Privacy Notice for PathCraft

As of: 18 April 2026
Contact for privacy inquiries: kontakt@SuGreenX.eu

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described in this privacy notice is:

Christian Techmer
Mühlbachstr. 29
88697 Bermatingen
Germany
Email: kontakt@SuGreenX.eu

Privacy-related inquiries may be sent to the contact details above.

2. Short Overview

3. Scope and Allocation of Roles

  1. This privacy notice describes the processing of personal data by the app operator in connection with PathCraft.
  2. According to the described architecture, PathCraft is largely designed to operate locally. Many contents and settings remain on the user's device or—if iCloud synchronisation is enabled—in the private iCloud area of the Apple account used by the user.
  3. This privacy notice distinguishes between local storage on the device or in the user's private iCloud area, technical, purchase-related, consent-related, and security-related data processed online by the app operator, and processing operations that the user directly triggers with the respective third-party provider by using external third-party functions.
  4. To the extent data is transmitted directly from the app to a third-party provider selected by the user and the app operator does not receive that content through its own backend, this notice describes the data flow and the role of the app only in a supplementary manner. The third-party provider's own privacy and contractual documents are decisive for the subsequent processing by that provider.

4. Basic Processing Principles in PathCraft

  1. The core functions of the app do not require a general online account or a permanent online content profile with the app operator.
  2. According to the described system architecture, local file contents, conversation contents, translations, attachments, routes, imported GPX or KML files, images, audio, and comparable content data are not collected, analysed, or shared online by the app operator for its own advertising, profiling, or general tracking purposes.
  3. This does not preclude the app operator from processing limited technical data relating to feature unlocks, purchases, credits, weather credit usage, consent records, misuse prevention, integrity checks, error analysis, or simple usage aggregates to the extent this is necessary to provide and secure the functions offered.
  4. Where conversation, translation, or transcription histories are stored in the app, this is generally done locally on the device or—if iCloud synchronisation is enabled—in the private iCloud area of the user's Apple account, until the user changes or deletes them.

5. Operator-Side Online Processing and Storage Areas

5.1 User Mapping, Trials, and Activations

Technical storage areas: users, trial_grants, apple_transactions, entitlements

Processed data: Depending on usage, this includes in particular a pseudonymous Apple identifier derived from Sign in with Apple, internal user ID, session or access tokens, trial start and end times, product and product type, transaction ID, original transaction ID, app account token, purchase, expiry, revocation, or unlock times, as well as authorisation and status data.

Purposes:

Legal bases:

Retention period or criteria: The data is stored for as long as it is required for the respective trial, purchase, unlock, restoration, or evidentiary function. It is then deleted or anonymised unless statutory retention obligations or legitimate interests in asserting, exercising, or defending legal claims prevent this.

5.2 Credits, Weather Credit Usage, Tip Purchases, and Managed Usage Events

Technical storage areas: credit_ledger, managed_usage_events, tip_purchases, and—where implemented separately for technical reasons—functionally comparable storage areas for monthly weather credit usage records

Processed data: Depending on the function, this includes in particular internal user or installation references, pseudonymous software or installation ID, credit bookings, debit or credit events, product reference, functional area, timestamps, month period, usage-related counters, billing data relating to models, providers, or weather functions, technical location references for weather requests, references to purchases or feature unlocks, as well as status and verification data.

Purposes:

Legal bases:

Retention period or criteria: Booking, purchase, and billing-related data is regularly stored until the respective contractual, evidentiary, or retention purpose no longer applies; statutory commercial, tax, or other retention obligations remain unaffected. Purely technical usage events are deleted, condensed, or anonymised as soon as they are no longer required for billing, prevention of misuse, or defence of rights. Weather credit usage records are kept in a personal or pseudonymous form only for as long as required for the ongoing monthly logic, credit calculation, restoration, error resolution, prevention of misuse, or defence of rights; they are then deleted, condensed, or anonymised unless overriding evidentiary or retention obligations apply.

Special note on weather credits: To the extent PathCraft offers a credit-based weather function, the currently described setup may allow one credit to cover one weather location for one calendar month. In order for the app to calculate usage correctly, recognise weather locations already billed within the same month, keep credit balances traceable, and prevent misuse, the operator backend may store, per pseudonymous software or installation ID, whether a weather query for a particular weather location or technical location reference has already been billed in a given monthly period. To the extent technically possible and sufficient for billing, full clear-text addresses should not be stored as the location reference; instead, minimised references such as normalised, truncated, or gridded coordinates, hash, geohash, or provider location identifiers should be used. This processing does not serve to create a movement profile, presence profile, or advertising profile.

No separate consent is obtained for this necessary credit and usage record to the extent the processing is required exclusively to provide the credit-based weather function requested by the user, to maintain the credit balance, to restore usage status, to clarify errors, or to prevent misuse. Should any additional, non-essential analysis, convenience history, profiling, or advertising use of such weather usage data be planned in the future, this would only take place on a separate legal basis and, where legally required, after separate consent.

If a software or installation ID is stored on or read from the device for this function, this occurs, for the required credit function, only to the extent necessary to provide the expressly requested digital service. Non-essential device access, for example for general analytics or advertising purposes, is not covered by this.

Important note: To the extent the app operator offers managed AI usage, managed_usage_events according to this notice refers to billing-related and usage-related event data. This does not automatically describe storage of the actual content data such as prompts, audio, responses, images, or attachments in the operator backend, and such storage would have to be disclosed separately if it actually takes place.

5.3 Consent and Policy Records

Technical storage areas: byok_consents, byok_consent_events, service_consent_policies, service_consents, service_consent_events, route_playback_consent_policies, route_playback_consent_events

Processed data: Depending on the function, this includes in particular installation or subject identifier, provider, functional area, policy version, text version, language, region, platform, app version, build, UI context, hash values, links to the legal texts shown, event type such as shown, accepted, declined, or withdrawn, time, and limited evidentiary data.

Purposes:

Legal bases:

Retention period or criteria: The data remains stored for as long as the relevant function is used or can be reactivated and for as long as records of display, consent, withdrawal, or permission events are required for legal, security, or defence purposes. Policy text versions and hash values may be retained for longer to the extent event logs refer to them.

5.4 Installation Authenticity, Technical Integrity, and Simple Usage Aggregates

Technical storage areas: route_playback_app_attest_installations, route_playback_usage_daily

Processed data: Depending on the function, this includes in particular technical installation identifiers, attestation-related or registration-related verification data, event type, timestamps, platform and language data, and daily usage aggregates or counters.

Purposes:

Legal bases:

Retention period or criteria: Security and installation data is stored for as long as required for integrity checks and misuse prevention. Simple daily usage aggregates are deleted, condensed, or anonymised as soon as they are no longer needed for monitoring, capacity planning, or security evaluation.

5.5 Support and Communication

If the user contacts the app operator, for example by email at kontakt@SuGreenX.eu, the app operator may process the contact details communicated by the user, the content of the request, attachments, as well as processing and response data.

Purposes: handling support inquiries, error analysis, performance of the contract, communication, and defence of rights.
Legal bases: Article 6(1)(b) GDPR to the extent the request relates to a contractual relationship or pre-contractual measures; otherwise Article 6(1)(f) GDPR.
Retention period: until final handling of the inquiry and beyond only to the extent statutory retention obligations or legitimate interests in documentation and defence of rights apply.

6. Third-Party Processing Triggered Directly from the App

6.1 Apple Services

When using map, search, geocoding, Look Around, route calculation, weather, Sign in with Apple, App Store, or iCloud-related functions, search texts, addresses, coordinates, start and destination points, location data, query context, Apple-related identifiers, purchase or sign-in information, as well as synchronised app content may, depending on the function, be transmitted directly to Apple or to services connected via Apple.

To the extent the app operator does not receive this content through its own backend, Apple's own documents govern the subsequent processing by Apple. The technical maintenance of a weather credit usage record by the app operator must be distinguished from this and does not mean that the app operator monitors the accuracy of the weather data or controls actual on-site use.

6.2 Google Services and YouTube

For optional Street View or Street View metadata functions, search terms, coordinates, metadata queries, and, where applicable, a Google API key used by the user may, depending on the function, be transmitted directly to Google services.

Upon the explicit invocation of optional YouTube functions, the app may pass search terms, target URLs, coordinates, search radius, or other parameters selected by the user to a Google or YouTube link and open the external YouTube app or an external website. Any further processing from the moment the external service is opened is carried out by the respective provider under its own terms and privacy notices.

6.3 External AI, Speech, and Translation Services

When using external AI, speech, transcription, text-to-speech, or translation services, texts, audio data, voices, images, attachments, transcriptions, translations, speech outputs, system instructions, conversation states, and, where applicable, contextual data may, depending on the function, be transmitted directly to the third-party provider selected by the user.

Where the user uses their own API key and the app sends the request directly to the third-party provider, the app operator, according to the described architecture, generally does not receive this content data through its own backend. This does not affect the limited operator-side processing described in Section 5, for example for consent records, feature unlocks, credits, security events, or managed billing data.

The subsequent processing by the respective third-party provider is governed by that provider's current privacy and contractual documents.

7. Categories of Recipients

Depending on the function, personal data may be transmitted to the following recipients or categories of recipients:

Should additional technical processors be added in the future for operator purposes, this privacy notice will be updated in the event of material changes.

8. Transfers to Third Countries

  1. Depending on the third-party function used and on the operator service provider involved, personal data may be transferred to countries outside the European Union or the European Economic Area, in particular to the United States or to other countries in which the respective provider or its subprocessors operate.
  2. To the extent the app operator uses its own service providers with a third-country nexus—currently in particular Cloudflare for hosting, edge delivery, security, and backend functions—such transfers take place only in accordance with Articles 44 et seq. GDPR.
  3. Depending on the recipient and data flow, the legal transfer mechanisms may include in particular:
    • an adequacy decision pursuant to Article 45 GDPR,
    • appropriate safeguards pursuant to Article 46 GDPR, in particular EU Standard Contractual Clauses,
    • and, where required, supplementary technical and organisational protection measures.
  4. To the extent a recipient is validly certified under a relevant adequacy framework such as the EU-U.S. Data Privacy Framework, the transfer may also be based on that framework.
  5. For third-party providers that the user selects themselves or uses directly via their own API keys or external links, transfers to third countries take place directly to the respective third-party provider or service opened by the user. The concrete processing locations, storage practices, and protection mechanisms are then determined by the current documents of that provider.

9. Requirement to Provide Data

  1. For the mere core use of local functions, only a limited amount of personal data must be provided to the app operator.
  2. Certain data is, however, required if the user wishes to use optional trial, purchase, unlock, restoration, credit, weather credit, or consent functions. Without this data, the relevant functions cannot be provided technically or legally. For credit-based weather functions, this may in particular include a pseudonymous software or installation ID and a month and location reference for usage calculation.
  3. Anyone wishing to use external third-party functions must transmit the data required for that function directly to the respective third-party provider or external service; otherwise the respective function cannot be performed.

10. Retention Periods at a Glance

Unless a specific period is stated in this privacy notice, personal data is deleted or anonymised once the respective processing purpose no longer applies and no statutory retention obligations or legitimate interests of the app operator in further storage—especially for the defence of rights, prevention of misuse, IT security, or documentation—prevent this.

11. Legal Bases at a Glance

The app operator processes personal data in particular on the basis of:

12. Rights of Data Subjects

Subject to the statutory requirements, data subjects have in particular the right:

13. Right to Object under Article 21 GDPR

To the extent the app operator processes personal data on the basis of Article 6(1)(f) GDPR, the user has the right to object to such processing at any time on grounds relating to the user's particular situation. The app operator will then no longer process the data concerned unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or unless the processing serves the establishment, exercise, or defence of legal claims.

14. Automated Decisions

Automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning the user or similarly significantly affects the user is not intended under the currently described system. Technical checks and automated security, authorisation, or misuse-prevention mechanisms may nevertheless be used to manage feature unlocks, prevent manipulation, or protect the integrity of the app.

15. Current Version and Changes

This privacy notice reflects the currently described state of the app architecture and operator-side processing. If the technical or legal design of PathCraft changes materially, this privacy notice will be updated accordingly.