GPS Toolbox Privacy Policy
Effective date: August 18, 2026
Last updated: August 18, 2026
The developer of GPS Toolbox ("we," "us," or "our") respects your privacy. This policy explains how the GPS Toolbox iOS app, help website, and live location sharing service process personal information.
Policy summary
- Most measurements, tracks, notes, and attachments are stored only on your device by default.
- Formal records and attachments are synced through your private Apple iCloud space only when you enable iCloud sync.
- Your location and nickname are sent to our configured location-sharing server only when you create or join a live-sharing group and enable location sharing.
- We currently do not integrate advertising SDKs, track you across apps or websites, or sell personal information.
- You can deny or revoke system permissions, stop sharing, leave a group, delete local records, or contact us about server-side data.
Information we process
1. On-device location and sensor data
When you use Home, Map, measurement tools, Altimeter, Speedometer, track tools, Track Following, or Watermark Camera, the app may read:
- precise latitude and longitude, location time, and horizontal or vertical accuracy;
- altitude, speed, speed accuracy, and course;
- device heading, three-axis magnetic-field values and strength, pitch, and roll;
- results produced by coordinate conversion, distance, area, track matching, and related calculations.
This information is used to show your current location and calculate or save results for tools you choose to use. It is processed on your device except when you use live sharing or intentionally export or share it.
2. Content you create or select
This includes record and waypoint names, notes, track annotations, photos, videos, KML or other imported files, and exported data files. Photo selection uses the iOS system photo picker. The app receives only the items you select and does not require access to your entire photo library.
This content is used for editing, previewing, saving, importing, and exporting. Watermark Camera creates the finished image on your device and writes it to the system photo library after you take the photo.
3. Local preferences and drafts
The app stores your language, coordinate system, units, measurement algorithm, iCloud sync setting, unfinished drafts, and live-sharing session recovery information on your device. This keeps your preferences and helps restore work after an unexpected exit.
4. iCloud data
After you enable iCloud sync and restart the app, formal structured records may sync through SwiftData and CloudKit, while formal media attachments may be stored in the app's iCloud container. This data is associated with the private space of the Apple ID signed in on the device and is processed using Apple's infrastructure. Draft media is not placed in the formal iCloud sync domain.
5. Live location sharing data
When you create or join a group, the server processes:
- the group ID, creation and expiration times, and status;
- a one-way hash of the optional group password; the plaintext password is not stored;
- member nicknames, random member IDs, hashes of member tokens, join and leave times, and online and sharing status;
- the precise location, altitude, accuracy, speed, course, collection time, and server receipt time that you share;
- HTTPS and WSS request and connection information used for real-time synchronization.
This data is used to create and authenticate temporary groups, show live locations to members of the same group, restore sessions, prevent duplicate uploads, and protect the service. Your plaintext member token is stored locally on your device and used for session authentication; the server stores its hash.
6. Network and diagnostic information
For security, troubleshooting, and operations, the server or reverse proxy may record request times, IP addresses, API paths, response status codes, and error information. Production logs should not contain group passwords, member tokens, or complete location tracks. Debug builds of the app may write location or media-processing information to the device console. The app does not automatically upload these logs, and sensitive debug output should be disabled in release builds.
7. Help website
This VitePress website does not provide registered accounts, advertising, or behavioral analytics. When you use the live-location Web viewer, the site sends the group ID, password, or read-only viewing token to the GPS Toolbox sharing server for authorization and retrieves member nicknames, sharing status, and recent locations for that group. The hosting provider may process IP addresses, request times, User-Agent values, and access logs to deliver and protect the site.
The viewer can load its basemap from Mapbox or AMap. Under their own rules, the selected map provider may process IP addresses, browser and device information, referring domain, map viewport, and tile requests. Member markers are overlaid in the browser. AMap receives GCJ-02 display coordinates while the sharing server retains the original WGS84 coordinates. Actual processing depends on the provider enabled by the operator and that provider's privacy policy.
System permissions
| Permission | Purpose | Required? |
|---|---|---|
| Location While Using the App | Map display, location sampling, measurements, speed and altitude, watermarks, and track following | Only for related features |
| Always Allow Location | Continue track recording or live sharing in the background | Only for continuous background features |
| Camera | Watermark Camera and waypoint attachment photos | Only for taking photos |
| Add to Photos | Save finished watermarked images | Only when saving to the system photo library |
| Photo picker | Import photos or videos you select as attachments | Optional |
| Local Network | Connect to a location-sharing test service on the same local network | Only for that deployment method |
| Motion and sensor capabilities | Read values for Level, Magnetic Field, and related tools | Only for related features |
You can revoke access in iOS Settings → Privacy & Security. After revocation, we stop obtaining new data through the relevant system interface, but previously saved data is not deleted automatically.
How information is shared
We share information or engage processors only in the following limited circumstances:
- Members of the same live-sharing group: They can see your nickname, sharing status, recent location, and related group information.
- Apple: Apple provides infrastructure under its own rules when you use MapKit, iCloud or CloudKit, the system photo library, the photo picker, or the system share sheet.
- Mapbox or AMap: The enabled provider supplies basemap loading and interaction on the Web viewer.
- Third-party apps or recipients you choose: They receive coordinates, photos, or data files when you copy, open, export, or share them.
- Hosting and operations providers: They process information only as needed to host the location-sharing server, database, network, and website, and should be bound by confidentiality and security obligations no less protective than this policy.
- Legal requirements: We may provide information when there is a lawful basis and it is necessary to meet legal obligations, protect users or the public, or investigate unlawful activity.
We do not sell personal information, use location, photos, or sensor data for advertising, use this information to track you across apps or websites, or send this information to third-party AI services.
Retention and deletion
- Local formal records and attachments: Retained until you delete the record, clear the app's data, or uninstall the app. Copies exported before uninstalling are not affected.
- Local drafts: Retained until you restore and formally save them, explicitly discard them, clear the relevant content, or the system removes the app's data.
- iCloud data: Retained until you delete it in the app or relevant iCloud container, or manage it through Apple's account and cloud-data controls. Turning off sync does not guarantee deletion of copies already stored in iCloud.
- Photos in the system photo library: Managed by the Photos app until you delete them there. Deleting a GPS Toolbox record does not delete a photo saved to the photo library.
- Live-sharing data: Valid session access stops after the group expires or a member leaves. A production location-sharing service should delete or irreversibly anonymize group, member, and location records within 30 days after group expiration. Residual copies in security backups should be removed through backup rotation within 90 days, except where otherwise required by law or necessary to handle a security incident.
- Network and security logs: Normally retained for no more than 90 days. Retention may be extended for the period necessary to handle a security incident, dispute, or legal requirement.
Deployment requirement
The live-sharing backend must have automatic cleanup or recurring operational procedures that match the periods above. If the production environment does not yet implement them, the feature must not be launched publicly, and the operator must revise this policy to state the actual retention periods before release.
Security measures
We use measures proportionate to the risks, including the system sandbox and private containers, limited permission scopes, optional group password hashing, random session tokens, access authentication, HTTPS and WSS in production, database access control, log redaction, and backup protection. No storage or transmission method can guarantee absolute security. You should also protect your device passcode, group ID, password, member session, and exported files.
International data processing
Apple iCloud and the servers selected for deployment may process data in different countries or regions depending on your Apple ID region, device location, and the service's deployment region. Before production release, the operator should publish the actual names, regions, and contact details of the server providers and principal processors. Where personal information is transferred across borders, we will meet applicable notice, consent, security assessment, certification, standard contractual clause, or other legal requirements.
Children and minors
The service is not primarily directed to minors and does not intentionally request a real name, age, or contact information. Minors should use the service with guidance from a parent or guardian and should not independently create a publicly distributable location-sharing group. A parent or guardian who believes we have processed a minor's information inappropriately may contact us to request deletion.
Your rights and controls
Subject to applicable law, you may request access to, a copy of, correction of, supplementation of, deletion of, or restrictions on the processing of personal information. You may also withdraw consent and request an explanation of our processing rules. You can additionally:
- revoke location, camera, photo, local-network, and sensor permissions in system settings;
- turn off Share My Location or leave the group from the live-sharing screen;
- delete local formal records and attachments from record details;
- discard a recovered draft;
- turn off future iCloud sync under Data & Sync, then separately use Apple's iCloud management features to handle cloud data;
- delete exported copies in the Photos app, Files app, or the recipient service.
The current server-side live-sharing service does not use registered accounts. To request deletion of server-side group data, provide the group ID, your member nickname, the approximate creation time, and information that can reasonably demonstrate your membership. Do not send the group password or member token through a public channel. We will respond within 15 working days after verification. For a complex request, we will explain the reason and expected processing time.
Policy updates
If there is a material change to the categories of information, processing purposes, recipients, or retention periods, we will update this policy and provide notice through the app, website, release notes, or another prominent method. Where separate consent is required for sensitive personal information or a change of purpose, we will obtain it before processing.
Contact us
For privacy questions, complaints, or data-rights requests, use App Support on the App Store product page, or submit a request without sensitive information on the project issue tracker and ask to continue through a private channel. State that the request is a "GPS Toolbox privacy request" and describe what you want us to address.
Required before release
To meet App Store and applicable legal contact requirements, the operator must add its real legal name, regular office or registered address (where applicable), and a non-public email address that directly receives privacy requests to both the App Store support page and this policy before release. A public issue tracker is not a substitute for a dedicated channel for sensitive data requests.
If you are dissatisfied with the response, you may complain to the consumer protection, data protection, communications, cybersecurity, or other competent authority in your jurisdiction.