Privacy Policy – Virtual Walk Journey

Effective: June 2025

1. Controller

Torsten Uhlmann / Goethestr.32 / 10625 Berlin 7 Germany]
Email: master@virtualwalk.app

2. Principles

We respect your privacy. We do not sell data, do not run ads, and do not track you across apps.

3. What data we process

3.1 Account data: name, email, password (bcrypt hash). Legal basis: contract (Art. 6 (1) (b) GDPR).

3.2 Activity & journey data: step count (CMPedometer counter only, no GPS), distance, start/destination city, route geometry, elevation. We never process your actual GPS position.

3.3 Group & chat data: memberships, messages (text, timestamp, sender), reports & blocks.

3.4 Game mechanics: league standings, awards.

4. Third parties

OpenRouteService (HeiGIT DE) · OSM Nominatim/Photon (OSMF UK / komoot DE) · Wikipedia (Wikimedia US) · Claude Sonnet (Anthropic/Emergent) · Resend (US). SCCs in place for US providers where available.

5. What we do NOT do

❌ No ad tracking · ❌ No third-party analytics · ❌ No location tracking · ❌ No camera/mic · ❌ No data sharing with ad networks

6. Retention

Account/journey data: until you delete your account · Chat: until you delete it · Reports: up to 12 months.

7. Your rights (GDPR)

Access (15), Rectification (16), Erasure (17 — in-app: Profile → Delete account), Restriction (18), Portability (20), Object (21), complain to supervisory authority.
Contact: privacy@virtualwalk.app

8. Security

HTTPS/TLS 1.2+, bcrypt cost 12, signed JWT, authenticated DB access.

9. Children

Not directed at children under 13.

10. Changes

Material changes will be announced in the app.