Privacy Policy
The short version: your coordinates are processed in your browser and never stored on our servers; helper lookups are proxied so third parties never see you; history and saved places live only on your device; analytics are our own, cookieless and anonymous — no identifiers, no IP address stored, Do Not Track honored.
What we process, and where
- Your position: read by your browser's Geolocation API with your permission, rendered on your screen. Not transmitted to us, not stored by us.
- Helper lookups (address, weather, what3words): your coordinates are sent to our own server, which queries the upstream service and returns the answer. Upstreams see our server, not you. Our proxies truncate any logged coordinates to 3 decimals (~110 m).
- IP lookups: to answer “what is my IP location”, our server consults IP databases with the IP your connection presents. Nothing is retained.
- History & saved places: stored exclusively in your browser's local storage. We cannot read them. Clearing site data deletes them.
- Analytics: first-party and cookieless — each pageview sends our own server the page path, the referring site's domain and your browser language, nothing else. No cookies, no identifiers, no fingerprinting, no coordinates; your IP address is never stored — visitors are counted with a hash that rotates daily, so even we cannot follow a device from one day to the next. Do Not Track and Global Privacy Control switch it off entirely. Blocking it changes nothing about how the tools work.
- Developer API signups: name, email, and a hash of your key are stored (SQLite on our server) to operate the service — the one place we keep personal data, used solely for abuse control and breaking-change notices.
What we never do
- We never sell your data, and we never share your location, your saved places or your search history with anyone.
- No cross-site tracking and no fingerprinting.
- No cookies beyond the strictly-functional ones described above, plus any advertising cookies you consent to — see Advertising below for exactly what that means today.
Questions or deletion requests (API signups): contact us. GDPR/CCPA: local-only data is under your control by design; for API signup data, email us for access or erasure.
Hiker's guide feedback
The hiking destinations guide has an optional suggestion form. If you use it, we store exactly what the form contains: your note, its category and destination, and optional remarks — in a separate small database used only for reviewing guide feedback. Two things are opt-in and off by default: an approximate location (stored only if you press the attach button, rounded to ~110 m like everything else here) and an email or mobile number (used only to reply to your note, never published, never shared). We do not record your IP address, user agent, or anything you didn't type. Contact details can be deleted on request via the contact page, and we routinely purge them once a conversation is closed.
Advertising
Advertising is a runtime setting on this site, and it is currently switched off: no ad script is emitted on these pages and no advertising cookies are set. The only external resource your browser fetches is OpenStreetMap map tiles, and only when you view a map.
If advertising is enabled to help keep the tools free, this section changes with it: it is generated from the site's live configuration rather than written by hand, so what you read here always matches what actually runs.