TROD · PRIVACY
Your map stays yours.
Effective September 1, 2026
trod is a travel log for recording countries, cities, journeys, and profile places. The app works without an account. Cloud features are optional.
Data stored on your iPhone
Your travel records, selected profile places, profile text, settings, and resized profile photo are stored locally on your device. Without an account, they are not sent to a trod-controlled backend.
Optional Trod account and cloud features
If you choose Sign in with Apple, Supabase processes an account identifier, authentication metadata, and the email address supplied by Apple, which may be a private relay address. Trod can store an initial account display name supplied by Apple, a generated account handle, visited country and city records, selected origin and current-country settings, public-profile choice, notification preferences, blocks, and reports. This data is used only to provide authentication, sync, Rank, public traveler maps, safety controls, and notifications.
Your custom local display name, profile photo, custom handle, and bio are not uploaded in this release.
Signing in alone does not upload an unlinked journey. If you explicitly connect your journey, Trod stores a private backup of its travel years, trip IDs and order, countries, cities, and profile-place settings. This backup is readable only by your account. Restoring a cloud journey keeps one previous local journey on this iPhone so you can undo the restore; an older recovery copy is replaced after confirmation. Erasing local data also removes this recovery copy and disconnects sync, without deleting the cloud backup.
Public maps and safety
Your travel map is private by default. If you turn on “Appear in Rank,” signed-in Trod users can see your account display name, generated handle, country and city totals, and travel map. Free-form custom places remain private; only places resolved through Apple Maps are included in public city data. Other users cannot see the local profile photo or bio. You can report a profile or block another traveler. Blocking prevents both accounts from seeing each other's public profile and Rank entry.
Travel years and trip order are not included in public maps. Turning off “Show profile places” removes the origin/current-country fields from the public map data; the owner-only records remain available to your account.
Notifications
Rank-change and weekly-summary notifications are off by default and controlled separately in the app. If you enable one, Trod stores an Apple Push Notification service device token linked to your account. You can turn either category off without losing access to other features.
Apple Maps
When you search for a city or place, the app sends the search request to Apple Maps through MapKit. Apple processes that request under Apple's Privacy Policy. trod does not receive the request on a developer-controlled server.
Photos and sharing
Optional photo import reads location and capture year from photos you select, up to 50 per batch. Original travel photos are not copied into Trod storage or uploaded to our backend. iCloud may download selected items. To find country and city names, the app sends photo coordinates to Apple's geocoding service, subject to Apple's privacy practices. Exact photo coordinates are processed transiently and are not stored in your Trod journey or sent to our backend. After your confirmation, country, city, year and city-level map coordinates become ordinary travel records under your existing sync and public-map settings. Deleting the source photo does not delete a confirmed visit. An on-device receipt allows undoing unchanged additions from the most recent import.
If you choose a profile photo, iOS gives the app only the item you select. The resized image remains on your device. Share-card images are created locally and leave the app only after you choose a destination in the iOS share sheet.
When you explicitly share a Travel Card link, the display name, handle, bio, visited-country identifiers, city names, journey years, and any From or Now country you chose to display are encoded into the link fragment. Anyone who receives the link can view and forward those fields. The profile photo and exact coordinates are not included. Browsers do not send the fragment to the hosting server, so those card fields are decoded only in the recipient's browser and are not included in ordinary server request logs.
No tracking or advertising
trod does not include advertising, analytics, attribution, payment, or third-party crash-reporting SDKs. Account and travel data is not used to track you across apps or websites and is not sold.
Delete your data
Open Profile → Data & privacy → Erase all local data to remove records stored only on the iPhone. If you have an account, open Profile → Trod account → Delete account and all data. After recent Apple confirmation, Trod revokes its Apple authorization, deletes the account and associated cloud records, and erases local Trod data. Deleting the app alone removes local data but does not delete an existing cloud account.
Service provider and retention
Supabase provides authentication, database, and server-function infrastructure. Apple provides Sign in with Apple, Maps, and push delivery. Account data remains until you delete the account, except where limited retention is required for security, abuse prevention, or law. Open reports may be reviewed to protect users and the service.
Changes and contact
This policy will be updated before materially different data processing is released.
For privacy questions or requests, email wadetoearth@gmail.com.