Untraced
Privacy Policy
Version 1.2 — Last updated: 30 August 2026
This Privacy Policy explains how personal data is processed when you use the mobile application Untraced ("the App") and the website untraced.app ("the Website"). It is written to meet the requirements of the EU General Data Protection Regulation (GDPR / DSGVO) and the German Digital Services Act (DDG) and Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
The controller responsible for data processing within the meaning of Art. 4(7) GDPR is:
Batuhan Kabaktepe
Hamburger Straße 5
22941 Bargteheide
Germany
Email: batuhan.kabaktepe23@hotmail.com
Untraced is operated by a sole trader (Einzelunternehmen), not a corporation. You can contact me directly at the email address above regarding any question about this policy or your rights.
Data Protection Officer: I am not required to appoint a Data Protection Officer under Art. 37 GDPR / § 38 BDSG, and have not appointed one. Please direct all data protection enquiries to the contact details above.
2. The Core Principle: Your Drives Stay on Your Device
This is the most important thing to understand about Untraced:
Untraced has no user accounts, no login, and no server of its own. Your drives, routes, GPS coordinates, unlocked road segments, map, statistics, badges and chapters are stored exclusively in the local database on your iPhone. This data is never transmitted to me, and I have no access to it whatsoever.
I cannot see where you have driven. I cannot retrieve your map. I could not hand your routes over to anyone even if I were asked to, because they never leave your device.
Two limited things do leave your device, and neither contains coordinates, routes or location information:
- Anonymous onboarding statistics (Section 4.5) — which onboarding steps were reached and which answers were chosen, with no identifier of any kind attached.
- Usage and crash analytics (Section 4.4) — but only if you explicitly agree when asked during onboarding. If you decline, nothing is collected, and you can change your mind at any time in Settings.
3. Categories of Data Processed on Your Device Only
The following data is processed locally on your device and is not transmitted to me or to any third party by the App:
3.1 Location data
With your permission, the App records your position (latitude, longitude, timestamp, speed, accuracy) while a drive is being recorded, in order to draw your route and unlock road segments on your personal map. If you grant "Always" permission, recording can also start and stop automatically in the background while you are driving.
3.2 Motion and activity data
With your permission, the App uses the motion coprocessor of your device (Core Motion) to detect automatically when a drive begins and ends. This is used solely to start and stop recording so you do not have to. Motion data is evaluated on the device and is not stored beyond that purpose.
3.3 Derived trip data
From the above, the App calculates and stores locally: distance travelled, duration, average and maximum speed, the road segments ("traces") you have unlocked, experience points, levels, badges, streaks, chapters, and the cities and countries you have visited.
3.4 App settings and technical flags
The following is stored locally in the App's settings storage on your device and is never transmitted:
- Your preferences: auto-detection on/off, notifications on/off, accent colour, map style, and whether onboarding has been completed.
- Your privacy decision: whether you agreed to share anonymous usage and crash data (Section 4.4), together with the date of that decision and the version of this policy it was given against. This is stored so that your choice is respected on every launch, and so that I can demonstrate it if required (Art. 7(1) GDPR).
- Counting flags for the anonymous statistics described in Section 4.5: markers recording that a given onboarding step has already been counted once. These contain no identifier and cannot be used to recognise you; their only purpose is to prevent the same installation from being counted twice.
Legal basis: To the extent that processing on your device involves personal data at all, it takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR, which you give by granting the respective iOS system permission (location, motion, notifications), and on the basis of performance of a contract pursuant to Art. 6(1)(b) GDPR, as recording your drives is the core function of the App you have chosen to use. Access to and storage of information on your terminal equipment is based on your consent pursuant to § 25(1) TDDDG, or is strictly necessary to provide the service you expressly requested pursuant to § 25(2) No. 2 TDDDG.
You can withdraw your consent at any time with effect for the future by revoking the relevant permission in the iOS Settings app, or by disabling auto-detection in the App's own settings.
4. Data Transmitted to Third Parties
4.1 Apple — Map display (MapKit)
The App displays maps using Apple's MapKit framework. When map tiles are loaded, technical data (including your IP address and the map section requested) is transmitted to Apple. This is technically unavoidable when displaying a map.
- Recipient: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA, and Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract — the map is the central feature of the App).
- Apple's privacy policy: https://www.apple.com/legal/privacy/
4.2 Apple — Reverse geocoding
To name the cities and countries in your collection, the App sends individual coordinates to Apple's geocoding service to translate them into a place name. Apple states that this data is not associated with your Apple Account for this purpose.
- Recipient: Apple (as above).
- Legal basis: Art. 6(1)(b) GDPR.
4.3 Apple — Purchases and subscriptions (StoreKit)
If you purchase Untraced Pro, the entire payment transaction is handled by Apple through the App Store. I never receive your payment data, card details, address or name. I only receive anonymous, aggregated sales reports from Apple, from which individual customers cannot be identified. The App queries Apple locally to determine whether a valid Pro entitlement exists.
- Recipient: Apple (as above).
- Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract concluded with Apple).
4.4 Google — Firebase Analytics and Crashlytics (only with your consent)
The App can use Firebase Analytics and Firebase Crashlytics, services provided by Google, to understand how the App is used in aggregate and to detect crashes.
This only happens if you have expressly agreed to it. Both services start switched off. During onboarding you are asked once whether you want to share anonymous usage and crash data, with "Share anonymous data" and "No thanks" presented as equally available choices. Nothing is collected by these services before you agree, and nothing is collected at all if you decline.
What is transmitted:
- Event names and technical parameters, e.g.
onboarding_completed,trip_recorded(with the distance in km and the number of newly unlocked segments as a number),paywall_viewed,level_up,share_card_created. - Your answers to the optional onboarding questions ("What excites you most?", "How did you hear about Untraced?").
- Automatically collected technical data: a randomly generated app instance identifier, device model, operating system version, language and region settings, app version, and an approximate, coarse location derived from the IP address at country/region level.
- In the event of a crash: the crash stack trace, the device state at the time of the crash, and the app version.
What is expressly NOT transmitted: your GPS coordinates, your routes, your recorded drives, your personal map, or any information that would allow me or Google to reconstruct where you have driven.
- Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
- Legal basis: Your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG.
- Third-country transfer: Data may be processed in the USA. Google LLC is certified under the EU–U.S. Data Privacy Framework, so transfers take place on the basis of the European Commission's adequacy decision pursuant to Art. 45 GDPR. In addition, Google's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR apply.
- Processing agreement: A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google in the form of the Google Firebase Data Processing and Security Terms.
- Google's privacy policy: https://policies.google.com/privacy
- Firebase data handling: https://firebase.google.com/support/privacy
Withdrawing consent: You may withdraw your consent at any time with effect for the future, in the App under Settings → Privacy → "Share anonymous usage data". Withdrawal is as simple as giving consent (Art. 7(3) GDPR). When you withdraw, collection stops immediately and the identifier held by Firebase Analytics on your device is deleted.
Retention: Firebase Analytics event data is retained for a maximum of 14 months and is then deleted automatically. Crash reports are retained for a maximum of 90 days.
4.5 Google — Firestore (anonymous onboarding statistics)
Separately from Section 4.4, and regardless of whether you agreed to analytics or declined, the App transmits strictly anonymous statistics about the onboarding process to Google Cloud Firestore: which onboarding steps were reached, which answers were selected, whether location permission was granted, plus country, language and app version.
This runs without asking for consent, and the reason is the crucial difference from Section 4.4: nothing here identifies you or your device, so there is nothing to consent to.
This data contains no identifier of any kind — no user account, no device identifier, no advertising identifier, no installation identifier. Each record receives a random identifier that is never stored on your device and is never linked to anything. It is therefore not possible for me, or for anyone else, to trace this data back to you, to your device, or to your other records, or to recognise you again.
Because this data is anonymous within the meaning of Recital 26 GDPR and no information capable of identifying you is read from or written to your device for this purpose, it is not personal data and is processed without consent. It contains no coordinates, no routes, no free text and no drive data.
- Recipient: Google Ireland Limited / Google LLC (as above). Data is stored in the Firestore region configured for the project.
- Legal basis: Not applicable, as no personal data is processed. Insofar as one were nevertheless to be assumed, processing would be based on my legitimate interest in understanding and improving the onboarding process, Art. 6(1)(f) GDPR.
4.6 Apple — Push notifications
If you enable notifications, the App schedules local notifications on your device (for example, when a drive has been saved, or before a weekly streak expires). These are generated on the device. No push server is used and no notification content is transmitted to me.
- Legal basis: Your consent pursuant to Art. 6(1)(a) GDPR, given via the iOS notification permission dialog. You can withdraw it at any time in the App's settings or in the iOS Settings app.
4.7 Sharing content yourself
If you actively share a drive or your map as an image, the image is generated on your device and passed to the iOS share sheet. Where the data then goes is determined solely by you, by choosing the target app (Messages, Instagram, email, etc.). I am not involved in this transmission and have no knowledge of it. The privacy policy of the app you choose applies from that point onward.
5. The Website (untraced.app)
The Website is a purely informational page with no user accounts and no contact forms.
When you visit the Website, the hosting provider automatically processes server log data (IP address, date and time of the request, browser type and version, operating system, referrer URL, and the amount of data transferred) for the purpose of delivering the site and maintaining its technical security and stability.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient operation of the Website).
- Retention: Server logs are deleted after a maximum of 7 days, unless retention is required to investigate a specific security incident.
The Website does not use tracking cookies or analytics. If this changes, this policy will be updated and, where required, consent will be obtained beforehand.
6. Retention Periods
| Data | Retention |
|---|---|
| Drives, routes, map, statistics, settings (on your device) | Until you delete the App or delete the data yourself. I have no influence over this and no access to it. |
| Firebase Analytics event data (only with consent) | Maximum 14 months, then automatically deleted |
| Crashlytics crash reports (only with consent) | Maximum 90 days |
| Anonymous onboarding statistics (Firestore) | Stored indefinitely as anonymous aggregates; contains no personal data and cannot be attributed to you |
| Your consent decision (on your device) | Until you change it or delete the App |
| Website server logs | Maximum 7 days |
| Correspondence with me by email | For as long as needed to handle your enquiry, plus statutory retention periods where these apply (up to 6 or 10 years under §§ 257 HGB, 147 AO for commercially or fiscally relevant correspondence) |
Deleting all your data: Because your drives are stored exclusively on your device, deleting the App from your iPhone permanently and irreversibly deletes all your drives, your map and your progress. There is no backup on my side, and I cannot restore this data for you.
7. Your Rights
You have the following rights in relation to your personal data. Exercising them is free of charge.
- Right of access (Art. 15 GDPR) — to obtain confirmation as to whether personal data concerning you is being processed, and a copy of that data.
- Right to rectification (Art. 16 GDPR) — to have inaccurate data corrected.
- Right to erasure (Art. 17 GDPR) — to have your data deleted.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR) — to receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR) — to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR.
- Right to withdraw consent (Art. 7(3) GDPR) — to withdraw any consent you have given at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
- Right to lodge a complaint (Art. 77 GDPR) — with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
Please note in practice: For the data stored locally on your device, I cannot provide access, rectification, portability or erasure, because I have no access to it. You have full and direct control over this data yourself at all times through the iOS Settings app and by deleting the App. For data processed by Firebase Analytics, please contact me and I will forward your request to Google or handle it accordingly.
To exercise your rights, contact: batuhan.kabaktepe23@hotmail.com
Competent supervisory authority for the controller:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98
24103 Kiel
Germany
https://www.datenschutzzentrum.de
8. Children
Untraced is not directed at children and is not intended for use by persons under the age of 16. I do not knowingly process personal data of children under 16. If you are a parent or guardian and believe that a child has provided personal data through the App, please contact me and I will delete any such data I hold without undue delay.
9. Automated Decision-Making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Levels, badges and statistics in the App are calculated locally on your device and have no legal effect on you or similarly significant impact.
10. Data Security
Your drives are stored in the App's private container on your device, protected by iOS's own sandboxing and, if you have enabled a device passcode, by the device encryption iOS provides. Data transmitted to Apple and Google is transmitted using encrypted connections (TLS).
Please be aware that no method of electronic transmission or storage is completely secure, and that the security of the data on your device also depends on you keeping your device and its operating system secure and up to date.
11. No Obligation to Provide Data
You are under no legal or contractual obligation to provide any personal data. Granting location and motion permissions is voluntary. However, without location permission the App cannot record drives, which is its central function.
12. Changes to This Privacy Policy
I may update this Privacy Policy to reflect changes to the App or to legal requirements. The current version is always available at https://untraced.app/privacy and within the App under Settings → Legal. In the event of material changes, I will inform you appropriately within the App. The version and date at the top of this document indicate the current status.
13. Contact
For any question, request or complaint regarding data protection:
Batuhan Kabaktepe
Hamburger Straße 5
22941 Bargteheide
Germany
batuhan.kabaktepe23@hotmail.com