← Back to Inukshuk
Inukshuk — Privacy Policy
Last updated: 1 October 2026
Inukshuk is a free, open-source app for offline trail navigation: it displays georeferenced
PDF maps with your GPS position and records your routes as GPX files. This policy explains
what the app does and does not do with your data. The short version:
your data stays on your device.
Who we are
Inukshuk is developed by Marc-André Vigneault. For any privacy question, contact:
marcandre.vigneault.96@gmail.com.
Data the app uses
-
Location (GPS). With your permission, the app reads your device location
while it is open to show where you are on the map and, when you start a recording, to build
your trail. We never receive your location — Inukshuk has no server of ours
that it sends positions to, and your location is never used for advertising or analytics.
Your trail itself stays on your device.
-
The two exceptions, both narrow. Naming a saved recording sends that
outing's first recorded point to your device's own built-in geocoder to look up a
place name, and connecting a Strava account lets you upload chosen outings to Strava. Both
are described in detail under "Network connections" below. Everything else about your
position is handled on your device.
-
Files you import and create. PDF maps you import, the GPX tracks you
record, and the activity files you import (FIT, TCX, GPX, or a Strava or Garmin export zip)
are stored locally on your device, inside the app's private storage.
Imported files are read and converted into trails on your device; nothing about them is sent
anywhere. We never upload them, and the only way one leaves your device is if you choose to
share or export it yourself — or upload an outing to Strava, if you have connected an
account. You can delete any map or track inside the app at any time, and uninstalling the
app removes all of them.
-
Activities you import from Strava, Apple Health or Health Connect. If you
connect Strava or allow access to Apple Health (iOS) or Health Connect (Android), the app
can import your past activities as trails. What is read, and how, is described under
"Strava" and "Apple Health and Health Connect" below. The imported trails are stored only on
your device and shown only to you.
Data we collect
The app collects no personal data. Inukshuk has no user accounts, no
analytics, and no advertising. Your maps, trails, waypoints and photos never leave your device
through us, and neither do the activities you import or any health data: they stay on your
device. The one thing the app does send on its own is a technical error report, described
next.
The only requests that reach servers of ours are map tile requests (see "Our tile server"
below), the Explore map catalogue downloaded from our website, the points of a route you draw
in Trails or Roads mode (see "Snapping a drawn route to trails or roads" below), and, if you
connect Strava, the sign-in tokens that pass through our tile server on their way to Strava.
None of them carry your identity or your GPS position, and the tokens are not stored.
Tips. An optional tip (Settings → Support Inukshuk) is processed entirely by
Apple or Google; we receive no payment details. That screen also downloads the public
support page's figures from our website, which carries nothing about
you.
Donors list (optional). After a generous gift, the app offers to add your
name to the public "Prominent donors" list. Only if you choose to, it sends the display name
you type, an optional town or region, your platform (iOS or Android) and the store receipt
numbers of your tips, so we can check the gift before publishing. No email or account is asked
for. After our check, the name and place are shown publicly in the app and on the
support page. To have your name removed, or an unpublished
submission deleted, write to
marc-andre.vigneault@mvxtechnologies.com.
"I already donated" (optional). If you gave some other way, the Support
screen can hide the tip button on your device for a year. It asks for an email address and
sends a one-time code to it through our email provider (Resend). The address is used only to
send that code and is never shared. Our server does not store the address: it keeps only a
salted hash of it with the code, which expires after 15 minutes and is deleted once used, or
within a day at most (it is kept that long only to limit repeated requests). We do not check
whether you donated.
Apart from these optional steps, the one place we ask for anything is the Android beta signup
on our website, which is optional and separate from the app — see below.
Joining the Android beta
Android testing is invitation-only while the app is in closed testing, so joining means giving
us an email address. That address is used for one thing: sending you the link to join the
test, and the occasional note about the beta itself. We do not sell it, share it, or use it to
advertise to you, and it is not connected to anything you do inside the app.
Signing up is handled by Google, so your address is stored in Google's systems and is subject
to Google's privacy policy as well as this
one. Joining the test also means Google Play knows you are a tester, which is how the app
reaches your device.
You can leave at any time: unsubscribe from the list, or ask us to remove your address by
opening an issue on
our GitHub repository. Once
the app is published publicly on Google Play, the list has served its purpose and will be
deleted.
Error reports
When the app hits an error, it records a report and — if error reporting is enabled — sends it
automatically so the problem can be fixed. A report contains only technical details: the error
message and stack trace, the app version, the operating-system version and device model, and a
short list of the actions the app took just before the failure. It contains
no location, no map or trail content, and nothing that identifies you.
Reports are filed as issues in the app's public
GitHub repository, so their
technical contents are publicly visible. You can turn this off at any time:
Settings → Privacy → Automatic error reporting. With it off, nothing is sent.
Network connections
Inukshuk works offline, but a few features fetch data over HTTPS — from our own tile server
and directly from third-party servers. In each case that server receives your device's IP
address and the map area or tile coordinates being requested — the normal information any web
request carries. None of them receive an account or identity (the app has none), and the PDF
maps you import are rendered entirely offline with no network connection.
-
Our tile server. The default base map, its contour lines, named peaks and
the map's label font come from our own tile server, which runs on
Cloudflare. The map data is from
OpenStreetMap (built by Protomaps), and the contour lines are drawn from the open "Terrain
Tiles" elevation dataset. A request carries only the tile being asked for and your IP
address: no identity, and no location beyond the map area on your screen. Our server keeps
no logs of its own and stores nothing about you; it only caches the map tiles themselves.
The requests are processed by Cloudflare, which hosts the server, under Cloudflare's privacy
policy.
-
Snapping a drawn route to trails or roads. When you draw a route on the map
in Trails or Roads mode, each stretch between two points you placed is
sent to our tile server, which asks a routing service for the path along real trails or
roads: BRouter (brouter.de) for trails,
and the FOSSGIS e.V. Valhalla
server (valhalla1.openstreetmap.de) for roads. What is sent is only the coordinates of the
two points you tapped (rounded to about a metre) and the mode — not your GPS position, no
identity, and nothing else about your trails. The routing service sees our server's address,
not yours, but it may keep those coordinates in its logs for a short time (BRouter states
two weeks). Our server keeps the answer in Cloudflare's cache for up to 7 days, under a
fingerprint of the request, so that the same stretch is not asked twice; it keeps no log of
who asked. Freehand mode sends nothing: its straight lines are drawn on your
device. Routes come from OpenStreetMap data (© OpenStreetMap contributors).
-
Other base maps. The satellite and relief base maps, the map draped over
the 3D terrain view, and the maps you make for printing load image tiles from
Esri / ArcGIS Online.
-
Elevation data. The shaded relief on the map and the 3D terrain view
download public elevation tiles hosted on Amazon Web Services (the open "Terrain Tiles"
dataset).
-
Naming a downloaded map area. When you download an offline map area, the
app asks OpenStreetMap's
Nominatim service for the name
of the nearest place, so the download can be labelled something memorable ("Sainte-Adèle")
instead of a set of coordinates. That request sends the centre coordinates of the area you
chose to download — not your own position, and only at the moment you start a download. If
Nominatim does not answer, the app falls back to your device's own built-in geocoder (Apple
on iOS, Google Play services on Android), which receives the same coordinates.
-
Naming a saved recording. When a recording is saved, the app asks your
device's built-in geocoder (Apple on iOS, Google Play services on Android) for the place
name at the recording's first recorded point, so the outing can be titled
"Sainte-Adèle — morning" instead of a timestamp. Unlike the map-area case above, these
coordinates are a position you actually visited — the place you started. The
request goes to your device's operating system, which handles it under
Apple's or
Google's own privacy policy; it is not
sent to us. If the geocoder does not answer within five seconds the app gives up and names
the outing by time of day instead.
-
Long-distance trails. Explore downloads a list of long-distance trails
(built from OpenStreetMap data) from
our own tile server, and, when you open a trail, that trail's route. Only the trail's id is
requested — never your identity or your location; which trails are near you is worked out on
your phone.
-
Searching for a place. When you type a place name into the map's
Search places box, the app sends what you typed, your phone's language (English or
French), and an approximate location — your position, or the map's centre if the app has no
position, rounded to about 1 km — to our own tile server, so nearby places come
first. Our server passes the same three things on to
Photon, an OpenStreetMap place search run by
komoot, which answers with matching places;
Photon sees our server's address, not yours. Answers are cached on our server for a day so
repeated searches do not reach Photon again, and our server counts requests per IP address
for a minute to prevent abuse; nothing is logged or kept beyond that. Coordinates you type
into the box are never sent anywhere. With no connection, or with
Locally downloaded only on, nothing is sent: the box searches your own trails,
waypoints and maps on the device. The last ten places you picked are kept on your phone
only, and Clear in the search box removes them.
-
Explore (the map catalogue). The Explore tab downloads a catalogue of free
public maps, and the lists of activities, terrain and collections it is sorted by, from our
own site (
inukshuk.mvxtechnologies.com). That request carries no location and
no identity; maps "near you" are picked on your device. When you then download a map, the
file comes directly from the publisher that hosts it — the U.S. Geological Survey, Natural
Resources Canada, the U.S. Forest Service or Geoscience Australia — and that publisher's
server sees your IP address and which map sheet you asked for. The Parcs Québec collection
opens the park's page on sepaq.com in your browser,
where Sépaq's own privacy policy applies.
-
Strava (only if you connect it). Described in its own section below. If you
never connect a Strava account, the app never contacts Strava.
-
App updates. On launch the app asks
Expo's update service (EAS Update) whether newer app
code is available. That request carries basic technical details such as the app version and
platform — not your location or any personal data.
-
Error reports. If automatic error reporting is on, technical error reports
are sent to GitHub as described above. They are queued on your device while you are offline
and sent when a connection returns.
Strava
Connecting Strava is optional, from
Settings → Connections. It opens Strava's own sign-in page in your browser, where you
choose what to allow: uploading activities, reading your activities, or both. We never see
your Strava password.
-
Sign-in tokens. Strava requires the app's secret key to complete a sign-in,
and that key must not be built into the app. So the one-time authorization code from the
sign-in, and later the refresh token used to renew access, pass
through our tile server, which adds the key and forwards the request to
Strava. Strava's answer goes straight back to the app. Our server does not store or cache
any of it. The resulting tokens are stored on your device only.
-
Importing your activities. If you allow reading your activities, the app
reads your Strava activity list and, for each activity it imports, its recorded streams —
position, time, altitude and heart rate — to save it as a trail on your device. You can run
an import yourself, and by default the app also imports new activities automatically when
you open it (at most every 15 minutes); you can turn that off with
Import new activities automatically. Imported Strava data is stored only on your
device and shown only to you. It is never sent to us or to anyone else.
-
Uploading outings. If you allow uploads, you can send an outing you choose
to Strava. Doing so sends that outing's route and statistics to Strava under your Strava
account. Nothing is uploaded unless you ask for it.
-
Disconnecting. Disconnect revokes the app's access on Strava's
side, deletes the tokens from your device, and can also delete every trail that was imported
from Strava. You can also remove Inukshuk from your Strava settings at any time.
What Strava does with your data on its side is governed by Strava's privacy policy. Inukshuk
does not connect to Garmin: the Connections screen only explains how to link Garmin Connect to
Strava, so your Garmin activities can reach Inukshuk through Strava.
Apple Health and Health Connect
On iOS, Inukshuk can read from Apple Health; on Android, from Health Connect. Both are
optional, and the app reads nothing until you allow it in the system's own permission screen.
-
What is read. Apple Health: your workouts and their routes. Health Connect:
your exercise sessions, their exercise routes, and distance, plus access to that history
beyond the last 30 days so older workouts can be imported. Nothing else — no heart rate,
sleep, body measurements or any other health data.
-
Why. Only to import those workouts as trails on your device, so you can see
them on your maps. The access is read-only: Inukshuk never writes to Apple Health or Health
Connect.
-
Where it goes. Nowhere. Health data and the trails imported from it stay on
your device. They are never sent to us or to any third party, and never used for
advertising, marketing, data mining or any purpose other than showing you your own trails.
The app does not store health data in iCloud; like the rest of the app's data on your phone,
imported trails can be part of your device's own backup if you have turned device backups
on. An imported trail leaves your device only if you yourself share or export it, or send it
to Strava.
-
Stopping it. You can revoke access at any time — in the Health app or
Settings → Health → Data Access & Devices on iOS, or in Health Connect's
settings on Android — and delete imported trails in the app.
Permissions
-
Location (while using the app): to show your position and record trails.
-
Location (in the background, optional): only so that a trail you are
recording keeps recording when the screen turns off or you switch apps — the reason you
started the recording in the first place. It is used
only while a recording is running, a notification shows whenever it is
active, and it stops the moment you stop the recording. The positions go into your GPX track
on your device and nowhere else. If you decline this permission, recording still works while
the app is open on screen.
-
Apple Health (iOS, optional): read access to workouts and workout routes,
to import them as trails on your device. Inukshuk asks for no write access and never saves
anything to Health.
-
Health Connect (Android, optional): read exercise sessions, read exercise
routes, read distance, and read data older than 30 days — to import your workouts, with
their routes, as trails on your device. All four are read-only.
Children
Inukshuk is a general-audience utility and is not directed at children under 13.
Your control and rights
Because all of your maps and tracks live only on your device, you are in full control: delete
individual items in the app, revoke the location permission in your device settings, revoke
Apple Health or Health Connect access in the Health app or Health Connect settings, disconnect
Strava in Settings → Connections (optionally deleting the trails imported from it),
turn off automatic error reporting in Settings, export a copy of everything from
Settings → Your data → Download your data, or uninstall the app to erase everything.
Apart from the technical error reports described above, there is no server-side copy for us to
delete.
Changes to this policy
If this policy changes, the updated version will be posted at this URL with a new "last
updated" date.