Privacy Policy

Last updated: September 29, 2026

What we collect

Account info: your email, a username, a display name, and a password (stored hashed — we never see it in plain text). Optionally: a profile photo, a freeform location string, and whatever visits, trips, notes, ratings, photos, and recorded hikes you choose to log.

  • If you sign up through Google, we receive your name, email, and profile photo from Google. If you sign in with Apple, we receive your name and email instead — Apple sends your name only the first time you authorize the app, never again after that, and the email may be a private relay address (something like @privaterelay.appleid.com) that forwards to your real one if you chose "Hide My Email." Apple doesn't give us a profile photo.
  • If you set up a passkey — signing in with your device's fingerprint, face, or PIN unlock instead of a password — we store the public half of that credential and the label you give it ("MacBook," "iPhone"). The fingerprint, face, or PIN itself never leaves your device; we never receive it and couldn't reconstruct it from what we store.
  • If you turn on push notifications, we store an address to deliver them to: for a browser, the push service's endpoint URL and the encryption keys it requires; for the iOS or Android app, a device token issued by Apple or Google's push service. It identifies your device to the notification service, not you personally, and is deleted when you turn notifications off or the address stops responding. We also keep a short description of the browser it belongs to.
  • For each signed-in session we store the IP address and the browser or device description your request came from, for security. They stay until the session is removed or you delete your account. We also use IP addresses to limit repeated sign-in and sign-up attempts.

What we don't do

  • No ad tracking, no selling data. We don't currently use any third-party analytics — if that changes, this policy will say so first, including what's collected and why.
  • No location tracking, with one exception you control. The "Location" field on your profile is plain text you type yourself, never geocoded. "Near me", the photo scan, and auto check-in compare your position against park boundaries on your own device and never send it to us. The exception is hike recording in the iOS app: when you tap Record, the route you walk is saved to your account so you can see it on a map later. A recorded hike is visible only to you, never on your profile or any public page, included in your data export, and deleted when you delete the hike or your account. Nothing is recorded unless you start a recording. If you turn on “Also save to Apple Health” in the iOS app, each saved hike is also written to Apple Health on your phone as a workout with its route; that copy is managed by Apple and by you, and NP Tracker never reads anything from Health. If you turn on “Keep the hike on your watch screen”, your Apple Watch runs a workout while you record, which lets it record your heart rate the way it does during any workout; the watch app itself saves nothing and reads nothing.
  • Photos are re-encoded on upload specifically to strip embedded location metadata (EXIF GPS) before they're ever stored or shown to anyone. We do read those coordinates once, in memory, and only to offer you a suggestion — "this looks like it was taken at Ellis Island; add it to this visit?" — for units made up of several separate places. The coordinates are discarded in the same breath: never written down, never logged, never shown to anyone else. Ignore the suggestion and nothing is kept at all.
  • No marketing email. We send account email only — verification and password reset. Social notifications (someone you follow earning a badge, someone asking to follow you) stay inside the app; we don't email them to you.

Who can see your data

Your profile is private by default. You choose whether it's private, visible to approved followers, or public — and that choice is yours to change or revert at any time in Settings. A private profile's page doesn't exist to anyone else — visitors see the same "not found" page as for a username that was never registered. (One unavoidable exception: because usernames are unique, signup will say a taken name is taken.)

Profile pages ask search engines not to list them, so a profile is found through its link, not by searching. Search engines don't always honor that, and one that already holds a copy of a page may keep it for a while after you make your profile private or delete your account.

If you report a profile, an admin sees your username, the reported profile's username, and the reason you gave, to review it. A report isn't shown to anyone else, including the person you reported.

Services we use

Other companies run parts of NP Tracker. Each receives only what its job needs.

  • Vercel hosts the site. It handles your requests, including your IP address, and keeps standard server logs.
  • Neon hosts our database, which holds your account and everything you log.
  • Backblaze provides our cloud storage. It holds photos only if you upload them to your account, plus your profile photo if you set one.
  • Resend sends our verification and password-reset email, so it receives your email address and those messages.
  • Cloudflare provides the bot check on sign-up and password reset. It runs in your browser and sees signals such as your IP address.
  • Apple and Google handle sign-in if you choose it, and deliver push notifications to the iOS and Android apps, so notification text passes through their push services.
  • Apple Maps works out driving routes in the trip planner. Our servers send it the start and end places you type and the locations of the parks on your trip.
  • OpenFreeMap supplies the map. Your browser loads map tiles from it directly, so it sees your IP address and the area you view.
  • The National Park Service supplies park photos, which your browser loads from nps.gov directly, so it sees your IP address. Park information and forecasts from the NPS, the National Weather Service and MET Norway are fetched by our servers using park locations, never yours.

Cookies

Only cookies that make the site work. No advertising cookies, and no analytics cookies today.

  • Staying signed in: a session cookie, plus a companion that lasts 5 minutes and saves a database lookup on each page.
  • Signing in: while you sign in with Google, Apple, a passkey, or an MFA code, a short-lived cookie carries that step. The MFA one lasts up to 10 minutes and is deleted the moment you enter your code.
  • Time zone: your browser's time zone, such as America/New_York, so dates and times show correctly. It is set for every visitor, signed in or not, and lasts a year.
  • Parks near you: whether you turned that part of the dashboard on or off, for a year. It records your choice, never your location.

Your data is yours

Download your data as JSON at any time from Settings: your account details, visits, trips with their planned parks, start and end places, stays and daily hours, and recorded hikes with their routes. A CSV of your visit log is also available. The download does not include everything we hold. It leaves out, for example, your photos, badges and stamps, the people you follow, and notifications. Deleting your account is real deletion — your rows and any uploaded photos are permanently removed, not just hidden.

Delete your account

Sign in, go to Settings → Your data, and choose Delete account at the bottom of the page. You'll be asked to confirm your password (or sign in again, if your account has no password — Google, Apple, and passkey-only accounts) before anything happens. There's no waiting period — deletion is immediate and permanent, and removes your account along with every visit, trip, note, rating, photo, and recorded hike you've logged.

Can't sign in to reach that page — lost access to your email, forgot your password with no way to reset it — email support@nptracker.travel from the address on the account and we'll delete it for you.

Contact

Questions about this policy: support@nptracker.travel.