Zum Inhalt springen
Skip to content
HenriettaHiking · Spontaneous · Together
  • How it works
  • Features
  • Safety
  • Roadmap
  • FAQ
  • DE|EN
  • Try the beta

Hiking·Spontaneous·Together

Privacy Policy

Last updated: October 2026 · Version 11

Contents

  1. 1. Controller
  2. 2. Data we collect
  3. 3. Purpose of processing
  4. 4. Legal basis
  5. 5. Processors
  6. 6. Location data
  7. 7. Push notifications
  8. 8. Biometric login
  9. 9. Emergency contact & SOS
  10. 10. Retention period
  11. 11. Your rights
  12. 12. Security
  13. 13. Changes
  14. 14. Contact
  15. 15. This website (henrietta.jetzt)

1. Controller

The controller responsible for processing personal data under the GDPR is:

Mattia
Email: hello@henrietta.jetzt
App: Henrietta (personal project)

2. Data we collect

We only collect data necessary to operate the app:

  • Email addressFor registration and sign-in. Used exclusively for authentication and password resets.
  • Profile informationFirst name, region, short bio, and optional profile photo. Shown to other users so hiking partners can find each other.
  • Mountain Portfolio (photos)To create your own tours, at least 2 photos of yourself in a mountain/outdoor setting are required (self-declaration); you don’t need them to join a tour. These photos are stored publicly in our cloud storage (Supabase Storage) and shown to other users on your profile to establish a basis of trust.
  • Location dataApproximate GPS location — used only to show tours near you. Not stored permanently (exception: the optional tour alert, see section 6) and never shared with third parties.
  • Tours and messagesTours you create and chat messages with hiking partners are stored in our database.
  • RatingsStar ratings and difficulty feedback submitted after a tour. Used anonymously to calibrate tour difficulty levels.
  • Peer verificationYour anonymous assessment of whether your partner’s hiking level matched their actual ability. Helps improve level recommendations.
  • Push tokenWhen you grant push notification permission, an anonymous FCM device token is generated and stored per device in a separate table (not in your profile). The token is used solely to deliver app notifications and contains no personal data. It is deleted when you log out, when you turn off push notifications in the app and when you delete your account; after an uninstall it is removed as soon as it becomes invalid.
  • Biometric login (optional)If you enable fingerprint login, your session token is stored encrypted in the Android Keystore on your device. This data is processed locally only — neither your fingerprint nor any biometric raw data is ever transmitted to our servers.
  • Emergency contact (optional)You may voluntarily store a trusted person’s name and phone number. Used exclusively for the SOS emergency button and never shared with third parties.
  • Community routes (optional)When you use the automatic route computation feature and save a tour, the computed route (GPS track, distance, elevation, title) is stored anonymously in our community library and made available to other users. No personal data is linked to the route.
  • Shared tour linksWhen you share a tour, the message contains a link. Anyone who opens it sees a preview without signing in: title, date, starting point, region, difficulty, pace, duration, distance, elevation and whether spots are still free. The host’s name and profile, the description, the meeting point and the participants are only visible to signed-in users in the app.
  • Game score & name (Easter Egg game, optional)If you play the hidden mini-game and achieve a score, your display name and high score are stored in a public leaderboard visible to all app users. No data is saved if you finish the game without scoring.

3. Purpose of processing

Your data is used exclusively to:

  • manage and secure your account,
  • suggest suitable hiking partners at your level and near you,
  • enable communication between hiking partners (chat),
  • operate the rating system,
  • automatically calibrate tour difficulty based on community ratings,
  • calibrate hiking levels through anonymous peer verification,
  • establish trust between users through the Mountain Portfolio (at least 2 photos as a self-declaration before you create your own tours),
  • reach a predefined contact person via SMS in an emergency (SOS function),
  • deliver push notifications about new messages,
  • process reports of other users (your name and reason are forwarded internally to the operator),
  • operate an optional public leaderboard in the Easter Egg mini-game,
  • store computed hiking routes anonymously in the community library and make them available to other users,
  • delete your account completely and immediately upon your explicit request, directly from the app.

No data is processed for advertising purposes and no data is sold to third parties.

4. Legal basis

Processing is based on Art. 6(1)(b) GDPR (contract performance). Where you provide data optionally (e.g. bio, profile photo, biometric login), this is based on your consent under Art. 6(1)(a) GDPR.

5. Processors

We use the following third-party services to operate the app:

  • Supabase (Supabase Inc., USA)Backend infrastructure: database, authentication, real-time chat, file storage. Contractually bound to GDPR compliance. Data stored on EU servers (Ireland, AWS eu-west-1).
  • Firebase Cloud Messaging (Google LLC, USA)Delivery of push notifications to your device. An anonymous FCM device token is generated and stored on our servers. No message content is transmitted to Google — only the token used to address your device. More information: policies.google.com/privacy
  • Google Sign-In (Google LLC, USA)Optional sign-in via your Google account. When you use „Continue with Google“, Supabase receives your Google display name and email address to create your account. Google itself processes the authentication in an external browser. More information: policies.google.com/privacy
  • Sign in with Apple (Apple Inc., USA)Optional sign-in via your Apple ID (iOS only). When you use „Continue with Apple“, Supabase receives your name and email address (optionally a private Apple relay address) to create your account. Apple processes the authentication directly on your device. More information: apple.com/legal/privacy
  • Resend (Resend Inc., USA)Delivery of transactional emails (registration confirmation, password reset). Your email address is processed to deliver the email. No email content is stored. More information: resend.com/privacy

Services that do not store personal data:

  • GeoSphere Austria (AROME weather model, data under CC BY 4.0, adapted for the app — anonymous, only the coordinates of the place)
  • MET Norway / Norwegian Meteorological Institute (weather forecast, data under CC BY 4.0, adapted for the app — anonymous, only the coordinates of the place)
  • Photon / komoot (place search, anonymous — only the search text or the coordinates of a tapped point)
  • OpenStreetMap / Nominatim (map data and map tiles; exact altitude of a selected summit, anonymous)
  • OpenTopoMap (map tiles, anonymous — tile.opentopomap.org)
  • Overpass API (huts, drinking water, parking and trail difficulty from OpenStreetMap, anonymous — only the map area or route corridor)
  • BRouter (brouter.de) and GraphHopper (route computation, anonymous — only start and end coordinates)
  • Valhalla / openstreetmap.de (route computation, elevation data and way types, anonymous — only coordinates or the route line, no personal data)
  • OpenTopoData (elevation data, anonymous — only coordinates)

6. Location data

The app requests your GPS location to show tours near you. Location is used only during active use and is not stored permanently.

If you switch on “Tours Near You”, we additionally store your approximate location (rounded to about 1 km) to notify you about matching new tours. If you switch it off again, it is deleted.

You can revoke location access at any time in your device settings.

7. Push notifications

With your permission, we send push notifications (e.g. new messages, tour requests). You can disable push notifications at any time in your device or app settings.

8. Biometric login

The optional fingerprint login stores your session token encrypted in the Android Keystore — the secure hardware storage on your device.

  • Your fingerprint never leaves the device.
  • We have no access to biometric raw data.
  • The stored token is fully deleted when you disable this feature.
  • You can disable fingerprint login at any time in profile settings.

9. Emergency contact & SOS

You may voluntarily add an emergency contact in your profile. When you trigger the SOS button, the app opens a pre-filled SMS — the app itself does not send any SMS. Without a contact, emergency number 112 is dialled.

10. Retention period

Your data is stored for as long as your account is active. You can delete your account at any time directly in the app (Profile → Delete Account). All personal data — profile, tours, chats, ratings — is deleted immediately and completely.

11. Your rights

Under the GDPR you have the right to:

  • Access — what data we hold about you
  • Rectification — correction of inaccurate data
  • Erasure — delete your account and all data directly in the app (Profile → Delete Account) or request by email
  • Restriction — restriction of processing
  • Portability — export of your data
  • Objection — to processing

Contact: hello@henrietta.jetzt

12. Security

All data is transmitted encrypted (HTTPS/TLS). Passwords are never stored in plain text. Biometric login data remains exclusively on your device.

13. Changes

We reserve the right to update this privacy policy for material changes. You will be notified in the app.

14. Contact

Questions about privacy? Write to us: hello@henrietta.jetzt

15. This website (henrietta.jetzt)

This privacy policy also applies to the website henrietta.jetzt. The website sets no cookies, uses no analytics or tracking services and loads no content or fonts from third parties; it uses your device’s system font.

  • HostingThe website runs on WordPress at IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. According to IONOS, the data is not passed on to third parties and not transferred to third countries.
  • Server log filesWith every visit, IONOS automatically stores the page or file requested, the previously visited page (referrer), browser type and version, operating system, device type, the time of access and your IP address, which according to IONOS is anonymised immediately. The log files are deleted after 8 weeks. The legal basis is our legitimate interest in operating the website securely and reliably (Art. 6(1)(f) GDPR).
  • Privacy settingsOn your first visit, a banner asks for your choice. It is stored only in your browser (localStorage, entry “henrietta_consent”: your choice and the time) and never leaves your device. You can change or withdraw it at any time via “Privacy settings” in the footer. We currently use no optional services. Legal basis: § 165(3) Austrian Telecommunications Act (TKG) and Art. 6(1)(c) GDPR (proof of consent).
  • Email contactIf you write to us at hello@henrietta.jetzt, for example to get beta access, we use your email address and your message only to reply to you and, where applicable, to give you access to the beta (Art. 6(1)(b) GDPR).
  • Password reset, email confirmation & tour linksThe pages under henrietta.jetzt/auth/ are part of signing in to the app, and henrietta.jetzt/t/ shows shared hikes. The password reset page sends your new password directly to Supabase, and the hike preview loads the hike data directly from Supabase (see section 5, servers in Ireland). No other services are loaded (Art. 6(1)(b) GDPR).
Henrietta

Hiking·Spontaneous·Together

The app for people who would rather head out together than alone today.

Explore

  • How it works
  • Features
  • Safety
  • Roadmap
  • FAQ

Contact & legal

  • hello@henrietta.jetzt
  • Privacy policy

© 2026 Henrietta. See you on the trail.

Get in touch

Datenschutz-Einstellungen

Wir verwenden keine Cookies, kein Tracking und laden keine Inhalte von Drittanbietern. Für den Betrieb brauchen wir nur die notwendigen Dienste unten. Optionale Dienste setzen wir nur mit deiner Einwilligung ein, derzeit gibt es keine. Datenschutzerklärung

NotwendigImmer aktiv

  • IONOS (Hosting)
    Anbieter
    IONOS SE, Montabaur, Deutschland
    Zweck
    Auslieferung der Website, Server-Logs (IP laut IONOS sofort anonymisiert, Löschung nach 8 Wochen)
    Ort
    EU, keine Übermittlung in Drittländer
    Rechtsgrundlage
    Art. 6 Abs. 1 lit. f DSGVO
    Seiten
    alle
  • Supabase (Anmeldung & Tour-Links)
    Anbieter
    Supabase Inc., USA – Server in Irland (EU)
    Zweck
    Neues Passwort speichern, Vorschau geteilter Touren laden
    Ort
    EU (Irland, AWS eu-west-1)
    Rechtsgrundlage
    Art. 6 Abs. 1 lit. b DSGVO
    Seiten
    /auth/reset/, /t/
  • Einwilligungs-Speicher
    Anbieter
    dein Browser (localStorage „henrietta_consent“)
    Zweck
    merkt sich deine Auswahl in diesem Banner
    Ort
    nur auf deinem Gerät
    Rechtsgrundlage
    § 165 Abs. 3 TKG, Art. 6 Abs. 1 lit. c DSGVO
    Seiten
    alle

Derzeit keine optionalen Dienste. Kommen z. B. Karten oder Statistik dazu, fragen wir dich hier vorher.

Privacy settings

We use no cookies, no tracking and load no third-party content. To run the site we only need the necessary services below. We only use optional services with your consent, and there are none at the moment. Privacy policy

NecessaryAlways on

  • IONOS (hosting)
    Provider
    IONOS SE, Montabaur, Germany
    Purpose
    Delivering the website, server logs (IP anonymised immediately according to IONOS, deleted after 8 weeks)
    Location
    EU, no transfer to third countries
    Legal basis
    Art. 6(1)(f) GDPR
    Pages
    all
  • Supabase (sign-in & tour links)
    Provider
    Supabase Inc., USA – servers in Ireland (EU)
    Purpose
    Saving a new password, loading previews of shared hikes
    Location
    EU (Ireland, AWS eu-west-1)
    Legal basis
    Art. 6(1)(b) GDPR
    Pages
    /auth/reset/, /t/
  • Consent storage
    Provider
    your browser (localStorage “henrietta_consent”)
    Purpose
    remembers your choice in this banner
    Location
    only on your device
    Legal basis
    § 165(3) Austrian TKG, Art. 6(1)(c) GDPR
    Pages
    all

No optional services at the moment. If we add maps or statistics, for example, we will ask you here first.