation (§ 6A), which is stored as a message of that conversation.
- Photos, microphone audio, contacts, calendar, or any other personal data on your device.
- Analytics events, ad identifiers, or behavioural telemetry.
- Web-browsing history. Crash logs are NOT collected by us (app-store pre-launch testing runs its own diagnostics outside this scope).
4. Why each piece of data is collected (lawful basis)
Under GDPR Art. 6:
| Data | Purpose | Lawful basis |
| Anonymous user ID | Authenticate API calls; prevent abuse | Legitimate interest (Art. 6(1)(f)) |
| FCM token | Deliver SOS push notifications | Consent (Art. 6(1)(a)) — implicit in installing an off-road app + granting POST_NOTIFICATIONS |
| Location of a POI / hazard / SOS post | Show the post on a shared map | Consent — you explicitly chose to post |
| Live convoy position | Show your position to convoy members | Consent — you explicitly joined a convoy and granted background-location permission |
| Free-text content in posts | Display to other users | Consent |
| Email address + password (if you create an account) | Create your account; back up & sync your data across devices | Consent (Art. 6(1)(a)) — you chose to create an account |
| Backed-up tracks / inventory / maintenance | Restore your personal data on a new device | Consent (Art. 6(1)(a)) |
| IP address (transient, in HTTP headers) | Connect to our backend | Legitimate interest (Art. 6(1)(f)) — network protocol requires it |
| Map / routing / search queries to third-party providers | Show maps; calculate routes; find addresses | Legitimate interest (Art. 6(1)(f)) — these are the requested user actions |
No data collection is based on a contract (Art. 6(1)(b)) — there is no paid subscription — and none of it falls under the "vital interest" or "public task" bases.
5. Third parties that receive your data
NavTrail does not sell your data and does not share it for advertising. Data passes to the following service providers strictly to make the app work:
5.1 Supabase (primary backend)
- What: Anonymous-auth records, account email addresses, POIs, hazards, SOS alerts, convoy memberships, FCM tokens, moderation reports, and — for account holders — backed-up tracks, inventory and maintenance records plus the GPX track files in private Storage.
- Where: EU region (Frankfurt, Germany). Operated by Supabase Inc.
- Why: Our database, authentication server, and Realtime push channel.
- Privacy policy: https://supabase.com/privacy.
5.2 Firebase Cloud Messaging (push notifications)
- What: Your FCM registration token + the contents of any SOS notification we send your way.
- Where: Google global infrastructure. Operated by Google LLC.
- Why: Deliver heads-up notifications when another user posts an SOS in your geohash cell.
- Privacy policy: https://policies.google.com/privacy.
5.3 Routing (turn-by-turn directions)
When you ask for directions, the latitude/longitude of your current position and of your chosen destination are sent over HTTPS to one of three routing servers, tried in this order. None of them receives your user ID or any account data; each can see the IP address your device connects from.
- NavTrail's own routing server —
routing.navtrail.app, operated by us on a rented server hosted by Hetzner Online GmbH in Germany (EU). Used first, for trips inside the area it covers (Romania at the time of writing). We use these requests for nothing other than answering them, and they are not passed to anyone else.
- FOSSGIS OSRM —
routing.openstreetmap.de, a community-operated server in Germany, used when the trip is outside our own server's coverage or our server does not answer. Privacy policy: https://routing.openstreetmap.de/about.html.
- Mapbox Directions —
api.mapbox.com, operated by Mapbox, Inc. (United States), used only as a last resort when both servers above fail. Privacy policy: https://www.mapbox.com/legal/privacy.
5.4 Photon (Komoot) — geocoding
- What: The text you type into the search bar, plus your current position as a bias (to rank nearby results higher).
- Where:
photon.komoot.io — operated by Komoot GmbH.
- Why: Convert "Cabana Padina" into a map coordinate.
- Privacy policy: https://www.komoot.com/privacy.
5.5 OpenStreetMap tile servers
- What: Map-tile requests (
{z}/{x}/{y} URL segments) — these effectively reveal which map regions you are looking at.
- Where:
a/b/c.tile.openstreetmap.org (OpenStreetMap Foundation, UK).
- Why: Render the standard online map style.
- Privacy policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy.
5.6 OpenTopoMap, CyclOSM, Esri/ArcGIS World Imagery, OpenFreeMap
- What: Same shape as § 5.5 (tile requests revealing the regions you view) for the alternative map styles.
- Where: Various community-operated servers + Esri (ArcGIS).
- Privacy policies:
5.7 What no third party receives
- None of the third-party services above receives your anonymous user ID.
- None of them receives the contents of POIs / hazards / SOS posts (those stay between your device and Supabase).
- None of them receives any contact information you may have entered in an SOS
contact_hint.
6. The convoy feature in detail
This deserves its own section because it is the only feature that uses background location, and it is the only feature where your real-time position becomes visible to other people.
6.1 How it works
- You explicitly create or join a convoy by entering a 6-character code shared by the convoy owner (think "AirDrop for off-road groups"). Convoys are capped at 12 members.
- Before background broadcasting starts, the app shows an in-app disclosure dialog explaining what's about to happen, and then asks your device for the background-location permission.
- While broadcasting, a persistent notification appears showing "Convoy active — your position is being shared" with a one-tap "STOP SHARING" button.
- Broadcasting automatically stops after 2 hours of cumulative foreground-screen-off use, even if you forget you joined.
6.2 What flows where during a convoy
- Your live position (lat/lon/heading) is sent every ~5 seconds to Supabase Realtime Broadcast and immediately relayed to the other convoy members. It is not stored — there is no database row written for any single position ping.
- Your convoy membership (anonymous user ID + nickname + color) is stored in a database row for the lifetime of the convoy. Convoys auto-expire 48 hours after the last activity (last position broadcast or heartbeat) and are then deleted server-side.
6.3 Who can see your position
- Only other members of the same convoy. Membership is gated by the 6-character code and enforced by Supabase Row-Level Security.
- The convoy owner can kick any member, immediately revoking their ability to see other members' positions.
- Any member can leave the convoy at any time, immediately stopping their broadcasting and removing them from the others' maps.
6.4 How to stop
- Tap the persistent notification's "STOP SHARING" button — instant.
- Open the app → MENU → Convoy → LEAVE CONVOY — instant + removes your membership row.
- Disable the app's background-location permission in your device's Settings → Apps → NavTrail → Permissions — at the OS level, instant.
- Force-quit the app — the foreground service stops, broadcasting stops. The system will not relaunch it.
6A. The travel-partners board in detail
6A.1 What is public
A trip you post is visible to everyone using the app, signed in or not, anywhere in the world: its title and description, the start and destination, the dates, the difficulty, vehicle and sleeping style, how many partners you look for, its photos, your public username, your vehicle profile if you have one, and your partner reputation — an average shown only once you have at least three ratings, how many partners said they would travel with you again, and how many trips you completed together. Finished trips stay on the board for 60 days.
6A.2 What is private
A request to join is seen only by you and the poster. A conversation is seen only by its two participants, and by the operator when a message in it is reported or as described in § 6A.4. A "would not travel again" answer and a private rating note are never shown to anyone but the operator. Your phone number is stored nowhere unless you send it inside a conversation, where it becomes one message of that conversation.
6A.3 Notifications
With your permission, the app notifies you of a new request, a reply, a confirmation, a new message, a reminder a week before a trip and — unless you turn it off in Settings — a weekly note when new trips were posted. They travel through the push service described in § 5.2; a message notification carries at most the first 80 characters of a text message, never a shared phone number.
6A.4 Retention and deletion
Conversations and their messages are deleted 90 days after the trip's last day (and become read-only 30 days after it). Requests and the trips themselves stay with your account: they are your history and they count towards trips completed together. The operator can remove a listing that breaks the rules and keeps a record of its title, the reason and the date. Deleting your account deletes your trips, your requests, your vehicle profile, your ratings and the messages you sent; messages other people sent you stay in their conversations without your identity.
6B. Badges, comments, ratings and following in detail
6B.1 Badges and the public profile
Every member has a public profile, in the app and at navtrail.app/u/<username>: username, rank, points, Respect, the number of points of interest added, routes published, hazards reported, kilometres recorded, trips completed with partners, followers and following, and the badges earned. Badges are computed on our server from what you do in the app; challenge badges reveal that you drove through a curated place (a mountain pass, a lake, a route) and when. Badges and your kilometres are public by default; the switch "Show my badges to others" in Settings hides both from other members and from the web page. The recording that earned a challenge badge is never shown to anyone.
6B.2 Comments and ratings
A comment is public, carries your username and rank, and can be edited or deleted by you at any time. A rating is stored with your account but shown to others only as part of an average and a count. Both follow the item: a hidden or deleted point of interest, or a route made private again, takes its comments and ratings out of sight. The owner of a point of interest or route is notified by push when someone comments on it (the notification carries at most the first 80 characters).
6B.3 Following
Who you follow and who follows you is visible only to you; the counts are public on your profile. Following subscribes your phone to that member's news through the push service described in § 5.2 (a topic named after their account id; nothing about you is sent to them). The switch "News from the people I follow" in Settings turns these notifications off. Blocking a member removes the follow in both directions.
7. How long data is kept
| Data | Retention |
| Anonymous user ID | Until you delete the app or email us to wipe it |
| FCM token | Until your device deregisters (uninstall / clear data) or you wipe the account |
| Account email address (if you created an account) | Until you delete your account |
| Public username (if you set one) | Until you delete your account |
| Backed-up tracks / inventory / maintenance (account holders) | Until you delete the individual record, or your account |
| GPS tracks | On-device by default. With an account, also backed up to your private cloud storage until you delete the track or your account. You control them in the "Saved Tracks" screen. |
| POIs | Permanent until you delete them, or auto-hidden if ≥ 3 distinct users report them (see Moderation Policy) |
| Hazard reports | 4 hours after creation (auto-deleted by a 15-minute cron job) |
| SOS alerts | 24 hours after creation (auto-resolved + deleted after the resolved-state retention) |
| Convoy membership rows | 48 hours after the last activity from any member |
| Live convoy positions | Not stored — relayed via Realtime Broadcast and discarded |
| Moderation reports you file | Kept while your account exists (audit log for the ≥ 3-report auto-hide); deleted when you delete your account/data. Visible only to you and the operator. |
| Travel-partner trips, requests, vehicle profile, ratings | Until you delete them or your account; a finished trip leaves the public board 60 days after its last day |
| Travel-partner conversations and messages | Read-only 30 days after the trip's last day, deleted 90 days after it (a nightly job) |
| Comments | Until you delete them, or with the point of interest / route they belong to, or with your account |
| Ratings | Until you remove them, or with the item, or with your account |
| Badges earned, Respect, rank | Until you delete your account (a badge is permanent while the account exists) |
| Follows (who you follow / who follows you) | Until you unfollow, until a block, or until either account is deleted |
8. International transfers
- Supabase data — including account emails and your backed-up tracks, inventory, maintenance and GPX files — is hosted in Frankfurt, Germany (EU). No transfer outside the EU/EEA happens for the primary backend.
- Firebase Cloud Messaging operates on Google's global infrastructure. Google relies on Standard Contractual Clauses (Art. 46 GDPR) for transfers outside the EEA — details in their privacy policy.
- Our own routing server (§ 5.3) is hosted by Hetzner Online GmbH in Germany (EU) — no transfer outside the EU/EEA.
- The third-party tile / routing / geocoding services listed in § 5 are operated by entities in the EU (Komoot — Germany; FOSSGIS — Germany; OpenStreetMap Foundation — UK + community mirrors) and the US (Esri; Mapbox, Inc., which receives route coordinates and your IP address only in the last-resort case described in § 5.3). Each request is a transient HTTP call; nothing about you persists with those providers beyond their own server logs.
9. Your rights under GDPR
You have the right to:
- Access the data we hold about you. Email
contact@navtrail.app with the anonymous user ID visible in the app's Settings → About screen. We'll send a JSON export within 30 days.
- Rectification — correct anything that's wrong. POIs and SOS alerts you created are editable / deletable directly in the app. For other corrections, email us.
- Erasure / "Right to be forgotten" — delete everything yourself, instantly, from inside the app: Settings → Personal data → Delete account and all my data, or the Account & backup screen. This removes your account and all personal data (cloud backups, devices, convoy data, your hazard/SOS posts and the moderation reports you filed) immediately; your community POIs are kept but anonymized (de-linked from you). If you have uninstalled the app, email
contact@navtrail.app instead and we will complete it within 30 days. Full details: our data-deletion page.
- Restriction of processing — same email; tell us which processing you want paused.
- Object to processing based on legitimate interest — same email.
- Data portability — request your data export under "Access" above; the format will be machine-readable JSON.
- Withdraw consent at any time, where consent was the basis (e.g. revoke the notification or background-location permissions in your device's Settings).
- Lodge a complaint with the Romanian data-protection authority (ANSPDCP — dataprotection.ro) if you believe we've mishandled your data.
10. Children's privacy
NavTrail is not directed at children under 16 and we do not knowingly collect data from them. The travel-partners board is for adults only: posting a trip or asking to join one requires a declaration that you are 18 or older. If you believe a child has used the app and you'd like their data removed, email contact@navtrail.app.
11. Security
- All network traffic is over TLS 1.2+ (HTTPS). Plain HTTP is disabled at the OkHttp + manifest level.
- Database access is gated by Row-Level Security policies on every table, so a compromised anon-auth token cannot read other users' data beyond what the in-app UX exposes.
- Anonymous user IDs are random UUIDs — they cannot be reversed into PII because no PII was collected to begin with.
- The Supabase publishable API key shipped in the APK is intentionally public; it grants no privileges beyond what RLS allows.
- If you create an account, your password is never stored or seen by us — Supabase Auth keeps only a salted hash, and email confirmation is required before the account activates.
This said, no system is perfectly secure. If you discover a vulnerability, please email contact@navtrail.app rather than posting it publicly so we can fix it before bad actors notice.
12. Changes to this policy
Material changes (new third parties, new data categories, changed retention) will be announced in the app's release notes and reflected in the "Effective date" at the top of this document. Continued use of the app after a change implies acceptance of the new policy. If a change is significant enough that it requires fresh consent (e.g. adding analytics — which we won't), the app will prompt you in-app.
The current version always lives at https://navtrail.app/privacy.