Privacy Policy

Curiosity Route Journal

Effective date: 2026-09-28

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Curiosity Route Journal stores routes, discovery photos, notes, categories, manually entered addresses, achievements, and preferences on your device. If you turn on online backup, the app sends an encrypted backup, its encryption nonce, a random installation identifier, and an installation secret to our server. The server stores the backup and a hash of the secret, not the secret itself. We cannot use the backup endpoint to read the contents of the encrypted archive. Requests to the public challenge catalog and privacy page also reach the hosting service, which may process technical connection information such as an IP address and request metadata. The app does not require an account or ask for an email address.

How we use information

Local information powers your routes, albums, challenges, and achievements while the app is offline. The server uses the installation identifier and secret to restrict backup access to that installation. It stores the encrypted archive so the app can retrieve it with the same secret and provides the public challenge catalog. Technical connection information is used by the hosting infrastructure to deliver and protect the service and diagnose failures. We do not use the app to run advertising, analytics, or email campaigns.

Service providers and sharing

Railway hosts this service and its PostgreSQL database and processes network requests and stored data as infrastructure for the app. The app may use Apple system services when you choose the camera, photo library, sharing, or local notifications; those services are controlled by your device settings and Apple's terms. We do not provide personal route or discovery data to other users. Exporting or sharing an album is your action and sends the selected content to the destination you choose.

Data retention

Routes, photos, and preferences remain on your device until you remove them or uninstall the app, subject to any device backups you control. A server backup remains until it is replaced or deleted through the app. The anonymous installation record and hashed secret remain so the same installation can access its backup; deleting a backup does not remove that credential record. Railway may retain operational logs or infrastructure backups under its own practices, and deletion from active storage may not immediately erase those copies. We do not promise a fixed retention period for those provider records.

Deleting your information

You can remove a discovery or your local app data in the app. The app's delete-server-backup action removes the active encrypted archive for your installation from the service. Because the app has no account recovery, losing the device's installation secret can make that server backup inaccessible. Deleting the app alone does not send a deletion request to the service. For help with an inaccessible backup or the remaining installation record, contact the privacy email below and provide the installation identifier if you still have it; we may be unable to locate an anonymous record without it.

Permissions and your choices

Camera access is used only when you take a discovery photo. Photo library access is used when you select an existing photo. Local notification permission, if enabled, is used for reminders about challenges on your device. You can deny or withdraw these permissions in iOS Settings and continue using available parts of the app. You can use routes and discoveries offline; online backup and catalog updates need a network connection. You choose when to export or share an album.

Your privacy rights

You can inspect, edit, and delete discoveries in the app, and export a route album as a PDF using its available controls. You can remove the active server backup from the app while you still hold its installation secret. For other privacy questions or requests, use the contact address below. Since there is no named account, include the installation identifier when available so we can identify the relevant server record. Applicable privacy rights depend on your location and circumstances.

Security

The app is designed to encrypt backup content before upload, and the server stores the supplied ciphertext and nonce without decrypting them. Backup requests require a random secret stored by the app in the device Keychain; the server stores a hash of that secret and checks it before serving or changing a backup. The deployed service uses HTTPS for data in transit and a hosted PostgreSQL database for persistent storage. No method of transmission or storage can be guaranteed completely secure. Keep your device and its backups protected because possession of the installation secret grants access to the corresponding server backup.

Children’s privacy

Curiosity Route Journal is intended for people aged 16 and older, including adults and older teens. It is not designed for young children, and it does not ask users to create accounts or provide birth dates. If you believe a young child's information has been sent to the service, contact us using the address below and include any available installation identifier.

Changes to this policy

We may update this policy when the app or its data practices change. The current version and effective date will be published on this page. Material changes to the app's handling of information will be reflected here when they take effect. You can revisit this page from the app's settings.