Privacy

Your data, clearly explained.

Henro Navigator works in important areas without an account. This policy explains local storage, optional cloud features, location use, external map services, and voluntary website analytics.

Version 1.8 · 30 August 2026

Website analytics settings

You can allow or disable voluntary website analytics in this browser at any time. This setting applies only to this website in this browser; the Henro Navigator mobile app is not measured.

Website analytics is disabled in this browser.

Facility observations and problem reports

When you deliberately choose “I found this place” and then “Send for review”, the app immediately stores a local marker and submits an anonymous on-site observation to Cloud Firestore. It contains the facility reference, the position and details already held in the data set, observation time, app language, app version, and submission time. The document contains neither a UID nor an email address and does not collect your current device or GPS location.

The submission is initially not public and can be read only by administrators. After manual approval, it may be included in the published data set as a dated community observation and become visible to everyone. It confirms existence only—not access, opening, availability, or safety. You can remove the local marker; because the submission is anonymous, it cannot automatically be linked back to an account. Correction and problem reports are also reviewed manually and retained only as long as review and traceability require.

Privacy Policy

1. Controller and contact

Karl Dumser, Germany · support@henro-navigator.com

2. Use without an account and local data

Maps, navigation, trip planning, and local notes can be used without an account. Travel profile, settings, plan, route progress, notes, walking records, and visited map tiles are stored locally on the device. Walking records contain only aggregate values such as distance, recorded duration, elevation, timestamp, and live/simulation status – never raw coordinates or track geometry. They are not transmitted automatically and can be removed using the app controls or by deleting the app or website data.

3. Optional account and cloud sync

If you register voluntarily, Firebase Authentication processes your email address, display name, user ID, and technical authentication data. Cloud Firestore may store profile preferences, visited temples, walking records, and submitted correction or new-facility proposals. Your walking plan and plan progress are stored as an additional private cloud snapshot only if you explicitly enable this in your account. The local offline copy remains authoritative; before overwriting a conflicting cloud state, the app keeps a limited local conflict backup. A new-facility proposal sends the contact details, description, selected map position, app language/version, and account ID that the user deliberately provides for review. Its marker is immediately visible only in that account's local device scope; other users see it only after manual review and inclusion in the published data set. Recordings are stored locally first within the currently signed-in account's scope and synchronised idempotently when a connection is available; pending transfers retry automatically. Anonymous recordings are not assigned to an account you sign into later. This provides the requested account, sync, statistics, and data-quality features.

4. Location and online routes

Precise location is used only after device permission for the map, progress, and active navigation. Henro Navigator does not record a continuous background location history. Online walking, bicycle, or car routing sends the selected start and destination coordinates to BRouter only after visible consent. For a Henro-near route, the same calculation may use several requests to test additional intermediate and exit points. After you tap “Allow”, permission is stored locally on this device and can be withdrawn in the travel-mode dialog or Settings. Only if local storage fails for technical reasons does the permission apply to the current calculation only. BRouter also technically receives the IP address, access time, requested resource, and user agent. According to the BRouter privacy policy, regular logs are deleted after two weeks and backups after a further ten days. If you deliberately open a public-transport route in Google Maps or Apple Maps, the selected coordinates are sent to that service.

5. Maps, external content, direct beta feedback, and optional Discord

Map tiles load from OpenStreetMap or CARTO and are cached locally with a fixed limit. Facility and temple images may load from Wikimedia Commons. These providers receive technically necessary connection information such as an IP address. Firebase, OpenStreetMap, CARTO, BRouter, Wikimedia, Google Maps, and Apple process data under their own policies.

When the user deliberately taps “Send feedback” in the beta feedback dialog, the entered bug report or feature request plus app version, beta version, platform, and app language are stored in Cloud Firestore. The stored feedback document contains no Firebase UID or email address, and Henro Navigator does not use the report content to identify the tester. If a Firebase sign-in session already exists when the report is sent, Firebase may technically process its authentication status and identifier during transport and security-rule evaluation without storing them as fields in the feedback document. Precise location, diagnostic files, and screenshots are not captured automatically. Only when the user expressly selects an image file is it reduced to at most 1,600 pixels and 500 KiB, rendered as a new JPEG without carrying over embedded EXIF/GPS metadata, and stored as bounded image data in the same private Firestore document; the user must check any visibly private content before sending. Free text may contain information the user enters themselves. An unconfirmed report, random report ID, and optional compressed screenshot remain stored locally for safe retries until delivery is confirmed or the app/website data are deleted. Reports and screenshots are not public and are manually reviewed for deletion no later than twelve months after submission unless an ongoing safety or defect investigation requires longer retention. Discord remains a separate, optional community feature. Discord processes a connection and user-posted content under the Discord Privacy Policy only if the user deliberately opens Discord and posts there.

Beta location check: The first beta information dialog does not request location. Only after the language and onboarding questions are completed does the device ask for location permission so Henro Navigator can check once whether the position is within Shikoku. Those coordinates are neither stored nor sent. If permission is denied, the location cannot be determined, or it is outside Shikoku, the app instead uses a safe test location on Shikoku and explains the change. The test location is not a real location and is stored only locally for beta testing. For an explicitly started, temporary Mittenwald field test, the beta may obtain a fresh device location only for that test navigation; those coordinates are not stored or sent by the field-test check itself. If an online route calculation is started after separate consent, BRouter receives the start and destination coordinates as described above. When it ends or is cancelled, the app returns to Shikoku test mode.

6. Website analytics with consent

On the public HTTPS pages of www.henro-navigator.com, we use our self-operated Umami analytics service only after you have given voluntary consent. It helps us understand which pages are useful, which domain or campaign visitors come from, and whether information, Discord, or support links are used. The Henro Navigator mobile app and local previews never load this tracker. The website remains fully usable without consent. Where the GDPR applies, the legal basis is your consent under Article 6(1)(a) GDPR.

We process the access time, page path and title, referring domain, expressly allowed UTM campaign information, fixed click events, browser, operating system, device type, screen size, browser language, and country derived from the IP address. We do not collect account or email identifiers, form entries or notes, device or GPS location, and we do not create advertising or cross-site profiles. The Umami tracker does not use analytics cookies. The IP address is processed only briefly to determine country and a pseudonymous session value that rotates daily; it is not stored in the Umami analytics database.

We operate Umami and its database on Railway in US West (California, USA), which can involve processing in the United States. Analytics data currently has no automatic deletion period; we review it regularly and reset the website analytics when it is no longer necessary for the purposes above. Your choice is stored only locally in your browser. You can withdraw consent at any time under Website analytics settings; the tracker will then no longer load. Previously stored pseudonymous data cannot be assigned to an individual. We respect your browser’s Do Not Track setting.

7. Purpose and retention

Data is processed to provide the app and features you explicitly choose and, where necessary, to meet legal duties and legitimate security interests. Cloud account data generally remains until account deletion. Correction suggestions are retained only as long as review and traceability require. Beta feedback is generally retained for no more than twelve months. Technical providers may apply their own log-retention periods.

8. Deletion and your rights

Signed-in users can choose Account → Delete account and associated data to remove the authentication account, profile, temple visits, cloud walking records, associated local walking records, and correction suggestions. Because no UID or email is stored in a feedback document, account deletion does not automatically identify or delete it; for access or deletion, contact support with the report title and approximate submission time. Saved BRouter permission can be withdrawn from Settings at any time. If you cannot access the app, contact support from the registered email address. Depending on applicable law, you may have rights to access, correction, deletion, restriction, portability, objection, and a complaint with a data-protection authority.

9. Security and updates

Transfers use HTTPS encryption. No technical system is entirely risk-free. This policy will be updated when features, providers, or legal requirements change.