Privacy

What stays on your phone, what reaches the community service and what other hikers can see.

Updated August 25, 2026

Sunshine Coast Trail Planner is an independent app operated by Leah Gerber. No account is required. The app has no third-party advertising or analytics SDK.

The app does not sell personal information or share it for advertising. Links you open from the app and services you choose through the system share sheet have their own privacy practices.

Current beta: The app is distributed through Apple TestFlight. No subscription or in-app purchase is offered in the beta, so the app does not receive payment information.

Location on your phone

Map position

When you enable location, the app reads your precise coordinate, GPS accuracy and timestamp. It uses that fix on your phone to draw your position and estimate a nearby trail-marker interval. Foreground fixes are not kept as a trip history.

Trip recording

Trip Recording is off until you tap Start. If you allow background location, the app stores coordinates, timestamps and any accuracy, altitude, speed, heading and mock-location fields supplied by the operating system. Recording can continue while the screen is locked until you stop it or the operating system interrupts it.

Recorded tracks stay in the app's local storage. They are not uploaded to the community service. You can export a track as GPX or delete it from the Trip Recording screen.

Manual sharing

A one-time family update can include an exact GPS fix, a rough trail section or no position. You choose the level before opening the system share sheet. The person or service you select receives the message.

Other data kept on your phone

Saved trips, destinations, hut-night plans, feed drafts and posts, pending sync operations, display and unit settings, the weather cache, journal entries, blocked-hiker choices and family-sharing settings are stored locally. The offline map and trail dataset ship with the app.

The app creates a random installation identifier for community features. Its edit credential is stored in iOS Keychain or Android's encrypted secure storage when available. Ordinary community data is stored in the app's local storage.

Community service

With a network connection, the TestFlight build contacts the community service when the app opens or returns to the foreground. It downloads current posts and plans and sends queued changes. The request includes the random installation identifier and edit credential. The server stores a one-way hash of the credential.

Hut-night plans can include an optional first name, where you are travelling from, hut, night, party size, walking direction and sleeping preference. They are self-reported plans and are visible to synced app users.

Feed posts can include an optional first name, where you are travelling from, category, text, date, reply, selected marker kilometre, water report, ride date, photo and an optional public contact field for rides or lost-and-found. The current composer does not publish raw GPS coordinates with a feed post. Community posts are public to synced app users.

A phone number, email address or social handle entered in the contact field is public. Removing a post later cannot remove copies another person already saw or saved.

Community photos

When you attach a photo, the app copies it into app storage, resizes it and re-encodes it before upload. Re-encoding removes embedded metadata, including the photo's GPS metadata. The original in your photo library is unchanged.

Uploaded photo files are stored in a private Cloudflare R2 bucket. An opaque photo ID, file type, size, author ID, report ID, moderation status and upload time are stored in Cloudflare D1. A photo is available through an opaque community-service URL. Hiding or deleting its post prevents a new uncached request from receiving the photo. A previously cached response can remain available for up to 24 hours.

An uploaded photo that is never attached to a synchronized post is deleted by an hourly cleanup after 24 hours. Deleting your synchronized post queues deletion of its server photo and database row. That deletion reaches the server after the app reconnects and syncs. Clearing a post does not delete the original from your photo library, and an app-managed local copy may remain until app storage is cleared.

A post already synchronized to another phone can remain in that phone’s local storage after it is hidden or deleted on the server. Treat community posts and photos as public when publishing them.

Family follow links

A family link contains only the feed posts and planned hut nights you publish. It does not contain your complete recorded track or automatic GPS updates. Anyone with the private link can open it.

The page updates after your phone reconnects and synchronizes, so it may be hours or days behind. Turning off family sharing revokes the link after the revocation syncs. Call 911 if a hiker is overdue; the page does not monitor emergencies.

Cloudflare and network data

The community service runs on Cloudflare Workers. Community records are stored in Cloudflare D1 and photos in Cloudflare R2. Cloudflare processes normal request data, including IP address and technical request details, to deliver and protect the service.

The service uses the anonymous installation ID and IP address in fixed hourly rate-limit counters. These counters are used to limit abuse, not to build a profile. Expired counter windows are eligible for deletion during later service requests.

The app also checks the community service for an operator-written trail notice when it has signal. If you tap Check weather snapshot, the app requests current Powell River-area weather from Environment and Climate Change Canada and stores the returned snapshot on your phone. Opening an outside map, social link, official trail site or transport site sends you to that provider.

Moderation

You can report a community post or hut plan and block another hiker. Blocking is stored on your phone. A report sends the community service your anonymous author ID, the content ID, a fixed reason and the report time. Reported content is hidden on your phone immediately. Some non-safety content can be hidden automatically after enough separate reports. Safety reports wait for human review.

Leah Gerber is the community moderator. Email sct@milecheckapp.com if a post needs review or an in-app report does not cover the problem.

Local-service listings

A paid local-service listing, if included, is bundled directory content and labelled Sponsored. The app does not send listing views, calls or link taps to the listed business and does not build an advertising profile.

Retention and deletion

The beta service does not yet apply a fixed automatic deletion period to synchronized author records, posts, hut plans, flags or family-link records. A post can stop appearing in the current feed because of its age without being erased from the server.

  • Delete your own feed post in the feed. Its server copy and uploaded photos are removed after the deletion syncs, subject to the cache and already-synced-copy limits above.
  • Cancel a hut-night plan to remove it after the cancellation syncs.
  • Turn off family sharing to revoke the follow link after the change syncs.
  • Delete a recorded trip from the Trip Recording screen.
  • Clear the app's storage or remove the app to remove data in its app container. Secure-storage and device-backup behaviour is controlled by Apple or Google.

For an access, correction or server-deletion request, email sct@milecheckapp.com. There is no account, so an email address alone may not identify your records. We may ask for details about the post, plan or family link you want located.

Contact and changes

Privacy questions: sct@milecheckapp.com.

This page will be updated before the app begins selling a trail pack or materially changes its data handling. The date at the top shows the latest revision.