Privacy Policy

Last updated: August 2026

This page explains what information Monopatia (monopatia.info and the Monopatia mobile apps) collects, why, and how it is handled. We try to keep things minimal: most of the site and apps work without an account, and the only personal data we store is what you choose to provide by signing in and using them. App-specific behavior is described in In the mobile apps below.

What we store on your device

  • Theme preferencelocalStorage value used by the dark/light toggle.
  • Saved location — when you use the Near Me page and either grant geolocation access or pick a point on the map, your chosen coordinates are stored in localStorage under the key monopatia-location so the home page and trail cards can show distances and drive-time estimates. This value never leaves your browser.

You can clear both at any time via your browser's site-data settings or by tapping "Change location" on the Near Me page.

What we collect with Google Analytics

Monopatia uses Google Analytics 4 (G-ZJ24JZDT55) to understand which pages are visited and which features are used. Google Analytics collects anonymized traffic data: pageviews, referring pages, approximate location, device and browser type. We do not use Google Analytics for advertising and do not link analytics data to any user account. See Google's privacy policy for details.

Alongside pageviews we record a small set of product events, so we can tell which parts of the site actually help people find and judge a trail — for example opening a trail page, expanding the weather or shade panel, applying a filter, opening directions, downloading a GPX file, bookmarking, or posting a review. Each event carries only what the measurement needs: the trail's short name (its URL slug), which part of the site you came from, and coarse details like difficulty or district. We also set a few coarse properties: whether you are signed in, your interface language, how many trails you have completed as a broad band (0, 1–4, 5–19, 20+), and — if you have saved a location — the nearest of 21 Cyprus towns, never your actual coordinates.

We do not send Google your name, email, avatar, review text, photos, precise location, or any account identifier, and advertising and ad-personalization signals are switched off. Analytics data is retained for 14 months. Search terms typed into the trail search box are recorded, because knowing which trails people look for tells us what the catalogue is missing — please don't type anything personal there. If you prefer to send nothing at all, any browser-level tracking protection, ad blocker, or Google's opt-out add-on will block the tag; the site works exactly the same without it.

In the mobile apps

The iOS app (from version 0.5.1) and the Android app report the same kind of product events into the same Google Analytics property, through Google Analytics for Firebase. Both use the build of that SDK which never touches the device advertising identifier — Apple's IDFA or Android's advertising ID — so the iOS app shows no App Tracking Transparency prompt, neither app shares anything for cross-app advertising, and neither is classed as tracking you.

The events mirror the website's — opening a trail, expanding weather or shade, filtering, opening directions, downloading a GPX file, bookmarking, reviewing — plus the ones only the apps have: starting and finishing a recorded hike (its distance, duration, ascent, and how often you went off route), how a hike was uploaded and whether it verified, photo-scanner suggestions, and cues and notifications you tap. As on the website, an event carries the trail's URL slug and coarse context — never your coordinates, your recorded track, your photos, or your review text.

Your app is identified to Google by a random per-install identifier, not by your account, and it changes if you delete and reinstall the app. The same coarse properties as the website apply, plus whether trailhead alerts, hike cues, or health-app saving are switched on, and whether you granted photo access.

You can turn all of this off in Settings → Privacy → Anonymous usage statistics, on both platforms. It is on by default; switching it off stops collection immediately, and every other feature works exactly the same.

What happens when you sign in

Sign-in is optional and only required to bookmark trails, mark completions, write reviews, upload photos, sync your Strava activities, or appear on the leaderboard. You can sign in with Apple, Google, or Strava. Google is available on the website and both mobile apps; Apple is available on the website and iOS; Strava sign-in is available on the website and can be linked to an existing account in either app. You can link providers to the same account. Sign in with Apple shares only your name and email (or Apple's private relay address if you choose to hide it).

  • Apple uses Sign in with Apple for sign-in only.
  • Strava uses Strava OAuth with the scopes read,profile:read_all,activity:read.
  • Google uses standard Google OAuth for sign-in only.

When you sign in, the following data lands in our database (Neon serverless Postgres, EU region). Some of it comes from the sign-in provider; the rest is created by your actions on this site.

Received from the sign-in provider:

  • Your display name and profile picture URL.
  • Your provider account ID (your Strava athlete ID, Google account ID, and/or Apple user identifier).
  • Your email address, if you sign in with Google or Apple (with Apple, this may be a private relay address if you chose to hide your email). If you sign in with Strava only, Strava does not share an email, so we store a non-working placeholder address instead of a real one. Linking a Google or Apple account later upgrades that placeholder to your real email.
  • OAuth access and refresh tokens, used to keep you signed in and (for Strava) to fetch your activities. These are never shared with anyone else.

Received from Strava (activity sync):

  • Cached Strava activities relevant to Cyprus hiking: name, sport type, start date, distance, elevation gain, moving time, start coordinates, and the encoded summary polyline. We use these to auto-match your activities to trails on the site, and to compute your coverage of the E4 long-distance path.

Created by you on Monopatia:

  • A login session, including IP address and user agent — set by Better Auth so we can keep you signed in and detect abuse.
  • Your bookmarked trails and completion flags. These are stored only in Monopatia's database and are never sent to Strava.
  • Reviews you write: a rating, an optional comment, and the language you wrote it in.
  • Photos you upload with a review. Images are stored in Vercel Blob storage; the database keeps their URLs and dimensions.
  • Sync state: when your activities were last fetched, how many were synced, how many matched a trail, and your E4 coverage.

From Strava we do not receive or store your full activity stream, private photos, segments, or any heart-rate / cadence / power data.

How your data is used

  • To show you your bookmarks, completions, stats, and matched activities.
  • To rank you on the public leaderboard. The leaderboard displays your display name, profile picture, and aggregate stats (number of completed trails, total distance, total elevation, activity count). For Strava-linked accounts it links to your public Strava athlete page.
  • To rank you on the E4 coverage leaderboard, which shows how much of the E4 long-distance path you've covered.
  • To improve trail-matching accuracy in the future.

Your email address is used only to recognise your account across sign-in providers and to verify deletion requests. We do not send marketing email.

We do not sell, rent, or share your data with third parties. We do not use it for advertising or profiling.

What is shown publicly

Some of your activity is visible to anyone, not just you:

  • Your display name and profile picture on the leaderboards, the Community feed, and on any reviews you write.
  • Reviews, ratings, and photos you post appear on the relevant trail page and in the Community feed.
  • The Community feed also shows recent completions and when new members join.

Your email address, OAuth tokens, session details, and saved location are never shown publicly. If you'd rather not appear publicly, don't post reviews or photos, and email us to remove existing ones (see below).

In the mobile apps

The Monopatia iOS and Android apps add a few features with their own data behavior:

  • Hike recording. When you record a hike, the app tracks your GPS position (and barometric altitude) on the device. When you finish, the recorded track — the full route line, distance, elevation gain, and times — is uploaded to Monopatia's server, where it is matched against trails to verify completions. The recording, including your track, appears in your profile, and the resulting completion can appear on the public Community feed (the track itself is not shown there). If you are signed out, recordings stay on the device until you sign in. You can discard a recording instead of keeping it.
  • Photo-library scanning. If you enable the photo scanner, the app reads your photos' locations and dates entirely on the device to find past hikes. Nothing from your library leaves the phone unless you explicitly confirm a found hike (which uploads a route line derived from photo locations) or choose to share specific photos with a review. Photos are re-encoded before upload, which removes their location (EXIF) metadata.
  • In-hike camera. Photos you take with the in-app camera stay on the device, attached to the recording; they are only uploaded if you share them to the trail gallery.
  • Apple Health and Health Connect. With your permission, finished hikes are saved to Apple Health on iOS or Health Connect on Android as hiking workouts with their routes. The apps only write workout data — they read nothing from either health service, and no health-service data is ever sent to our server.
  • Trailhead alerts on iOS. The optional arrival-alert feature registers geofences around nearby trailheads on the device. Arrival events trigger a local notification only; no location data from this feature leaves the phone.
  • Weather. The trail-weather panel requests the forecast for the trail's coordinates, never your own location.

The apps store your session token in the iOS Keychain or Android Keystore and contact only the services listed on this page: Monopatia's own API, Vercel Blob for photo uploads, the weather service, your chosen sign-in provider, and Google Analytics, described under In the mobile apps above. Neither app contains advertising SDKs and neither shows ads.

Data retention and deletion

You can delete your own reviews and their photos at any time from the site or the app while signed in.

You can sign out at any time. To permanently delete your Monopatia account and all associated data (sessions, bookmarks, completions, cached Strava activities, recorded hikes, reviews, and uploaded photos), open either mobile app while signed in and use You → Delete account. Deletion is immediate. If you cannot access the app, email v@bougay.com from the address linked to your account and request account deletion; we will complete it within a few business days. We do not retain personal account data after deletion, except where temporary backups or applicable law require limited retention.

You can also revoke Monopatia's access to your Strava account at any time from your Strava settings, which will block further syncs.

Cookies

Monopatia uses a single first-party cookie set by Better Auth to keep you signed in. Google Analytics sets its own cookies for traffic measurement. The mobile apps use no cookies at all; their analytics uses the random per-install identifier described above.

Children

Monopatia is not directed at children under 13 and does not knowingly collect data from them.

Changes

This policy may be updated as the site evolves. Material changes will be reflected on this page with a new "Last updated" date.

Contact

Questions, deletion requests, or anything else: v@bougay.com.