Privacy Policy
Last updated: 3 August 2026
This privacy policy explains which personal data we process when you use the website www.mymovement.app and the mymovement app (iOS and Android), for which purposes, and which rights you have. In case of doubt, the German version of this privacy policy prevails.
At a glance
The most important points in brief:
- Your tours belong to you. New routes, photos and albums are private by default; you decide for each item whether it is visible to followers or publicly.
- Location data is only processed while you have the ride view of the app open, or while a recording or navigation you started yourself is running — there is no permanent tracking.
- Health data (e.g. heart rate) is only processed with your explicit consent and is never shared with third parties.
- Crash reports and usage statistics are off by default and are only activated after your consent — as is Google Analytics on the website.
- No data sales, no advertising: we do not share your data for advertising purposes and do not sell it.
- Your core data stays on our own servers (account, routes, photos, health data); we use external services only for individual features described below.
You will find the details in the following sections.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Carsten Eilers
Neuwerker Straße 26
40549 Düsseldorf, Germany
E-mail: info@mymovement.app
2. Your rights
With regard to your personal data, you have the following rights against us:
- right of access (Art. 15 GDPR),
- right to rectification (Art. 16 GDPR),
- right to erasure (Art. 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to object to processing (Art. 21 GDPR).
You may withdraw any consent you have given at any time with effect for the future — in the app directly in the settings under "Privacy", on the website via the cookie settings in the footer. The lawfulness of processing carried out before the withdrawal remains unaffected.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
3. Data processing on the website
3.1 Server log data
When you visit the website, your browser automatically transmits data to our server (IP address, date and time of access, page accessed, browser type and version, operating system, referrer URL). This data is stored in server log files and used exclusively to ensure trouble-free operation, analyse errors and defend against attacks. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and stable operation). Log data is deleted automatically after a short period.
3.2 Cookies and consent
We use technically necessary cookies (e.g. to store your language preference and your cookie decision) on the basis of Section 25 (2) TDDDG and Art. 6 (1) (f) GDPR. All non-essential services (see Google Analytics) are only loaded after your explicit consent via the consent dialog. You can change your selection at any time via "Cookie settings" in the footer.
In detail, the website uses the following cookies and comparable storage techniques:
| Name | Purpose | Category | Duration |
|---|---|---|---|
mm_consent_v1 | Stores your decision in the consent dialog (cookie and localStorage) | Necessary | 180 days |
i18n_redirected | Stores your language selection (German/English) | Necessary | 1 year |
_ga | Google Analytics: distinguishing visitors | Statistics (only with consent) | 2 years |
_ga_* | Google Analytics: session and campaign state | Statistics (only with consent) | 2 years |
If you withdraw your consent, we automatically delete the Google Analytics cookies.
3.3 Google Analytics
If you have given your consent, this website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies to analyse how the website is used. The information generated is usually transferred to Google servers, including in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework. The legal basis is your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). Without consent, Google Analytics is not loaded; if you withdraw consent, we delete the associated cookies and stop collecting data.
4. Data processing in the app
4.1 Account and sign-in
A user account is required to use the community features. During registration and sign-in we process your e-mail address, your username, your password (encrypted/hashed only) and, optionally, a profile picture. Sign-in is handled by our own identity service (Keycloak) on servers operated by us. The legal basis is Art. 6 (1) (b) GDPR (performance of contract).
4.2 Route, location and sensor data
The core function of the app is recording and planning tours. For this purpose we process — only during a recording you have started — your GPS position (including in the background while the recording is running), speed, altitude and motion/attitude sensor data (e.g. to calculate lean angles). Your routes and statistics are created from this data and stored in your account. The legal basis is Art. 6 (1) (b) GDPR.
If you have enabled the speed limit display, the app additionally sends your current position and a few points calculated ahead of you to our server in order to look up the speed limit recorded for that road section in OpenStreetMap. This also happens when no recording is running — but only while the ride view is open, and only for motorised activities. These positions are not stored; the request is passed on to our own routing service and then discarded. You can switch the display off at any time in the layers menu of the ride view, which stops the transmission entirely. The legal basis is Art. 6 (1) (b) GDPR.
Newly created content is private by default. You decide on the visibility of each route and album yourself (private, followers only, or public). Public content can be viewed by all users of the app.
4.3 Photos and other content
You can add photos, markers, comments and albums to your routes. Photos may contain metadata (e.g. time and place of capture), which we use to display them on the map and in the timeline. Processing is based on Art. 6 (1) (b) GDPR; your visibility settings from section 4.2 apply.
4.4 Health data (Art. 9 GDPR)
Optionally, you can import activities and heart-rate data from Apple Health (iOS) or Health Connect (Android), or have your heart rate added to recorded tours. This constitutes health data within the meaning of Art. 9 GDPR. We process it exclusively on the basis of your explicit consent (Art. 9 (2) (a) GDPR), which we obtain separately before the first connection. The data is linked to your activities and stored in your account; it is not shared with third parties. You can withdraw your consent at any time by disconnecting the integration in the settings — automatic import stops immediately. You can delete data that has already been imported by deleting the activities concerned or your account.
4.5 Crash reports and usage statistics (opt-in)
When you first start the app, we ask whether the app may send crash reports (Firebase Crashlytics) and anonymous usage statistics (Firebase Analytics) to us. Both services are disabled by default and are only activated after your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; data may be transferred to the USA (Google LLC is certified under the EU-U.S. Data Privacy Framework). The data transmitted comprises technical device information, the app version and, in the case of Crashlytics, the state of the app at the time of the crash. You can withdraw both consents at any time in the settings under "Privacy".
4.6 Push notifications
If you enable push notifications (e.g. for new followers, sparks or invitations), we use Firebase Cloud Messaging (Google) and the Apple Push Notification Service for delivery. A pseudonymous device token is processed for this purpose. The legal basis is your consent via the system permission (Art. 6 (1) (a) GDPR); you can disable notifications at any time in the system settings.
4.7 Map display
To display maps, the app loads map tiles from OpenFreeMap (tiles.openfreemap.org), a non-commercial open-source map service based on OpenStreetMap data. For technical reasons, your IP address is transmitted to the map server; no other data (in particular your position or route) is transferred. The legal basis is Art. 6 (1) (b) GDPR (provision of the map function). For offline use, map regions can be stored locally on your device.
4.8 Address search (geocoding)
For place and address search (e.g. when planning routes) we use the Photon geocoding service based on OpenStreetMap data. Your search queries are processed via our servers; the search text may be transmitted to the Photon service. The legal basis is Art. 6 (1) (b) GDPR.
4.9 Route calculation and traffic data
Planned routes (including curvy routes and navigation) are calculated on our own servers using the open-source software Valhalla based on OpenStreetMap data; your start, destination and waypoints are processed for this purpose (Art. 6 (1) (b) GDPR). Information on roadworks and traffic disruptions is obtained server-side from TomTom; no personal data of our users is transmitted to TomTom.
4.10 AI-assisted name suggestions
For automatic route name suggestions we use the OpenAI API server-side (OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland). Only route characteristics (e.g. place names along the route) are transmitted — no account or contact data. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a convenient naming feature); you can change or discard the suggestions at any time.
4.11 Community, reporting and blocking
Your profile (username, profile picture, public content) is visible to other users. You can block other users and report content or users. When you submit a report, we process the reported content, the information you provide and the user identifiers involved in order to review the case and take action where necessary (Art. 6 (1) (f) GDPR — legitimate interest in a safe platform — and legal obligations under the Digital Services Act).
4.12 E-mail communication and product news
We contact you at the e-mail address you provided during registration where this is necessary to operate the service — for example when this privacy policy or the Terms of Service change, for security-relevant notices, or for important changes to your account. The legal basis is Art. 6 (1) (b) GDPR (performance of contract) or Art. 6 (1) (c) GDPR (legal obligation). These messages are part of the user relationship and cannot be unsubscribed from while your account exists.
Beyond that, we inform you about new features and product news only if you have given your explicit consent (Art. 6 (1) (a) GDPR, Section 7 (2) UWG). You give this consent voluntarily via the "Product news by e-mail" toggle in the app settings; it is not a condition for using the service. For this purpose we store the time of your consent and the version of the consent text in order to be able to demonstrate it (Art. 7 (1) GDPR). You can withdraw your consent at any time with effect for the future — via the same toggle or via the unsubscribe link in each of these e-mails.
5. Recipients and third-country transfers
Our servers (application, database, identity service, route calculation) are operated in a data centre in Germany; your account data, routes, photos and health data only leave this infrastructure in the cases described in this policy. Encrypted backups are stored with Microsoft Azure (Microsoft Ireland Operations Ltd.) in a data centre in Frankfurt am Main, Germany; backups are encrypted on our systems before transfer, so Microsoft has no access to their contents, and are deleted automatically after 30 days. Where services provided by Google, Apple or OpenAI transfer data to the USA, the transfer is based on the adequacy decision for the EU-U.S. Data Privacy Framework or on EU standard contractual clauses. We have concluded data processing agreements pursuant to Art. 28 GDPR with our processors.
6. Storage period and deletion
We store your data for as long as your user account exists. You can delete individual content (routes, photos, albums, comments) in the app at any time. If you delete your account, your personal data is removed from the active systems; for technical reasons it may still be contained in encrypted backups for up to 30 days and is then permanently deleted automatically. Statutory retention obligations remain unaffected.
7. Data security
All connections between the app or browser and our servers are TLS-encrypted. Backups are additionally encrypted client-side. We implement technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorised access.
8. Changes to this privacy policy
We will update this privacy policy when the app, the website or the legal situation changes. The current version is always available at www.mymovement.app/en/privacy.