// Privacy

Privacy Policy

Last updated: 28 June 2026

Vodach ("the App", "we") is a mobile and web app for mountain hiking. This policy explains what personal data we process and your rights under the EU General Data Protection Regulation (GDPR).

1. Who we are (Controller)

Vodach is built by two people — Vasilen Polimenov and Georgi Stoyanov. We are also the joint controllers of your personal data within the meaning of Art. 26 GDPR. For anything related to your data, write to [email protected].

2. What data we collect and why

2.1 Account data

Email, password (stored only as a bcrypt hash — never in clear text), name/display name, and optionally a profile photo, age, text location and free-text preferences. With Google Sign-In: email, name and profile photo from your Google profile. Used to create and run your account and to authenticate you. Legal basis: performance of a contract (Art. 6(1)(b)).

2.2 GPS & location data

Real-time location during an active hike (high accuracy), the recorded route, point GPS samples (accuracy, altitude, speed, heading, battery), start/current/end points, optional home coordinates, and the location of trail condition reports. Used for tracking and recording hikes, navigation, showing nearby trails, live sharing (only if you enable public mode), and crowdsourcing trail conditions. Legal basis: contract for tracking; explicit consent for background tracking and live public sharing. You can hide your start/end point and define privacy zones that mask your coordinates when sharing.

2.3 Photos

Photos you upload to places, trails, reports, reviews and your own recorded hikes, plus an optional profile photo (avatar). Stored on our own server (not third-party cloud storage). We strip EXIF metadata (including GPS coordinates and device model) before storing. Legal basis: consent / contract for the published photos; legitimate interest (community safety, Art. 6(1)(f)) for the automated check below.

Automated safety check:before a photo is stored, a downscaled copy is sent to OpenAI's moderation service to classify it for harmful/illegal content (nudity/sexual content, violence, child sexual abuse material, etc.); a photo flagged as harmful is rejected and not stored. Per OpenAI's public terms, data sent through its API is not used to train its models, and the moderation endpoint is operated with no content retention. This is a transfer to a third country (USA) covered by OpenAI's Data Processing Addendum incorporating the EU Standard Contractual Clauses — see section 4.

2.4 Activity (fitness) data

Step count and distance from Apple Health (HealthKit) / Android Health Connect, live step counts from your device's motion sensor (Apple's pedometer / Android's step counter, with your motion & fitness / physical activity permission), and barometer/altimeter data for elevation. Used for daily activity on the map, live progress during the "Virtual Hike" feature and accurate ascent. Motion-sensor step counts are read on the device only while a virtual hike is running; only the resulting step total of that session is stored with the hike. Legal basis: consent (Art. 6(1)(a)). These are ordinary activity figures, not medical data, and are never used for advertising. You can withdraw access any time in your device settings.

Imported workouts (smartwatch/band): if you enable health access, the app can also find finished workouts recorded by your watch or band in Apple Health / Health Connect — activity type, start/end time, duration, distance, GPS route where the source app shared one, and the name of the app that recorded it. Nothing is uploaded automatically: a workout is stored on our server as an activity in your history only after you confirm it in the review list (or if you explicitly turn on auto-import in Settings). Heart rate is never read. Imported activities are visible only to you unless you share them, can be deleted individually at any time (deleting removes them from our server), and are removed with account deletion. You can turn workout scanning off entirely in Settings → Personalization, and revoke the underlying permission in your device settings. Legal basis: consent (Art. 6(1)(a)); never used for advertising and never shared with third parties.

2.5 Device & push data

IP address, device type/name/model, OS and app version, push token (APNs for iOS / FCM for Android). Used to deliver notifications, for security and troubleshooting. Legal basis: legitimate interest (security/diagnostics); consent for push notifications.

2.6 Activity & gamification

Hike statistics, report and voting activity, reputation/trust points, badges, streaks and sign-in times. Legal basis: contract / legitimate interest.

3. Who we share data with (processors)

We do not sell your data. We share it only as needed to run the service, with: Google (Sign-In — email, name, photo), Apple APNs & Google FCM (push notifications — push token), OpenAI's moderation service (automated content safety screening — a downscaled copy of uploaded photos and the text of reports/reviews), map providers (OpenStreetMap / MapLibre / Protomaps — IP address on tile requests), and our hosting provider DigitalOcean LLC (server in Germany — EU; company headquartered in the USA; all data on the server).

4. International transfers

OpenAI, which provides our automated content moderation, processes data outside the EU/EEA (in the USA). When a downscaled copy of an uploaded photo (and the text of a report/review) is sent to OpenAI for safety screening, that personal data is transferred to a third country (USA), safeguarded by the European Commission's Standard Contractual Clauses (SCCs), incorporated via OpenAI's Data Processing Addendum.

5. Retention

  • Recorded hikes and their GPS track: kept until you delete the hike or your account.
  • Transient location data (abandoned/unsaved tracking, live-share points): automatically deleted after 24 hours.
  • Sign-in sessions: up to 30 days.
  • Account, reports, photos: until you delete your account.
  • On account deletion we erase or anonymise the related personal data promptly.

6. Cookies & local storage

The web app uses only functional cookies/local storage needed to run the service — no third-party advertising or tracking cookies: a sign-in session cookie (NextAuth) and a NEXT_LOCALE language cookie. The mobile app keeps data locally on your device (secure token storage; a local database for offline maps/trails/report drafts). We do not use Google Analytics, ad networks or cross-site tracking.

7. Automated decisions & moderation

To keep the community safe, user content (reports, reviews, and all uploaded photos) goes through automated screening (safety and relevance moderation, partly AI-assisted). Photos are screened for harmful content at upload; content flagged as problematic may be automatically rejected or hidden and sent for human review. This processing has no legal effect on you under Art. 22 GDPR, and you can always contest a decision by contacting us. Leaderboards, reputation points and trust levels are computed automatically from your activity but likewise have no legal or similarly significant effect.

8. Your rights (GDPR)

You have the right to access, rectification, erasure ("right to be forgotten"), restriction, portability and objection, and to withdraw consent at any time (including for location and activity data, via your device settings). To exercise these, email [email protected].

Account deletion: you can delete your account and personal data directly in the app — mobile: Settings → Account → Delete account; web: Settings → Personal → Delete account. Deletion is immediate and irreversible; your community content (trail reports and reviews) is kept but anonymised. Full instructions: /delete-account.

You have the right to complain to the supervisory authority — the Bulgarian Commission for Personal Data Protection (CPDP), Sofia, cpdp.bg.

9. Security

Passwords are stored as bcrypt hashes and access tokens as hashes (never in clear text). Traffic is over HTTPS (with HSTS). We strip EXIF metadata from uploaded photos, apply rate limiting against abuse and standard security headers, and transient location data (abandoned/unsaved tracking) is deleted after 24 hours. Server access is restricted. We apply reasonable technical and organisational measures, but no system is perfectly secure.

10. Children

The App is not intended for anyone under 16. We do not knowingly collect data from children under that age without parental consent.

11. Changes

We may update this policy. We will announce material changes in the app. Last updated: 28 June 2026.

12. Contact

Privacy questions: [email protected].