Privacy Policy

Effective: 27 August 2026 · revised 28 September 2026 Data controller: Maksim Efimov, a private individual in Portugal, developer of Unbeen Contact: hi@unbeen.app

1. In short

Unbeen records your walks and paints the streets you have walked onto the map.

Your walk routes, satellite points and notes are kept on your phone. They reach our server only inside an encrypted copy that your phone can open and we cannot.

Numbers about your walks and a technical log of how the app works, without coordinates, go to our server. They show us what breaks so we can fix it. One toggle switches this off.

The app has no sign-up, no email and no password. To the server you are a random number your phone created itself. There is no advertising, no advertising identifier and no third-party analytics.

Everything that leaves your phone, and where it goes, is listed below. The app has no other paths for sending data anywhere.

2. What stays on your phone only

This never leaves your phone in readable form:

The only exceptions are described below: the encrypted copy (§3.6), which we cannot read; a route you yourself draw for a group walk (§3.8); note photos and videos in your own iCloud (§3.12); reports and pictures you send yourself (§3.1).

3. What leaves your phone, and where it goes

3.1. The Apple map and what you send yourself

The app shows an Apple map (MapKit). Like any app with a map, it requests map imagery from Apple for the area you are looking at. Apple handles that under its own privacy policy.

What happensWhat is sentTo whom
You build a route to a point or draw a group walk routethe points of that routeApple (directions service)
You open a route in Google Mapsthe route points: start, finish, waypointsGoogle Maps on your phone, or their website
You share a picture of a walk or a citythat picturewhoever you choose
You email uswhatever is in the emailus, at hi@unbeen.app

Tester builds contain a technical walk report: a file with the real coordinates of that walk. It goes only to the recipient you pick yourself. The App Store build does not have this section.

3.2. City maps

For your line to land on the streets, the app needs a street map of the city: a file of usually a few megabytes, up to 20 MB for the largest cities. The files live in the project's public storage on GitHub (github.com/Efimother/unbeen-citypacks).

GitHub receives only the request for the file: the file name shows which city's map was needed, and, like any website, it sees the address of your connection. Coordinates, your walk history and your player number are not sent to it.

3.3. Our server and who you are to it

The unbeen.app server runs on Cloudflare. Data is stored in a Supabase database in Frankfurt (Germany).

Who you are to the server. On installation your phone creates a random player number and a secret key. The key is kept in your phone's keychain and, if iCloud Keychain is on, there too, so that a new phone with the same Apple ID gets it back. The server never receives the key itself. From it the phone derives a pass for requests (the server stores only its fingerprint) and a seal for the encrypted copy.

Your nickname is the name you entered in your profile or, if there is none, an automatic one such as Otter-03.

Introducing itself to the server. Once a day and whenever something changes, the phone reports: your player number and a random number for the phone within the app, the app version, the phone model, the iOS version, whether notifications are on, your nickname, the app language, the country from your phone's region settings, your time zone and the positions of the "My data" toggles. If statistics are off, once a day the phone reports only the numbers, the app version and the toggle positions, so that the server can ask you to update a version that is too old.

Request log. The server records which address was called, the response, the duration, the size and which Cloudflare location handled the request. Cloudflare sees the address of your connection and uses it to protect against overload; it is not written to our database.

3.4. Statistics and technical log

The "Statistics and technical log" toggle: Settings → Privacy → My data. It is on by default; the first time you open the app, a screen explains it. Switch it off and the queue of unsent items is wiped and nothing more is sent, apart from the introduction in §3.3.

While it is on, the following is sent:

As a safeguard, the server strips from the log any field that looks like coordinates, addresses, street names or text.

Messages to the developer. While the app has fewer than 300 players, the developer receives a short Telegram message when each walk starts and ends: nickname, the first characters of the player number, time, walking or cycling, distance, duration, number of points, how the recording ended, app version and any technical recording problems. The messages contain no coordinates and no place names. A copy of each message is kept in our database. These messages are sent only while statistics are on.

3.5. Anonymised walk map

The "Anonymised walk map" toggle in "My data" is off by default. Until you switch it on, nothing is sent.

If you switch it on, after a walk the following is sent: the grid squares, about 60 metres on a side, that the track touched; street segments by their numbers in the city map; the hour of the week; the city; and a category: level band (1–4, 5–9, 10–19, 20 and above), walking or cycling, time in the app (under a week, a month, a year, or longer) and country. The server only adds one to the weekly counter of each square or segment. Neither the player number nor the walk number is written into the map, and the request log does not record the player for this address either. Since the 28 September 2026 version the squares are sent with no player number at all: the app attaches a one-time token that the server issues when the app says hello and does not link to you. Older versions send the number and pass; the server checks them only to keep strangers out and stores them nowhere. We may show this street summary to partners.

3.6. Encrypted copy

The "Encrypted copy with us" toggle in "My data" is on by default.

What the copy contains. A copy of your phone's database: walks with routes, note text, progress. Note photos and videos are not included.

How it is protected. Before sending, the phone compresses the copy and encrypts it (AES-GCM) with a seal derived from your key. The server and the developer see only its size, date, checksum, version and number of walks; only a phone with your key can open it. If the key is lost (iCloud Keychain was off and the phone is gone), nobody can open the copy, including us.

When it is sent. Only over a network without data limits (Wi-Fi), at most once every 15 minutes, and only if there is at least one walk on the phone.

Where it is kept. In Cloudflare R2 storage, the 7 most recent copies; older ones are deleted. Each night the latest copy of each player is duplicated to Supabase storage in case of failure; a copy that is no longer in R2 is removed from that duplicate the same night.

Getting it back. After reinstalling, or on a new phone with the same Apple ID and iCloud Keychain on, the copy comes back by itself. By hand: "My data" → "Restore from our server".

Switching the toggle off stops new copies; copies already stored are deleted by "Delete everything on our side".

3.7. Leaderboard and profile photo

The leaderboard is on by default and is switched off with a single toggle: Settings → Privacy → "Take part in the leaderboard".

While it is on, your row is stored on the server and visible to all players: nickname · profile photo, if you set one (a small picture) · photo frame · level · experience · number of streets explored · kilometres and number of walks in total, on foot and by bike · average walk length · day streak (a number, not dates) · how many text notes, photos and videos you have (counts only) · kilometres and walks for the current and previous week · time of the last update.

Never published: coordinates, routes, your live position, street and city names, the dates of your walks, the content of your notes.

Switch participation off and the row and photo are deleted from the server. If someone reports a nickname or photo (§3.11), the developer can hide that player's nickname, photo and "Capture" territory from everyone.

3.8. Friends, group walks, challenges and gifts

All of this is stored on our server and visible only to the people involved.

When the organiser deletes a group walk, it is deleted for everyone; removing a friend ends the friendship for both people.

3.9. Notifications about other people's actions

Notifications such as "someone added you as a friend" or "you are invited for a walk" are delivered by our server through Apple's notification service.

What the notification service keeps (Cloudflare): your phone's notification address, issued by Apple; your player number; your secret notification address; the notification language; your time zone (between 22:00 and 08:00 notifications arrive silently); the time of the last update. Also: who you allowed to write to you and who you blocked, your friend code, one-time invite links (valid until used or for 30 days) and friend requests (valid for 30 days). The hourly notification counter disappears after two hours, the "already delivered" mark after six hours.

A copy in our database for the developer: friendships, requests, codes, a fingerprint of the address (not the address itself) and a log of notifications sent: kind, from whom, to whom, whether delivered and whether opened. Notification texts are not stored.

Who can send you a notification. Only someone you yourself gave your invite link or friend code to and who is your friend. A number from the leaderboard is not enough.

Turning notifications off erases your phone's address. The rest of the record stays, so that friends do not lose you when you turn them back on; "Delete everything on our side" erases it in full. When Apple reports that the app has been removed from the phone, the phone's address is erased automatically. In countries where Cloudflare is blocked, notifications do not work.

3.10. The "Capture" game mode

If you play "Capture", the areas of completed captures, the parts of the city you have enclosed, are stored on the server and visible to all players, with the capture time to the minute, your nickname and colour. Your live position and the route itself are not published.

Plainly: from an area, other players can see which part of the city you were walking in and roughly when. The mode's introduction warns you about this. "Leave the game" deletes your territory from the server.

3.11. Feedback and reports

"Report a problem" and "Suggest an idea" send to our database your text, a contact for our reply if you give one, the app version, the iOS version, the phone model, the language and your player number, so that we can reply and look at the technical log.

Reporting a nickname or photo ("Report") records who reported whom, where (leaderboard, "Capture", friends) and when. The developer immediately receives a Telegram message with the first characters of the reported player's number, and may hide that player from everyone.

3.12. What remains of Apple's cloud

Until 13 September 2026 the leaderboard, friends, group walks and the backup lived in Apple's cloud (CloudKit). Now:

3.13. Who processes data on our behalf

Each of them is bound by its data processing terms to protect the data and may not use it for its own purposes.

4. Permissions the app asks for

PermissionWhat for
Locationto record your walk route and paint the streets you have walked
Location "Always"optional: to start recording from a widget or on its own without opening the app, and to keep recording with the screen off
Motion & Fitnessoptional: to tell walking apart from riding, so recording can start on its own
Notificationsoptional: reminders and news from friends
Cameraoptional: photo and video notes on the map
Add to Photosoptional: to save a picture of a walk or of your city
Face IDoptional: to lock the app from other people

The profile photo is picked in a system window: the app receives only the chosen picture, with no access to your whole library. The microphone is never requested: video notes are recorded without sound.

You can revoke any permission in your phone settings. The app keeps working, just without whatever that permission enabled.

5. What the app does not have

6. The unbeen.app website

What the site collects. An email address, and only if you enter it yourself so we can tell you when the app is released. A separate button lets you leave an address for an Android version. Together with the address we store the page language, which version you signed up for (iPhone or Android), the country determined from the address of your connection, and the date, so that we can write to you in your language when the app becomes available in your country.

Why. To send you one email when the app launches. For that and nothing else: there will be no marketing mailings.

Where it is stored. On Cloudflare infrastructure, where the site itself is hosted.

For how long. Until launch plus thirty days, or until you ask us to delete it. After that the address is erased.

Unsubscribing. Every email has an unsubscribe link. You can also simply write to hi@unbeen.app and we will delete your address.

The site uses no advertising or analytics cookies.

7. Legal basis

The app makes no automated decisions with legal effects and does no profiling.

8. How long data is kept

9. Where the data physically lives

10. Your rights and how to delete your data

If you are in the European Economic Area or the United Kingdom, you have the right to obtain a copy of your data in a machine-readable form, correct it, delete it, restrict its processing, object to processing, withdraw consent, and lodge a complaint with a supervisory authority.

How to do this in Unbeen:

We answer any request within one month.

The supervisory authority in Portugal is the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1º, 1200-651 Lisboa, geral@cnpd.pt; complaints can be filed at cnpd.pt. You may also contact the supervisory authority of your own country.

11. Children

The app is not directed at children under 13, and we deliberately do not collect children's data. If you believe a child has given us their data, write to us and we will delete it. In countries where the age of digital consent is higher than 13, the leaderboard and friends are available from that age.

12. Changes

If this policy changes, the new version will appear on this page with a new date. If a change affects email addresses already collected, we will say so by email.

13. Contact

Maksim Efimov · hi@unbeen.app

← Unbeen