GoneCycling

Privacy Policy

Privacy Policy for GoneCycling

Last updated: 12 June 2026

This privacy policy explains which personal data the iPhone app GoneCycling processes when you use it, what we use that data for, and which rights you have.

1. Data Controller

Responsible for the data processing related to the app is:

Mario Gaida

Dornbuschweg 17

33649 Bielefeld, Germany

Email: mario.j.gaida@gmail.com

2. Overview

GoneCycling does not process any personal data on our servers – there is no provider backend, no account and no sign‑in. All recorded rides, planned routes and settings live on your device by default. Optionally you can manually back up individual rides to your own iCloud Drive (see section 7.1); even then no data is transmitted to us.

The sections below describe which data we process locally and in which cases data is transmitted to third parties such as routing providers.

3. Location data

### 3.1 What we process

When you start a recording or a route plan, the app accesses the precise location of your device. Position fixes are delivered by iOS at regular intervals and processed in‑app.

### 3.2 Purpose

  • Showing your current position on the map
  • Recording rides (distance, duration, speed, elevation profile)
  • Computing routes from your current location to a destination
  • Live navigation along a planned route

### 3.3 Where the data goes

  • Recorded rides are stored only as a JSON file in the app's sandbox (Documents/rides.json). They are not transmitted to us or to third parties.
  • Routing requests include start and destination coordinates and are sent — depending on your settings — to the routing provider you chose (see section 6).
  • Reverse geocoding (turning coordinates into "City, Region") is performed via Apple's iOS‑integrated geocoding service after a ride ends.

### 3.4 Legal basis

Article 6(1)(b) GDPR (contract — the app's core function cannot be delivered without location) and Article 6(1)(a) GDPR (consent given through the iOS permission dialog).

4. Contacts access (optional)

When you use the "Pick from Contacts" feature, iOS asks once for permission to access your contacts. We then process only the postal address of the contact you actively pick. That address is converted to coordinates via Apple's geocoding service and used as a route destination. There is no reading, storing or transmitting of your whole address book.

Legal basis: Article 6(1)(a) GDPR (consent).

5. Background location access (optional)

If you grant the "Always" location permission, recordings can continue while the screen is locked or while you switch to other apps. We recommend this option only for longer rides where active screen interaction isn't possible.

Legal basis: Article 6(1)(a) GDPR (consent given through the iOS permission dialog).

6. Third‑party services (routing, maps, search)

Which data is sent where depends on your settings.

### 6.1 Routing providers

For route computation you can choose between several providers:

  • Apple MapKit (default): Route computation uses Apple's MapKit interface. Start, intermediate and destination coordinates are transmitted to Apple. See Apple's Privacy Policy.
  • OpenRouteService (HeiGIT / Heidelberg University, or self‑hosted): If you select this provider and enter an API key, the route coordinates are sent to the HeiGIT endpoint at api.heigit.org (or the URL you configured). See the HeiGIT privacy statement.
  • BRouter (public or self‑hosted endpoint): If you select this provider, the route coordinates are sent to the BRouter endpoint you configured. The operator's privacy terms apply.
  • OSRM (Open Source Routing Machine, optional): If you configure this provider, the coordinates are sent to the OSRM endpoint you set. The operator's privacy terms apply.

In all cases only the coordinates for the routing request are transmitted. No identifiers, device IDs, user accounts or tracking data are sent.

### 6.2 Map display (map tiles)

By default the app shows Apple Maps. Optionally you can select alternative, OpenStreetMap‑based map styles in the settings (e.g. CyclOSM, OpenTopoMap, OpenStreetMap.de). In that case the app loads the displayed map tiles directly from the respective providers' servers. For technical reasons this transmits your IP address and the map area you are currently viewing to the tile provider. The respective provider's privacy terms apply. With the default Apple map, tiles are served by Apple.

### 6.3 Location search and address resolution

When you search for a destination (text search or the configurable quick destinations such as "Café", "Supermarket") or auto‑plan a stage, the search query and the viewed map region are sent to Apple's MapKit search service. When you finish a ride and to name stages, coordinates are resolved into place names via Apple's geocoding service (reverse geocoding). See Apple's Privacy Policy.

If you enable live POIs while riding, then during a recording or active route guidance a search query for each enabled category — together with your approximate position — is additionally sent to Apple's MapKit search service at regular intervals (at most about every 45 seconds, and only after some distance travelled) to surface nearby places. This feature is off by default.

7. Locally stored data

The following data is stored exclusively on your device and removed completely when you uninstall the app:

  • Recorded and imported rides (GPX, JSON), including optional notes and ratings
  • App settings (language, routing provider, API key, voice guidance, POI categories, position icon)
  • Recently used destinations and template rides
  • A small statistics summary (kilometres ridden) for the home‑screen widget, stored in an on‑device storage area shared between the app and the widget (App Group) — this data does not leave your device

None of this data leaves your device without your explicit action (e.g. by exporting a GPX file or via the optional iCloud backup described in section 7.1).

### 7.1 Optional backup to iCloud Drive

In the rides list you can manually back up individual rides to your own iCloud Drive via the cloud button. The ride is then stored as a JSON file in the "GoneCycling" app folder of your iCloud Drive and synced by Apple across the devices signed in with the same Apple ID. This feature is off by default and only triggers when you tap it for a given ride.

  • The data resides solely in your iCloud account with Apple; Apple's Privacy Policy applies. The provider of this app has no access to it.
  • You can remove a backed‑up ride at any time – tap the cloud button again, or delete the file in the Files app.

Legal basis: Article 6(1)(a) GDPR (consent).

8. Apple Watch and health data (HealthKit)

If you use GoneCycling's Apple Watch companion to record rides directly on the watch, the following additional data is processed:

  • Watch location: The watch records the route via its own GPS (as described in section 3). The position data is processed on the watch and stored as a ride.
  • Health data via HealthKit: Recording runs as a workout. For this the watch asks once for permission to read heart rate, active energy and distance, and to write a workout to the Health app. Heart rate and energy are only shown live on the watch and stored together with the workout in your Health app (Apple); they contribute to your Activity rings.
  • Transfer to the iPhone: When you finish the ride, the recorded route (coordinates, distance, time) is transferred straight to your paired iPhone via Apple WatchConnectivity and stored there like any other ride. This transfer happens device‑locally between your watch and your iPhone; no data is sent to us or third parties. Heart‑rate and energy data never leave the Health app and are not added to the iPhone app's ride archive.

The health data resides solely in your Health database with Apple; Apple's Privacy Policy applies. The provider of this app has no access to it. You can revoke the health and location permissions at any time via the watch's system settings or the Health app.

Legal basis: Article 6(1)(a) GDPR (consent via the health and location permission dialogs).

9. Tracking, analytics, advertising

The app contains:

  • No tracking across apps or websites
  • No analytics frameworks (no Firebase, no Google Analytics, no Crashlytics or similar)
  • No advertising
  • No third‑party SDKs that link to identity

10. Retention

Rides and settings remain on the device until you delete them via the app or uninstall the app. There is no automated deletion.

11. Your rights

Under GDPR you have the right to

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21)
  • Withdrawal of consent at any time (e.g. revoking the location permission via iOS Settings)

Because personal data is processed only on your device, you can exercise these rights by operating the app itself (deleting rides, resetting the app) or via iOS Settings.

For any questions reach us at mario.j.gaida@gmail.com.

12. Right to lodge a complaint

You have the right to lodge a complaint with a data protection authority if you consider that the processing of your data infringes GDPR.

13. Changes to this policy

We may adapt this privacy policy if the app's features or legal requirements change. The current version is available from the App Store listing and at https://gaida.de/en/projects/gonecycling/privacy/.