HikeCue Privacy Policy
Oct 7, 2026 ยท Version 1.0
HikeCue collects the minimum needed to notify the people you choose if you do not check in after a solo hike. No phone numbers, no advertising, no sale of data. Location is used only while a trip is active, and trip details are erased 7 days after the trip ends.
1. Who we are and what this covers
HikeCue is operated by the individual developer listed as the seller of HikeCue on the App Store ("HikeCue", "we"). Contact: support@hikecue.app.
This policy covers the HikeCue iOS app, the status pages and invitation pages at hikecue.app, and the emails we send. It applies to two groups of people:
- Hikers: people who sign in and register trips.
- Contacts: people a hiker adds as an emergency contact. Contacts do not need an account. Section 4 is written for them.
Effective date: October 7, 2026. Version 1.0.
2. What we collect
We collect only what the notification chain needs. We never collect phone numbers, contact lists from your phone, advertising identifiers, or precise location outside an active trip.
| Category | What exactly | Source | Why |
|---|---|---|---|
| Account | Apple user identifier from Sign in with Apple; the display name you enter; your email if Apple shares it (may be a private relay address) | You, via Apple | Sign you in; show your name to contacts in notices |
| Emergency contacts | Name, relationship word you choose (for example "father"), email address; whether that person also uses HikeCue | You | Send invitations and notices to the people you chose |
| Trip details | Start location (coordinates and place name), planned return time, grace period, call-for-help interval, optional route name or link, party size, notes, optional departure photo | You | Register the trip; show contacts where you went if you are overdue |
| Location during a trip | Coordinates, accuracy, battery level and timestamp, sampled while a trip is active (section 3) | Your device | Show contacts your last known position if you are overdue |
| Device | Push notification token, iOS version, app version, language and time zone settings | Your device | Deliver push notifications; keep one active device per account; show times in your time zone |
| Notices and receipts | Which notices were sent to whom, by push or email, and whether they were delivered or opened | Our servers, Apple, email provider | Resend when a notice is not delivered; show you what your contacts received |
| Status page activity | When a contact opens the status page and which action they take (for example "I reached Alex" or "I called for help") | Contacts | Resolve or escalate an alert; keep an activity record for the trip |
| Consents | Version of the terms you accepted and when | You | Record agreement |
| Usage events | Screen views and feature use, tied to a random install ID and your account ID. Never coordinates | Your device | Fix problems and see which features are used. No third-party analytics SDK |
| Briefing locations | Name and coordinates of the places you save for the weather briefing | You | Show the forecast for those places |
| Weather lookups | A coarse area code (about 1 km square) and the trip date, with no account identifier | Our servers | Fetch the briefing forecast |
Usage events from a trip carry that trip's ID, so for the 7 days before the trip's location data is erased they could in principle be matched to it. After that the location data is gone.
We do not use third-party advertising or tracking SDKs, and we do not sell or share personal data for advertising.
3. Location data
- Permission: HikeCue asks for "While Using the App" location access. It does not ask for "Always" access.
- When: Location is read between the moment you register a trip and the moment the trip ends (check-in, cancel, or closure), and once when you tap "Use current location" to set a trip's start. Otherwise the app does not read location.
- How: During a trip the app keeps a background activity session so samples continue while your phone is locked or the app is in the background. iOS shows the location indicator while this runs.
- What is sent: Coordinates, accuracy, battery level and time. Samples are batched and uploaded when a connection is available.
- Who sees it: Only the contacts you chose, only on the status page, and only after you are overdue or a contact has been alerted. Before that, contacts do not see your position.
- Deletion: All location samples for a trip are deleted from our servers 7 days after the trip ends, and sooner if you delete your account.
- Weather: The briefing uses a coarse area code derived from your trip start, not your exact coordinates, and sends no account identifier to the weather provider.
4. If you were added as an emergency contact
A hiker gave us your name, a relationship word and your email address so we can tell you if they do not check in. You do not need an account.
- What you receive: an invitation, then notices only when a trip is registered, overdue, resolved, cancelled or closed. If you also use the HikeCue app, you may receive the same notices as push notifications.
- What you can see: a status page link that is unique to you. During an alert it shows the hiker's name, planned return time, start location, route details and notes they entered, their last recorded position and battery level, and an optional departure photo. The link stops working 7 days after the trip ends.
- What we record about you: your name, relationship word and email as the hiker entered them; whether you confirmed your email; when you open a notice or the status page; and the actions you take on it.
- Your choices: every email has an opt-out link. Opting out stops all future notices from that hiker and tells them you opted out. You can also write to support@hikecue.app to have your details removed from a hiker's contact list.
- Your responsibilities: the status page shows another person's location and plans. Do not forward the link. Whether to call anyone on the hiker's behalf is your decision; HikeCue does not contact police, search teams or medical services.
5. How we use data and the legal bases
| Use | Data | Legal basis (EU, UK) |
|---|---|---|
| Run the notification chain: register trips, send notices, resend on failure, resolve alerts | Account, contacts, trip details, device, notices and receipts, status page activity | Performance of a contract with you |
| Show contacts your position and trip details when you are overdue | Location during a trip, trip details, departure photo | Your consent, given when you grant location access and register a trip; you can withdraw by ending the trip or revoking the permission |
| Send invitations and notices to contacts | Contact name, relationship word, email | Legitimate interest of you and your contact in the contact being informed; the contact can opt out at any time |
| Pre-trip weather briefing | Coarse area code, trip date | Performance of a contract |
| Fix problems and improve the app | Usage events, device | Legitimate interest in a working product; no profiling |
| Keep records of consent and handle requests | Consents, account | Legal obligation |
| Prevent abuse: rate limits, one active device, test alert limits | Device, account, usage events | Legitimate interest in preventing misuse |
We make no automated decisions with legal or similar effects. Alerts fire on a timer you set, not on a judgement about you.
6. Who receives data
We use these providers to run HikeCue. Each receives only what its role needs.
| Provider | Role | Data | Location |
|---|---|---|---|
| Apple (Sign in with Apple, Push Notification service, WeatherKit, Maps) | Sign-in, push delivery, weather forecasts, place search and the status page map | Apple user identifier; push tokens and notice text; coarse area code for weather; search text and map area; the last recorded position for the status page map image | Apple's infrastructure |
| Resend | Email delivery for invitations and notices | Recipient email, hiker name, notice text, status page link | United States |
| Cloudflare | Serves hikecue.app pages and proxies our API | Request data in transit; status page content while it renders | Global edge network |
| Oracle Cloud | Hosts our servers and database | All data in this policy, encrypted at rest | United States |
We disclose personal data outside these providers only when required by law, or to prevent serious harm to someone's life or health, and we tell you unless the law prevents it. We never sell personal data.
7. Retention and deletion
| Data | Kept until |
|---|---|
| Location samples, departure photo, notes, route details, notice log for a trip | 7 days after the trip ends, then deleted |
| Status page link | Stops working 7 days after the trip ends; immediately if you delete your account or the contact opts out |
| Trip record (times, state, which contacts were alerted) | While your account exists, shown in your trip history |
| Contacts | Until you remove them or delete your account |
| Briefing locations | Until you remove them or delete your account |
| Account, device, consents | Until you delete your account |
| Server backups | 14 days, then overwritten |
Deleting your account: Settings, Account, Delete account. Any active trip is cancelled and your contacts are told. Your sessions end at once. Within the deletion job that follows we revoke your Apple sign-in, delete stored files, delete all rows tied to your account and send one confirmation email. Backups age out within 14 days.
Deleting a contact: removing a contact invalidates any status page link issued to them. Trips already in history keep the contact's name and relationship word as part of the record.
8. Security
- All traffic uses TLS. Our servers are reachable only through our edge provider.
- Status page links are random 256-bit tokens. We store a hash to look them up and an encrypted copy whose key is kept outside the database, so a database copy cannot be used to open a page.
- Data is encrypted at rest on our hosting provider.
- Access to production systems is limited to the operator.
- Rate limits apply to sign-in, invitations, test alerts and status page actions.
No system is fully secure. If we learn of a breach affecting your data we will notify you by email and, where required, the relevant authority, without undue delay.
9. Your rights
Everyone can: see and change their name and contacts in the app, end location use by ending a trip or revoking the permission in iOS Settings, export trip history on request, and delete their account in the app.
EU, EEA, UK and Switzerland: you also have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting earlier processing. You can complain to your local supervisory authority.
California: you have the rights to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal data as defined by the CCPA, and we do not use sensitive personal information to infer characteristics. We will not treat you differently for exercising rights.
Contacts who are not users: the same rights apply to the data we hold about you. Use the opt-out link in any email or write to us.
To exercise a right, email support@hikecue.app from the address on your account, or from the address a hiker entered for you. We respond within 30 days. For account deletion, use the app; it is faster and needs no identity check.
10. Children, transfers, changes, contact
Children: HikeCue is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, write to us and we will delete it.
International transfers: our servers are in the United States. If you use HikeCue from elsewhere, your data is transferred there. For transfers from the EU, EEA, UK and Switzerland we rely on your explicit consent when you create an account and, with our providers, on standard contractual clauses.
Changes: we show the current version number and date at the top. For material changes the app asks you to review and accept again before you register a new trip, and lists what changed. Earlier versions are available on request.
Contact: support@hikecue.app. Postal address available on request.