PeakList Legal

Privacy Policy

Effective Date: July 11, 2026 • Last Updated: July 11, 2026

This Privacy Policy explains how PeakList collects, uses, stores, shares, and protects information when you use the PeakList iOS app, widgets, public share links, related web pages, and backend services. PeakList is operated by Nathan Sobol. In this Policy, "PeakList," "we," "us," and "our" refer to Nathan Sobol and the services used to provide PeakList.

This Policy is intended to describe the app as it exists today, including accounts, public and private profiles, social features, hidden profiles and blocks, hike logs, photo uploads, guide-photo delivery, generated share cards, Mountain Postcard, Wallpaper Studio, Apple Health imports, Strava imports, Garmin imports, AllTrails exported-file imports, route imports, local-first Custom Route, explicit online route fallback, Snap route calculation, Custom Peak Lists, Community Downloads, Alpine Plant ID, Pro billing, public plan links, live shared planning and join codes, public route previews and GeoJSON downloads, trail reports, access-road follows and alerts, native push notifications, home announcements, offline maps, streamed and downloaded 3D Terrain, standard terrain layers, widgets, Live Activities, Control Widgets, Siri, Shortcuts, App Intents, Spotlight, analytics, first-party Supabase analytics, admin moderation tools, Trails, Navigate, Long Trail navigation, PeakList Global, maps, weather, Conditions Map layers, Sun Path AR, Night Sky AR, AR visible-peaks maps, Sun-Moon and aurora or space-weather tools, Compass and field diagnostics, Device Info, Water Calculator, Plan Builder, Food Library and nutrition planning, gear and carry planning, to-do queues, remote capability controls, and other location-based tools.

1. Age Requirement 2. Summary of Our Practices 3. Information We Collect 4. How We Use Information 5. Public Content and Visibility 6. How We Share Information 7. HealthKit and Sensitive Data 8. Data Retention 9. Your Choices and Privacy Rights 10. Security 11. International Processing 12. Cookies and Tracking Technologies 13. Changes to This Policy 14. Contact

1. Age Requirement

PeakList is not directed to children under 13 and is intended for users who are at least 13 years old. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information through PeakList, contact us at [email protected] and we will take appropriate steps to delete it.

2. Summary of Our Practices

  • We do not sell your personal information.
  • We do not share your personal information for cross-app behavioral advertising.
  • We do not use HealthKit data or consumer health data for advertising and do not sell consumer health data.
  • We do not run continuous background location tracking outside an active Navigate session.
  • If you start Navigate, PeakList may use background location while Navigate is active to keep navigation and local GPX recording working when your phone is locked or the app is in the background.
  • Live location and Navigate GPX traces are not uploaded or synced unless you choose to save, sync, share, upload, or publish content that includes route or location data.
  • We use precise or approximate location only when you grant permission and use features that need it, such as maps, Trails, Navigate, Mountain Finder AR, Sun Path AR, Night Sky AR, Conditions Map, weather or conditions tools, Compass and field diagnostics, Device Info, Water Calculator context, Plan Builder context, or Share Location Snapshot.
  • Custom Route, Snap, trail elevation, weather, Conditions Map, astronomy, aurora and space-weather, Alpine Plant ID, and similar provider-backed features may send the minimum coordinates, route samples, selected images, or context needed to return the result.
  • Custom Route first attempts local route calculation with bundled or downloaded trail context. A successful local calculation does not upload route points for routing. If you explicitly request online fallback, the route points and parameters needed for that request are sent to the remote routing service.
  • Opening a selected 3D Terrain region does not by itself require or transmit your live location. Terrain and offline-map requests may process account or entitlement state, selected region and asset identifiers, byte-range or download information, and ordinary network metadata.
  • If you enable notifications, PeakList and Apple Push Notification service process a linked device token and delivery information. Notification text may be visible on your lock screen or other connected Apple surfaces according to your settings.
  • Connecting Strava is optional. If you connect Strava, we request the Strava scopes shown during authorization, store OAuth tokens encrypted on our server, and use Strava activity data only to provide connection, review, import, sync, validation, and disconnect features you request.
  • AllTrails imports are user-selected exported files. PeakList does not connect to AllTrails accounts in this phase; if you import an AllTrails export, PeakList may process the file contents and source metadata needed to preview, save, deduplicate, reset, support, or validate the import.
  • Food Library search uses a bundled USDA FoodData Central-derived dataset in the app. If you save or sync planning records, food selections, quantities, weights, USDA source identifiers, and nutrition totals may be stored with your planning data.
  • Public features can make information visible to other users or to anyone with a public link, depending on the visibility choices you make.
  • Publishing a custom or community peak list can make list metadata, custom peak data, photos, creator identity, downloadable list packages, public manifests, changelogs, and related public links visible, copyable, installable, and cacheable by others.
  • Long Trail navigation sync may store session progress, daily progress, last known coordinates, accuracy, timestamps, elevation context, and optional full breadcrumb backups when you enable supported sync or backup features.
  • Authorized administrators may review reports, public or reported content, moderation context, PeakList Global validation evidence, track previews, and audit records for safety, support, abuse prevention, security, and competitive integrity.
  • Remote capability and maintenance controls may process platform, app version, build number, feature key, manifest version, rollout context, public status messages, and related audit metadata so PeakList can enable, disable, hide, rate-limit, make read-only, or require updates for features when needed.
  • Live Activities, widgets, Control Widgets, Siri, Shortcuts, App Intents, and Spotlight may display route, hike, plan, progress, checklist, ETA, risk, and status information on Apple system surfaces depending on your device settings and feature choices.
  • PeakList Global uses in-app Navigate telemetry and validated Strava, Garmin, or AllTrails imports where enabled from official routes to support personal analytics, validation, standings, titles, and anti-abuse review. Public standings require opt-in. Private navigated efforts and imported efforts may still support your personal analytics.
  • PeakList Global public surfaces may show holder identity, scope names, scores, elapsed time, achieved date, summary stats, and leaderboard placement, but raw GPS tracks are not shown publicly.
  • Health, fitness, route, location, planning, food, gear, water, and safety-diagnostic information can be sensitive. We use it only to provide requested app features, sync features you enable, safety and diagnostics tools, and related support.

3. Information We Collect

Account and Authentication Data

If you create an account, we may collect your email address, authentication user identifier, display name, profile metadata, profile visibility setting, avatar or profile picture selection, sign-in provider identifiers, connected service identifiers such as Strava athlete identifiers or usernames, and related account settings. Sign in with Apple, Google sign-in, Strava authorization, or email/password sign-in may provide authentication or connection identifiers needed to create, secure, or connect your account.

Profile, Social, and Public Activity Data

If you use profile or social features, we may collect profile text, display name, profile image choices, website or social links you add, hiking stats you choose to show, friend requests, friendships, blocks, hidden-profile state, moderation reports, profile visibility settings, and public activity. To enforce privacy choices and prevent spam, enumeration, or abuse, we may store pseudonymized request-attempt records, rate-limit ledgers, relationship state, and aggregate security audit counts. If you make a profile, hike log, photo, trail report, achievement, PeakList Global standing, or activity public, it may be visible to other users and may appear in public profile, recent activity, leaderboard, map, or community surfaces.

Hiking, Checklist, Planning, and Journal Data

PeakList may store checklist progress, peak lists, favorites, wishlists, to-do queues, achievements, games, scores, streaks, saved hikes, hike logs, completion dates, notes, tags, routes, custom route drafts, snapped route results, distance, duration, elevation gain, gear plans, inventory items, Food Library selections, food names, USDA source identifiers, quantities, weights, calories, macronutrients, sodium, calories per day, calories per ounce, saved trip plans, templates, generated plan content, public plan share links, live plan edits, live plan participation, short-lived join codes and anti-guessing attempts, meeting spots, participant identity choices, presence state, review-factor choices, carry, food, and water-planning values, trail condition reports, access reports, followed access roads and alert state, home-announcement read or dismissal state, PeakList Global participation state, navigated or imported effort summaries, holder titles, leaderboard placement, and other information you enter or generate in the app. Some features work locally on your device; signed-in users may sync supported data through cloud services.

Custom Peak Lists and Community Downloads

If you create, sync, publish, download, install, or update Custom Peak Lists or Community Downloads, PeakList may process list title, description, creator display name, visibility, publication state, version, schema version, region, map or trail association, list identifiers, list JSON, manifests, changelogs, custom peak names, slugs, coordinates, elevation, prominence, routes, notes, extra fields, photo counts, uploaded peak-list photos, content type, dimensions, byte count, file hash, object keys, installation records, installed version, update read or dismissal state, custom-list progress, downloaded-list progress, completion state, favorite or wishlist state, monthly or date-based progress, and related metadata. Draft and private lists are intended for your account and supported sync features. Published community lists, public list photos, manifests, changelogs, and downloadable packages are public features and may be visible, copied, installed, cached, indexed, screenshotted, or stored by others.

Long Trail Navigation Data

If you use Long Trail navigation or related cloud restore features, PeakList may store trail identifier, direction, active or completed state, local session identifier, start, update, and completion timestamps, pack version, total miles, start and end mile markers, current and farthest progress, current elevation, daily progress, last known latitude and longitude, horizontal accuracy, last location timestamp, sparse checkpoint data, optional full-track breadcrumb points, recorded timestamps, elevation samples, accuracy values, canonical mile markers, and related metadata. Long Trail navigation data is intended to be owner-scoped for private restore and continuity unless you choose to save, sync, share, export, submit, or publish content that includes it.

PeakList Global Competitive Telemetry

If you use Navigate on official PeakList trail data, or if you submit a validated Strava, Garmin, or AllTrails import where PeakList enables that source, PeakList may create a PeakList Global effort draft or effort record. This may include the linked hike log, user identifier, list, peak, trail, trail segment, route context, trailhead identifiers, source application, external workout identifier, start and end time, elapsed and moving time, distance, elevation gain and loss, highest and lowest elevation, summit and checkpoint matching, route-match score, GPS quality score, speed and pace summaries, season identifier, eligibility status, invalid or review reason, public/private visibility, telemetry digest, downsampled validation samples, and related metadata. We use this information to determine whether an effort is navigated, validated from Strava, Garmin, or AllTrails, not navigated, needs review, or rejected; to compute Peak Holder, Trail Holder, Trail Segment Holder, Segment Best, Personal Best, targets, achievements, metadata leaderboards, and analytics; to prevent duplicate or manipulated submissions; and to audit holder changes.

Manual logs, generic imported GPX, Apple Health, FIT, TCX, bulk import, web import, duplicated logs, and similar non-Navigate sources may still support personal hike history where available, but they are not intended to create public PeakList Global standings. Validated Strava, Garmin, or AllTrails imports may qualify for public PeakList Global only where PeakList expressly enables that source and the same server-side route, segment, summit, and integrity checks pass. AllTrails exported files are not automatically eligible. Raw or downsampled validation tracks are treated as private owner/service data and are not displayed on public standings. If you opt into public PeakList Global standings, public surfaces may show your display name, profile image or initials, relevant public profile identity, scope held or attempted, score, elapsed time, achieved date, rank, title, route or peak name, summary telemetry, and recent activity related to public standings.

Imported Route, Fitness, and Health Data

If you choose to import workouts or routes from Apple Health, Strava, Garmin, AllTrails exported files, GPX, TCX, FIT, KML, or similar files, PeakList may process workout dates, activity labels, duration, distance, source app metadata, route summaries, track points, elevation data, source filenames, file format, file digests, and route file contents. Apple Health access is requested through Apple's permission prompts. Strava access is requested through Strava OAuth; PeakList may store Strava connection status, athlete identifier, username or profile names returned by Strava, requested and granted scopes, whether private-activity access was requested, connection and token expiration dates, last sync time, encrypted access and refresh tokens, OAuth state records, webhook receipts, activity summaries, route streams, external workout identifiers, and imported activity details needed to review, import, validate, disconnect, troubleshoot, and prevent abuse. Garmin access is requested through Garmin authorization or Garmin Activity API consent flows; PeakList may store Garmin connection status, Garmin account identifiers or display names returned by Garmin, requested and granted scopes, connection and token expiration dates, last sync time, encrypted access and refresh tokens or subscription secrets, OAuth state records, webhook receipts, activity summaries, FIT/GPX/TCX files, route samples, external workout identifiers, and imported activity details needed to review, import, validate, disconnect, troubleshoot, and prevent abuse. AllTrails exported files are user-provided imports; PeakList does not connect to AllTrails accounts, does not request AllTrails account credentials, and does not store AllTrails tokens. Provider route streams and files may include latitude/longitude, altitude, time, and distance samples. If you authorize private activity access from a connected provider, PeakList may request private activities for the import flow until you disconnect the provider, revoke access, or the authorization expires. Route retention for Apple Health imports is optional and controlled by your settings. Custom Route and Snap may process selected endpoints, waypoints, route geometry, snapped waypoints, distance, duration, and elevation summaries to calculate or save a route. Custom Route first attempts local route calculation using bundled or downloaded public trail context. Successful local route calculation does not upload route points for routing. Public trail-context downloads may disclose ordinary network metadata to the delivery provider. If you explicitly request an online routing fallback, PeakList sends the route points and routing parameters needed to GraphHopper or another disclosed routing provider. Route hashes, quota records, bounded diagnostics, and provider-response metadata may be processed to return results, reduce duplicate calls, enforce limits, and prevent abuse. If you save or sync a hike log that includes imported health, fitness, Strava, Garmin, AllTrails, or route data, that data may be stored with the hike log.

Location, Sensor, Camera, and Photo Permission Data

PeakList may request access to location, camera, photo library, motion, altitude, heading, and related sensor data for features such as Mountain Finder AR, Night Sky AR, Sun Path AR, Compass, Field Diagnostics, Trails and Navigate, map centering, weather and conditions lookup, Conditions Map layers, aurora or space-weather context, Device Info diagnostics, Water Calculator or Plan Builder context, Custom Route, Snap, Share Location Snapshot, Alpine Plant ID, wallpaper or image saving, hike photo selection, and PeakList Global validation. Environment and astronomy requests may use rounded coordinates, elevation, date, time, and timezone context to return weather, daylight, night-sky, Sun-Moon, aurora, or other conditions results. Device Info and field diagnostics may process device, battery, motion, compass, altitude, location-permission, camera-permission, and network-reachability signals to display diagnostics. PeakList uses background location only during an active Navigate session, and only to keep navigation and local GPX recording working while your phone is locked or the app is in the background. Live location and locally recorded Navigate GPX traces are not uploaded or synced unless you choose to save, sync, share, upload, submit, or publish content that includes route or location data, including PeakList Global efforts. Location and sensor data may otherwise remain local unless you save, sync, share, upload, submit, or publish content that includes it.

3D Terrain, Offline Maps, and Asset Delivery

When you open 3D Terrain, a standard terrain layer, or an offline-map feature, PeakList may process your authenticated account or applicable entitlement status, selected list, map, or region identifiers, catalog and manifest versions, requested asset paths and byte ranges, download progress and integrity information, app and build information, cache state, and ordinary network metadata through PeakList asset services hosted with Cloudflare. Opening a selected 3D Terrain region does not by itself require or transmit your live device location.

Terrain catalogs and streamed visual or elevation assets may be cached on your device. The streaming cache is managed under the limit you select where controls are offered. Complete offline regional packages may include large PMTiles, GeoTIFF, trail-context, or related files and can consume substantial device storage, network data, battery, memory, and processing resources. Downloaded files generally remain until you remove or repair them, clear app data, uninstall the app, or the operating system removes eligible cached data, subject to device backup behavior. Access may require an account and/or an applicable paid entitlement. Asset sources, formats, availability, and entitlement rules may change.

If analytics is enabled, PeakList may record terrain events such as map or region identifier, layer type, open, close, abandonment, render or download failure, time to readiness, reset action, and subscription status. PeakList is designed not to include route coordinates in these terrain analytics events.

Guide photos and other first-party media may be delivered from PeakList or White Mountain Pictures domains using Cloudflare/R2 and image-transformation services. Those requests may expose the requested asset, device request information, IP address, and ordinary delivery logs to the hosting provider. Guide photos are app content, not user-uploaded photos.

Native Push Notifications and Access-Road Alerts

If you enable notifications, PeakList registers an Apple Push Notification service device token and stores the token and a cryptographic hash linked to your account. We may also store push environment, bundle identifier, platform, app version and build, install identifier, locale, time zone, permission status, notification preferences, enabled or revoked state, and last-seen timestamps. Notification delivery records may include notification type and category, recipient and device identifiers, status, attempt count, scheduled, sent, failed, opened, expired, or updated timestamps, deduplication or collapse identifiers, provider response or error details, and limited operational metadata.

If you follow an access road, PeakList stores the road source identifiers, display information, follow and notification state, last-notified history reference, and timestamps needed to monitor and alert you to status changes. Apple receives the device token and notification payload needed to deliver a push. Depending on your iOS, lock-screen, Focus, Apple Watch, CarPlay, or notification-preview settings, notification content may be visible to anyone with access to those surfaces. You can change PeakList notification preferences, unfollow an access road, or disable notifications in iOS Settings. Delivery is not guaranteed, and PeakList is not an emergency notification service.

Uploaded Photos and Media

If you upload hike-log photos, custom peak-list photos, or create, save, export, or share generated images such as share cards, Mountain Postcard cards, wallpapers, or Plant ID cards, the app may process selected images, generated renders, captions, visibility settings, file size, content type, file hash, dimensions, object keys, hike-log identifiers, custom list identifiers, peak or route context, style choices, and related metadata. Photo files that you upload for cloud storage are stored in Cloudflare R2 using upload URLs issued by PeakList backend services, and metadata is stored in Supabase. Generated images saved to your device may remain local unless you share, upload, sync, publish, or otherwise choose to send them through app features or iOS share sheets. Uploaded photos may be private or public depending on the visibility settings for the photo, hike log, custom list, community list, or related feature. Public photos may be visible to other users or public viewers and may be copied, cached, installed, indexed, screenshotted, or stored outside PeakList. Deleted photos and related metadata are removed from active app surfaces, subject to backups, security logs, moderation records, audit records, and legal retention needs.

Alpine Plant ID Data

If you use Alpine Plant ID, the selected camera or photo-library image is sent to PeakList backend services and then to the plant identification provider, currently PlantNet, for live identification. Original Plant ID images are not stored by default for the current version, but PeakList may store request metadata, quota usage, image hashes, provider response metadata, normalized identification results, and saved share-card metadata when needed to provide the feature, prevent abuse, or show your history.

Support, Suggest Edit, and Safety Reports

If you contact support, submit a suggested edit, report a trail issue, report a user, or send a moderation report, we may collect your message, reply email, selected list or screen, support category, app version, build number, device model, operating system, platform, network reachability, authentication state, last known error, reported content identifiers, and other diagnostics you choose to include. If you request or include a support health snapshot, PeakList may process sync health, last-updated timestamps, row counts, pending sync counts, active plan state, entitlement state, database or schema versions, and related account diagnostics to troubleshoot your account. Backend services may hash IP address and user-agent information for rate limiting and abuse prevention. Where support anti-abuse verification is enabled, PeakList or Cloudflare Turnstile may process a challenge token and ordinary network metadata, and the verification request may include your IP address. Support messages and important operational notices may be delivered through Resend or similar email services.

Moderation and Administrative Review Data

PeakList may use authorized administrative tools to review reports, public or reported content, public profiles, friend-request or block context, public hike logs, public plans, trail condition reports, public media, Custom Peak Lists, Community Downloads, PeakList Global efforts, manual review requests, validation telemetry, simplified track previews, profile safety context, moderation queues, backend capability status, account status, and feature status where needed for safety, support, abuse prevention, security, policy enforcement, legal compliance, competitive integrity, maintenance, or release safety. Administrative records may include moderator allowlist records, moderator email or user identifier, role, permitted actions, moderation cases, capability or feature keys, action type, target type, target identifier, reason code, public messages, notes, previous state, new state, audit metadata, timestamps, and idempotency keys. Moderation, capability, and audit records may preserve information after content is edited, hidden, removed, unpublished, deleted from active surfaces, disabled, made read-only, or otherwise changed.

Billing and Entitlement Data

If you purchase PeakList Pro or another paid feature, the payment provider depends on where you made the purchase. For purchases made in the iOS app, Apple processes payment. For purchases made on PeakList web, Stripe processes payment. PeakList does not receive or store your full payment card number. We may receive and store App Store transaction identifiers, product identifiers, signed transaction data, app account tokens, subscription status, renewal state, grace period state, refund or revocation state, lifetime purchase status, and entitlement history. For web purchases, we may receive and store Stripe customer identifiers, subscription identifiers, price and plan codes, billing email, invoice identifiers, payment status, payment amount and currency, tax and refund status, webhook event identifiers, webhook/audit records, subscription cancellation or renewal status, and related entitlement history. We use this billing information to unlock Pro features, process taxes, invoices, refunds, support requests, prevent fraud, reconcile webhooks, and provide billing support.

Analytics, Crash, Performance, and Gameplay Data

PeakList may collect product interaction, crash, performance, diagnostic, and gameplay content data, including app version, build number, device type, operating system, screen or feature events, feature engagement, Custom Route calculation events, 3D Terrain map or region identifiers and render events, custom list and community download actions, notification preference or delivery events, support or report actions, subscription or paywall actions, remote capability or maintenance events, game sessions, game rounds, saved game progress, scores, streaks, unlocks, achievement progression, PeakList Global standings and submission states, and similar usage data. Firebase Analytics delivery is controlled by your analytics preference where applicable; when enabled, Firebase may process app instance identifiers or device-level identifiers for analytics. When analytics are enabled and you are signed in, PeakList may also send allowlisted first-party analytics events to Supabase, linked to your authenticated user identifier, with event name, source, platform, app version, session identifier, event time, and sanitized top-level scalar properties. PeakList filters sensitive property keys and text where supported, but linked analytics may still be personal information. Some local functional analytics may still be processed on-device or in app storage to power achievements, game progression, PeakList Global, admin aggregate reporting, backend capability controls, and app functionality.

Widgets, App Intents, App Group, and Local Storage

PeakList stores data locally on your device using UserDefaults, app storage, local files, caches, app group storage, and similar mechanisms. This may include preferences, read or dismissed home announcements, offline datasets, downloaded maps, terrain packages, trail-context files, streamed terrain caches, trail files, cached images, widget snapshots, Live Activity state, Lock Screen, Dynamic Island, StandBy, Home Screen or Control Widget snapshots, Siri and Shortcuts data, App Intents data, Spotlight indexing or search metadata, checklist state, recent app state, tutorial state, local hike logs, local custom-list drafts, local navigation sessions, cached backend capability manifests, and imported files. PeakList may read or store local file metadata such as modification dates, sizes, hashes, integrity results, or cache freshness timestamps to manage downloads, offline assets, local caches, sync freshness, imported files, and app functionality. Widgets and extensions are designed to use shared app-group snapshots and local preferences and do not independently collect data for tracking or advertising. Apple system surfaces may display route, hike, plan, progress, checklist, ETA, risk, navigation, offline, notification, or status information depending on your device settings and feature choices. Device backups, iCloud device backup settings, Spotlight behavior, or other iOS behavior may also affect local copies.

4. How We Use Information

We use information to:

  • Provide and personalize app features, accounts, sync, public profiles, hike logs, photos, social features, hidden profiles, Trails, Navigate, Long Trail navigation, maps, 3D Terrain, offline terrain and maps, weather, Conditions Map, Sun Path AR, Night Sky AR, AR visible-peaks maps, Sun-Moon tools, aurora and space-weather tools, Compass and field diagnostics, Device Info, Water Calculator, Plan Builder, Food Library, local and remote Custom Route calculation, Snap, Custom Peak Lists, Community Downloads, live shared plans and join codes, access-road follows and alerts, native notifications, home announcements, public route previews, planning tools, widgets, Live Activities, Siri, App Intents, games, PeakList Global, achievements, and Pro access.
  • Process Apple Health, Strava, Garmin, route, image, location, weather-query, route calculation, terrain/elevation, sensor, conditions, astronomy, aurora, notification, gear, food, water, and planning data when you request related features.
  • Display public content according to your visibility choices.
  • Validate Navigate efforts and eligible Strava or Garmin imports, compute PeakList Global standings, detect duplicate or manipulated submissions, process holder changes, provide personal targets, and preserve audit records for competitive integrity.
  • Operate billing, subscription, trial, grace-period, restore-purchase, refund, and entitlement systems.
  • Provide support, respond to privacy requests, investigate bugs, process support health snapshots, and process suggested edits or safety reports.
  • Moderate content, enforce community rules, review reports, preserve audit records, prevent abuse, protect security, rate-limit backend services, verify support anti-abuse challenges, and operate remote capability, read-only, maintenance, and update controls.
  • Improve app performance, diagnose crashes, understand feature usage, prepare aggregate admin analytics, and develop new features.
  • Comply with legal obligations, accounting requirements, App Store requirements, fraud prevention needs, and enforceable requests from authorities.

Where law requires a legal basis, we rely on contract performance, consent, legitimate interests, legal obligations, and, when relevant, your decision to make information public or request a specific feature.

5. Public Content and Visibility

Some PeakList features are private by default, while others are designed for sharing. Public profile information, public hike logs, public photos, public custom or community peak lists, public custom-list photos, downloadable list packages, manifests, changelogs, recent activity entries, public trail condition reports, public plan links, live shared plan content, public route previews, GeoJSON downloads, public achievements, public PeakList Global standings, holder titles, ranks, and similar content may be visible to other users or anyone with access to a public link or public app surface. Public plan links, public profile pages, public custom or community lists, public route previews, downloadable route geometry, and public leaderboard or map surfaces should be treated as public. Public web pages, shared links, list packages, photos, standings, and map or leaderboard entries may be copied, cached, linked, indexed, installed, downloaded, screenshotted, or viewed outside PeakList. Do not publish or opt into public features for content that you do not want others to see.

Live-plan join codes are intended to be short-lived access credentials, but anyone who receives a valid code may be able to request access to the associated plan. Do not post a join code publicly unless you intend broad access, and revoke or replace a code if it is disclosed unexpectedly. Plan names, timing, route context, participant state, meeting information, or urgent-status content may also be visible to invited participants or in notifications on their devices.

You can change many visibility settings in the app, delete supported content, unpublish or delete supported custom lists and photos, revoke public plan links, leave supported live plan sessions, turn off public PeakList Global standings where supported, block users, or report content. Turning off public PeakList Global standings generally stops new public holder appearances, but private navigated efforts may still support personal analytics, and copies or historical records may remain in backups, logs, moderation records, audit records, caches, screenshots, external shares, downloaded packages, installed community lists, or places where other users already accessed the content.

6. How We Share Information

Service Providers

We use service providers to operate PeakList. These may include Supabase for authentication, database, storage metadata, edge functions, Strava and Garmin token vault records, first-party analytics, moderation and admin data, backend capability manifests, and account services; Cloudflare Workers, Cloudflare Access, Turnstile, Workers KV, and R2 for backend APIs, support anti-abuse verification, admin worker access controls, photo storage, custom-list storage, public assets, downloadable list packages, offline map and trail downloads, StoreKit sync, Strava and Garmin integration endpoints, Stripe webhook handling, account deletion workflows, and user-owned object cleanup; Firebase and Google services for analytics, crash, and performance diagnostics; Resend for support and operational email; Apple for App Store payments, Sign in with Apple, HealthKit, MapKit, StoreKit, ActivityKit, widgets, App Intents, Spotlight, Siri, Shortcuts, and system permissions; Stripe for PeakList web billing, Customer Portal, invoices, tax and refund support, webhook delivery, and payment processing metadata; Google for Google sign-in and related platform services; Strava and Garmin for user-authorized activity import; GraphHopper and OpenStreetMap contributors for route calculation and route data; PlantNet for plant identification; NOAA/NWS and NOAA/SWPC for weather, alerts, space-weather, and aurora data; and USDA FoodData Central as the source for bundled food and nutrition reference data.

Cloudflare also supports PeakList-hosted terrain, standard-map, public trail-context, offline-download, and White Mountain Pictures guide-photo delivery. Apple Push Notification service delivers optional notifications. Sunrise-Sunset API (`api.sunrise-sunset.org`) may support daylight calculations. GraphHopper receives route points only when an online route request is made, including when you explicitly choose online fallback after local route calculation is unavailable or unsuccessful. These providers may process the request data and ordinary network metadata needed to perform their role.

Public and User-Directed Sharing

We share information when you direct us to do so, such as publishing a public profile, uploading public photos, publishing a custom or community peak list, making custom-list photos public, joining public PeakList Global standings, sharing a location snapshot, creating or joining a public plan link, sharing live plan content with collaborators, exporting a route, making a route preview or GeoJSON download available through a public link, connecting or disconnecting Strava or Garmin, submitting a public trail report, using native iOS share sheets, or sending a support request.

External Data Providers

PeakList uses public and third-party data sources for maps, route calculation, route snapping, weather, forecasts, alerts, trail and access information, trail elevation profiles, Conditions Map layers, wildfire, streamflow, air quality, snow depth, UV, observations, sunrise and sunset, astronomy, night-sky previews, aurora and space-weather, plant identification, mountain content, activity import, and food and nutrition reference data. Providers may include Apple, Strava, Garmin, GraphHopper, OpenStreetMap contributors, NOAA/NWS, NOAA/SWPC, Open-Meteo, OpenTopoData, USGS, NASA FIRMS, AirNow, NOAA NOHRSC, NOAA UV data sources, U.S. Naval Observatory, PlantNet, USDA FoodData Central, Wikimedia Commons, and other public or licensed sources. When the app or backend requests data from these providers, they may receive the requested coordinates, waypoints, route samples, route or peak context, activity identifiers, query details, dates, times, timezone, elevation, endpoint information, and ordinary network metadata needed to return the data. Bundled USDA FoodData Central-derived food data is searched locally in the app unless a future feature clearly states otherwise.

Legal, Safety, and Business Reasons

We may disclose information if we believe it is reasonably necessary to comply with law, protect users, investigate fraud or abuse, enforce our Terms, respond to lawful requests, protect rights or safety, or transfer the service in connection with a merger, acquisition, restructuring, or similar transaction. PeakList is not an emergency monitoring or dispatch service, and we do not routinely review user data to identify emergencies.

7. HealthKit and Sensitive Data

PeakList uses Apple Health data only with your permission and only for app functionality you request, such as importing workouts into hike logs. PeakList does not use HealthKit data for advertising, does not sell HealthKit data, and does not share HealthKit data with advertising platforms. You can revoke Apple Health permissions in iOS settings or the Health app. If you save or sync a hike log containing HealthKit-derived information, it will be handled under this Policy like other hike-log data.

Precise location, route tracks, custom routes, custom or community list coordinates and routes, public downloadable route geometry, Long Trail progress and breadcrumbs, Strava activities, health, fitness, photos, planning notes, food selections, nutrition estimates, gear lists, water estimates, public plans, live shared plans, Live Activity and widget status, Conditions Map lookups, astronomy or night-sky context, trail reports, PeakList Global standings, and safety diagnostics can reveal sensitive information about where you go, when you hike, how fast you move, what you carry or eat, and what routes you prefer. Use visibility controls, device-surface settings, and publication choices carefully before publishing, sharing, importing, backing up, displaying, or joining public standings for content that includes this information.

PeakList also publishes a separate Consumer Health Data Privacy Policy that describes health, fitness, nutrition, route, location-derived, and related consumer health data in greater detail, including its sources, purposes, sharing, consent, and deletion rights. That notice supplements this Policy and controls for consumer health data where it provides more specific protections. Consent to the Terms or acknowledgement of this general Policy is not treated as consent to collect or share consumer health data where separate affirmative consent is required by law.

8. Data Retention

We retain information for as long as needed to provide PeakList, maintain your account, preserve synced content, operate Pro billing, provide support, comply with law, resolve disputes, prevent abuse, and enforce our Terms.

In general:

  • Account data remains until you delete your account or request deletion, subject to limited retention for legal, security, billing, fraud-prevention, and backup purposes.
  • Synced hike logs, photos, profile content, social data, saved plans, food selections, nutrition totals, custom routes, public reports, PeakList Global efforts, standings, holder-change events, validation summaries, imported Strava or Garmin activity details saved into hike logs, and game progression remain until deleted, unpublished, reset, superseded, seasonally replaced, or removed by moderation, subject to backups, audit needs, fraud-prevention, dispute resolution, and legal retention.
  • Custom list drafts, published versions, manifests, changelogs, uploaded custom-list photos, install records, update-read state, and custom or downloaded list progress remain until deleted, unpublished, superseded, removed by moderation, or no longer needed to provide the feature, subject to public copies, downloaded or installed copies, caches, backups, moderation records, audit records, legal needs, and abuse-prevention needs.
  • Long Trail navigation sessions, daily progress, last known location summaries, and optional full-track breadcrumb points remain until deleted, overwritten, reset, or no longer needed to provide sync and restore, subject to backups, security, legal, dispute-resolution, and abuse-prevention needs.
  • First-party analytics event rows and aggregate admin analytics may be retained as needed to understand feature usage, diagnose issues, prevent abuse, support users, and improve PeakList. Aggregated, de-identified, or non-identifying analytics may be retained longer for product improvement.
  • Moderation cases, moderation actions, admin allowlist records, backend capability records, maintenance events, notes, previous and new states, and audit metadata may be retained as needed for safety, support, abuse prevention, competitive integrity, legal compliance, dispute resolution, release safety, and enforcement, even when the underlying content is later edited, unpublished, hidden, removed, disabled, made read-only, or deleted from active user surfaces.
  • Strava and Garmin connection records, encrypted OAuth tokens, and encrypted Garmin subscription secrets remain until you disconnect the provider, revoke access, delete your account, or the connection is otherwise removed, subject to limited retention for security, abuse-prevention, webhook processing, troubleshooting, audit, backup, legal, and dispute-resolution needs. Disconnecting Strava or Garmin stops future provider import access but does not automatically delete hike logs or PeakList Global records you already saved or submitted from that provider. Deleting imported hike logs, deleting eligible PeakList Global records where supported, or deleting your account removes provider-derived data from active PeakList surfaces subject to backups, logs, audit, moderation, legal, dispute-resolution, and technical retention limits.
  • Custom Route calculation cache, route hashes, quota records, and provider response metadata may be retained for a limited period to return requested routes, reduce repeated provider calls, enforce limits, diagnose failures, and prevent abuse.
  • StoreKit, Stripe, webhook audit, and billing records may be retained as needed for accounting, tax, entitlement, invoice, refund, fraud-prevention, dispute, customer support, App Store compliance, payment-provider compliance, and legal needs.
  • Support emails, support health snapshots, challenge-verification metadata, rate-limit records, and diagnostics may be retained as needed to respond, maintain service quality, prevent abuse, investigate account or sync issues, and keep business records.
  • Raw first-party analytics events are generally deleted after 180 days under the current operational-retention schedule. Aggregated, de-identified, or non-identifying statistics may be retained longer.
  • Used or expired OAuth state records are generally deleted after 1 day. Strava and Garmin webhook records are generally deleted after 90 days.
  • Abandoned or discarded AllTrails import batches are generally deleted after 30 days; non-qualified AllTrails import receipts may be retained for up to 365 days for integrity, duplicate prevention, support, and audit purposes.
  • Completed terminal outbox and repair-job records are generally deleted after 90 days. Cron execution logs are generally deleted after 30 days.
  • Live-plan join-code attempt records are generally deleted after 1 day. Join codes may expire or be revoked sooner according to plan state and security controls.
  • Moderation actions and closed moderation cases are generally retained for up to 365 days under the implemented closure criteria, and longer where reasonably necessary for an active investigation, repeat-abuse prevention, legal hold, safety, or dispute.
  • Active push-device registrations and notification preferences are retained while needed to provide notifications or until disabled, revoked, replaced, account deletion is completed, or the record is no longer operationally necessary. Notification and delivery records are retained according to their expiry, delivery, security, troubleshooting, and cleanup criteria. We do not promise a shorter fixed period until the corresponding cleanup is technically enforced.
  • Local data remains on your device until you delete it, reset it, uninstall the app, clear app data, or change device backup settings.

Deletion from active systems may not immediately remove information from encrypted backups, provider systems, public copies, downloaded packages, device backups, security logs, legal holds, or records we must retain for tax, billing, fraud, safety, moderation, dispute, or compliance purposes. We limit retained information to what is reasonably necessary for those purposes and delete or de-identify it when the applicable need ends.

9. Your Choices and Privacy Rights

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or information about how your personal data is used. California and other US state privacy laws may also provide rights to know, access, correct, delete, obtain a copy, opt out of sale or sharing, limit certain uses of sensitive personal information, and avoid discrimination for exercising privacy rights.

PeakList does not sell personal information or share personal information for cross-context behavioral advertising. We use sensitive personal information only for the features, security, support, and legal purposes described in this Policy.

You can use in-app controls to change profile visibility, manage public content, publish, unpublish, or delete supported custom lists and photos, delete supported custom or downloaded list progress, export supported records, reset synced app data, delete supported content, delete supported saved plans, food selections, or routes, disable supported full-track backups, stop background location by ending navigation or changing iOS location permissions, manage Live Activities, widgets, Siri, Shortcuts, App Intents, and Spotlight through app or iOS settings where available, disconnect Strava or Garmin, disable analytics delivery where available, revoke public plan links, leave supported live plan sessions, turn off public PeakList Global standings where supported, revoke Health and location permissions through iOS, revoke Strava access through Strava where available, revoke Garmin access through Garmin where available, and request account deletion. Account deletion uses a backend-mediated workflow that may revoke Supabase sessions, remove active user-owned Cloudflare R2 objects, delete active Supabase account data, and ask Apple or Google to revoke available social sign-in tokens where provider credentials are available. Deleting your PeakList account does not automatically cancel App Store or PeakList web subscriptions, which must be managed through the payment provider. You may also contact [email protected]. We may need to verify your identity before fulfilling a request, and some requests may be limited where allowed by law, such as when records must be retained for security, legal, tax, billing, fraud-prevention, moderation, competitive integrity, audit, dispute-resolution, public-interest, or safety reasons.

To submit a privacy request, email [email protected] with the subject “Privacy Request” and identify the right you wish to exercise. An authorized agent may submit a request where applicable, but we may require proof of authority and may verify the request directly with you. If we deny or limit a request, you may appeal by emailing [email protected] with the subject “Privacy Appeal” and explaining why you believe the decision should be reconsidered. We will review the appeal and respond within the time required by applicable law. You may also complain to your state attorney general, data-protection authority, or other regulator where that right applies.

You may withdraw consent prospectively through the relevant in-app or iOS permission control, by disconnecting the relevant provider, or by contacting support. Withdrawal does not affect processing already performed lawfully and may make the related feature unavailable. PeakList will not discriminate against you for exercising applicable privacy rights, although a feature may require information that is necessary to perform it.

10. Security

We use reasonable technical, administrative, and organizational safeguards designed to protect information. These include platform permission prompts, authentication, access controls, row-level security where supported, scoped upload URLs, encryption for Strava and Garmin OAuth token storage, service-side secrets, rate limits, support anti-abuse checks, backend capability controls, and operational monitoring. No system is perfectly secure. You are responsible for maintaining the security of your device, account credentials, connected third-party accounts, and public sharing choices.

11. International Processing

PeakList is operated from the United States, and our service providers may process information in the United States and other countries. Privacy laws in those countries may differ from the laws where you live. Where required, we rely on appropriate legal mechanisms for international processing and transfers, which may include adequacy decisions, contractual safeguards, or another lawful transfer mechanism. You may contact us for information about safeguards that apply to your information.

Where the GDPR, UK GDPR, or a similar law applies, the controller is Nathan Sobol. Depending on the processing, our legal basis may be performance of the service contract; your consent for optional analytics, permissions, connected providers, public sharing, or sensitive processing where required; our legitimate interests in security, fraud prevention, service operation, support, product improvement, and enforcing rules; or compliance with legal obligations. You may have rights to access, correct, erase, restrict, port, or object to processing, withdraw consent, and complain to a supervisory authority. Whether information is required depends on the feature: account and authentication information is required for signed-in services, while optional permissions, imports, public sharing, notifications, and analytics can generally be declined, with the related feature unavailable or limited.

12. Cookies and Tracking Technologies

The native iOS app does not use traditional browser cookies. Public web pages, public share links, support endpoints, Cloudflare Turnstile where enabled, and backend services may create ordinary server logs or use similar technologies for security, diagnostics, abuse prevention, and service operation. PeakList does not track you across third-party apps or websites for advertising.

13. Changes to This Policy

We may update this Privacy Policy as PeakList changes. When we make material changes, we will update the “Last Updated” and effective dates and provide notice in the app, by email, through App Store metadata, or by other reasonable means appropriate to the change. The revised Policy governs processing after its effective date. Where law requires affirmative consent for new collection, use, or sharing, we will request that consent rather than treating continued use as consent.

14. Contact

For privacy requests, account deletion requests, legal notices, or questions about this Privacy Policy, contact:

Controller and operator: Nathan Sobol Email: [email protected]

Please include enough information for us to understand your request and verify your identity where required. If a law requires correspondence by mail, contact us by email to request the current mailing address for legal or privacy correspondence. Do not send passwords, full payment-card numbers, government identification numbers, or unnecessary health or location details in an initial email.

View Consumer Health Data Privacy Policy View Terms Open support Back to PeakList