What Trasely does — and does not do — with your information.
This Privacy Policy explains how information is handled when you use the Trasely app for iPhone and iPad and the website at trasely.app (together, the “Service”).
The Service is operated by Renat Tlebaldiev (“Trasely”, “we”, “us”). For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the processing described below.
This summary is for convenience only; the sections below are the binding text.
We have not appointed a Data Protection Officer, and we are not required to, because we do not carry out large-scale monitoring or large-scale processing of special-category data. Privacy questions go to the email address above.
Trasely is designed so that as little data as possible leaves your device. This section describes every case in which data is processed, together with our legal basis under Article 6 GDPR.
When you grant location access, iOS provides your device’s location to the app so that it can centre the map, place a shape near you, and start a route from where you are. Location is used only while you are using the app: Trasely does not request or use background location, does not record your movement, and does not track activities.
Your location is processed on your device. Coordinates leave your device only as part of a routing request, described in section 2.5. You can revoke location access at any time in iOS Settings → Privacy & Security → Location Services; Trasely stays usable, and you can place shapes manually on the map instead.
Legal basis: performance of a contract (Art. 6(1)(b)) and, where iOS requires a permission prompt, your consent (Art. 6(1)(a)).
If you use Photo to Route, iOS gives Trasely access to the individual image you select. That image is analysed entirely on your device using Apple’s Vision framework in order to extract the subject’s outline. The photo is never uploaded, never copied to a server, and never shared with us or with any third party. Only the resulting outline — a list of numbers, with no image content — is used in the next step. The same applies to shapes you draw by hand.
Legal basis: performance of a contract (Art. 6(1)(b)) and your consent to the photo permission (Art. 6(1)(a)).
Routes you generate or save, together with their settings, are stored locally on your device using Apple’s SwiftData. If you have iCloud Backup switched on, this data may be included in your encrypted device backup, which is controlled by Apple under Apple’s own privacy policy — we have no access to it. Deleting the app removes the local database from your device.
Legal basis: performance of a contract (Art. 6(1)(b)).
All purchases are processed by Apple through the App Store. We never receive or store your payment card details, billing address, or Apple Account credentials.
To work out whether your device is entitled to PRO features, we use RevenueCat. RevenueCat receives a randomly generated app user identifier, your App Store transaction and receipt data, and technical information such as country, device model and app version. That identifier is not linked to your name or email address, and we do not use it to contact you.
Legal basis: performance of a contract (Art. 6(1)(b)); retention of transaction records where required by law (Art. 6(1)(c)).
To turn a shape into a route that follows real streets, the app sends route coordinates and routing parameters to openrouteservice for point-to-point and loop routing. For GPS art, the app can request OpenStreetMap-derived road-network data from openrouteservice Export or an OpenStreetMap Overpass endpoint, then traces the shape on-device.
These requests contain coordinates and routing parameters only. They contain no name, no email address, no account identifier, no advertising identifier and no image data. They are processed in real time to answer your request. We do not receive the results on any server of ours, and we do not keep a copy.
Maps are displayed using Apple MapKit. Requests for map tiles are made by iOS to Apple, and Apple’s privacy policy applies to them.
Legal basis: performance of a contract (Art. 6(1)(b)).
The app obtains its routing credentials from an endpoint we operate on Cloudflare Workers. That endpoint uses Apple’s App Attest to confirm that a request comes from a genuine, unmodified installation of Trasely before it will issue anything, so that our routing quota cannot be drained by third parties.
Two things are involved:
Because a new key is generated on a fresh install, the record is retained for as long as your installation exists and is not tied to any expiry. Deleting and reinstalling the app leaves the old record orphaned and unusable.
We do not use any of this to identify you, we do not combine it with other data, and we do not build profiles from it.
Legal basis: our legitimate interest in securing the Service and preventing abuse (Art. 6(1)(f)). You may object to this processing, although we cannot supply routing without it.
If you email us, we receive your email address and whatever you choose to include in your message. We use it only to answer you and to keep a record of the issue.
Legal basis: our legitimate interest in providing user support (Art. 6(1)(f)).
Trasely contains no advertising SDK, no attribution or measurement SDK, and no third-party analytics SDK. We do not access the Advertising Identifier (IDFA), we do not present the App Tracking Transparency prompt, and we do not track you across apps or websites owned by other companies.
If you have opted in through iOS Settings → Privacy & Security → Analytics & Improvements → Share with App Developers, Apple may make aggregated crash and performance reports available to us. Those reports come from Apple, are not linked to you, and are controlled entirely by that iOS setting.
If we ever add analytics or crash reporting to the app, we will update this policy and the App Store privacy information before that version ships.
trasely.app is a set of static pages. It sets no cookies, runs no analytics, embeds no third-party fonts, trackers, pixels or social widgets, and has no contact form or login. Because there are no non-essential cookies or similar technologies, no cookie banner is required.
Your browser’s standard request data — IP address, user agent and the page requested — is processed by our hosting provider for the sole purpose of delivering the page and protecting the site against attacks, and is held in short-lived server logs.
Legal basis: our legitimate interest in operating and securing the website (Art. 6(1)(f)).
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not disclose it to data brokers. Information reaches the following recipients, each acting as our processor or as an independent controller for its own service:
Trasely has no account connection to Strava, Garmin, Komoot or any other fitness platform. Exporting a route means saving a GPX or TCX file on your device and choosing where to send it yourself; nothing is transmitted to those platforms by the app, and they receive whatever you upload under their own terms.
We may also disclose information where we are legally required to do so — for example to comply with a court order, a subpoena or a lawful request from a public authority — or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the safety of users or the public. If Trasely is ever transferred to another owner, this policy will continue to apply to information transferred with it until it is replaced, and you will be notified beforehand.
Some of the recipients listed above are established in the United States. Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on:
You may request details of the safeguards applied to a specific transfer by writing to trasely.app@gmail.com.
If you are in the European Economic Area or the United Kingdom, you have the right to request access to your personal data, its rectification or erasure, restriction of processing, and portability of data you have provided to us. You also have the right to object to processing carried out on the basis of legitimate interests, and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Because Trasely has no accounts and holds almost nothing about you centrally, the fastest way to exercise most of these rights is directly on your device: revoke the location or photo permission in iOS Settings, delete routes inside the app, or delete the app entirely. For everything else, write to trasely.app@gmail.com. We answer within one month, and will tell you if we need longer.
One limit is worth stating plainly: the App Attest key record described in section 2.6 contains no information that would let us connect it to you, so we cannot find, export or delete a specific person’s record on request. Article 11 GDPR covers exactly this situation. Deleting the app makes the record permanently unusable.
We may need to ask you for information that lets us locate the relevant records — for example the App Store transaction identifier for a purchase enquiry. We will not use that information for any other purpose.
You also have the right to lodge a complaint with the data protection supervisory authority in the country where you live, where you work, or where you believe an infringement occurred. We would appreciate the chance to address your concern first.
This section applies to California residents. In the preceding twelve months we have collected the following categories of personal information:
These come from you and from your device. We use them to provide and secure the Service, to deliver features you have purchased, and to answer support requests, and we disclose them for those business purposes to the service providers listed in section 4.
We have not sold or shared personal information in the preceding twelve months, and we do not sell or share the personal information of consumers we know to be under 16. We do not use personal information for cross-context behavioural advertising.
Precise geolocation is “sensitive personal information” under the CPRA. We use it only to perform the service you have requested and never to infer characteristics about you, which means the statutory right to limit its use does not apply — but you may still contact us with any concern about it.
You have the right to know, access, delete and correct personal information, the right to opt out of sale or sharing, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising any of these rights. Submit a request to trasely.app@gmail.com. An authorised agent may submit a request on your behalf with written proof of authorisation.
If you are a resident of a state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others — you have broadly equivalent rights of access, correction, deletion, portability and opt-out, together with the right to appeal a refused request. Use the same contact address; if we decline a request we will explain why and how to appeal.
Trasely is a general-audience app. It is not directed to children, and we do not knowingly collect personal information from children under 13, or under the applicable digital-consent age (which may be up to 16) in the European Economic Area and the United Kingdom. Where local law requires it, a parent or guardian must consent on the child’s behalf before the app is used.
If you believe a child has provided personal information to us, contact trasely.app@gmail.com and we will delete it promptly.
Data held on your device is protected by iOS file-level encryption and your device passcode. Access tokens, where present, are stored in the iOS Keychain. All network requests use TLS. Our routing credentials endpoint verifies app integrity through Apple App Attest and issues short-lived credentials rather than long-lived secrets, so no long-lived provider key is ever present in the app binary.
Our main safeguard is structural: because there is no account system and no Trasely-operated database of user content, there is very little for an attacker to obtain. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a breach affecting personal data occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly and without undue delay, describing the nature of the breach, its likely consequences and the measures taken.
We may update this Privacy Policy. The version number and effective date at the top of this page always reflect the current text. Where a change is material, we will give notice in the app or on this page at least 14 days before it takes effect, unless a shorter period is required by law, and we will seek your consent where consent is the applicable legal basis.
Previous versions are archived and available on request from trasely.app@gmail.com.
Questions, requests or complaints about privacy: trasely.app@gmail.com, or by post to Renat Tlebaldiev.
See also our Terms & Conditions.