Legal

Privacy Policy

Trailmark records where you have been. That is about as sensitive as data gets, so this policy explains exactly what the app stores, where it stores it, and the few cases in which anything leaves your phone.

Effective 24 August 2026 Last updated 24 August 2026 Applies to com.goodluck3301.gpstracking

The short version

  • Trailmark has no servers. There is no Trailmark account, no Trailmark backend, and nowhere for us to store your tracks even if we wanted to.
  • Your routes stay on your device in private app storage until you explicitly export, share, or back them up.
  • Location is recorded only while you are recording. Nothing is captured before you press start or after you press stop.
  • No advertising, no ad identifiers, no purchases.
  • Anonymous usage and crash diagnostics are on, and you can turn them off. They tell us which features get used and which crashes to fix. They never contain your coordinates, route or place names, notes, or photos. Both switches are in Settings → Privacy.
  • We never sell or rent your data, because we never receive it.

1. Who this policy covers

This policy describes how the Trailmark Android application (com.goodluck3301.gpstracking, "Trailmark", "the app") handles information. It is published by ("we", "us"), the developer of the app.

Because Trailmark operates entirely on your device, we act as a data controller only in the narrow sense of having designed how the app stores information locally. In everyday use, no personal data is transmitted to us at all.

2. What the app records

Everything in this section is created by you and stored on your device. None of it is transmitted anywhere on its own: your tracks, photos, and notes leave the device only when you export, share, or back them up yourself. The one thing the app does send by itself is anonymous diagnostics, which contain none of the below and are described in Usage and crash diagnostics.

Location data

When you start a recording, the app receives position fixes from Android's fused location provider. Each recorded point may contain latitude, longitude, timestamp, and — depending on your settings and what your hardware reports — altitude, horizontal and vertical accuracy, speed, bearing, and satellite count.

Recording continues while the app is in the background, the screen is off, or the device is locked, using an Android foreground service with a persistent notification, so a track does not need you watching the screen to stay complete. Recording stops when you stop it.

Photos you attach

You may attach photos to waypoints using the Android document picker. When you do, the app reads the image's EXIF metadata — including embedded GPS coordinates, altitude, and capture time — so it can place the photo on your track. A copy of the image is written into the app's own private storage so the route survives you clearing your camera roll. The app does not browse, index, or upload your gallery.

Route content you write

Route names, descriptions, waypoint names, categories, notes, tags, folders, and tracking templates. Whatever you type is stored as you typed it.

App settings

Theme, units, map preferences, tracking configuration, navigation and photo settings, file naming rules, and whether you have completed onboarding.

3. What the app never collects

To be explicit, Trailmark contains no code that does any of the following:

  • No advertising, ad networks, or advertising identifiers.
  • No Trailmark user account, login, email address collection, or password.
  • No access to your contacts, microphone, SMS, call logs, calendar, or browsing history.
  • No device fingerprinting, and no profiling or automated decision-making.
  • No sale, rental, or licensing of personal information to anyone.
  • No coordinates, route or place names, descriptions, notes, tags, folder names, search terms, photos, or file names in the diagnostics described next — the app is built so that none of them can be attached to a diagnostic report.

4. Usage and crash diagnostics

Trailmark uses two Google Firebase services to understand how the app is used and to find out when it breaks: Firebase Analytics and Firebase Crashlytics. This is the only data the app sends without you asking it to, and this section describes it in full.

Why it exists

Trailmark records multi-hour tracks in the background, often with the screen off and out of signal. When that fails it usually fails silently, and without diagnostics the first we hear of a lost recording is a one-star review that says "lost my hike" with no way to tell which device, which setting, or which bug caused it. Crash reports and feature counts are what make those faults fixable.

What is sent

  • Feature events. That an action happened and how it turned out — a recording started, a recording was saved, an export failed, a screen was opened.
  • Numbers and categories describing an action, never its content: how many points a track has, how long a recording ran, which built-in template or file format was chosen, whether GPS filtering was on, the error type when something failed.
  • Coarse buckets instead of exact figures where an exact figure would be too identifying — a distance is reported as a range such as "2–10 km", and the size of your route library as a range rather than a count.
  • Crash reports. The stack trace, and the state the app was in at the time: which screen you were on, whether a recording was running, roughly how large it was, and the quality of the GPS signal.
  • Standard device and app information collected by Firebase itself: app version, device model, operating-system version, language, coarse region, and a randomly generated installation identifier. That identifier is not your advertising ID and is not linked to any account.

What is never sent

No coordinates, no route or waypoint names, no descriptions, notes, tags, or folder names, no search text, no photos or captions, no file names or file paths, and no email address. Route names and search terms are reported only as a length or a count where they are reported at all. This is enforced in the app's code rather than left to convention: the events it can send are defined in one place, and each one decides which safe values to include.

The practical consequence is that a diagnostic report cannot say where you went, what you called it, or what you wrote about it.

Turning it off

Both services can be switched off independently and at any time in Settings → Privacy — one switch for usage analytics, one for crash reporting. Turning a switch off stops collection from that moment, for that install, and the choice survives resetting your other preferences. Nothing else in the app changes or stops working.

Where it goes and how long it stays

The data is processed by Google as our processor, under Google's Firebase Privacy and Security terms, and may be stored on Google servers outside your country. Crash reports are retained by Crashlytics for up to 90 days; aggregated analytics figures are retained for up to 14 months. We use it only to fix faults and decide what to build, we do not attempt to identify individual users from it, and we never sell it.

5. Permissions and why

Android will ask you to approve the sensitive ones. You can decline or later revoke any of them in Settings → Apps → Trailmark → Permissions; the affected feature stops working, but the app does not.

PermissionWhy the app asks
ACCESS_FINE_LOCATION
ACCESS_COARSE_LOCATION
Reading GPS position while recording a route and while navigating one. Without this the app cannot function.
ACCESS_BACKGROUND_LOCATION Continuing to record with the screen off or the app backgrounded. Requested separately, after foreground location, and only when you choose to allow it.
FOREGROUND_SERVICE
FOREGROUND_SERVICE_LOCATION
Running the recording service that Android requires for continuous location work.
POST_NOTIFICATIONS Showing the ongoing recording notification and navigation updates.
WAKE_LOCK Keeping the recording alive through long sessions so the device does not sleep through your hike.
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Optionally asking Android to stop killing the recording service. Entirely your choice to grant.
INTERNET
ACCESS_NETWORK_STATE
Loading Google Maps tiles, and sending the diagnostics described above while they are switched on. Recording, statistics, editing, and navigation all work offline.
CAMERA Declared for photo capture support. Photos are currently attached through the system document picker rather than in-app capture, so in practice the app does not open your camera.

6. Where your data lives

Everything sits in Trailmark's private application sandbox, which other apps on your device cannot read:

StoreContents
Local SQLite database (gps_tracking.db) Routes, GPS points in packed binary chunks, waypoints, photo metadata, folders, templates, tags, and crash-recovery state.
Private app files Copies of photos you attached, organised per route.
Preferences file Your app settings.
Cache Image thumbnails, and temporary export packages while a share is in progress.

No hosted database, no cloud mirror, no sync-by-default. If your phone is lost and you never exported or backed up a route, that route is gone — which is the honest trade-off of a local-first design.

7. Android system backup

Trailmark currently allows Android's built-in backup. If backup is enabled in your device settings, Android may copy app data — which can include your recorded routes and attached photos — to your own Google account's backup storage. This is a platform feature operated by Google under your Google account, not a Trailmark service, and we have no access to it.

You can turn it off system-wide in Settings → Google → Backup, or per app where your device offers that control.

8. Third-party services

The app is built on a small number of Google components. When these are used, your data is handled under Google's own Privacy Policy.

Google Play services — location

Supplies the position fixes the app records. Google may process device signals such as nearby Wi-Fi and cell towers to produce a fix, according to your device-level Google Location Accuracy and Location History settings, which you control in Android settings.

Google Maps

Used to draw maps. Displaying a map requires contacting Google's servers, which necessarily reveals to Google the map area being viewed and standard request data such as your IP address. Use of Maps is additionally governed by the Google Maps/Google Earth Additional Terms of Service.

Firebase Analytics and Firebase Crashlytics

Used for the anonymous usage and crash diagnostics described in Usage and crash diagnostics, which is where the detail of what is and is not sent lives. Both can be switched off in Settings → Privacy. Google acts as our processor for this data under the Firebase Privacy and Security terms.

Google Maps navigation hand-off

If you choose to navigate with the Google Maps app, Trailmark passes the destination coordinates to it via an Android intent. From that point the Google Maps app governs the experience and the data.

Other apps you share to

When you use the share sheet, the destination app receives the file you sent and applies its own privacy policy to it. Trailmark has no visibility into or control over what happens after that.

9. Sharing and export

Data leaves your device only through actions you take deliberately:

  • Exporting or sharing a route as .gptrack, GPX, KML, or GeoJSON. A route file contains the full coordinate trace, timestamps, your notes, and — for .gptrack — the attached photos. Treat it as sensitive; anyone holding it can reconstruct where you were and when.
  • Handing a destination to another navigation app.

Beyond the diagnostics above, we disclose your information to no one, for any reason, other than where we are legally compelled to — which, holding none of your route data, we could not meaningfully do anyway.

10. Retention and deletion

Your routes are kept until you delete them. There is no expiry and no server-side copy of them waiting to be purged. The only exception is the anonymous diagnostics, which Google holds on our behalf for up to 90 days for crash reports and up to 14 months for aggregated usage figures.

  • Delete one route: remove it in the app. Its points, waypoints, and photo copies are deleted with it.
  • Delete everything: uninstall Trailmark, or use Settings → Apps → Trailmark → Storage → Clear storage. This is irreversible.
  • Files you already shared cannot be recalled by us. You will need to delete them wherever you sent them.

11. Security

Your routes live in Android's private per-app storage, which is protected by the operating system's sandbox and by your device's full-disk encryption. Network calls to Google use HTTPS. Route files arriving from outside — a share sheet, an email — are parsed defensively, with archive path traversal rejected and uncompressed size capped.

The practical limits are worth stating plainly: data in the app is only as protected as the device itself. A phone with no screen lock, or one that has been rooted or compromised, offers your route history to whoever holds it. Exported files carry no encryption of their own.

12. Your rights

Depending on where you live, data protection law — such as the GDPR in the European Economic Area and the UK, or the CCPA/CPRA in California — grants you rights to access, correct, delete, restrict, object to, and port your personal data.

With Trailmark these rights are satisfied directly, without a request process, because you already hold the only copy: the app itself is your access mechanism, its editors are your correction mechanism, its export is your portability mechanism, and deletion or uninstall is your erasure mechanism. Where a legal basis is relevant, processing on your device happens on the basis of your consent, expressed through the permissions you grant and each recording you choose to start; you may withdraw it at any time by revoking permissions or removing the app.

The diagnostics are the one category we receive, and they are anonymous: they carry a random per-install identifier and no name, email, or coordinate, so we have no way to find "your" reports in order to show or erase them individually. The control we can give you over them is therefore the one that matters — the ability to stop them, in Settings → Privacy, which is also how you withdraw consent or object to that processing. Uninstalling the app ends it as well.

We hold no other personal data about you, nothing for us to look up or export on your behalf, and no personal information for us to sell or share for cross-context behavioural advertising. If you believe your rights have not been respected you may complain to your local supervisory authority.

13. Children

Trailmark is not directed to children under 13 (or the minimum age of digital consent in your country, where that is higher), and we do not knowingly collect information from them. A parent or guardian who wants a child's data removed can do so by deleting the routes or uninstalling the app, and can stop the anonymous diagnostics at any time in Settings → Privacy.

14. Changes to this policy

If the app's data practices change — a new integration, a new permission, an actual server — this policy will be updated before or alongside that release, and the "last updated" date at the top will change. Material changes will be signalled in the app or in the store listing's release notes. Continuing to use Trailmark after an update means you accept the revised policy.

15. Contact

Questions about this policy, or about privacy in the app, can go to levonmyan22@gmail.com.

Developer: