Explained transparently
Privacy
This notice describes the data that Hugos Bike-Touren App (HBTA) processes for accounts, tours, navigation, share links, the community, communications, moderation and voluntary app feedback.
1. Controller
The controller is Swen Hugowski as the private operator of HBTA. The address for service, telephone number and further operator details are provided in the HBTA legal notice. You can send privacy requests to admin@hugosbiketouren.de.
2. Data that is processed
Account and sign-in
- Email address, display name, and the server-defined version numbers and times at which you acknowledged the privacy notice and agreed to the terms of use, for registration, sign-in and account assignment.
- At each sign-in, the app also transmits the manufacturer and model name of the Android device. The server stores this information as an internal label for the associated session in order to assign sessions technically, secure access and revoke sessions when all devices are signed out. Users are not currently offered a list of individual device sessions; the information is not displayed to other users.
- Passwords are not stored in plain text, but only as a secure password hash. New passwords for registration and reset must contain 8 to 36 characters and at least one uppercase letter, one lowercase letter and one special character; digits are optional and spaces do not count as special characters. Existing longer passwords remain valid for sign-in, email verification and account deletion.
- Email verification, password reset, access, refresh and public share tokens are stored on the server only as cryptographic hashes. The respective raw token is transmitted to your device or held there securely only for its intended operation.
Private profile
- A profile photo is optional. Before upload, the Android app creates a smaller new image file and in doing so removes EXIF, GPS, file-name and other original metadata. The server stores only this processed image together with media type, image dimensions, file size, visibility, a cryptographic content checksum, a technical version identifier, and the creation or modification time.
- A new profile photo is private in the current app version and can be retrieved only by you. New sharing with the community or chat is not yet offered there. If an image already has the sharing status “Community”, you can switch it back to private in the app. The photo does not become part of public route links or the publicly accessible website. You can replace or delete it at any time.
- Fitness analysis is voluntary and separate from GPS recording, navigation and tour synchronisation. Only if you enable it are your age in full years (18 to 120) and your current weight (20 to 350 kg) required for this function. Both values are stored solely on your Android device, separated by account. An exact date of birth is not collected.
- A recording started while fitness analysis is enabled can contain a local age and weight snapshot and a resulting calorie estimate. Age, weight, these snapshots and calorie values are not transmitted to the HBTA server, synchronised on the server, shared or published.
- Date of birth, year of birth, height and gender are not collected in the current app version. At registration, you merely confirm that you are at least 18 years old. For the chat profile, the current app collects no postcode and transmits no region. The optional place and postcode search in the route planner is separate and is described in section 4.
Tours and location data
- Planned private routes contain the destinations and intermediate destinations you select and may be associated with your account for planning and navigation.
- When you prepare HBTA navigation, the app transmits your precise current location as the starting point, the selected destination, optional intermediate points and the bicycle profile over HTTPS to the HBTA routing endpoint. If a route deviation is detected while you are actively using navigation, your then-current location, the remaining points and the profile are transmitted again for route calculation.
- The returned route package contains the route line, distance, estimated duration, elevation values, turn instructions and technical version information. It is stored separately for the account in private app storage that is excluded from Android backup and device transfer. During the ride, HBTA processes ongoing location measurements, direction of travel and speed on the device for route matching, distance to the next instruction and voice output. Unless a deviation is detected, these ongoing measurements are not transmitted to the HBTA routing endpoint.
- Before the first GPS recording, HBTA asks for separate, express GPS/tour-data consent. It covers local processing of recording sessions, precise GPS track points and their measurement times, the start and end of the recording, and derived tour values such as distance, duration, speed and elevation gain. These data are initially stored only on your Android device, separated by account.
- The optional “Automatic pause detection” is disabled by default and can be enabled under “Profile & Settings”. Starting and ending a tour remain manual actions. During recording and an automatic pause, HBTA locally processes quality-checked location measurements and signals from the phone's motion sensor to recognise a standstill or resumed movement; active riding time is paused during a confirmed pause. The motion sensor only supports the assessment, and every automatic state change still requires reliable GPS movement. Its signals are processed transiently, are neither stored nor transmitted, and require no additional Android permission. GPS and motion detection continue to use battery and do not themselves cause any transmission to the HBTA server. A manual pause ends location capture and motion detection for the recording and is resumed manually only. Navigation running independently may continue to require location data. If the automatic function is disabled during an automatic pause, the recording remains paused manually.
- Recorded GPS tours are additionally transmitted and permanently associated with your account only while GPS/tour-data consent is active, over HTTPS, and either after your individual synchronisation action or when private tour synchronisation is enabled by you. This private server copy creates neither a share link nor a community publication or photo upload; each of these requires its own action. Disabling private tour synchronisation stops future automatic transmissions. Existing account routes and deliberately created shares or community publications remain unchanged and can continue to be deleted or withdrawn separately.
- Estimated calories are modelled on the device only when fitness analysis has been separately enabled, based on age, weight, active riding time and recorded pace. Age is used to classify the adult reference model; no supposedly precise, invented age correction factor is applied. The displayed consumption is a rough, non-binding estimate, not a measurement or medical value. E-bike assistance, wind, incline, surface, personal fitness, heart rate and other individual factors can lead to substantial differences.
Local features from version 0.7.11
Guest mode: A separate local guest profile lets you try HBTA without an account. GPS recordings start only after your voluntary GPS/tour-data consent and Android location permission. Guest tours stay on this phone; fitness analysis, automatic server synchronisation and account-dependent API functions remain off. Guest data are not automatically transferred into an account used later. Viewing the map still loads tiles from the self-hosted map server, which can see the IP address and requested area.
GPX files: After deliberate selection and preview, a confirmed GPX track or route is imported separately for your account or guest profile into private app storage excluded from Android backups. Importing alone does not send the tour to the HBTA server. Titles, coordinates, available elevations and valid measurement times may be retained locally; other third-party metadata are not imported. A GPX export, however, is an unencrypted file containing the full selected route including its start and destination, its title and optionally elevation. Exact timestamps are off by default and require an additional choice. Trimming a share link does not automatically trim this file. Your selected Android document provider may be a cloud service and may transmit or retain the selected file under its own rules. Copies saved outside HBTA or sent to others cannot be revoked; a failed write may leave an incomplete file at the selected destination.
Tour offline packages: For an already calculated route, you may choose to download a bounded map region together with the route, elevation profile and manoeuvres. Map requests go to the self-hosted map server and reveal the requested area and necessary connection data; they do not publish your tour. Maps are held in the private on-device MapLibre database, with an additional route copy in account-separated NoBackup storage. No additional application-level database or end-to-end encryption is claimed for this storage. Packages can be deleted separately; ordinary sign-out does not delete packages deliberately retained on the device. The interface shows actual download status. Full offline recalculation after leaving a route is not included and still needs internet. Voice guidance continues to require a suitable installed offline voice.
Share links and community tours
When you expressly share a route, a share is created with the route title, distance, duration, ascent and, if available for the route, a broad region. Destinations and intermediate points of a planned route are published only if you expressly include them. For a recorded tour, a simplified public GPS route line may appear after your additional selection; timestamps, elevation profiles and sensor values for individual track points are removed from it.
The share link can be revoked, is visible to anyone who possesses or receives it, and expires after no more than 30 days. Before sharing a recorded line, you can hide its first and last metres along the route and review the remaining line. This does not hide an entire surrounding area: the remaining route, places visited again or the title may still reveal private places. Profile details including profile photo, user ID, email address, display name, weight, calories and the complete private GPS track are not published through such share links. Share tokens are also held on the server only as hashes.
When you pass a deliberately created share link to a messenger or social service through the Android share sheet, or paste it there, the selected service receives the complete link. It may automatically open it and create and cache a preview containing the route title, distance, duration and ascent. By default, HBTA provides the summary already shared and a general HBTA image without a route line. The service processes connection data under its own terms. Revocation prevents future retrieval of tour data from HBTA but cannot retrieve previews already stored or sent by third parties.
From version 0.7.11: For new shares of recorded tours, you may separately and voluntarily enable a map image for messenger previews. Only then does the HBTA server process the explicitly shared route line, shortened by your selected start/end distances, into a PNG image with the title and tour statistics. Interrupted sections stay separate; private original points, GPS measurement times, fitness values and photos are not additionally included. The basemap comes from the existing self-hosted map service; if unavailable, only an explicitly labelled route outline is shown. HBTA creates no permanent image file or private image cache for this. Expiry and revocation are checked before and after rendering. Messengers and recipients can nevertheless store and forward their own image copies, which HBTA cannot delete. Trimming does not guarantee anonymity. Existing links are not retrospectively expanded to include a route image.
You can also deliberately publish a reduced copy of one of your own routes in the account-protected HBTA community. It can contain a description, difficulty, surface, e-bike suitability, cleaned route geometry and up to six photos. The community displays your display name only after a separate express selection; otherwise the neutral name “HBTA Rider” appears. A publication can be switched back to private. Live or current locations are not a community field and are not stored there.
The HBTA editorial team may additionally curate selected, non-personal route geometries from OpenStreetMap. The technical line dataset, source ID and URL, relation version and timestamp, semantic source and geometry checksums, licence and attribution details, processing status and an import batch are stored for this purpose. These datasets belong to a non-login system publisher and are not associated with a user account. They appear only in app versions capable of displaying the source information and can be provided to signed-in users as GeoJSON.
Selected photos are re-encoded on the Android device. In doing so, the app removes EXIF, GPS, file-name and other original metadata; only the newly created image with minimum technical details is stored. Uploaded tour photos follow the community tour's currently saved visibility. For an already published tour, they may therefore become visible to signed-in community users after upload. To make the tour private, save that change before uploading photos; changing only the selection in the edit form is not enough. Favourites store the association between the account and community tour. In-app reports contain a predefined reason without free text; the reporting account ID is used internally only for abuse prevention and duplicate checking and is not displayed to authors.
Optional tour video export
From version 0.7.10, an optional MP4 export is available. The video is created on your Android device from the route line you review, the editable title and the selected tour details. You can hide sections at the start and end along the route and check the visible preview before export. This does not protect an entire surrounding area: the remaining route, title or images may still reveal private places.
You can voluntarily add up to three images through the Android system picker. HBTA uses their image content only on your phone for the video and does not copy EXIF, GPS, file-name or other original metadata. Age, weight, calories, account and profile details, and measurement times of individual GPS points are not automatically included in the video. Visible people, places or details you enter may nevertheless be personal data. Use only images for which you hold the necessary rights to share them, and also respect the rights of identifiable people. The export has no music feature.
As in the map view, styles, fonts and map tiles for the background map are loaded over HTTPS from maps.mhui.de. The map server receives connection data and requested tile paths, which may reveal the region being viewed. Video rendering and the selected photos are not uploaded to an external video or AI cloud or to the HBTA server. Creating a video also creates no public share link or community publication.
When saving, you select the destination through Android yourself; a cloud storage service selected there may transfer and retain the file under its own settings. Only when you pass the finished video through the Android share sheet does your chosen app receive the video file. That app and its recipients can store and forward the video. Such a copy does not expire after 30 days and cannot be recalled by HBTA or removed by deleting your tour or account. Delete copies you saved yourself at the selected destination if needed. A tour video is a separate file; the automatic share-link preview described above remains a separate feature.
For a recording stored in your account, you can additionally choose to include a tour link for navigation. It is created only through this separate sharing action and uses the original tour title, not a title edited only for the video. The sharing and revocation rules above apply; revoking the link does not remove a video file already passed on. The video file alone contains no route package for navigation.
Temporary video files created by HBTA are kept in its private app cache. From version 0.7.10, signing out, account deletion and session changes stop ongoing video work, remove these temporary files and revoke their file-read grants. If cleanup fails, the app displays a message explaining how to clear the HBTA cache in Android app settings. Older temporary files are also cleaned up on the next video export; this does not guarantee deletion after a fixed number of hours. Data already received, already opened files or copies stored outside HBTA cannot be recalled this way.
Chat, direct messages and moderation
Communication functions are enabled only after separate acceptance of the current community rules and, while access is by invitation, approval by a moderator. For this purpose, HBTA stores a random public profile ID, your chosen pseudonym, access status, rules version and acceptance time. The current app offers no region selection for the chat profile. The public profile ID is separate from your internal account ID. The server is technically prepared for later authenticated profile-photo retrieval using this non-guessable reference; however, the current Android app does not enable this sharing for newly uploaded images. The email address and internal account ID are not returned.
Depending on the enabled function, messages in the general, regional, announcements, support or direct-message room are stored with the room, sender association and times. Email address, exact age, postcode, weight, gender, GPS location and private routes are not chat fields and are not returned in chat responses. Media, links and live locations are disabled in the current app version.
When you use community search, the app transmits the entered search text and selected filters over HTTPS to the HBTA server. From version 0.7.11, this may include the region you choose to enter; the region filter searches published region labels and does not automatically assign tours to official boundaries. If you expressly select the radius filter, the app additionally sends the coordinates of your chosen planning destination and the search radius to the HBTA server, not automatically your current GPS location. These details are processed there to identify the requested tours. HBTA does not create its own search-history profile from them; technically necessary connection logs may continue to include the API path, time, status, data volume, app identifier, IP address and a request ID.
Blocks store the internal relationship between two accounts without notifying the blocked user. Reports may include the affected tour, message or public profile ID, category, optional further explanation, processing status and, internally, the reporting account ID. Moderation decisions, time-limited restrictions and suspensions are recorded with the moderator, reason and time in an access-restricted audit log.
Voluntary app feedback
If you voluntarily send feedback from the profile, HBTA stores the selected category, your message text, the time and, internally, the association with your account. Only if you expressly include technical details are the app version and version code, Android version and device model additionally transmitted. Location, tour data, access credentials and other device information are not part of the feedback.
You decide separately whether a reply is permitted. Only in this case does a particularly restricted database function make your verified account email address available to the mail worker for that specific mail job; it is used as the reply address for the operator notification and is not copied into the feedback report. Without this permission, the mail worker receives no account email address for the feedback.
Voluntary support through PayPal
If you deliberately tap a support amount in the profile, Android opens the external PayPal.Me link in a browser or suitable app. No connection to PayPal is made before you tap it. The HBTA app and HBTA server receive no PayPal access credentials and do not request payment status. Processing takes place outside HBTA.
However, the operator's private PayPal account may display information provided by PayPal for the transaction, in particular the payer's name and email address, amount, currency, time, transaction identifier and status, and an optional payment message. This information is processed only to handle and associate the voluntary support, prevent misuse, and comply with any applicable statutory evidential and retention obligations. Depending on the operation, the legal bases are Article 6(1)(b), (c) or (f) GDPR. PayPal processes the payment as an independent controller; information about this and possible international data transfers is provided in PayPal's privacy statement.
Technical connection data
When the website and API are accessed, the server processes technically necessary information such as IP address, time, HTTP method, requested path, status code, volume of data transferred, browser or app identifier and a request ID. For the APK distributed directly through the HBTA website, this also includes checking current version information without association with an account when the app starts and at your manual request. Only when you confirm an offered update there does this variant download the installation file from the HBTA server. The variant distributed through Google Play does not use this HBTA update endpoint. Keys in share URLs are redacted from access logs. The data are used for operation, troubleshooting and protection against misuse.
Reports of problematic or allegedly illegal content
When a community tour is reported directly in the app, the affected tour, a predefined reason and, internally, the reporting account ID are stored for abuse prevention and duplicate checking; this tour-reporting function contains no free text. Reports about chat messages, users or community authors, by contrast, include a category and may include an optional further explanation. Authors or reported users receive no information identifying the reporting person. If you instead use the electronic reporting procedure in the legal notice, the operator processes the precise URL or location, your reasons and evidence, your good-faith declaration and, where required, your name and email address. The data are used to review the content, take necessary measures and communicate the decision to you where contact details are available.
Where a report contains information about another person, these data originate from the report by another user or reporting person, the identified content visible to the users involved and, where applicable, the subsequent human moderation review. In accordance with Article 14 GDPR, the affected person is generally informed no later than within one month, or at the time of an earlier communication with them or before an earlier disclosure. This does not apply where that person already has the information or a statutory exception or restriction applies, in particular under Article 14(5) GDPR. Information identifying the reporting person is not disclosed to the affected person.
3. Purposes and legal bases
Email address, display name, account data, planned private routes, a place/postcode search voluntarily requested by you, and the start, destination and intermediate points required for a route calculation requested by you are processed in order to provide registration, route planning, navigation and the account functions you select. The legal basis is Article 6(1)(b) GDPR. A route is handed over to Google Maps only after your own selection and separate confirmation if, instead of HBTA navigation, you expressly choose this external alternative. The separate consent and legal basis described below apply to GPS recording started by you and its optional synchronisation. Android location permission is an additional technical requirement for optional location display, HBTA navigation started by you or GPS recording, but is not in itself a legal basis under data-protection law.
Separate express GPS/tour-data consent is obtained in advance for local GPS recording, including track points and measurement times, the resulting tour analysis, and optional account-linked server storage of recorded GPS tours. It is not bundled with opening an account, agreeing to the terms of use or enabling fitness analysis. The additional automatic transmission is disabled by default and is enabled only through a separate switch on each device; the app stores the notice version and time of change there. For compatibility with older app versions, the server continues to store this consent under the technical name fitnessDataConsent, together with its version and time. Processing is based on Article 6(1)(a) GDPR and, where location and performance values constitute health data in the specific context, Article 9(2)(a) GDPR.
Local fitness analysis is expressly enabled through a further, independent switch. Only then are age and weight stored on the device and used for the approximate calorie model calculation. These details and results do not leave the device. The voluntary nature, limitation to purpose and ability to disable the function separately at any time apply regardless of whether you have enabled GPS/tour-data consent. Where these local details constitute health data and the General Data Protection Regulation applies to the operation, processing is based on your express consent under Article 6(1)(a) and Article 9(2)(a) GDPR.
You can withdraw GPS/tour-data consent in the app at any time with effect for the future. This immediately ends new GPS recordings and the synchronisation of recorded activities. Recorded tours stored on the server on the basis of this consent, including GPS track points and tour values, are removed; their associated share links, community publications and tour photos are consequently removed as well. If you choose to retain local recordings, their GPS data and existing local analyses remain until they are deleted locally. The separate fitness setting with age and weight is unaffected by this GPS withdrawal. Your account and planned routes and navigation remain usable. The lawfulness of processing up to the withdrawal remains unaffected.
You can also disable fitness analysis separately at any time. The locally stored age and weight, local age and weight snapshots, and estimated calorie values are then removed. A GPS recording in progress continues without calorie analysis; GPS routes, factual tour values, private server copies, shares and community publications remain.
If the purpose, scope of data or other material information relating to this consent changes, HBTA does not treat an older consent version as current agreement. GPS recording and synchronisation then remain blocked until you have reviewed and expressly accepted the new version. Existing data are not automatically published or deleted merely because a new version is provided.
Technical security and connection data are processed on the basis of the legitimate interest in secure and stable operation (Article 6(1)(f) GDPR).
Voluntary feedback is handled in order to respond to your request and to examine and improve errors, security and usability of HBTA. Depending on its content, this is done to perform the user relationship under Article 6(1)(b) GDPR or on the basis of the legitimate interest in support and product improvement under Article 6(1)(f) GDPR. Technical details and the use of your account email address as a reply address occur only following your respective express selection.
Deliberately created share links, community publications, selected community photos, the name display you choose, favourites, chat and community communications, and the profile photo you voluntarily upload, which is private in the current app version, are processed to perform the respective account, publication or communication function you request under Article 6(1)(b) GDPR. Storage and display of your own content technically required for a community publication are additionally governed by the non-exclusive licence described in the terms of use. Any future sharing of the profile photo with approved community and chat users would require a separate express selection; the current Android app does not yet provide this selection.
Access review, blocks, voluntary reports outside statutory notice procedures, abuse prevention, moderation and security logs are based on the legitimate interest in a safe, respectful and rules-compliant community under Article 6(1)(f) GDPR. Where processing is necessary to comply with statutory moderation, disclosure, evidential or reporting obligations, Article 6(1)(c) GDPR applies.
Where HBTA, as a hosting service provider, is subject to obligations under Articles 16 to 18 DSA, the operator processes the data required for notice procedures, decisions, statements of reasons and communication with authorities in order to comply with those statutory obligations, on the basis of Article 6(1)(c) GDPR in conjunction with Articles 16 to 18 DSA. For a report under Article 18 DSA, the Federal Criminal Police Office (Bundeskriminalamt) is the German central office under section 13 DDG and forwards the information to the competent law-enforcement authority.
4. Storage, recipients, email and external services
HBTA server data, including an optional processed profile photo, are stored on a server in Germany. To the extent required for operation, maintenance and security, the hosting and data-centre provider and technically appointed administrators may process data. Recipients of reports required by law may include the Federal Criminal Police Office as the central office under section 13 DDG and the respective competent law-enforcement or judicial authorities. The age and weight entered for fitness analysis, as well as age and weight snapshots and calorie values, are expressly not part of these server data in the current app version; they remain locally on your Android device.
System emails for account verification or recovery are sent through a technical HBTA sender that is not intended as a support contact. Feedback is sent through a separate internal outbox as a TLS-protected notification to the operator's support address. The subject and mail-worker logs contain no feedback text. Only where a reply is permitted does the message include your account email address, solely as its reply address. For delivery, the SMTP service used and participating mail servers process in particular the recipient address and, where applicable, reply address, technical delivery data and the content of the email. The current support contact is provided in the legal notice.
HBTA displays the map using the open-source MapLibre Native library and loads the map style and map data from the shared map endpoint maps.mhui.de provided by the operator. In doing so, the map server processes connection data technically necessary for delivery and the requested style, font, symbol and map-tile paths. The tiles retrieved reveal the approximate map region viewed in the app. HBTA does not transmit an email address, display name or raw GPS track to the map endpoint for this purpose; a location displayed on the device is drawn on the map locally. MapLibre contains no HBTA-specific analytics or advertising function. The map data originate from OpenStreetMap and are available under the Open Database License; the required attribution is displayed in the app.
For technical location provision during HBTA navigation or GPS recording started by you, HBTA uses Android's FusedLocationProviderClient; on compatible devices, Google Play services Location supplies the location measurement to HBTA. By contrast, location display alone on the MapLibre map uses the MapLibre location engine provided by the Android device. HBTA processes and transmits the respective measured points only as described in this notice and does not actively send a recorded track to Google. If Google Location Accuracy is enabled on your device, Google states in its information about Location Accuracy that it may process Wi-Fi access points, mobile network towers, GPS and sensor signals, IP address, device model, settings, usage metrics and a periodically changing identifier, among other data, to provide and improve location services and investigate errors. This device setting can be disabled independently of HBTA; GPS may remain available. Details are provided in the Google privacy policy.
Route calculation is performed for signed-in users only through the HBTA server. For planning requested by you, the app sends the current location as the starting point, the destination, optional intermediate points and the selected profile “Touring”, “Road”, “Gravel” or “MTB” in encrypted form to the HBTA routing endpoint. Within the isolated HBTA server environment, that endpoint passes the coordinates to BRouter. The routing endpoint does not store the request as a private tour; neither the request body nor the internally constructed routing address containing the coordinates is logged. Technically necessary connection logs may continue to include the API path, time, status, data volume, app identifier, IP address and request ID. The coordinates are processed in memory for the current calculation and then discarded.
The response containing the route line, distance, estimated duration, elevation profile, turn instructions, and data, profile and engine versions is stored for your account in private app storage. Route matching, display of speed and direction of travel, and selection of spoken instructions take place on the device during the ride. HBTA does not send a continuous location stream to the routing server. Only when the local analysis detects a significant deviation does the app retransmit the current location, the remaining points and the profile to the same HBTA routing endpoint for automatic recalculation. For voice instructions, HBTA selects only an already installed voice matching the selected German or English app language which, according to Android, requires no network connection and whose voice data are completely present on the device. Network voices are not used. If a suitable local voice is unavailable or local output fails, the map and visible turn instructions remain available; HBTA does not send the turn text to a cloud voice provider.
Google Maps remains exclusively an optional external alternative. If you expressly select it, HBTA displays its own confirmation before every handoff. Only then does HBTA open a universal Google Maps address and add the destination coordinate and no more than three intermediate coordinates to the complete HTTPS address. The app or browser selected by you in the Android chooser receives this address, including the coordinates; Google Maps processes them when it loads. HBTA does not set a navigation start (origin) in this handoff and does not read or transmit your device's current location for this purpose; Google Maps may determine a current start using its own location permission. For a recorded circular tour, the final coordinate passed as the destination may be at or near the recorded starting point. Google Maps calculates its own bicycle route outside HBTA, which does not necessarily follow a stored track line exactly. If there are more than three intermediate destinations, nothing is opened and none is silently omitted.
If you voluntarily search the route planner for a German place or postcode, the search text is transmitted in encrypted form to the HBTA server, evaluated there exclusively in memory against a locally installed GeoNames Germany index and then discarded. No third-party geocoding service is called at runtime; search text and results are not logged or stored permanently. The GeoNames data used are available under CC BY 4.0. You then set the street, house number and exact destination point yourself on the map. For a selected private route, HBTA continues to store only the selected map point or technical destination coordinates.
If you use the external Google Maps alternative or Google Play services Location supplies the location measurement on your device, Google may also process information outside the European Economic Area, particularly in the United States. According to Google's published information, transfers to certified Google LLC in the United States are based on the adequacy decision for the EU-US Data Privacy Framework; where no adequacy decision applies, Google states that it uses the European Commission's Standard Contractual Clauses. Details, the certification and a way to obtain the clauses are provided in Google's information about data transfers. The Google privacy policy and, for the external alternative, the Google Maps/Earth additional terms of service also apply.
The publicly accessible HBTA pages use no cookies, analytics or advertising trackers. Only after a successful sign-in to the protected moderation area does HBTA set the technically required first-party authentication cookie “__Host-hbta_admin”. It contains a random session value, is protected by Secure, HttpOnly and SameSite=Strict, is transmitted only over HTTPS, and is invalidated no later than 15 minutes after sign-in or on sign-out. It is used exclusively for administrator authentication and to protect the expressly requested moderation area. Access to the terminal equipment is based on section 25(2)(2) TDDDG; the associated processing of personal data is based on Article 6(1)(f) GDPR. No consent banner is required for this necessary cookie.
The Android app also stores information on your device or accesses it. Where strictly necessary for an app function expressly requested by you, this particularly concerns the account-separated local tour database for planned routes, the offline route package prepared by you, a technically necessary map cache and reliable app operation, the refresh token protected in Android Keystore, and the access token held in memory only. These operations necessary for the function are based on section 25(2)(2) TDDDG; whether an individual access is strictly necessary is assessed according to its specific purpose.
Optional GPS recording and synchronisation are enabled only after separate GPS/tour-data consent. The independent local fitness analysis is enabled only after its own activation and entry of age in full years and weight. Where information is stored in or read from the terminal equipment for the respective function and no exception under section 25(2) TDDDG applies, the respective prior consent also covers section 25(1) TDDDG. The processing of personal data is additionally governed by Article 6(1)(a) and, where applicable, Article 9(2)(a) GDPR as set out above. Both choices can be withdrawn separately; necessary account, route-planning and navigation functions remain separate from them.
For the verification and password pages described, no raw tokens are stored in the URL query, browser storage or analytics tools. The HBTA database, internal mail outbox, and application, proxy, mail-worker, backup and access logs do not store a raw token. The link sent necessarily contains the raw token, however, and is therefore processed by the participating mail servers and your mailbox.
5. Retention and deletion
- Account, profile and private tour data are stored until you delete them or the account is terminated, unless statutory obligations prevent deletion.
- A profile photo remains stored until it is replaced, you delete it individually, or the account is deleted. If a community status already exists, switching the photo back to “private” immediately ends the corresponding authenticated retrieval but does not delete the image until your separate deletion action.
- For safe retries and protection against simultaneous conflicting changes, technical records of profile-photo actions are stored for no more than 30 days. They contain no image content, but only a random operation identifier, operation type and technical state characteristics, a cryptographic request checksum, earlier technical image details, visibility, version identifier and time. When the account is deleted, these account-linked records are also deleted immediately.
- After GPS/tour-data consent is withdrawn, new activity synchronisation stops and server storage of recorded GPS tours, track points, distance, duration and elevation gain is removed. Retained local recordings remain until deleted locally; the app offers their additional confirmed deletion during the withdrawal flow. The separate local fitness profile remains unchanged. Planned routes are unaffected.
- After fitness analysis is disabled separately, the local age and weight, associated snapshots and estimated calorie values are removed. GPS recordings, factual tour data and private server copies are not deleted as a result.
- The navigation package downloaded for your account remains in private app storage excluded from backup and device transfer until you discard it in the app, it is replaced by a newly calculated route, or you delete the app data or uninstall the app. Technically cached map data are removed by the app or when its data are deleted.
- One-time authentication tokens expire after their intended short validity period or when used; server-side hashes are subsequently cleaned up.
- Public route shares can be revoked and expire after no more than 30 days.
- Community publications and their photos remain stored until you withdraw them, the underlying route or your account is deleted, or a necessary moderation measure takes place. Withdrawn drafts and photos remain editable by you until you delete the route or account. Editorially curated OSM routes are separate from this and remain stored until an administrative rollback or source update.
- Favourites are deleted when the favourite, community tour or account is removed. Community reports are stored only as long as necessary for duplicate checking, abuse prevention, moderation and required evidence.
- Ordinary chat messages are removed after 90 days by a regularly running automated cleanup process. Messages deleted by a user disappear from display immediately. Copies in encrypted backups are removed according to the backup cycle described below; cleanup of a temporarily unavailable offsite copy is caught up at the next successful synchronisation.
- Blocks remain until unblocked or an involved account is deleted. Completed moderation records are generally stored for no more than six months after the case is closed; they are retained longer only where there is a specific statutory evidential or legal-enforcement need.
- When an account is deleted, the user's own chat messages and direct account links in chat and moderation data are removed from the active production system. Content and contextual extracts already secured for a report or moderation case may remain without a direct account reference for the stated periods. Such detached information is not necessarily anonymous if a person can still be identified from its content or context.
- Technical logs are retained only as long as necessary for secure operation, troubleshooting and abuse prevention.
- Reports of allegedly illegal content and associated communications are retained only as long as necessary for review, decision-making, statutory evidence, and the establishment, exercise or defence of claims.
- App feedback and the associated internal mail outbox are deleted after 180 days by a regularly running automated cleanup process; if the account is deleted earlier, the feedback report and any pending mail job are also deleted. Any subsequent email reply correspondence is retained only as long as necessary for support, evidence or claims.
- Information relating to voluntary PayPal support remains in the PayPal account under PayPal's settings and periods and is retained by the operator only as long as necessary for processing, abuse prevention and any applicable statutory evidential and retention obligations.
- Encrypted backups are kept separately from active data. The server and the separate copy outside the server (offsite) each retain the newest 30 complete app recovery sets and the newest 7 mail backup sets. An app recovery set contains the database and the configuration needed for recovery. Scheduled daily backups and additional backups before releases count towards these limits. Backup generations are not calendar days; this does not establish a fixed 30-day deletion deadline.
- If the backup PC is switched off or unavailable, transfer and cleanup of its offsite copy are caught up at the next successful synchronisation. Failed safety or recovery checks stop cleanup and require operational follow-up. Until the sets leave the retention cycle and all copies are successfully cleaned up, backups may still contain data already deleted from the active system.
- As long as no independently stored and verified deletion journal is available, an older backup is not put into service as a new production system. In the event of a complete server loss, the service instead starts with an empty database and renewed registration so that previously deleted accounts and tours do not reappear from an older backup.
6. Your rights
Where the statutory requirements are met, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. You can also lodge a complaint with a competent data-protection supervisory authority.
Objection to processing based on legitimate interests
Where HBTA bases the processing of personal data on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. The processing concerned then ends unless the operator demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Data portability
The right to data portability covers personal data provided by you that are processed by automated means on the basis of your consent or a contract. You can receive them in a structured, commonly used and machine-readable format and, where technically feasible and the rights of others are not adversely affected, request their direct transmission to another controller.
Deletion of your account and private data can be requested using the account function provided for that purpose. For further privacy requests, please use the contact methods stated in the legal notice.
For the operator in Hesse, the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 3163, 65021 Wiesbaden, is one of the competent authorities. You may also contact another supervisory authority competent under Article 77 GDPR.
7. Required information and automated decisions
An email address, display name, password, confirmation of the minimum age, acknowledgement of the displayed privacy notice and agreement to the terms of use are required for an account. Without these details, no HBTA account can be created or provided. A chat profile, GPS/tour-data consent, fitness analysis, feedback, technical feedback details, permission to reply and support through PayPal are voluntary. Age in full years and weight become required only if you enable the optional fitness analysis; without these details, only that analysis remains disabled. Location permission is required only for functions that actually need your location: optional location display, HBTA navigation started by you, or GPS recording. HBTA does not request location permission merely to view the map, for the external Google Maps handoff, or for chat.
HBTA does not make decisions based solely on automated processing that produce legal or similarly significant effects and does not carry out profiling within the meaning of Article 22 GDPR.
8. Security and changes
Transmission between the app, website and HBTA server is encrypted using HTTPS. Access rights, limited validity periods, and authentication and share tokens stored exclusively as hashes limit access. The Android app holds the short-lived access token only in memory and protects the refresh token using Android Keystore. Authentication data and the private local tour database are excluded from Android backup and device transfer. Their local protection additionally relies on Android app isolation and device security.
Server backups are encrypted using age before permanent storage and are protected against unnoticed changes by checksums. The private decryption key is not stored on the server. This must be distinguished from active production data on the server: no additional full application-level encryption is claimed for those data; technically necessary access by the hosting provider remains possible to the extent described in section 4.
This notice is updated when functions or data flows change materially. Where a change requires new consent, consent is not assumed silently but is expressly requested again before the affected processing.