Privacy Policy
Trod turns real-world movement into a map you uncover. This policy explains what leaves your phone, what can be shared, and what stays private.
Effective 7 August 2026
The short version
- The map-reveal system converts location fixes into map-area identifiers on your phone. Trod stores those identifiers for signed-in accounts, not the raw fixes or a server-side route.
- Two features do store exact chosen coordinates: private saved places and community gems you submit. Gems can become public after review.
- Accepted friends can see selected profile and exploration information. Sharing is on by default, including a read-only explored-area map, and can be changed in Friends › Privacy.
- We do not sell personal data, show third-party ads, use advertising IDs, or run product or marketing analytics.
- You can delete your account in the app. Most account-linked data is removed immediately. Some contributions can remain without the account link, as explained below.
1. Who is responsible
Wanderlab is the public brand behind Trod. The service and its personal-data processing are operated by Omar Ajruli in Estonia.
Email: ajruli.omar@gmail.com.
2. What this policy covers
This policy covers the Trod Android app, gettrod.com, and Trod's public legal pages. A third-party site opened from Trod follows that site's own privacy policy.
3. Data Trod processes
Account and profile
- Email address, account ID, sign-in records, and authentication information.
- Name and profile photo supplied by Google if you choose Google sign-in.
- Display name, Trod handle, avatar, home-country choice, step goal, privacy controls, and notification preferences.
- A photo you deliberately choose as an avatar. Trod does not browse or upload the rest of your photo library.
Exploration and game progress
- Explored map-area identifiers created on your device from location fixes.
- Day-level exploration totals, city and country progress, landmarks found, Atlas and passport state, quests, streaks, coins, and related game records.
- Daily step totals for signed-in accounts when step counting is enabled. Trod does not upload the raw sensor stream or the time of each individual step.
Places you choose
- My Places: exact selected coordinates, category, name, and any note you add. These are private to your signed-in account.
- Community gems: exact selected coordinates, type, name, and optional note. A submission is private while pending. If approved, its location and content become public. Trod does not expose the reporter's account ID in the public gem feed.
Friends, circles, and notifications
- Friend requests, accepted friendships, blocks, cheers, shared quests, circle membership, and activity needed to run those features.
- Aggregated activity such as daily or weekly steps, newly explored areas, cities, countries, landmarks, and progress tiers.
- A device push token if a supported build has notification permission. It is used for transactional friend notifications and is removed on sign-out or account deletion.
Diagnostics and website requests
- Crash reports can include stack traces, error messages, app version, operating-system version, and device model. Sentry's default personal-information collection is disabled. Trod removes IP addresses from events and scrubs selected app fields and breadcrumbs. An unexpected error message can still contain information supplied to the failing feature, so crash reporting is not described as anonymous.
- Website hosts process normal request data needed to deliver and protect the site, such as IP address, requested URL, browser information, and timestamps. Trod has not added advertising trackers, product analytics, or analytics cookies to the public site.
4. How location works
- While you use the map, your phone receives location fixes and converts them into map-area identifiers. The reveal backend receives those identifiers, not the raw fixes.
- The recent visual walking trail and detailed visit dates used by the app are kept on the device. The recent trail is pruned after about six hours when it is loaded.
- Walking mode is started by you, shows an ongoing Android notification, and uses the normal location permission. Trod does not request Android's background-location permission.
- Weather requests use coordinates rounded to two decimal places, which is roughly 1 km and varies by latitude.
- MapTiler receives the map tiles or style areas your device requests. Like other web requests, these include an IP address and device user-agent.
- Exact coordinates leave the reveal path only when you deliberately save a place or submit a community gem.
5. What other people can see
Friend sharing. When two people become accepted friends, Trod's sharing controls are on by default. Depending on the individual switches, a friend can see your display name, handle, avatar, earned counts, walked city and country information, weekly activity, and a read-only map of explored-area coverage. The map contains coverage, not your current position, a route sequence, or reveal timestamps. It does not include private saved places.
You can turn off Share with friends, Weekly walking, Show me in Walked this week, and Share my map in Friends › Privacy. Turning a switch off stops future access through Trod. It cannot erase information another person already saw, saved, or captured. Explored-area coverage can reveal patterns about places you visit, so review these settings before adding people you do not know well.
Circles. Joining an invite-code circle makes your display identity and period totals for steps, explored areas, new cities, and landmarks visible to the members allowed to see you in that circle. Circles do not receive your map, coordinates, saved places, or live location. You can leave a circle.
Community gems. Approved gem locations, names, types, and notes are public. The public feed does not include your reporter ID. Trod can retain the account link while it is needed for moderation and abuse prevention.
6. Services Trod uses
| Service | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication, EU-hosted database, file storage, realtime features, and server functions | Account, profile, game progress, explored-area identifiers, daily totals, private saved places, gem submissions, social records, avatars, and push tokens |
| MapTiler | Base map and map styles | IP address, user-agent, and requested map area |
| Open-Meteo | Current weather and forecasts | Coordinates rounded to two decimal places, plus normal request data |
| Wikipedia and Wikimedia Commons | Place summaries and images requested when you open relevant place cards | Requested article or image and normal request data; Trod does not send your precise location in these requests |
| Optional Google sign-in and Firebase Cloud Messaging | OAuth data when selected; device push token and transactional notification content when notifications are available | |
| Sentry | App crash and error diagnostics through an EU ingest endpoint | Technical error information described in section 3 |
| Cloudflare and GitHub Pages | Website delivery, legacy legal-page hosting, and security | Normal HTTP request and security-log data |
| GetYourGuide and Viator | Optional partner links opened only when you tap them | The place named in the link, partner-link parameters, and normal browser request data. Their own policies apply after opening |
Trod does not sell or rent personal data. It does not use third-party advertising or product-analytics services. A partner booking link may earn Wanderlab a commission without changing your price.
7. Why we process data
- To provide the service you request: account access, map reveal, syncing, saved places, progress, friends, circles, and other game features.
- Based on your choices and device permissions: step counting, an avatar photo, notifications, and contributions you submit.
- For legitimate interests: service security, abuse prevention, troubleshooting, and keeping Trod reliable, balanced against your privacy rights.
- To meet legal obligations: responding to valid requests and enforcing applicable law.
Trod does not make decisions with legal or similarly significant effects using solely automated processing.
8. Retention and deletion
- Account, profile, social, and gameplay data is generally kept while the account exists.
- Private saved places remain until you delete the place or the account.
- Community gems can remain for moderation or public display. On account deletion, Trod removes the reporter ID link. The contribution itself may remain. Email us with enough detail to identify a gem if you want the content reviewed for removal.
- A circle can continue for its remaining members after its creator deletes an account. The deleted person's membership and account link are removed.
- Turning off a sensor or sharing feature stops future use by that feature but does not automatically erase information already stored. You can use account deletion or contact us for an erasure request.
- Crash reports and hosting or security logs are kept only for the period needed to investigate reliability, prevent abuse, and meet provider retention settings.
- Deleted data can remain temporarily in encrypted provider backups until those backups rotate. Backups are used for disaster recovery, not to continue serving a deleted account.
For exact account-deletion steps, read Delete your Trod account.
9. Your privacy rights
Depending on where you live, you can ask to access, correct, delete, restrict, object to processing, or receive a portable copy of personal data connected to your account. You can also withdraw a permission or optional choice for future processing. Withdrawing it does not make earlier lawful processing invalid.
Email ajruli.omar@gmail.com. We may need to verify that the request belongs to you. You can also complain to your local data-protection authority. In Estonia, that is the Data Protection Inspectorate.
10. Security
Trod uses encrypted network connections, account-scoped database rules, limited server functions, and data minimisation in the reveal path. Public community content and information you choose to share with friends or circles are exceptions to private account access. No service can promise perfect security.
11. International processing
The main account database is hosted in the European Union. Some providers can process request, support, or diagnostic data in other countries. Where required, those providers use recognised transfer safeguards. Their own privacy terms describe their processing locations and safeguards.
12. Children
Trod is not directed at children under 13. Do not use Trod if you are under 13. Where local law requires parental or guardian permission at a higher age, you must have that permission. If you believe a child has provided personal data without the required permission, contact us and we will review and remove it.
13. Changes
We will update this page when Trod's data practices change. If a change materially affects how existing account data is used or shared, we will provide a clear notice in the app or on the service before the change takes effect where required.
14. Contact
Wanderlab / Trod
Operator and data controller: Omar Ajruli, Estonia
ajruli.omar@gmail.com