Privacy Policy – Virtual Walk Journey
Effective: June 2025
1. Controller
Torsten Uhlmann / Goethestr.32 / 10625 Berlin 7 Germany]
Email: master@virtualwalk.app
2. Principles
We respect your privacy. We do not sell data, do not run ads, and do not track you across apps.
3. What data we process
3.1 Account data: name, email, password (bcrypt hash). Legal basis: contract (Art. 6 (1) (b) GDPR).
3.2 Activity & journey data: step count (CMPedometer counter only, no GPS), distance, start/destination city, route geometry, elevation. We never process your actual GPS position.
3.3 Group & chat data: memberships, messages (text, timestamp, sender), reports & blocks.
3.4 Game mechanics: league standings, awards.
4. Third parties
OpenRouteService (HeiGIT DE) · OSM Nominatim/Photon (OSMF UK / komoot DE) · Wikipedia (Wikimedia US) · Claude Sonnet (Anthropic/Emergent) · Resend (US). SCCs in place for US providers where available.
5. What we do NOT do
❌ No ad tracking · ❌ No third-party analytics · ❌ No location tracking · ❌ No camera/mic · ❌ No data sharing with ad networks
6. Retention
Account/journey data: until you delete your account · Chat: until you delete it · Reports: up to 12 months.
7. Your rights (GDPR)
Access (15), Rectification (16), Erasure (17 — in-app: Profile → Delete account), Restriction (18), Portability (20), Object (21), complain to supervisory authority.
Contact: privacy@virtualwalk.app
8. Security
HTTPS/TLS 1.2+, bcrypt cost 12, signed JWT, authenticated DB access.
9. Children
Not directed at children under 13.
10. Changes
Material changes will be announced in the app.