Privacy promise

Your data, your phone.

TrailFree is built to be private by default. It needs no account, keeps your rides on your phone, and has no analytics. This page explains, in plain language, what that means.

What we collect

Nothing. TrailFree has no sign-up and no user accounts, so there is nothing to send us, because there is no “us” to send it to. Your outings, routes, names, and settings are created and kept on your device.

Where everything lives

Every ride, hike, run and walk you record is stored locally, in the app's own storage on your phone, and so is everything else: your training plans, strength logs, challenges, goals, imported trails, and settings. None of it is uploaded, backed up to a server, or synced to any cloud. If you uninstall the app, that data is removed with it, so export anything you want to keep first.

That includes Android's own backup. TrailFree tells the system to exclude everything from cloud backup and from device-to-device transfer, so your outings, tracks, strength log and settings are not copied to Google's servers when your phone backs itself up. The only backup of your data is the one you make yourself, described below.

This on-device default is permanent. If we ever add optional features that need a server, such as a private club or an encrypted backup across your devices, they will be strictly opt-in, clearly marked, and off unless you turn them on. Using TrailFree on its own will never require an account or send your data anywhere.

When TrailFree uses the network

By default, the only thing that touches the network is map tiles: to draw the map beneath your route, the app streams standard tiles from OpenFreeMap (OpenStreetMap data), shaded relief from terrain tiles by Mapzen hosted on AWS Open Data, and, if you choose the satellite style, Esri imagery. Those requests contain only what any map viewer needs to fetch the right tiles, never your recorded tracks or personal data. You can also download map areas in advance so the map works fully offline.

One optional feature reaches the network if you turn it on: live weather in the greeting fetches the current conditions from Open-Meteo. It is off by default. Recording, training, strength and all your saved data work entirely offline.

If you buy the one-time TrailFree Pro unlock, the purchase is processed entirely by Google Play under Google's own terms and privacy policy. TrailFree receives confirmation that the unlock was purchased, and nothing else: no name, no card details, no billing address. The unlock is then remembered on your device.

Sharing a trail

Sharing is the one place where something you recorded deliberately leaves your phone, so here is exactly what happens. Nothing is shared until you tap share, one outing at a time. There is no feed, no profile, and no upload in the background.

When you share, TrailFree hands a file to whichever app you pick, a chat, mail, or a drive. From that moment the receiving app's terms and privacy policy apply to it, and TrailFree has no further say in where it goes.

What travels is deliberately thin:

  • Positions only. A shared trail carries the shape of the route and nothing else: no times, no dates, no heart rate, no elevation. This is enforced in the code rather than by promise, because the sharing path returns a positions-only type, so nothing else is able to travel with it.
  • Both ends trimmed. A set distance comes off the start and the finish, so a route posted to a group chat is not also your home address and the hour you leave. You choose the distance in Settings (off, 100 m, 200 m or 500 m), and it is 200 m unless you change it. A short outing is never cut back to nothing: the trim shrinks to fit rather than leaving a trail too small to follow.
  • A picture, if you pick that instead. The shared image shows the map, the outing's name and its three headline stats. It is drawn on your phone, not on a server.
  • No data in the link. The message carries a plain link to trailfree.app. No part of your route is ever encoded into a URL.

A trail someone sends you works the same way in reverse. It is read on your phone and stored there, nothing is looked up, and nothing is reported back to us. Opening a trail a friend sent you needs no account and no Pro.

Permissions, and why

  • Location: to record where your ride or hike goes. This is the core of the app.
  • Foreground service (location): to keep recording reliably while your screen is off and the phone is in your pocket.
  • Physical activity: to count steps and help tell a ride from a hike. Since v0.46.2 it also lets a guided strength session keep running with the phone in your pocket, because Android 14 requires this permission for the health-typed service that holds the session open between sets. Optional; the app works without it.
  • Foreground service (health): to keep a guided strength session running, and its rest timer accurate, while the screen is off.
  • Bluetooth: only if you pair a heart-rate strap or band. Scanning is used for nothing but finding your sensor, and heart rate stays on your phone. Entirely optional.
  • Notifications: for the recording status, the guided session, and any reminders you choose to switch on. Off by default, and the app asks for it at the moment a recording or a session first needs one, rather than at first launch.
  • Internet: to stream the map tiles described above, from OpenFreeMap, Mapzen terrain tiles on AWS Open Data and, for the satellite style, Esri, plus the opt-in weather if you enable it.

No trackers, no ads

There are no advertising networks and no third-party analytics or telemetry libraries in TrailFree. Your behaviour in the app is not measured, profiled, or sold.

You own your data

Any outing can be exported as a standard GPX file and shared wherever you like. You can save a full backup of everything, as one file of readable data, to any folder you choose, and Pro can do so automatically on a schedule. The folder is picked by you through Android's own file picker; if you point it at your Google Drive, the file goes to your Drive under your account. TrailFree has no access to it and no copy of it.

Importing works the same way in reverse: activity files you choose (a Strava archive, GPX or TCX files) are read on your phone and stored locally, never uploaded. Delete an outing and it's gone from your device. Your data is yours to keep, move, or remove at any time.

How long data is kept

We retain nothing, because we hold nothing. TrailFree has no server and no accounts, so no user data is ever stored or retained by us. Everything the app records, from outings and tracks to strength logs, sessions and settings, lives only on your device, and stays there until you delete it: remove an outing and it is deleted immediately and permanently; uninstall the app and Android removes all of its data with it. Backups exist only where you chose to save them, under your control, and sharing links contain their data inside the link itself, held by no one.

The services the app fetches map tiles and opt-in weather from receive only the standard technical details of each request (such as your IP address), handled under their own policies; we receive nothing.

Changes

If this promise ever changes, the updated version will be posted here before it takes effect. Any new feature that touches the network will be opt-in, and we will not weaken the private, on-device default described above.

Contact

Questions about privacy? Reach us at hello@trailfree.app.

Last updated 29 July 2026.

Back to home