Privacy Policy

Updated August 31, 2026

Privacy by default

AirPath can be used without an account. Optional diagnostics and usage analytics are off by default. Each category requires an explicit choice and can be disabled at any time in Settings & About.

Location

AirPath processes device location to display position and provide walking navigation. Exact positions and route geometry stay on the device during automatic diagnostics and usage analytics. AirPath does not use location for advertising. Optional background navigation is off by default. If the user enables it and grants the operating-system permission, location updates continue only while an active route is running; Android displays an ongoing notification and iOS displays its location indicator.

Optional diagnostics and analytics

With consent, AirPath may send allow-listed reliability events, app version, platform, coarse performance buckets, error type, and scrubbed stack traces. The collector rejects arbitrary properties, coordinates, addresses, route geometry, advertising identifiers, email addresses, IP addresses inside payloads, and local home-directory paths. Raw events are automatically deleted after 30 days. Non-identifying daily statistical summaries are retained for up to 365 days. On Android and iOS, Firebase Crashlytics processes consented native crash and Android app-not-responding reports. AirPath scrubs custom Flutter error text and stack traces before forwarding them. Native crash reports can include technical context such as app/OS version, device model, memory state and whether the app was in the background. Crash collection is off by default, AirPath does not set a Crashlytics user ID, and Firebase Analytics is not used. Enabling diagnostics, enabling usage analytics, or explicitly sending a route report can initialize Firebase services for secure delivery, including installation identifiers. Crashlytics uses its own installation identifier for crash reporting when diagnostics is enabled. These identifiers are not AirPath accounts or advertising identifiers. Firebase keeps Crashlytics reports and associated identifiers for 90 days before starting removal from its live and backup systems. Disabling diagnostics stops crash collection and deletes unsent native crash reports. Turning off a telemetry category also clears pending AirPath telemetry from the local queue.

Route problem reports

A route report is separate from automatic analytics. A report may include its category, city, app version, optional note, and a map position only after a separate confirmation. Report coordinates are not accepted without that explicit consent and are rounded to about a 100-metre grid before storage. The app warns against personal details and both client and server scrub common contact, coordinate, network-address, phone, and local-path patterns from notes. Reports are deleted after 90 days.

On-device data

Privacy choices, saved and recent places, active navigation state, route history, and downloaded city packages are stored locally. The active route is encrypted with a device-bound key. AirPath excludes its local route, history, saved-place, telemetry-queue, and downloadable package data from Android cloud/device-transfer backup and iOS iCloud backup. Deleting the app removes its local data.

Infrastructure and providers

Cloudflare delivers city packages, map assets and public pages and processes consent-based telemetry and reports. Vercel hosts the Web application and some application resources. Firebase Crashlytics processes native crash and Android app-not-responding reports only after diagnostics consent. Firebase App Check uses Google Play Integrity or Apple App Attest, with Apple DeviceCheck as a fallback, to reject forged telemetry and report requests; attestation and Firebase installation identifiers identify the app installation for security/reliability, not an AirPath account or advertising profile. Place searches run against the downloaded city index; search text is not sent to a public geocoding service. Weather is supplied through AirPath's server-side Open-Meteo cache for the selected city, not the device's precise position. OpenStreetMap and Overture Maps data are used under their applicable attribution and licence. Infrastructure providers can receive ordinary connection metadata such as an IP address when delivering files, as any network service does.

Email enquiries

If you email AirPath, your email address and message are received through Proton Mail and used to handle your enquiry. Do not send passwords, payment details or unnecessary personal information.

Contact and updates

For privacy questions or requests about information you have submitted, email AirpathHelp@proton.me. Other contact options are on the support page. Material changes to data use will be published here and, when required, presented in the app.