Privacy Policy for Fernweg
Controller
Felix Trier
c/o POSTFLEX PFX-036-304
Emsdettener Straße 10
48268 Greven
Email: fernweg@felix-trier.de
The short version
Fernweg keeps everything on your device. There is no server, no user account and no sign-in. The developer receives no data from you — neither your health data nor your progress, your name, or how you use the app.
There are no analytics, no tracking, no advertising, and no third-party libraries that could collect anything.
Health data
What is read. Fernweg reads your walking and
running distance (distanceWalkingRunning) from Apple
Health.
What for. The daily distance is used to work out how far along your chosen route you have come. That is its only purpose.
Read-only. The app never writes anything back to Apple Health. It holds no permission to do so.
Connections to the outside
Fernweg ships with all its photos and needs no internet connection in normal use. A connection occurs in one case only:
Wikimedia Commons
If a bundled photo is missing, the app fetches it from Wikimedia Commons.
In doing so Wikimedia learns — as with any website request — your
IP address and the name of the file requested. The app also
identifies itself (Fernweg/1.0), as Wikimedia requires of
applications.
No information about you, your journey or your health data is sent.
Wikimedia Foundation privacy policy: https://foundation.wikimedia.org/wiki/Policy:Privacy_policy
Children
Fernweg is not directed at children and knowingly collects no data from them — the app collects no data for the developer at all.
This website
What a visit records. The server delivering this page logs every request: IP address, time, the path requested, the HTTP status, your browser identification and the address called.
What for. Running the site and defending against attacks. A filtering system in front of it evaluates these entries and temporarily blocks IP addresses that stand out.
Legal basis. Legitimate interest in secure operation (Art. 6(1)(f) GDPR).
For how long. Seven days, after which the entries are deleted automatically.
Sharing on attack. When the attack detection triggers, the server reports the attacker's IP address, the kind of attack detected and the time to CrowdSec (CrowdSec SAS, France). In return it receives the shared blocklist that protects this site against addresses already seen misbehaving elsewhere. That is all that is sent: no log lines, no requested addresses, nothing about visitors who are not attacking. The basis is the legitimate interest in secure operation (Art. 6(1)(f) GDPR). CrowdSec's privacy policy: https://www.crowdsec.net/privacy-policy
What is not here. No cookies. No JavaScript. No measurement, no analytics, no advertising. No external fonts, no content from other servers, no embedded videos or maps. This page loads files from its own server only — visiting it opens a connection to nobody else.
Changes
If something changes in the app that affects this text, the text will be updated. The current version is always at the address given in the App Store.