Curvalia

This is a translation for convenience only. The German version is legally binding: Datenschutzerklärung der App.

Privacy Policy (App)

This page describes the data processing in the Curvalia app. A separate policy applies to the website. Information pursuant to Art. 13 and 14 GDPR.

1. Controller within the meaning of the GDPR

Jan Bittner
Sole proprietorship (small business)
Heinrich-Budde-Str. 29
04157 Leipzig
Germany
Email: kontakt@curvalia.app
Contact form: curvalia.app/en/kontakt.html

For data protection matters and all requests under section 8: datenschutz@curvalia.app

No data protection officer has been appointed: the requirements of § 38 BDSG (German Federal Data Protection Act: at least 20 persons constantly engaged in the processing) are not met by a sole proprietorship.

2. What data Curvalia processes

On your device

Ride book, recorded routes, saved routes, settings and your identifier are stored in the app’s storage on your device. The secret part of your account is stored in the operating system’s protected key store (Keychain or Keystore). This is strictly necessary for the operation of the app (§ 25 (2) no. 2 TDDDG, German Telecommunications Digital Services Data Protection Act). A backup of the device by the operating system (such as iCloud) may contain this data; Android backup is disabled for Curvalia.

Location (GPS)

The app needs your location for the map display and navigation. With background permission, location tracking continues even when the screen is locked (voice guidance). In the following cases, your position is sent to our own routing engine:

The engine answers the request and does not store the points. Only if a request fails can it appear in the server’s error log; we delete this log after 7 days at the latest. In addition, the app sends your position during a group ride you have actively joined (see “Group rides”).

Ridden routes

Recorded tracks (ride book, conquest map, statistics) remain on your device. Only when you back up your account key are they backed up on our server – end-to-end encrypted. The key for this never leaves your device; we are technically unable to read the contents of the backup. After each ride, the app also reports which dream roads you have ridden (a counter per road), so that you and your friends can see the progress.

Account & friends

On first launch, the app creates a random identifier without a name (no email, no password, no real name needed). This identifier is your friend code. Friend list, display name and – only for tours actually ridden – km, points and level are stored on our server for as long as your account exists. Friends only see which dream roads you ride once you have also added them. You appear in the global leaderboard only if you switch this on yourself in the settings; it shows display name, rank, points, kilometers and number of tours – never your identifier.

Shared routes

If you share a route, it is stored on our server and can be retrieved via its code – that is the purpose of sharing. These routes are therefore NOT encrypted, unlike your backup: anyone who has the code can view the route and ride it. If you also add them to your profile, your friends see them too. What is stored is the course of the route, a name, the length and your identifier as the owner. You can delete them yourself at any time in your profile.

Your own dream roads

If you publish your own dream road, we store its points, the name, your note and opening times as well as your identifier as its creator; if you wish, also your display name as a visible label. If you vote on a road or have ridden it, we store this under your identifier – only the total is shown, never who. You delete all of this together with the road or with your account.

Group rides

You join a group ride actively – with a code or QR code shown to you by the creator. While the ride is running, the app sends your position to our server about once a minute. Only your LAST position is stored there, never a history – and it is visible exclusively to the participants of the same ride: your display name, your last position and how old that report is. Instead of your account identifier, the others see a pseudonym that applies only to this one ride. Whoever navigates additionally transmits the planned route and, continuously, the track ridden so far, so that fellow riders can navigate along and get credit for the part they rode. Positions and the ongoing track are kept only in the server’s working memory, never on disk; they are deleted 30 minutes after the end of the ride, at the latest 12 hours after the start. The planned route and the track shared at the end, on the other hand, are stored on the server under a code like any shared route (see above) and remain there until the person who shared them deletes them or closes their account. The proofs of presence from which your credited part is calculated remain on your device.

Reported road closures

If you report a closed road, we store the marked area, the time of the report and an expiry date. Other riders see only the area and how long the report is valid – never who reported it. Your identifier is stored internally, solely so that you can withdraw your own report; it is never disclosed. Every report deletes itself after 14 days.

Notifications (push)

Only if you switch on “Receive notifications” does the app store a device identifier of the push service (Expo/Apple/Google) with your account, together with the platform and the time. We use it to tell you that a new version is available and to forward invitations from friends to group rides – an invitation contains the display name of the person inviting. If you switch the switch off in the settings, we delete the identifier from the server; likewise if the push service reports that it has become invalid. Navigation notifications on your device are independent of this and do not leave the device.

Bug reports

We store voluntary bug reports with your text, a technical status report (app version, platform, screen, running function), optionally a screenshot and your identifier – the latter so that the app can show you the processing status. The screenshot shows what was on the screen at that moment and can therefore contain names of friends or routes; if your account key is on the screen, no image is attached.

Contact form

If you write to us via the contact form on curvalia.app, we store your name (if given), your email address and your message on our server in order to reply to you.

App updates

On launch, the app asks Expo (u.expo.dev) whether a new version is available. In doing so, your IP address, platform, app version and a random installation identifier are sent to Expo.

3. Who else receives the data

The app calls these services. In each case your IP address is technically transmitted (this is the case with every internet connection), together with whatever the request needs:

Transfer to the USA: Cloudflare and Expo are based in the USA. The transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework, insofar as the provider is certified under it, and otherwise on the European Commission’s standard contractual clauses.

Map data © OpenStreetMap contributors, subject to their copyright (www.openstreetmap.org/copyright).

4. Legal basis

5. Storage period

6. Deletion – one tap is enough

Under Settings → Legal & version → “Delete account and all data” you remove, yourself and immediately: all local data, the record including the encrypted backup, your push identifier, your bug reports including screenshots, the routes and dream roads you have shared, and your votes. Reported road closures remain visible to others until they expire, but lose the link to you – they warn about the road, not about you.

This path is deliberately built into the app because it is the only one that works reliably: your rides are end-to-end encrypted, so we can neither read them nor look them up on request.

7. Security

The connection to our server is encrypted (HTTPS). The server can only be accessed with keys, the services on it are shielded from the outside, and your backup is end-to-end encrypted. With every request, you prove your identifier with a proof derived from your secret key.

8. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).

Right to object (Art. 21 GDPR): Insofar as we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object to this at any time on grounds relating to your particular situation.

You can withdraw consent at any time with effect for the future – for notifications directly in the settings.

You also have the right to lodge a complaint with a supervisory authority, for example the one responsible for us: Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte), Maternistraße 17, 01067 Dresden.

For everything else, contact datenschutz@curvalia.app. Most things are faster in the app itself, though – deletion and export need no request, see section 6 and the note on data portability below.

Access (Art. 15): On our server, your account holds exclusively the identifier, your self-chosen display name, verified km/points/number of tours, the counters of dream roads ridden, the identifiers of your friends, an encrypted data block that we cannot open, and – if you have switched on notifications – the device identifier of the push service. In addition, the routes and dream roads you have shared yourself, your votes, your bug reports and your road closure reports until they expire. During an ongoing group ride, additionally – temporarily – your last reported position. No name, no email, no address – we never ask for them in the app.

As a rule, our license server holds nothing about you: referring friends is paused, and Curvalia Plus is billed by the app store. If an older app version created something there, it is at most: a recognition counter for your referral code, which drops out again after 24 months at the latest without a new redemption; earned referral days not yet collected – they remain until you redeem them, because they are your entitlement and not a counter; and the information that your account has already redeemed a referral code once. Who referred whom is NOT stored there – the server keeps counters, not connections. The legal basis is our legitimate interest in detecting abuse of the referral program (Art. 6(1)(f) GDPR).

Curvalia Plus: purchase, payment, renewal and cancellation are handled by your device’s app store – you are their customer there. We receive no payment data. The app only asks the store whether a subscription is active and remembers the answer on the device.

Data portability (Art. 20): Every ride can be exported individually from the ride book as a GPX file – an open format that any other navigation app can import.