Privacy
Last updated: 13 September 2026
Prefer plain language over paragraphs? Read how we handle your privacy — same facts, no legalese.
1 · Controller
aditrix UG (haftungsbeschränkt), Hauptstr. 62, 97717 Sulzthal, Germany Email: contact@motonavigator.app — full details in the imprint.
2 · The principle first
MotoNavigator works without an account. No registration, no email address, no profile. The app identifies itself to our servers with a pseudonymous device UUID that is not tied to a person — and most of our servers never even get to see that (§ 5). Ride data stays on the device — only what the rider explicitly opts in to is uploaded.
The app is intended for people aged 18 and over.
3 · This website
When you visit, the web server processes the IP address, time, request and user agent — for the secure operation of the website: detecting disruptions and fending off attacks. From these logs we also compile access statistics; they contain no IP addresses and, once the logs are deleted after 14 days at the latest, no longer allow any conclusions about individual visitors. The legal basis is our legitimate interest in both (Art. 6 (1)(f) GDPR). We keep the logs for no longer than 14 days.
The site sets no cookies and embeds no trackers or external resources. Links to other sites, including our profiles on social networks (§ 7), are simple links: nothing is transmitted until you click. Hosting by a service provider under a data processing agreement per Art. 28 GDPR; the servers for this website are in the EU.
4 · The app
Unless stated otherwise, we process data in order to provide you with the app under the terms of use (Art. 6 (1)(b) GDPR).
Location data. The app uses your location for navigation and recording — including in the background if you allow it (the ride keeps running with the display off). Processing happens on the device.
Sensors. During a recording the app captures the device’s motion and environmental sensors. This raw data also lives on the device.
Other device functions. The app uses the camera only to scan codes, for example when joining a group ride; the image does not leave the device. The app generates notifications on the device itself. You can revoke permissions at any time in your device’s settings; individual features are then not available. Your phone’s backup takes app data with it, as with any app — map packs are excluded from it.
Recordings (ride records). Ridden tours are stored locally. Export and sharing happen exclusively by the rider via the phone’s share sheet.
Upload — only if you say yes. Recordings — positions, sensor data and the events the app detects during the ride, together with your responses to them — are transferred to our servers and processed there only after you have given your consent (Art. 6 (1)(a) GDPR). They travel under your pseudonymous device UUID.
We combine them with the rides of many others to improve routing, map and place data, and the analysis of ride data in the app — for example to identify significant routes and places, or events during the ride. We do not evaluate individual riders in the process: the results are based on many rides and name neither a ride nor a rider.
Consent is voluntary; without it, the app remains fully usable. You can withdraw it at any time in Settings. Withdrawal stops future uploads and does not affect the lawfulness of what happened up to that point; rides recorded before you gave consent are not sent retroactively.
Privacy zones. Around places you define (e.g. home), no readings are recorded at all — not on our servers, and not on your own phone. That is not just the position but every reading. The recording runs through the zone without a gap — the time axis stays complete, the readings in it are empty.
Map data and route calculation. When downloading offline maps, the server sees the IP address and the map data requested. For an online route calculation the app additionally transmits the points of the route you want. Neither learns who is asking: the credential the app identifies with there carries no device UUID. Where these servers stand and how long their access logs are kept is in § 5.
Group rides. Anyone who joins a group ride is visible to the other participants on the map while the ride is running. A display name is optional and visible to the group.
Information about places. Websites, phone numbers and similar information about places come from OpenStreetMap. Nothing is transmitted to third parties until you open such a link or dial a number; after that, their privacy notices apply.
Purchases. Subscriptions and purchases run as an in-app purchase through your device’s app store; we receive no payment data.
5 · Server locations and retention
Your recordings and everything derived from them are stored and processed in the EU only.
The other services are located where people ride — outside the EU too: the delivery of map packs, route calculation, running group rides and the management of your entitlements. The reason is distance: a map download or a group ride via a server on another continent is slow and prone to disruption; a server near you responds faster and more reliably. No ride data sits there. Map packs, route calculation and group rides don’t even learn who is asking — the credential the app identifies with there carries no device UUID. What does accrue there:
Access logs. IP address, time and request — for secure operation: detecting disruptions and fending off abuse (Art. 6 (1)(f) GDPR). We keep them for no longer than 14 days; statistics we compile from them contain no IP addresses.
Group rides. During a live ride the server holds the participants' positions, for the duration of the ride.
Entitlements. One row per device: your device UUID, a check value your device identifies with (the device secret itself is never stored), the date you enrolled, the day you last used the app, and how long booked features are valid. No name, no address, no payment data. After two years without use the row is deleted.
Our servers are operated on our behalf by data centre service providers (Art. 28 GDPR). Where services run outside the EU, the transfer is safeguarded by EU standard contractual clauses; you can obtain a copy on request. Beyond that, we do not pass on personal data unless we are legally obliged to do so.
Recordings you contribute stay for as long as you use the app. Two years after your last use they are deleted or reduced to anonymous aggregates that name no ride and no rider; the cut-off hangs on your use, not on the age of the individual ride. Such aggregates are no longer personal data; the location rule in the first paragraph does not apply to them.
6 · Contacting us
If you send us an email, we process your details in order to handle the enquiry — including a device UUID you give us. The legal basis is Art. 6 (1)(b) GDPR where the use of the app is concerned, otherwise Art. 6 (1)(f) GDPR.
We keep emails in our mailbox; they are not routinely deleted once a matter has been closed. For commercial and business letters we are legally obliged to keep them (§ 257 HGB, § 147 AO). Otherwise, retention is based on our legitimate interest in being able to trace matters and pick them up again later (Art. 6 (1)(f) GDPR). You can object to this at any time; we will then check whether statutory retention obligations stand in the way.
7 · Profiles on social networks
We maintain profiles on Facebook and Instagram in order to be reachable there (Art. 6 (1)(f) GDPR). For the reach statistics that Meta compiles about visits to these profiles, we are joint controllers with Meta Platforms Ireland Ltd. (Art. 26 GDPR); we ourselves receive only aggregated figures from them. The essence of the agreement is set out in the Page Insights Controller Addendum, how Meta processes data in its privacy policy. You can also exercise your rights directly against Meta.
8 · Your rights
You have the rights to access, rectification, erasure (Art. 17 GDPR), restriction and data portability. You can withdraw consent at any time. You can object to processing based on our legitimate interest on grounds relating to your particular situation (Art. 21 GDPR). Since we keep no accounts, erasure works via the device UUID, which is visible in the app — a request to contact@motonavigator.app is enough. You also have the right to lodge a complaint with a data protection supervisory authority.
You are not obliged to provide us with any data. Without location permission the app cannot navigate; without consent your rides stay on the device. We do not make automated decisions within the meaning of Art. 22 GDPR.
9 · Changes
We adapt this policy when the app, our services or the legal situation change. The version published here, with the “last updated” date given above, applies.