Privacy Policy

Geolete

Privacy Policy

This policy explains what personal information Geolete uses, why it is used, who can see it, and the choices available to you.

Effective and last updated: 10 August 2026

The short version

Geolete uses the information needed to run accounts, import or record activities, create routes, and operate challenges. We do not sell personal information or use it for targeted advertising.

1. Who is responsible for your information

Geolete is operated by Daniel Trevor in the United Kingdom (referred to as “Geolete”, “we”, “us” or “our”). Daniel Trevor is the controller of personal information processed for Geolete.

For privacy questions, rights requests or complaints, email danieltrevor.dt@gmail.com.

2. Information we collect

  • Account and profile information: email address, display name, profile image or avatar choices, account identifiers, and account dates. Password authentication is handled by Supabase; Geolete does not receive your password in readable form.
  • Health and activity information: manual activities you enter and, if you enable Apple Health, completed run, walk and cycle workout details such as date and time, distance, duration, indoor status, source app, device model and verification status. Geolete does not request workout GPS routes through HealthKit.
  • Challenges and social information:challenges you create or join, teams, invitations, participant records, route progress, standings, results, notifications, and content such as challenge names, descriptions and activity notes.
  • Route information: start, end and waypoint searches, place identifiers, coordinates, route lines and directions used to create a challenge route. Geolete does not currently request your device's live location.
  • Technical and support information: session identifiers, app or device details, request and security logs (which can include an IP address), notification preferences, and anything you include when contacting support. If you opt into push notifications, an Apple device token is also stored so alerts can be delivered to your iPhone.
  • Information stored on your device: login session data and limited preferences needed to keep you signed in, complete invitation flows and remember interface choices.

Activity information may reveal or allow inferences about fitness or health. We use it only for the features described here and obtain consent where the law requires it. We do not use Apple Health data for advertising, marketing, sale to data brokers, or unrelated data mining.

3. Where information comes from

  • Directly from you when you register, edit your profile, plan a route or add an activity.
  • From Apple Health after you choose to set it up and approve the permission shown by iOS. Compatible wearable apps may write workouts into Apple Health first.
  • From another user when they invite you to a challenge, which may include your email address.
  • Automatically from the app and its hosting and security providers.

4. Why we use information and our lawful bases

  • To provide the service and perform our contract:create and secure accounts, sync or record activities, calculate progress and results, operate invitations and notifications, and show challenge routes.
  • With your consent: read completed run, walk and cycle workouts from Apple Health and send optional push notifications. You can withdraw consent by changing the relevant iPhone setting.
  • For our legitimate interests: support users, keep Geolete secure and reliable, prevent abuse, maintain challenge integrity, diagnose faults and improve the service. We balance these interests against your rights.
  • To comply with law: respond to valid legal requests and meet legal, regulatory and record-keeping obligations.

You are not legally required to provide personal information, but an email address and account information are needed to use account-based features. Apple Health is optional; manual activities remain available without it.

5. Who can see or receive information

  • Other Geolete users: according to a challenge's visibility and membership, they may see your display name, avatar, participation, activity contributions, progress, standings and results. Manual activities are identified as manual rather than automatically synced.
  • Challenge organisers and team members: they may see the information needed to manage participation, teams, invitations and challenge integrity.
  • Service providers: Supabase provides authentication, database and storage services; Cloudflare provides hosting, delivery and security; Apple delivers iPhone push notifications when you opt in; Google Maps Platform provides place search, map and route features; and Apple Health provides activity data from your iPhone at your direction.
  • Legal and safety disclosures: we may disclose information where reasonably necessary to comply with law, protect users, investigate misuse, or establish or defend legal rights.
  • A future owner: information may transfer as part of a merger, reorganisation or sale of Geolete, subject to applicable law and appropriate notice.

We do not sell or rent personal information, and Geolete contains no advertising.

6. Connected services

Your use of connected services is also governed by their own terms and privacy notices:

Removing Geolete's Apple Health permission stops future reads from Apple Health. Activities already synced into Geolete remain so existing challenge records continue to work; you can remove them by deleting your Geolete account or contacting support about a data request. Existing accounts may also retain activities labelled Strava (historic), but Geolete has no active Strava connection and does not import any new Strava data.

7. International transfers

Some providers may process information outside the United Kingdom. Where required, we use providers that offer recognised transfer safeguards, such as approved contractual terms, adequacy regulations or another lawful transfer mechanism. You can contact us for more information about the safeguards relevant to your data.

8. Retention and deletion

We keep account, activity and challenge information while your account is active and for as long as it is needed to provide Geolete, preserve challenge integrity, resolve disputes, maintain security and meet legal obligations. Short-lived authorisation data expires when it is no longer needed. Provider security logs and backups follow the provider's normal retention cycle.

You can permanently delete your account in Profile → Delete my account. This removes your active Geolete account, profile, runs, activity connection and associated challenge data; challenges you organised are also deleted, and affected results may be recalculated. Limited information may be retained where required for security, backups, legal compliance or legal claims, then deleted or anonymised when no longer needed.

9. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict or receive a copy of personal information, and to withdraw consent. You can edit some profile information and delete your account inside the app. For another request, email danieltrevor.dt@gmail.com. We may need to verify your identity before acting.

If you are in the UK, please contact us first so we can investigate. You also have the right to complain to the Information Commissioner's Office (ICO) (opens in a new tab).

10. Automated calculations and challenge decisions

Geolete automatically applies challenge rules to eligible runs to calculate distance, progress, standings and winners. The main inputs are the activity's timing, distance, source and the challenge's dates and rules. These recreational calculations do not produce legal or similarly significant effects. If a result appears wrong, contact support or the challenge organiser.

11. Security

We use reasonable technical and organisational safeguards, including access controls, server-side connection credentials and encrypted network connections. No online service can guarantee absolute security. Please use a unique password and contact us promptly if you believe your account has been compromised.

12. Children

Geolete is not intended for children under 13, and we do not knowingly collect their personal information. A parent or guardian who believes a child under 13 has created an account should contact us so we can investigate and delete it. Older children must have any consent required by the laws where they live.

13. Changes and contact

We may update this policy as Geolete or the law changes. The date at the top shows when it was last revised. We will give appropriate notice of material changes.

Privacy questions and requests can be sent through the Support page or by email to danieltrevor.dt@gmail.com.