PathieTürkçe

Privacy Policy

Effective date: 15 August 2026

Pathie records your walks, lets you draw routes, and — if you choose — share them. This document explains which of your data we process, why, and who we send it to. It contains everything shown on the notice screen when you first open the app, plus the company and country details promised there.

Data controller
Duhan Enes Ovalı ve Oğuzhan Çakıroğlu
İstanbul / Tuzla
Email: support@pathie.app

The data controller is established in Türkiye, so the processing is subject to Turkish data protection law (KVKK, Law no. 6698). If you are in the European Union you also have the rights granted by the GDPR, and this document is written to satisfy both.

1. What data is processed

What stays on your phone

Your location during walks (including in the background, with the screen off), the photos you take, your notes on stops, the map area you have uncovered (your "fog"), and statistics such as distance and duration. These live in your device's own database; Pathie works fully in airplane mode.

What is written to the server with your account

Your email address, the username you choose, your display name and avatar, your age range, your device's encryption key, and your friend list. These are written the moment you create an account, because they are what identifies it.

We also keep when you last connected — the time only, a single value refreshed at most once an hour. What you do in the app, which screens you open, what you tap is not recorded: Pathie has no analytics SDK, no advertising identifier and no behavioural logging. The one timestamp exists for an operational reason: knowing how many people are using the app.

If you allow notifications, your phone's notification address (push token) is kept with your account too — it is the only way a notification can reach you. It is deleted when you withdraw the permission or delete your account.

What leaves your phone only when you share

The routes you publish, room messages, the photos and voice messages you send in rooms, and — if you turn it on — your live location.

If you choose to share a walk, that walk's step count is written to the server as part of the share and is visible to the audience you chose (your friends, or everyone). Nothing is counted at all while the step counter is switched off in Settings.

Your interactions with shared content

When you like, save, copy or comment on a public route, or follow someone, that is recorded individually — there is no other way for a like to be undoable or for what you saved to stay in your list.

These records are also used to order the Discover feed for you. This is not an exception to the "no behavioural logging" sentence above but its boundary: what is recorded is your own action (what you liked), not your browsing behaviour — and none of it goes to advertising or to matching with a third party.

Your raw GPS trace is never sent to the server. When you share a walk, what goes to the server is not your individual location fixes but a line derived from them: each point's timestamp and accuracy value are dropped. Your room messages and the photos and audio you share in rooms are end-to-end encrypted — they are stored encrypted, and we cannot read them either.

2. Why it is processed, and on what legal basis

3. International transfers — who receives what

Map tiles, route calculation and weather cannot be produced on your phone; they come from outside. The list below is complete. None of these recipients is located in Türkiye, and Turkish law treats this as a transfer abroad; the transfer relies on your explicit consent and you can withdraw it at any time from Settings → Privacy.

RecipientLegal entityCountryData sentWhen
Expo (app updates) 650 Industries, Inc. United States Your IP address, device and version information On every launch — before the consent screen is shown
Mapbox Mapbox, Inc. United States The map area you are viewing, the words you search for While the map is open and when route lists are displayed
MET Norway (weather) Norwegian Meteorological Institute (Meteorologisk institutt), Postboks 43 Blindern, 0313 Oslo Norway Your stops rounded to ~1 km, and the estimated arrival time. Your IP address is not sent — the request is made by our own server While drawing a route and when a plan’s forecast is shown
OpenRouteService (fallback routing engine) HeiGIT gGmbH, Schloss-Wolfsbrunnenweg 33, 69118 Heidelberg Germany The coordinates of the stops you place When you draw a route — only if our own routing server does not respond
Amazon Web Services (hosting of our own routing engine) Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg Germany — the server runs in AWS's Frankfurt (eu-central-1) region; the engine is ours, AWS only hosts it The coordinates of the stops you place and — when a recording is map-matched — the coordinates of the trace you walked. Your IP address is not sent — the request is made by our own server When you draw a route and when a walk recording is map-matched
Apple / Google (your phone’s geocoding service) ❔ These companies’ privacy policies do not name a controller for Türkiye; they name one only for the EU/EEA, the United Kingdom and Switzerland ❔ Not declared, for the same reason Your location Automatically, if you have granted location permission
Spotify (playlist preview) Spotify AB, Regeringsgatan 19, 111 53 Stockholm Sweden The playlist link you paste When you attach a playlist to a memory
Apple Music (playlist preview) ❔ Not declared, for the same reason as the Apple row above The playlist link you paste When you attach a playlist to a memory
Cloudflare (our server) Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107 (EU/UK entity: Cloudflare, Ltd., London) United States — storage is provisioned with the "eu" jurisdiction restriction, so the data itself is held within the European Union Your account, profile, friend list and everything you share The moment you create your account; shared items when you share them
Resend (email delivery) Plus Five Five, Inc. (Resend is the brand name) United States Your email address and the one-time sign-in code sent to you When you request a sign-in code
Sentry (crash reporting) Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105 (EU representative: Sentry Software Netherlands B.V., Amsterdam) United States The error itself and your device model/version. Your location, routes and photos are not sent Only when an error occurs — and only if you consented
Cloudflare (the AI model) Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107 (EU/UK entity: Cloudflare, Ltd., London) United States The text you type in the chat, a photo only if you attach one yourself, and — when you ask about places nearby — your location rounded to ~1 km. The model itself never sees coordinates. An attached photo is described and discarded; it is not stored. Your walks, your photo library and your fog map are not sent Only when you send Pati a message, or attach a photo to one
Geoapify (places nearby) Geoapify GmbH, Karlsruhe Germany Your location rounded to ~1 km and the kind of place you asked for. Your IP address is not sent — the request is made by our own server When you ask Pati what is nearby
Tavily (web search) ❔ Not stated: the company’s legal entity and address have not been verified from source; it will be added once they are United States The name of the place being looked up and the city it is in — not your message, not your location, not who you are Only when Pati needs evidence about a place you asked about
Wikimedia (Wikipedia) Wikimedia Foundation, Inc., 1 Montgomery Street, Suite 1600, San Francisco, CA 94104 United States The area you are looking at, rounded to ~1 km. Your IP address is not sent — the request is made by our own server When a museum, park or historic place appears in Pati’s answer
DuckDuckGo (site icons) ❔ The company’s privacy policy does not name a controller for Türkiye (DuckDuckGo, Inc., Paoli, Pennsylvania) United States Only a source’s domain name, such as tripadvisor.com. Your IP address is not sent — our own server fetches the icon; nothing about you, your location or what you asked While a place card in Pati’s answer shows its sources
Overpass API (street data) ❔ A public endpoint run by OpenStreetMap volunteers (overpass-api.de); it declares no commercial controller Germany The bounding box of the neighbourhood you are looking at — the neighbourhood, not your location. Your IP address is not sent; the request is made by our own server The first time a neighbourhood’s streets are needed (the result is cached, so it is not asked twice)
Google (notification delivery) Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 United States Your phone’s notification address and the text of the notification sent to you When you allow notifications, and when one is sent to you
Amazon Web Services (elevation data) Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109 United States — the bucket read is in Frankfurt (eu-central-1), so the data is within the European Union The number of the map tile your route falls in — the tile, not your location. Your IP address is not sent While the route’s elevation profile is computed
Amazon Web Services (photo check) Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109 United States — the check runs in Frankfurt (eu-central-1), so the photo stays within the European Union The photo you upload, to be checked for pornography, violence and similar content. Who uploaded it is not sent — only the picture, and the picture is not stored there While a photo you upload is being saved

If you choose to sign in with Apple or Google, the only thing that company receives is which app you signed in to; what comes back to us is your name and email address (with Apple, optionally through a private relay address). This is a different processing operation from the geocoding row above.

The one transfer that happens before the consent screen: the app checks for a new version on launch (the Expo row), and that check runs beneath the app's own software layer, before the consent screen is drawn. There is no point at which we can gate it; rather than undercount, we state it as it is.

4. How long data is kept

5. Your rights

Under GDPR Art. 15–22 and KVKK Art. 11 you have the right to learn what data of yours is processed, to access it, to have it corrected or erased, to object to processing, and to receive your data in a portable form. Most of these can be exercised inside the app, without asking anyone:

Server-side deletion is queued and normally completes within minutes; the screen does not say "deleted" until the work has actually finished. For written requests: support@pathie.app. You also have the right to lodge a complaint with your national supervisory authority in the EU, or with the Turkish Personal Data Protection Authority (KVKK).

6. Security

7. Age limit

You must be at least 16 years old to use Pathie. The app is not directed at children; people under 16 may not use Pathie and we do not knowingly collect their data.

8. If this document changes

Whenever the text changes materially, the app asks for your approval again — the document carries a version number, and raising it re-shows the screen. Changes are never made silently.