Privacy Policy for Fernweg
Last updated: 9. August 2026
Draft. This text describes exactly what the app does — checked against the source code, not copied from a template. The legal wording should still be reviewed by someone qualified to do so.
German version: Deutsche Fassung
Controller
Felix Trier
Musterstraße 1
12345 Musterstadt
Deutschland
Email: fernweg@felix-trier.de
The short version
Fernweg keeps everything on your device. There is no server, no user account and no sign-in. The developer receives no data from you — neither your health data nor your progress, your name, or how you use the app.
There are no analytics, no tracking, no advertising, and no third-party libraries that could collect anything.
Health data
What is read. Fernweg reads your walking and
running distance (distanceWalkingRunning) from Apple
Health.
What for. The daily distance is used to work out how far along your chosen route you have come. That is its only purpose.
Read-only. The app never writes anything back to Apple Health. It holds no permission to do so.
It does not leave your device. The values are read on the device, calculated on the device and stored on the device. They are not transmitted, not analysed, not shared and not sold.
Legal basis. Processing rests solely on your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR). You give it in the iOS system dialog and can withdraw it at any time under Settings → Privacy & Security → Health → Fernweg. Without it the app shows no progress; everything else keeps working.
In the background. Fernweg asks iOS to wake it when new distance has been recorded, so it can check whether you have reached a place on the route. That too happens entirely on the device.
What is stored on your device
| What | Where | For how long |
|---|---|---|
| The current journey: route id, start date, travel mode | the app’s protected storage | until you delete it or remove the app |
| Photos of the places you have reached | the app’s protected storage | journal photos permanently, preview photos are cleaned up automatically |
| A short summary of the route for the Home Screen widget | storage shared between app and widget | while a journey is running |
None of this is transmitted anywhere. Removing the app removes all of it.
No access to your location. Fernweg does not request your location and holds no permission for it. The map shows the route and your calculated point on it — derived from the distance you have walked, not from GPS. Where you actually are is something the app never learns.
Connections to the outside
Fernweg ships with all its photos and needs no internet connection in normal use. There are exactly two cases where a connection occurs:
Wikimedia Commons
If a bundled photo is missing, the app fetches it from Wikimedia Commons.
In doing so Wikimedia learns — as with any website request — your
IP address and the name of the file requested. The app also
identifies itself (Fernweg/1.0), as Wikimedia requires of
applications.
No information about you, your journey or your health data is sent.
Wikimedia Foundation privacy policy: https://foundation.wikimedia.org/wiki/Policy:Privacy_policy
Apple (purchase)
The one-time unlock runs entirely through Apple. The app sees no payment details, no name and no address — it merely asks Apple whether this Apple ID has purchased, and receives yes or no.
Apple’s privacy policy: https://www.apple.com/legal/privacy/
Notifications
When you reach a place on the route, Fernweg can send you a notification. It is created and triggered on the device itself. There is no push service, no server, and no device token sent anywhere.
You can turn notifications off at any time under Settings → Notifications → Fernweg.
This website
Everything above is about the app. This section is about the page you are looking at.
What a visit records. The server delivering this page logs every request: IP address, time, the path requested, the HTTP status, your browser identification and the address called.
What for. Running the site and defending against attacks. A filtering system in front of it evaluates these entries and temporarily blocks IP addresses that stand out.
Legal basis. Legitimate interest in secure operation (Art. 6(1)(f) GDPR).
For how long. Seven days, after which the entries are deleted automatically.
Sharing on attack. When the attack detection triggers, the server reports the attacker's IP address, the kind of attack detected and the time to CrowdSec (CrowdSec SAS, France). In return it receives the shared blocklist that protects this site against addresses already seen misbehaving elsewhere. That is all that is sent: no log lines, no requested addresses, nothing about visitors who are not attacking. The basis is the legitimate interest in secure operation (Art. 6(1)(f) GDPR). CrowdSec's privacy policy: https://www.crowdsec.net/privacy-policy
What is not here. No cookies. No JavaScript. No measurement, no analytics, no advertising. No external fonts, no content from other servers, no embedded videos or maps. This page loads files from its own server only — visiting it opens a connection to nobody else.
Children
Fernweg is not directed at children and knowingly collects no data from them — the app collects no data for the developer at all.
Changes
If something changes in the app that affects this text, the text will be updated. The current version is always at the address given in the App Store. The date above is authoritative.
Questions
fernweg@felix-trier.de