Privacy policy
Last updated: 17.09.2026
1. Controller
The controller for data processing on this website and in the TripPhoto app is:
Michael Grewelding
Michael-Erhard-Straße 66
77855 Achern-Oberachern, Germany
michael@grewelding.com ·
+49 (0)7841 6655-919
2. Principle
TripPhoto uses no advertising or analytics tools. There is no tracking, no reach measurement and no sharing with advertising networks. Fonts, map and icons are served from our own server; only a few additional features load a program library from a content delivery network (see section 5). That is also why no consent banner is required: apart from the technically necessary session and your display settings, nothing is stored that would need consent.
3. What data is processed
- Account: Email address, display name, hashed password, chosen language and units, plan, and your entitlements (Pro) with their origin and term. Optionally: profile picture, two-factor secret, passkeys, postal address.
- Photos and their metadata: The image file itself plus data read from EXIF: capture time, time zone, GPS coordinates, altitude, camera, lens, exposure values. If the image lacks time or place – for example photos you take in the app – we take the capture time from the device and the place from the device or from your running recording of that trip.
- Location and movement data: If you start recording in the app: coordinates, time, accuracy, speed, altitude and heading – including while the app runs in the background. This forms a movement profile of your trip. Recording only ever starts on your instruction and can be stopped at any time.
- Device sensor data: During a recording, additionally and only if your device provides them: the movement type detected by the operating system (stationary, walking, cycling, in a vehicle), air pressure and barometric altitude, steps and floors. They improve transport detection and the elevation profile. The operating system asks separately for permission; without it recording still works, just less precisely.
- Stays: During a recording, iOS reports places where you stayed for a while. They remain on the device at first and are suggested to you as waypoints after the trip. They are only stored once you accept them.
- Your own input: Trip titles, descriptions, notes, waypoints, ratings, comments, equipment, and optionally a home location.
- Imported files: Positions, times, altitudes and names are taken from uploaded GPX, KML, GeoJSON or CSV files. The file itself is not stored permanently.
- Day texts and title suggestions (Apple Intelligence): On iPhones with Apple Intelligence the app can write day texts and suggest trip titles. The language model runs on the iPhone itself; for this the app loads the facts of your trip (distance, places, number of photos) from our server. Neither we nor any AI service receive the trip for writing. We store the written texts with the trip so they also appear on the website; you can edit or delete them.
- Corrections to automatic detection: When you change a detected mode of transport, move a photo or change a capture time, we store WHAT was changed (e.g. “bike → car”) with speed, duration, length and the iPhone’s motion type – but without location and without time of day. We evaluate this in aggregate to improve detection. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). It is deleted with your account and included in your data export.
- Health data (sport mode, Apple Watch): If you switch on sport mode on the Apple Watch, the watch measures your heart rate and saves the workout to Apple Health. TripPhoto NEITHER stores NOR transmits these values: they only leave your watch towards Apple Health and reach neither the iPhone nor our server. We therefore do not process health data within the meaning of Art. 9 GDPR. Sport mode is a separate button; if you never press it, you are never asked about Health.
- Reports and blocks: If you report a comment or a trip we store: who reported, what was reported, the chosen reason, the time and a copy of the reported text. The copy is needed because the content may be deleted before anyone reviews the report. If you block someone we store only the pair of identifiers and the time – the blocked person is not told. The legal basis is our legitimate interest in a service free of harassment. If you delete your account, your blocks and the reports you filed go with it.
- Following: If you follow someone we store the pair of identifiers and the time. When that person makes a trip public you get a notice once on the website and – if you allowed push notifications – on your iPhone. Only public trips are announced, never private ones or trips shared by link. The person you follow only sees how many people follow them – not who. The legal basis is the performance of the user agreement: you chose to follow. You can stop at any time in your profile; if either of you blocks the other it ends automatically, and it is removed when you delete your account.
- Last sign-in: On every sign-in (website or app) we store the time, the channel and an approximate location (city and country). The location is derived from the IP address on our own server using the "IP to City Lite" database by DB-IP; the IP address is not sent to anyone and is not stored. There is no history – each sign-in replaces the previous one. You can see it yourself under Settings ▸ Sign-in & security; the operator sees it in user administration. The purpose is to detect sign-ins by someone else: if you sign in from a different country than last time, you receive an email (at most one a day). It is deleted together with the account.
- Notifications to the operator: The operator receives an email when someone registers (email address, name, sign-up channel), when a trip is created or made public (title, number of photos) and when content is reported. For a deleted account only figures, without the email address. The purpose is operating and moderating the platform.
- Server logs: On each request the host logs IP address, time, requested address, browser and amount of data transferred. This serves operation and defence against attacks.
- Protection against attack scanners: If someone requests addresses that do not exist here and are only probed by automated attack tools (such as /wp-admin/ or /xmlrpc.php), we store a keyed hash of the IP address (not the address itself) with the time. After three such requests within ten minutes, that IP address is refused for 24 hours. The entry is deleted 24 hours after the last request. Signed-in users and the app are exempt.
- Error log: Occasionally – for example during a disruption or when you report a problem – we log which page or app feature was called, when, with what result and how long it took, plus actions (e.g. "photos uploaded: 5") and errors that occurred. We store your user number and a shortened session identifier; no IP address, no content, no locations and no search terms. The log stays on our server, only the operator can see it, and it is deleted after 14 days. You can object under Settings ▸ Your data; you will then never be logged.
4. Purposes and legal bases
- Account, trips, photos, recordings and every analysis derived from them: to perform the user agreement, Art. 6(1)(b) GDPR.
- Server logs, error log, last sign-in, protection against misuse and attack scanners, technical stability: legitimate interest, Art. 6(1)(f) GDPR. You can object to the error log at any time.
- Publishing a trip, push notifications, signing in via Google, Apple or Facebook: your consent, Art. 6(1)(a) GDPR – revocable at any time.
5. Services contacted during operation
To make maps, places, routes and weather work, TripPhoto calls external services. Only the necessary information is transmitted – for server-side requests just coordinates, not your IP address. Where your browser loads directly, this is noted explicitly.
- OpenStreetMap Foundation (United Kingdom) — Map tiles (your browser loads them directly, transmitting your IP address), place lookup via Nominatim and Overpass (server-side, coordinates only).
- LocationIQ (Canada/EU data centre) — Place lookup, server-side, coordinates only. Since 17 September 2026 the first service we ask, because Nominatim permanently throttles our shared server address; if it does not answer, we ask Nominatim.
- OSRM (router.project-osrm.org) and FOSSGIS e.V. (routing.openstreetmap.de, Germany) — Road and cycling route calculation, server-side, coordinates only.
- Overpass-API (overpass-api.de, overpass.openstreetmap.fr, overpass.kumi.systems) — Railway lines and places from OpenStreetMap data, server-side, coordinates or map areas only.
- Open-Meteo (Germany) — Weather at capture time, server-side, coordinates and time only.
- Wikimedia — Background information about places, server-side.
- jsDelivr, Cloudflare (CDN) — Program libraries for a few additional features: 3D terrain, converting HEIC photos on upload, the QR code when setting up two-factor sign-in, and sorting planner stops. Your browser only loads them when you use the feature, transmitting your IP address.
- Amazon Web Services (USA) — Openly available elevation data (Terrain Tiles) for 3D terrain; your browser loads them directly, but only when you open the 3D view, transmitting your IP address.
- flagcdn.com — Small country flags in lists and the atlas; your browser loads them directly, transmitting your IP address.
- Apple (USA) — Push notifications to iPhones (APNs) and, if chosen, “Sign in with Apple”. In the app, also operating-system features that only work between your own devices: Handoff passes the address of the trip currently open to a Mac or iPad on the same Apple ID; iPhone search (Spotlight) receives the title and photo count of your trips and keeps them on the device. This search index is deleted when you sign out.
- Google (USA) — Only if chosen: sign in with Google. Fonts are NOT loaded from Google but from our own server.
- Meta/Facebook (USA) — Only if chosen: sign in with Facebook.
- YouTube (USA) — Only if you add a video to a trip. Embedded in privacy-enhanced mode (youtube-nocookie.com).
6. Processing on our behalf and transfers to third countries
The website runs at Strato AG, Pascalstraße 10, 10587 Berlin, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Strato; the servers are located in Germany.
Apple, Google, Meta and Amazon are based in the USA, as is Cloudflare. A transfer to Apple, Google or Meta only takes place if you enable push notifications or sign in via one of these providers; Amazon and the content delivery networks only receive your IP address when you use one of the additional features named above. These companies are certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023).
7. Visibility of your content
Trips are private to begin with. You decide per trip: private, reachable via link only, or public. A trip that is “reachable via link only” can only be opened through that link – including for signed-in users. Only public trips appear in the Discover overview and in search engines. A photo spot only appears there once at least three different people have taken public photos at that place. Individual photos can additionally be marked private, or have their GPS or EXIF data hidden. Private photos are only visible to the trip's owner – people you share a trip with do not see them either. Photos with hidden GPS data are not used for photo spots. Wherever others view a trip, private photos and private waypoints are missing, and photos with hidden GPS data have no coordinates. Images from private trips and private photos are kept outside the public web folder; their addresses are signed and expire after two days at the latest. If you set a trip to “private”, image addresses from it that were passed on earlier stop working.
8. Cookies and local storage
Technically necessary and always active are the session cookie that keeps you signed in (it contains no personal content and expires on sign-out or when the browser closes) and the “tp_einwilligung” cookie, which stores your choice in the cookie notice for 12 months (legal basis § 25(2) no. 2 TDDDG). Only with your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR) does the website remember display settings such as light/dark, sorting or the ticks of the trip checklist in your browser’s local storage – they never leave your device – and load embedded YouTube videos directly. Without consent videos show a placeholder and you can load each one individually. We set no advertising, analytics or tracking cookies. You can change or withdraw your consent at any time via “Cookie settings” in the footer; anything already stored is deleted. The app stores settings and not-yet-uploaded track points locally on your device.
9. Retention
Your content is stored as long as your account exists. If you delete a trip, a photo or an import, the associated data is removed. If you delete your account, the account, trips, photos, recordings, uploaded files, invitations you sent and reports about your content are deleted completely and immediately – this cannot be undone. We send you one last email as confirmation. The error log is deleted after 14 days. The host's server logs are deleted according to its own periods. Caches for places, weather and routes expire automatically.
10. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). You may withdraw consent at any time with effect for the future.
You can download your data yourself – as an archive with all trips, photos and GPX files or as JSON – and delete your account with all content yourself: both in the website settings under “Your data”, deletion also in the app profile. For anything else, an email to michael@grewelding.com.
11. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for me is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
12. No automated decision-making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. Analyses such as milestones, statistics or the photo score are solely for your own view and have no legal effect.