anordery

Privacy notice · version 2026-09-11

Your trail data should never be a surprise.

This notice explains what the private Anordery project collects, why it is used, who receives it, and the choices available to you.

1. Controller and contact

The controller uses the public name anordery.com and operates this private project from Finland. Privacy questions and requests can be sent to [email protected].

Effective 11 September 2026. The service is intended only for people aged 18 or over.

2. Data we process

  • Account data: name, email, password hash, approval state, and account timestamps.
  • Journey content: titles, descriptions, photographs, routes, dates, and publication settings.
  • Precise tracking data: Garmin points, timestamps, elevation, movement, derived stages, overnight areas, and progress.
  • Sensor data: Ruuvi identifiers, timestamps, temperature, humidity, pressure, movement, acceleration, import files, and rejected rows.
  • Integration and device data: private Garmin feed details, hashed device credentials, device activity, and import provenance.
  • Operational data: service usage, scheduled-job results, audit events, security logs, IP addresses processed by infrastructure providers, and support messages.
  • Environmental and briefing data: route-ahead samples, weather and hazard facts, generated narrative, and email-delivery status.

Data comes from you, your connected Garmin and Ruuvi services or devices, public environmental providers, and normal operation of the website. Do not upload another person's data unless you have authority to do so.

3. Purposes and legal bases

  • Providing the service and private dashboard: performance of the Terms of Service.
  • Publishing delayed locations: your separate, optional and withdrawable consent.
  • Publishing delayed carried-sensor readings: your separate, optional and withdrawable consent.
  • Account approval, security, abuse prevention, cost controls, and audit evidence: legitimate interests in operating a small, safe service.
  • Responding to rights requests and incidents: compliance with legal obligations.

Private tracking does not require public publication. Withdrawing publication consent does not delete the private source data or your account; it immediately blocks that category from Anordery's public APIs. Copies already made by visitors cannot always be recalled.

4. Recipients and services

Anordery uses Hetzner for the server, DigitalOcean Spaces for media, private imports and backups, Cloudflare for DNS, proxying and security, and Brevo for transactional email. Garmin supplies tracking data and Ruuvi supplies sensor data when you connect them.

Open-Meteo and GeoNet receive sampled coordinates needed for forecasts and hazards. OpenAI receives sanitized deterministic weather facts for optional briefing prose—not exact coordinates or raw tracking points—and API response storage is disabled. When a visitor opens a map, OpenStreetMap or LINZ may receive normal request data such as an IP address and browser information. The landing page does not load map tiles.

Some providers may process data outside the EEA. Where required, Anordery relies on the provider's data-processing terms and recognised transfer safeguards such as adequacy arrangements or EU Standard Contractual Clauses. Details are available on request.

5. Publication and safety

Publication is off by default. A Journey owner must separately permit delayed tracking and sensor publication, and can pause tracking or hide a day. By default a completed day is published at 08:00 the following morning; an owner may instead choose a shorter delay for their own track, down to ten minutes, which publishes each position that long after it was recorded. A shorter delay reduces the head start it gives. The delay reduces immediate safety risk either way but does not anonymise a Journey: routes, routines, overnight areas, and sensor timestamps can identify or locate a person. Public pages are not a navigation or emergency service.

6. Retention

Account, Journey, location, and sensor records are kept while the account is open. A scheduled job enforces the following periods automatically:

  • Raw sensor import and rejected-row files: erased from private storage after 30 days; the import keeps only counts and provenance.
  • Sensor import previews that were never confirmed: deleted after 30 days.
  • Audit events: deleted after one year.
  • Scheduled job results: deleted after 90 days.
  • Monthly service-usage counters: deleted after 13 months.
  • Account requests still pending after six months that own no Journey: deleted.
  • Encrypted database backups: 30 days.
  • Companion positions: deleted after 30 days, unless the companion chose to keep them as journey history.
  • Positions shared on an official trail season: kept while that season runs, then deleted 90 days after it closes.

A trail season is a record of that season, so what is shared into one is kept while it runs rather than swept after a month. Closing the season starts the grace period above, and you can delete everything about yourself at any time without waiting for either.

Erasing a Journey or closing an account removes those records from the live service immediately and deletes the stored media and import objects. Because backups are kept for 30 days, erased rows can remain in encrypted recovery copies until those copies expire.

7. Cookies and local device storage

The website uses only necessary Django session and CSRF cookies for sign-in and request security. No advertising or analytics cookies are currently used, so no cookie-consent banner is shown. If non-essential cookies are added, they will remain off until consent.

The private iPhone companion stores its device credential in Keychain, configuration in app preferences, and unsent sensor batches in the protected app sandbox. Its morning notification is optional and local to the device.

8. Your rights

Signed-in users exercise most rights themselves under Privacy controls: see what is stored, correct your name and email, download a machine-readable JSON export, withdraw publication consent, erase an individual Journey, or close the account and erase everything it owns. No request or waiting period is required.

You may also request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Send requests to [email protected]. Identity may need to be verified. Requests are normally answered within one month.

You may also complain to the Finnish Office of the Data Protection Ombudsman at tietosuoja.fi.

9. Automated processing and changes

Account approval is performed by a person. Automated calculations and optional LLM prose do not make decisions with legal or similarly significant effects. Material privacy changes will be dated and communicated through the account interface where appropriate.

Related document: Terms of Service.