Privacy Policy
Last updated: September 2026
CityWalker is a tool to help you track your walking progress and street coverage. This page explains what data the app uses, what leaves your phone, and who receives it, on both Android and iOS.
1. Location
CityWalker is designed with a privacy first approach. Your walk history stays on your phone.
- During walks: The app uses your device's GPS (Fine/Precise Location) to record your walks and calculate which streets you have covered.
- Background tracking: To keep recording your walk accurately when the app is in the background or your screen is off, the app uses a foreground service with a persistent notification on Android, and background location updates on iOS.
- Outside walks: The app also reads your current location when you add a city, to show which city or street you are in on the Walk and Stats screens, to highlight "you are here" in the region picker, and when you tap "centre on me" on a map. It never tracks you in the background outside a walk.
2. What Stays on Your Phone
Your walk history, GPS tracks, covered streets, and city progress are stored locally in a private database on your phone. They are never uploaded to CityWalker. The only exceptions are the optional View on Computer feature (Android only, encrypted, described below) and your phone's own backup and transfer features (see section 6).
3. What Leaves Your Phone, and Who Receives It
Every service below receives your IP address as a normal part of connecting to it.
- Cloudflare Workers (CityWalker proxy): Requests for a city's street data go through a Cloudflare-hosted proxy that caches OpenStreetMap data. A request usually names a city or region. When a city is too large to download whole and you are inside it, the app instead requests a small area (about 3 km across) around your current location, and the proxy keeps that area as part of its cache. If a city is too large to download at all, its name is sent so it can be prepared for download later. Cloudflare may log your IP address and the request for security and abuse prevention.
- Overpass API (overpass-api.de and mirrors): Public OpenStreetMap servers used when the proxy is unavailable. They receive the same request as the proxy, including the small area around your location in the case described above.
- Nominatim (OpenStreetMap): Turns city names into map boundaries and coordinates into place names. It receives the city name you search for, together with an approximate search area around your location. On Android, it also receives coordinates when the app needs the name of a place, and the centre point of an imported GPX track, to work out which city it belongs to.
- Your phone's geocoder (Google on most Android phones, Apple on iPhone): Receives your current location to look up the name of the city or street you are in (on the Walk and Stats screens, and when detecting your city). On iPhone, it also receives the centre point of an imported GPX track. Google's or Apple's own privacy policy applies.
- Your phone's location services (Google Play Services on Android, Core Location on iOS): Provide your device's location to the app. The platform provider's own privacy policy applies.
- Map tiles (OpenFreeMap via MapLibre on Android, iOS and the View on Computer page; Apple Maps for route previews and the nearby streets map on iPhone): Display the base map. The tile server receives your IP address and the map area being shown. Your walk history is not transmitted.
- Firebase Anonymous Authentication (Google): Each time the app starts, it signs in to Firebase anonymously and uses the resulting identifier to authenticate requests to the CityWalker proxy, for rate limiting and abuse prevention. This happens regardless of the privacy settings below. The identifier is not linked to your name, email, or any other personal information, is not shared with advertisers or data brokers, and is never used for tracking. On iPhone, it may survive deleting and reinstalling the app.
- Firebase Crashlytics (Google, optional, on by default): Crash reports include stack traces, device model, operating system version, app version, and a Firebase installation identifier. No GPS coordinates or walk history are included. You saw a disclosure during onboarding and can turn this off at any time in Settings › Privacy.
-
Aptabase (optional, on by default): I use
Aptabase,
an open-source, cookie-free analytics provider, to understand how the
app is used. Events describe app usage, for example: app opens, walk
starts and completions (duration and distance), suggested and saved
routes (distances), milestones reached, cities added, downloads,
permission prompts, and screens viewed. With each event, Aptabase
also receives the app version, device model, operating system,
language, and a random session identifier.
The app never sends your location, the routes you walk, or the streets you have covered to Aptabase. Events do not include the names of the cities you add. Aptabase works out an approximate country and region from your IP address when an event arrives.
You can turn usage stats off at any time in Settings › Privacy.
- View on Computer relay (Android only, optional, off unless you use it): If you use the View on Computer feature from the Coverage tab, the app builds a snapshot of that city's street coverage (including street coordinates and walk stats), encrypts it on your device with AES-256-GCM, and uploads only the encrypted file to a Cloudflare-hosted relay. The relay never receives the decryption key and cannot read the contents. The encrypted snapshot is deleted after a short expiry or once viewed on your other device. This only happens if you actively start this feature; it never runs in the background.
- Street reports (optional): If you report that a street is not walkable, the app sends the street's OpenStreetMap IDs, the point you tapped on the map, and any reason you type to the CityWalker proxy, where I review it. Reports are anonymous: they are not linked to you or your device. The reported location (without your reason) is shown on the map to other users while the report is pending and after it is approved.
- Share from Google Maps (Android, optional): When you share a place from Google Maps into CityWalker, the app opens the shared link to find the place (Google receives this request), then looks the place up with Photon (by komoot) or Nominatim.
- GitHub: The app downloads the list of pre-prepared city regions from GitHub. No personal data is sent beyond your IP address.
- Google Play (Android): Used to check for app updates and to show the in-app review prompt. Firebase Authentication also uses Google Play Integrity and reCAPTCHA to protect against abuse.
4. Permissions
- Fine/Precise and Coarse Location: Required to record walks, to show which city or street you are in, and to detect which area of a multi-region city you are currently in.
- Background Location: Allows walk recording to continue when the app is in the background or the screen is off. On Android, this is implemented as a Foreground Service with a persistent notification while tracking is active.
- Foreground Service - Data Sync (Android): Used to download a city's street data in the background when you start a walk before the city has finished loading.
- Notifications: Used to display tracking and download notifications, and walk reminders.
- Internet and Network State: Required to download map tiles and street data, and to check whether you are online.
- Run at Startup (Android): Restores scheduled walk reminders after your phone restarts.
- Wake Lock (Android): Keeps the CPU active during walk recording so GPS samples are not dropped.
- Vibrate / Haptics: Used for short haptic feedback (for example, confirming a walk has started or finished).
- Photo Library (Save Only, iOS): Used only to save a walk summary card image to your photos when you tap Save. The app does not read your existing photos.
- Camera (Android): Used only to scan the QR code shown on the View on Computer web page, to pair your phone with that browser session. The camera is active only while that scanner screen is open. No photos or video are captured, stored, or transmitted.
5. Importing Walks (GPX)
You can optionally import walks from GPX files (for example, exported from Strava, Garmin, or Komoot). When you import a GPX file:
- The file is read directly from your device's storage using the platform's standard file picker.
- Matching the route against city streets happens entirely on your device.
- The file itself and the route are never uploaded. Only the centre point of the track is sent to Nominatim (Android) or Apple's geocoder (iPhone) to work out which city it belongs to, and the app may download that city's street data as described above.
6. Backups and Switching Phones
- Android: Your walk history is not included in Google Drive backups; only app settings are. When you copy data directly from your old phone to a new one during setup, your walk history moves with it.
- iPhone: Your walk history is included in your iPhone's iCloud or computer backup, like other app data, so it comes back when you restore or set up a new iPhone. These backups are stored in your own Apple account; I cannot access them.
7. Children's Privacy
CityWalker is rated for all ages and does not require an account. The app never asks for your name, email, or other contact details, from any user, including children.
8. How to Delete Your Data
Your walks and progress are stored only on your phone. To delete them:
- Open CityWalker
- Go to Settings
- Scroll to the About section
- Tap Delete All Data
- Confirm deletion
This permanently removes all cities, street data, walk history, GPS tracks, coverage progress, and app preferences from your phone.
Delete All Data does not affect the data held by the services in section 3: anonymous usage events (Aptabase), crash reports (Crashlytics), and the anonymous Firebase identifier. None of these are tied to your name or email, so I cannot look them up by person. Crash reports are deleted automatically after 90 days.
9. Changes to This Policy
I may update this Privacy Policy from time to time. You are advised to review this page periodically for any changes.
10. Contact
If you have any questions about this Privacy Policy, contact me at citywalker.dev@outlook.com.
