Privacy Policy
Effective 16 August 2026
BaggedIt is a hillwalking app for planning, recording and logging walks in the British Isles. This policy explains what it collects, why, and what leaves your device.
The short version. Your hills, adventures, routes and photos live on your phone. Nothing is uploaded unless you sign in and switch on cloud backup, or choose to share a route with the community. The app shows ads and reports crashes, which involves third parties described below.
Who is responsible for your data
The data controller is TODO: your name or trading name, TODO: postal address — required for UK GDPR controller identification. Contact: support@baggedit.net.
Data stored on your device
Most of what BaggedIt holds never leaves your phone. It is kept in a local database and in the app’s own storage:
- Hills you have marked as climbed, with dates and notes
- Adventures you have planned, including dates and day structure
- GPX routes you have built, imported or recorded
- Adventure stories and any photos you attach to them
- Offline map packs you have downloaded
- Your settings and preferences
Deleting the app removes all of it. If you have cloud backup switched on, see below.
Location
BaggedIt asks for location access to show where you are on the map and to record a GPS track while you walk. If you enable track recording in the background, it continues to collect location while the app is minimised or the screen is off, because that is the whole point of recording a walk.
Location data is written to your device. It leaves your device only if you enable cloud backup, or if you choose to share a route publicly. It is never sold, and it is not used for advertising.
Contacts
If you choose to tag the people you are walking with, BaggedIt asks for contacts access and stores the name and phone number of the contacts you pick against that adventure. This is optional — the rest of the app works without it, and the app only reads your address book when you open the contact picker.
Please note: tagged contacts form part of your adventure record, so if you enable cloud backup they are included in the backup uploaded to our cloud storage. Only you can read your backup. Please only tag people who are happy for you to store their details this way.
Accounts and cloud backup
You can use BaggedIt without an account. Signing in is optional and unlocks cloud backup, restoring onto a new device, and submitting routes to the community.
Sign-in uses Google Sign-In or Sign in with Apple, via Firebase Authentication. We receive your email address, display name, and an account identifier. We never see your password.
When cloud backup is on, the app uploads a snapshot of your data to private cloud storage, readable only by your account. The snapshot contains your logged hills, adventures (including any tagged contacts), walk logs, GPX routes, adventure story text, and your story photos.
Community routes
If you submit a route to the community library, that route and the name you give it become publicly visible to other users once it has been reviewed and approved. Do not submit a route that starts at your front door, or whose name reveals something you would rather keep private. You can delete a route you submitted.
Analytics, crash reporting and ads
| Service | What it receives | Why |
|---|---|---|
| Firebase Analytics (Google) | Anonymous usage events — hills viewed, hills logged, routes saved, map packs downloaded — plus device and app identifiers | To understand which features get used and where people get stuck |
| Firebase Crashlytics (Google) | Crash reports: stack traces, device model, OS version, app version | To find and fix crashes |
| Google AdMob | Your device advertising identifier and coarse ad-request data | To show banner ads, which fund the free version |
| Mapbox | Map tile requests, which reveal the area of the map you are viewing | To draw maps and calculate routes |
| Stay22 | The area you are viewing, when you open the accommodation feature | To show nearby places to stay. These are affiliate links — we may earn a commission if you book |
Each of these is an independent controller of the data it receives, under its own privacy policy. On iOS you can limit ad tracking through system settings; on Android you can reset or delete your advertising ID.
Photos
When you add a photo to an adventure story, BaggedIt uses your system photo picker, so it only ever receives the specific photos you select — it has no access to the rest of your library. Saving a flythrough video writes that video to your library and reads nothing.
How long we keep things
Local data stays until you delete it or uninstall the app. Cloud backups stay until you overwrite them, turn backup off, or delete your account. Analytics and crash data are retained by Google under their standard retention periods. Community routes stay published until you remove them.
Your rights
Under UK GDPR you have the right to access, correct, export, or erase your personal data, to object to processing, and to complain to the Information Commissioner’s Office.
You can delete your account and everything stored in the cloud from within the app, under Settings. For anything else, email support@baggedit.net and we will respond within one month.
Children
BaggedIt is not directed at children under 13, and we do not knowingly collect their personal data.
Changes
If this policy changes materially we will update the effective date above and note the change in the app’s release notes.