Privacy Policy – “Journory”

Last updated: 24 August 2026
Scope: iOS/Android app and connected web services, worldwide (esp. EU/EEA, UK, CH)

1) Controller

Controller (Art. 4(7) GDPR): Journory GmbH
Address: Kirchstraße 15c, 37081 Göttingen, Germany
Email: contact@journory.com
Legal notice (Imprint): https://journory.com/imprint

Data protection contact: contact@journory.com
Authority/DSA contact point: legal@journory.com

Data Protection Officer (DPO): We are not required in all cases to appoint a DPO. If we appoint a DPO, we will publish the contact details here and in-app. (DPO: NAME/ADDRESS/EMAIL)

Languages & governing version. This policy is drafted in German; translations are provided for convenience only. In case of discrepancies, the German version shall prevail.

2) Quick overview (TL;DR)

We process account data (email, name), content (journal/photos), location & motion data (incl. background—only with your consent where required), device/usage data, push tokens, purchase data (store receipts; no card handling by us), friends/social data, and—where applicable—advertising IDs (only with consent and, on iOS, only after App Tracking Transparency permission).

Purposes: account/sync, journeys/stops, maps & weather, friends & sharing, notifications, security/abuse prevention, subscription management (Lite/Gold/Platinum), games, waypoints & leaderboards, the "Birdy" companion & collections, (optional) advertising and (optional) tree planting through our partner.
Legal bases: contract (Art. 6(1)(b) GDPR), consent (Art. 6(1)(a)), legitimate interests (Art. 6(1)(f)), legal obligations (Art. 6(1)(c)). In addition, rules on access to end-user devices/local storage apply (in Germany in particular the Telecommunications Digital Services Data Protection Act (TDDDG, formerly TTDSG) and in the EU/UK ePrivacy/PECR principles). [oai_citation:0‡Robin Data GmbH](https://www.robin-data.io/en/data-protection-and-data-security-academy/wiki/german-telecommunication-and-telemedia-privacy-law?utm_source=chatgpt.com)
Your rights: access, rectification, erasure, portability, objection/withdrawal, complaint. Details below.

3) What data do we process – and why?

3.1 Account & login

  • Data: email, name (optional), password hash (server-side), OAuth data/tokens (Google/Apple), session/refresh tokens, timestamps, security-related login metadata (e.g., IP address, device information to the extent necessary).
  • Purpose: registration, login, account management, fraud/abuse prevention, session management.
  • Legal basis: Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (security/abuse prevention).

3.2 Location (foreground/background) & motion

  • Data: precise/approximate location, motion/activity data, timestamps; derived: trips/stops.
  • Purpose: automatic trip/stop detection, maps/weather, journaling convenience.
  • Legal basis: Art. 6(1)(b) GDPR (core functionality where necessary) and/or Art. 6(1)(a) GDPR (consent), in particular for background tracking, continuous tracking, precise tracking, or motion profiles.
  • Note: Background location may run when the app is closed. You can withdraw it at any time in your system settings. Features may then be limited.

3.3 Media (gallery/camera/sharing)

  • Data: photos/videos you select (including EXIF if present).
  • Purpose: upload/display/share within entries.
  • Legal basis: Art. 6(1)(b) GDPR (feature provision) and, where applicable, Art. 6(1)(a) GDPR (consent/OS permission).
  • Note: You decide which media you select. You can revoke OS permissions at any time.

3.4 Maps/places & weather

  • Data: map/tile requests (e.g., Google Maps), place search/Places, (reverse) geocoding requests, possibly coordinates; weather requests for your stops (OpenWeather API); device/usage data, timestamps.
  • Purpose: map display, place search, geocoding/reverse geocoding, weather display and history.
  • Legal basis: Art. 6(1)(b) GDPR; location disclosure/precision (where required): Art. 6(1)(a) GDPR.

3.5 Push notifications

  • Data: push token (APNs/FCM), event metadata (e.g., “invitation”, “new stop”, “friend request”).
  • Purpose: delivery of notifications.
  • Legal basis: Art. 6(1)(a) GDPR (consent/OS opt-in) or—where purely transactional and strictly necessary system notices—Art. 6(1)(b) GDPR (where applicable).

3.6 Friends & social features

  • Data: user ID, name, profile picture (if provided), friends list, friend requests/status, trips/stops shared with you, access-control/sharing metadata.
  • Purpose: add/manage friends, send/accept/decline requests, share trips/stops with selected people, load/display profile pictures.
  • Legal basis: Art. 6(1)(b) GDPR (contractual feature). Sharing occurs on your initiative/control; where legally required, Art. 6(1)(a) GDPR (consent).

3.7 In-app purchases/subscriptions & entitlement system

  • Data: product ID (e.g., journorygoldmonthly, journoryplatinmonthly), transaction/receipt IDs, subscription status (active, grace, expired, revoked), plan tier (Lite/Gold/Platinum), stop limit & count, expiry date, source (App Store/Play Store); no payment card data with us.
  • Purpose: provision of the subscribed tier, quota management, receipt verification with Apple/Google (server-to-server), and—if applicable—archiving where quota is exceeded after subscription ends (prune policy).
  • Legal basis: Art. 6(1)(b) GDPR.
  • Note: Payments are handled exclusively by Apple/Google. We store receipts/status only for verification and to provide your tier.

3.8 Advertising (optional; Lite plan only)

  • Data: advertising ID (IDFA/AAID), IP/device information, app interaction/usage data; possibly location (only with consent and only if technically used).
  • Purpose: serving (non-)personalized ads (e.g., Google AdMob), frequency capping, measurement/attribution within the lawful scope, fraud prevention.
  • Legal basis: consent (Art. 6(1)(a) GDPR) for personalized advertising and device access/IDs. Without consent, we serve only non-personalized ads (where ads are active).
  • iOS note (ATT): If data is used for “tracking” as defined by Apple, additional permission via App Tracking Transparency (ATT) is required. Without ATT permission, the IDFA is not used.
  • EEA/UK/CH note: When serving personalized ads to users in the EEA/UK (and Switzerland), Google requires a certified CMP integrated with the IAB TCF. [oai_citation:1‡Google Hilfe](https://support.google.com/admanager/answer/13554116?hl=en&utm_source=chatgpt.com)

3.9 Support, reports & moderation

  • Data: support communications, abuse reports, moderation decisions, necessary audit/trail logs (e.g., who reported what, processing status, reasons for decisions).
  • Purpose: support, enforcement of rules (incl. DSA notice-and-action where applicable), quality/security, abuse prevention.
  • Legal basis: Art. 6(1)(b) GDPR (support/contract), Art. 6(1)(f) GDPR (security/defense), and where applicable Art. 6(1)(c) GDPR (legal obligations).

3.10 Logs, diagnostics & security

  • Data: server/security logs (e.g., timestamps, request metadata, error codes), possibly device information (e.g., OS version) to the extent necessary.
  • Purpose: operations, troubleshooting, performance, security monitoring, abuse/fraud prevention.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operations) and, where applicable, Art. 6(1)(b) GDPR (service provision).

3.11 Games, waypoints & leaderboards

  • Data: game results (scores, timestamp, game type), waypoint balance ("◈"), credits and what triggered them (e.g. a completed quiz), leaderboard entries (user name, result, ranking), signals used to detect abuse (e.g. frequency and plausibility of credits).
  • Purpose: providing the games and the waypoint system, unlocking cosmetic content, displaying leaderboards, detecting and preventing manipulation (including daily and per-grant limits).
  • Legal basis: Art. 6(1)(b) GDPR (providing the features you use), Art. 6(1)(f) GDPR (legitimate interest in fair play and abuse prevention).
  • Visibility: if you take part in leaderboards while signed in, your user name and result are visible to other users — depending on the view, within your circle of friends or globally. No results are transmitted in guest mode. You may change your user name in the settings at any time and object to processing for leaderboard purposes under Art. 21 GDPR; we will then remove your entries and no longer include you. Write to contact@journory.com.
  • Retention: until you object, until the entry is deleted, or until your account is deleted; leaderboards may be reset periodically.

3.12 Companion ("Birdy"), studio & collections

  • Data: companion progress values (e.g. distance travelled, number of countries, continents, trips, stops, years), unlocked and worn cosmetic items, studio furnishing, collection status ("cabinet of curiosities"), passport stamps, achievements; when visiting a friend's studio, the associated visibility setting.
  • Purpose: displaying the companion and its progress, unlock logic, collections and statistics, synchronisation across devices.
  • Legal basis: Art. 6(1)(b) GDPR (providing the feature).
  • Note: these values are derived from your travel data. They do not create a profile for advertising purposes and are not passed to third parties.

3.13 Planting trees (partner Tree-Nation)

  • Data: your name; when gifting, additionally the name of the recipient; purchase receipt and transaction data from the relevant store; allocation of the certificate to your account.
  • Purpose: commissioning the planting and issuing the personalised certificate through our partner Tree-Nation.
  • Legal basis: Art. 6(1)(a) GDPR (express consent, obtained in the app before purchase) together with Art. 6(1)(b) GDPR for processing the purchase. Without consent the service cannot be performed; consent may be withdrawn with effect for the future, without affecting certificates already issued.
  • Recipient: Tree-Nation (see Section 5). If you gift a tree, the recipient is notified in the app and can view the certificate; please make sure they are content for their name to be used.

3.14 Use without an account (guest mode)

  • If you use Journory as a guest, your journeys, stops, images and diary entries remain exclusively on your device. No transfer to our servers takes place; we have no access to them and can neither provide them by way of access request nor restore them.
  • Data subject rights against us are accordingly without object, because no personal data is held by us. You can delete the data yourself at any time by removing it in the app or uninstalling the app.
  • If you register later and transfer the data into an account, the remaining provisions of this policy apply from that point on.

4) Overview of legal bases

  • Contract Art. 6(1)(b): account, sync, trips/stops, maps/weather, purchases/subscriptions, friends/sharing.
  • Consent Art. 6(1)(a): background location/motion (where required), media access (OS), push (OS), personalized ads/IDs/tracking, possibly location for ads, and non-essential device access.
  • Legitimate interests Art. 6(1)(f): IT security, abuse/fraud prevention, stability/troubleshooting to the minimum necessary extent.
  • Legal obligations Art. 6(1)(c): authority requests/retention duties, DSA-related processes (e.g., documentation obligations).

5) Recipients & categories of service providers

• Hosting/backend: EU/EEA (with data processing agreement under Art. 28 GDPR where required).
• Google: auth (Google Sign-In), Maps/Places/Geocoding (Google Maps Platform), AdMob/UMP (ads/consent), FCM (push, possibly via Expo).
• Apple: Sign in with Apple, App Store billing, server-to-server receipt verification.
• OpenWeather: provision of weather data (One Call API 3.0).
• Mapbox: provision of map tiles and map styles. When the map loads, technically necessary connection data (including IP address and the requested map area) is transmitted to Mapbox.
• Tree-Nation: planting of trees and issuance of personalised certificates. Your name and — when gifting — the recipient's name are transmitted, solely on the basis of your prior consent (Section 3.13). In this respect Tree-Nation acts as an independent controller for planting and certification.
• Journory backend (self-operated): entitlement management, receipt verification, user account management, friend management.
We conclude data processing agreements with processors where required (Art. 28 GDPR) or otherwise ensure appropriate contractual safeguards.

6) International data transfers

Where data is transferred to recipients outside the EEA, we use appropriate safeguards:
• USA: transfer to recipients certified under the EU–US Data Privacy Framework (certification is checked) or based on the EU Standard Contractual Clauses (SCCs) and, where necessary, additional measures. [oai_citation:2‡European Commission](https://ec.europa.eu/commission/presscorner/detail/en/qanda_23_3752?utm_source=chatgpt.com)
• UK: UK IDTA or UK addendum to the SCCs.
• Switzerland: Swiss–US DPF extension or Swiss-recognized clauses.

We also apply technical and organizational measures (e.g., encryption, access controls).

7) Retention periods

We store personal data only as long as necessary for the respective purposes and delete it thereafter unless statutory retention obligations require longer storage.

• Account/profile: until deletion; thereafter typically up to 6 months for evidence/abuse prevention purposes (if necessary).
• Trips/stops/journal/media: until you delete them or your account is deleted; after subscription expiry, excess stops may be archived under the prune policy (prior in-app notice).
• Friend data: until unfriending or account deletion.
• Entitlement/subscription data: until account deletion; evidence/accounting data under commercial/tax law may be retained up to 10 years.
• Push tokens: until withdrawal/new token or uninstall/logout.
• Logs/security/error logs: typically 7–30 days (longer only where needed to investigate incidents/claims).
• Support/moderation: typically 3–6 years (evidence/compliance) where necessary.
Statutory retention periods (e.g., German tax/commercial rules) take precedence where applicable.

8) Consent management (CMP), device access & TDDDG/ePrivacy

8.1 In-app consents
For certain features we obtain consent where required (e.g., background location, push, personalized ads). You can withdraw consent at any time with effect for the future (in-app and/or in system settings).

8.2 Ads/TCF (EEA/UK/CH)
If we serve ads in the EEA/UK/CH, we use a consent management platform (CMP) for personalized advertising and vendor sharing where required. If we use Google AdMob, we use (where required) a Google-certified CMP compatible with the IAB TCF. Without consent, only non-personalized ads are served (where ads are active in the Lite plan). [oai_citation:3‡Google Hilfe](https://support.google.com/admanager/answer/13554116?hl=en&utm_source=chatgpt.com)

8.3 Device access / on-device storage
For access to information stored on your device (e.g., advertising IDs, local storage like AsyncStorage, similar identifiers), we obtain prior opt-in where legally required (in Germany in particular under the TDDDG; in the EU/UK under ePrivacy/PECR principles). Technically necessary storage access for core functions may be exempt. [oai_citation:4‡Robin Data GmbH](https://www.robin-data.io/en/data-protection-and-data-security-academy/wiki/german-telecommunication-and-telemedia-privacy-law?utm_source=chatgpt.com)

8.4 Consent management services (Germany, optional)
In Germany, recognized consent management services may exist under the Consent Management Ordinance (Einwilligungsverwaltungsverordnung, EinwV). If/when we support such signals, we will provide transparent information here. [oai_citation:5‡cookieyes.com](https://www.cookieyes.com/blog/german-consent-management-ordinance/?utm_source=chatgpt.com)

9) Children & teenagers

The app is intended for persons aged 16 and above (default in Germany under Art. 8(1) GDPR). In some countries, the age of consent ranges from 13–16. If we allow access for younger users in a region, we will obtain parental consent where technically feasible and legally required.

10) Security

Transport encryption (TLS), role-based access, API-key-protected endpoints, logging/monitoring, hardening/updates, backups and incident processes (Art. 32 GDPR). We test backup/restore regularly.

11) Data breaches (breach response)

We maintain a process under Art. 33/34 GDPR (including notification to authorities within 72 hours where applicable, notification of affected users where required, and documentation). Contact: contact@journory.com / legal@journory.com.

12) Your rights (EU/EEA, UK, CH)

  • Access, rectification, erasure, restriction, portability (Arts. 15–20 GDPR or UK/CH equivalents).
  • Objection to processing based on Art. 6(1)(f) (Art. 21 GDPR).
  • Withdrawal of consents (effective for the future).
  • Complaint to a supervisory authority (e.g., in your place of residence). Responsible for us: The State Commissioner for Data Protection of Lower Saxony.

Contact for data subject rights: contact@journory.com (or in-app “Legal”).
Data export: You may request a copy of your personal data in a structured, commonly used, machine-readable format (e.g., JSON).
Rest of world: We respect mandatory rights under your applicable laws (where applicable). Upon request, we will inform you about your relevant rights and implement valid requests.

13) WebView/links & third-party content

When external websites are displayed in the app (WebView), the privacy notices of those websites apply in addition. Those third parties are solely responsible for such content.

14) Automated decisions / profiling

No automated decision-making with legal effect for you (Art. 22 GDPR). Profiling occurs, if at all, only in a limited form for ad personalization—and only if you have consented (see Section 8). Automatic stop archiving after subscription expiry (prune policy) is not an automated individual decision within the meaning of Art. 22 GDPR because it is based on the contractual plan quota and you are informed in advance.

15) Changes to this policy

We update this policy when features or legal requirements change. The current version is available in-app/on the website; material changes are communicated in-app (with version/date).

16) Contact

Data protection contact: contact@journory.com
Journory GmbH, Kirchstraße 15c, 37081 Göttingen, Germany
Authority/DSA contact point: legal@journory.com

17) UK/CH representative (only if applicable)

UK: If we are required under UK GDPR to appoint a UK representative, we will publish the contact details here: (UK Representative: NAME/ADDRESS/EMAIL)

Switzerland: If we are required under Art. 14 Swiss FADP to appoint a Swiss representative, we will publish the contact details here: (CH Representative: NAME/ADDRESS/EMAIL)

Annex A – SDK/feature matrix (excerpt)

AreaModules/SDKs (examples)PurposeLegal basis
Authexpo-auth-session, expo-apple-authenticationLogin (Google/Apple), sessionsArt. 6(1)(b)/(f)
Location/motionexpo-location, react-native-background-geolocation, react-native-background-fetchTrip/stop detection (incl. background)Art. 6(1)(a) / (b)
Mapsreact-native-maps, Google Maps/Places/Geocoding APIMap/geocoding/POIs/reverse geocoding(b)/(a)
WeatherOpenWeather One Call API 3.0Weather per stop, min/max temperature, history(b)/(a)
Mediaexpo-image-picker, expo-media-library, expo-sharingPhoto/video upload & sharing(a)/(b)
Text editorreact-native-pell-rich-editorRich-text editing for journal entries(b)
Pushexpo-notifications (APNs/FCM)Notices/invitations/friend requests(a)/(b) (depending on message type)
Adsreact-native-google-mobile-ads + CMP (IAB TCF v2)(Non-)personalized ads (Lite plan only)(a)
Purchases/subscriptionsreact-native-iap v13In-app subscriptions (Gold/Platinum), receipt verification (Apple S2S, Google S2S)(b)
System/UX@react-native-async-storage/async-storage, @react-native-community/netinfo, react-native-webview, react-native-reanimated, react-native-screens, react-native-gesture-handler, @react-navigation/*, expo-router, react-native-svg, expo-splash-screen, expo-status-bar, @react-native-community/datetimepicker, react-native-linear-gradient, react-native-safe-area-context, expo-crypto, react-native-dotenv, i18next/react-i18next, axiosCaches/settings, network status, UI/navigation, i18n/translation, crypto, configuration, API communication(a)/(f)/(b) (depending on feature)

Annex B – Regional notes (transparency)

  • EU/EEA (incl. Germany): GDPR + ePrivacy; in Germany additionally TDDDG (formerly TTDSG) for device access/similar technologies. Consent is required for personalized ads/IDs and non-essential device access where applicable. [oai_citation:6‡Robin Data GmbH](https://www.robin-data.io/en/data-protection-and-data-security-academy/wiki/german-telecommunication-and-telemedia-privacy-law?utm_source=chatgpt.com)
  • UK: UK GDPR + PECR. CMP accordingly; IDTA/SCC-UK for transfers.
  • Switzerland: Swiss FADP (revised, in force since 01/09/2023). Swiss–US DPF extension/SCC-CH for transfers; Swiss representative may be required only if statutory conditions are met.
  • Rest of world: We apply the above principles accordingly; mandatory privacy rights under your jurisdiction remain unaffected.

Start free — 500 stops included.

Get it