Privacy Notice for PathCraft
As of: 18 April 2026
Contact for privacy inquiries: kontakt@SuGreenX.eu
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described in this privacy notice is:
Christian Techmer
Mühlbachstr. 29
88697 Bermatingen
Germany
Email: kontakt@SuGreenX.eu
Privacy-related inquiries may be sent to the contact details above.
2. Short Overview
- The core functions of PathCraft do not require a general online account or a permanent online content profile with the app operator.
- Many contents and settings remain locally on the device or—if iCloud synchronisation is enabled—in the private iCloud area of the Apple account used.
- The app operator mainly processes limited technical, purchase-related, consent-related, and security-related data online for trials, purchases, entitlements, credits, weather credit usage, evidentiary records, and integrity protection.
- Optional third-party functions such as Apple services, Street View, YouTube links, and AI, speech, or translation providers selected by the user may transmit data directly to the respective third-party provider.
3. Scope and Allocation of Roles
- This privacy notice describes the processing of personal data by the app operator in connection with PathCraft.
- According to the described architecture, PathCraft is largely designed to operate locally. Many contents and settings remain on the user's device or—if iCloud synchronisation is enabled—in the private iCloud area of the Apple account used by the user.
- This privacy notice distinguishes between local storage on the device or in the user's private iCloud area, technical, purchase-related, consent-related, and security-related data processed online by the app operator, and processing operations that the user directly triggers with the respective third-party provider by using external third-party functions.
- To the extent data is transmitted directly from the app to a third-party provider selected by the user and the app operator does not receive that content through its own backend, this notice describes the data flow and the role of the app only in a supplementary manner. The third-party provider's own privacy and contractual documents are decisive for the subsequent processing by that provider.
4. Basic Processing Principles in PathCraft
- The core functions of the app do not require a general online account or a permanent online content profile with the app operator.
- According to the described system architecture, local file contents, conversation contents, translations, attachments, routes, imported GPX or KML files, images, audio, and comparable content data are not collected, analysed, or shared online by the app operator for its own advertising, profiling, or general tracking purposes.
- This does not preclude the app operator from processing limited technical data relating to feature unlocks, purchases, credits, weather credit usage, consent records, misuse prevention, integrity checks, error analysis, or simple usage aggregates to the extent this is necessary to provide and secure the functions offered.
- Where conversation, translation, or transcription histories are stored in the app, this is generally done locally on the device or—if iCloud synchronisation is enabled—in the private iCloud area of the user's Apple account, until the user changes or deletes them.
5. Operator-Side Online Processing and Storage Areas
5.1 User Mapping, Trials, and Activations
Technical storage areas: users, trial_grants, apple_transactions, entitlements
Processed data: Depending on usage, this includes in particular a pseudonymous Apple identifier derived from Sign in with Apple, internal user ID, session or access tokens, trial start and end times, product and product type, transaction ID, original transaction ID, app account token, purchase, expiry, revocation, or unlock times, as well as authorisation and status data.
Purposes:
- allocation of an internal user ID to an Apple-related identifier
- administration and verification of trial periods
- verification and technical traceability of App Store transactions
- granting, restoring, synchronising, and enforcing server-side entitlements and feature unlocks
- prevention of misuse and technical integrity
Legal bases:
- Article 6(1)(b) GDPR to the extent processing is necessary for the performance of a contract or pre-contractual steps for trial, purchase, unlock, or restoration functions
- Article 6(1)(c) GDPR to the extent statutory retention or evidentiary obligations apply
- Article 6(1)(f) GDPR to the extent processing serves system security, prevention of misuse, defence of rights, or technical traceability
Retention period or criteria: The data is stored for as long as it is required for the respective trial, purchase, unlock, restoration, or evidentiary function. It is then deleted or anonymised unless statutory retention obligations or legitimate interests in asserting, exercising, or defending legal claims prevent this.
5.2 Credits, Weather Credit Usage, Tip Purchases, and Managed Usage Events
Technical storage areas: credit_ledger, managed_usage_events, tip_purchases, and—where implemented separately for technical reasons—functionally comparable storage areas for monthly weather credit usage records
Processed data: Depending on the function, this includes in particular internal user or installation references, pseudonymous software or installation ID, credit bookings, debit or credit events, product reference, functional area, timestamps, month period, usage-related counters, billing data relating to models, providers, or weather functions, technical location references for weather requests, references to purchases or feature unlocks, as well as status and verification data.
Purposes:
- maintaining a traceable credit ledger
- technical billing of usage-based functions
- maintaining usage records for credit-based weather queries, in particular to implement one credit per weather location and month where that usage logic is used in the app
- separate recording of voluntary support or tip purchases
- prevention of misuse, error analysis, and defence of rights
- restoration and verification of access rights
Legal bases:
- Article 6(1)(b) GDPR to the extent processing is necessary to provide a usage-based or paid function
- Article 6(1)(c) GDPR to the extent statutory retention obligations apply
- Article 6(1)(f) GDPR to the extent processing serves traceability, fraud prevention, technical stability, or defence against abusive use
Retention period or criteria: Booking, purchase, and billing-related data is regularly stored until the respective contractual, evidentiary, or retention purpose no longer applies; statutory commercial, tax, or other retention obligations remain unaffected. Purely technical usage events are deleted, condensed, or anonymised as soon as they are no longer required for billing, prevention of misuse, or defence of rights. Weather credit usage records are kept in a personal or pseudonymous form only for as long as required for the ongoing monthly logic, credit calculation, restoration, error resolution, prevention of misuse, or defence of rights; they are then deleted, condensed, or anonymised unless overriding evidentiary or retention obligations apply.
Special note on weather credits: To the extent PathCraft offers a credit-based weather function, the currently described setup may allow one credit to cover one weather location for one calendar month. In order for the app to calculate usage correctly, recognise weather locations already billed within the same month, keep credit balances traceable, and prevent misuse, the operator backend may store, per pseudonymous software or installation ID, whether a weather query for a particular weather location or technical location reference has already been billed in a given monthly period. To the extent technically possible and sufficient for billing, full clear-text addresses should not be stored as the location reference; instead, minimised references such as normalised, truncated, or gridded coordinates, hash, geohash, or provider location identifiers should be used. This processing does not serve to create a movement profile, presence profile, or advertising profile.
No separate consent is obtained for this necessary credit and usage record to the extent the processing is required exclusively to provide the credit-based weather function requested by the user, to maintain the credit balance, to restore usage status, to clarify errors, or to prevent misuse. Should any additional, non-essential analysis, convenience history, profiling, or advertising use of such weather usage data be planned in the future, this would only take place on a separate legal basis and, where legally required, after separate consent.
If a software or installation ID is stored on or read from the device for this function, this occurs, for the required credit function, only to the extent necessary to provide the expressly requested digital service. Non-essential device access, for example for general analytics or advertising purposes, is not covered by this.
Important note: To the extent the app operator offers managed AI usage, managed_usage_events according to this notice refers to billing-related and usage-related event data. This does not automatically describe storage of the actual content data such as prompts, audio, responses, images, or attachments in the operator backend, and such storage would have to be disclosed separately if it actually takes place.
5.3 Consent and Policy Records
Technical storage areas: byok_consents, byok_consent_events, service_consent_policies, service_consents, service_consent_events, route_playback_consent_policies, route_playback_consent_events
Processed data: Depending on the function, this includes in particular installation or subject identifier, provider, functional area, policy version, text version, language, region, platform, app version, build, UI context, hash values, links to the legal texts shown, event type such as shown, accepted, declined, or withdrawn, time, and limited evidentiary data.
Purposes:
- provision, versioning, and assignment of the applicable legal texts
- proof of whether and when particular notices, consents, or permissions were shown, accepted, declined, or withdrawn
- live verification of whether certain optional functions may be activated
- fulfilment of documentation-related data protection and compliance requirements
- prevention of misuse and technical integrity in connection with sensitive feature unlocks
Legal bases:
- Article 6(1)(b) GDPR to the extent processing is necessary to carry out the optional function requested by the user
- Article 6(1)(c) GDPR to the extent statutory evidentiary or documentation obligations apply
- Article 6(1)(f) GDPR to the extent processing serves the legitimate interest in maintaining a revision-safe record of legally relevant notices, preventing misuse, and technically implementing feature-unlock decisions correctly
Retention period or criteria: The data remains stored for as long as the relevant function is used or can be reactivated and for as long as records of display, consent, withdrawal, or permission events are required for legal, security, or defence purposes. Policy text versions and hash values may be retained for longer to the extent event logs refer to them.
5.4 Installation Authenticity, Technical Integrity, and Simple Usage Aggregates
Technical storage areas: route_playback_app_attest_installations, route_playback_usage_daily
Processed data: Depending on the function, this includes in particular technical installation identifiers, attestation-related or registration-related verification data, event type, timestamps, platform and language data, and daily usage aggregates or counters.
Purposes:
- cryptographic or comparable verification of whether a genuine installation exists
- protection against tampering, abusive use, replay attacks, or circumvention of activation logic
- monitoring, stability, capacity planning, and simple usage statistics
Legal bases:
- Article 6(1)(f) GDPR on the basis of the legitimate interest in system security, integrity, fraud and misuse prevention, and operational stability
- Article 6(1)(b) GDPR to the extent such data is technically necessary to provide a function requested by the user
Retention period or criteria: Security and installation data is stored for as long as required for integrity checks and misuse prevention. Simple daily usage aggregates are deleted, condensed, or anonymised as soon as they are no longer needed for monitoring, capacity planning, or security evaluation.
5.5 Support and Communication
If the user contacts the app operator, for example by email at kontakt@SuGreenX.eu, the app operator may process the contact details communicated by the user, the content of the request, attachments, as well as processing and response data.
Purposes: handling support inquiries, error analysis, performance of the contract, communication, and defence of rights.
Legal bases: Article 6(1)(b) GDPR to the extent the request relates to a contractual relationship or pre-contractual measures; otherwise Article 6(1)(f) GDPR.
Retention period: until final handling of the inquiry and beyond only to the extent statutory retention obligations or legitimate interests in documentation and defence of rights apply.
6. Third-Party Processing Triggered Directly from the App
6.1 Apple Services
When using map, search, geocoding, Look Around, route calculation, weather, Sign in with Apple, App Store, or iCloud-related functions, search texts, addresses, coordinates, start and destination points, location data, query context, Apple-related identifiers, purchase or sign-in information, as well as synchronised app content may, depending on the function, be transmitted directly to Apple or to services connected via Apple.
To the extent the app operator does not receive this content through its own backend, Apple's own documents govern the subsequent processing by Apple. The technical maintenance of a weather credit usage record by the app operator must be distinguished from this and does not mean that the app operator monitors the accuracy of the weather data or controls actual on-site use.
6.2 Google Services and YouTube
For optional Street View or Street View metadata functions, search terms, coordinates, metadata queries, and, where applicable, a Google API key used by the user may, depending on the function, be transmitted directly to Google services.
Upon the explicit invocation of optional YouTube functions, the app may pass search terms, target URLs, coordinates, search radius, or other parameters selected by the user to a Google or YouTube link and open the external YouTube app or an external website. Any further processing from the moment the external service is opened is carried out by the respective provider under its own terms and privacy notices.
6.3 External AI, Speech, and Translation Services
When using external AI, speech, transcription, text-to-speech, or translation services, texts, audio data, voices, images, attachments, transcriptions, translations, speech outputs, system instructions, conversation states, and, where applicable, contextual data may, depending on the function, be transmitted directly to the third-party provider selected by the user.
Where the user uses their own API key and the app sends the request directly to the third-party provider, the app operator, according to the described architecture, generally does not receive this content data through its own backend. This does not affect the limited operator-side processing described in Section 5, for example for consent records, feature unlocks, credits, security events, or managed billing data.
The subsequent processing by the respective third-party provider is governed by that provider's current privacy and contractual documents.
7. Categories of Recipients
Depending on the function, personal data may be transmitted to the following recipients or categories of recipients:
- technical operator service providers for hosting, edge delivery, security, and backend functions, currently in particular Cloudflare
- Apple and services connected with Apple when Apple-related functions are used
- Google or YouTube when corresponding optional functions are activated
- external AI, speech, or translation providers selected by the user, in particular in the case of direct API use
- store or payment service providers, to the extent purchases or feature unlocks are handled through such systems
- authorities, courts, advisers, or other third parties, to the extent this is required by law or necessary for the assertion, exercise, or defence of legal claims
Should additional technical processors be added in the future for operator purposes, this privacy notice will be updated in the event of material changes.
8. Transfers to Third Countries
- Depending on the third-party function used and on the operator service provider involved, personal data may be transferred to countries outside the European Union or the European Economic Area, in particular to the United States or to other countries in which the respective provider or its subprocessors operate.
- To the extent the app operator uses its own service providers with a third-country nexus—currently in particular Cloudflare for hosting, edge delivery, security, and backend functions—such transfers take place only in accordance with Articles 44 et seq. GDPR.
- Depending on the recipient and data flow, the legal transfer mechanisms may include in particular:
- an adequacy decision pursuant to Article 45 GDPR,
- appropriate safeguards pursuant to Article 46 GDPR, in particular EU Standard Contractual Clauses,
- and, where required, supplementary technical and organisational protection measures.
- To the extent a recipient is validly certified under a relevant adequacy framework such as the EU-U.S. Data Privacy Framework, the transfer may also be based on that framework.
- For third-party providers that the user selects themselves or uses directly via their own API keys or external links, transfers to third countries take place directly to the respective third-party provider or service opened by the user. The concrete processing locations, storage practices, and protection mechanisms are then determined by the current documents of that provider.
9. Requirement to Provide Data
- For the mere core use of local functions, only a limited amount of personal data must be provided to the app operator.
- Certain data is, however, required if the user wishes to use optional trial, purchase, unlock, restoration, credit, weather credit, or consent functions. Without this data, the relevant functions cannot be provided technically or legally. For credit-based weather functions, this may in particular include a pseudonymous software or installation ID and a month and location reference for usage calculation.
- Anyone wishing to use external third-party functions must transmit the data required for that function directly to the respective third-party provider or external service; otherwise the respective function cannot be performed.
10. Retention Periods at a Glance
Unless a specific period is stated in this privacy notice, personal data is deleted or anonymised once the respective processing purpose no longer applies and no statutory retention obligations or legitimate interests of the app operator in further storage—especially for the defence of rights, prevention of misuse, IT security, or documentation—prevent this.
11. Legal Bases at a Glance
The app operator processes personal data in particular on the basis of:
- Article 6(1)(b) GDPR to the extent processing is necessary for the provision of contractual or pre-contractual functions
- Article 6(1)(c) GDPR to the extent processing is necessary for compliance with legal obligations
- Article 6(1)(f) GDPR to the extent processing serves the legitimate interest of the app operator in system security, misuse prevention, traceability, stability, support, defence of rights, or technically proper provision of the app
- Article 6(1)(a) GDPR to the extent processing is based on expressly granted consent; consent may be withdrawn at any time with effect for the future
12. Rights of Data Subjects
Subject to the statutory requirements, data subjects have in particular the right:
- to obtain information about the personal data processed (Article 15 GDPR)
- to rectification of inaccurate data or completion of incomplete data (Article 16 GDPR)
- to erasure of personal data (Article 17 GDPR)
- to restriction of processing (Article 18 GDPR)
- to data portability (Article 20 GDPR), to the extent processing is based on consent or contract and is carried out by automated means
- to object to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR)
- to withdraw any consent granted at any time with effect for the future
- to lodge a complaint with a data protection supervisory authority (Article 77 GDPR), in particular in the Member State of habitual residence, place of work, or the place of the alleged infringement
13. Right to Object under Article 21 GDPR
To the extent the app operator processes personal data on the basis of Article 6(1)(f) GDPR, the user has the right to object to such processing at any time on grounds relating to the user's particular situation. The app operator will then no longer process the data concerned unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or unless the processing serves the establishment, exercise, or defence of legal claims.
14. Automated Decisions
Automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning the user or similarly significantly affects the user is not intended under the currently described system. Technical checks and automated security, authorisation, or misuse-prevention mechanisms may nevertheless be used to manage feature unlocks, prevent manipulation, or protect the integrity of the app.
15. Current Version and Changes
This privacy notice reflects the currently described state of the app architecture and operator-side processing. If the technical or legal design of PathCraft changes materially, this privacy notice will be updated accordingly.