Skip to content

Privacy Policy

david galindo edited this page Sep 11, 2026 · 13 revisions

Privacy Policy for Routebox

Effective date: September 11, 2026

This privacy statement describes how David Galindo ("we") handles your information when you use the Routebox app on iOS.

The short version: Routebox collects nothing about you — no accounts, no analytics, no tracking. Your data stays on your device, apart from the notes, ratings, difficulty and the routes you import, which sync through your own iCloud. It can also download optional example routes from our public catalog on GitHub, but only when you ask it to.

Collection and Use

We do not collect, store or transmit any personal information. Routebox has no user accounts, no analytics, no advertising, no crash reporting and no tracking of any kind.

Your Health and Location Data

The app reads your workouts and their recorded GPS routes from Apple Health. Your workouts, routes, elevation data and statistics are read and displayed only on your device. They are never uploaded to us or to anyone else.

You grant this access yourself in the permission sheet shown the first time you open the Workouts tab — not at launch, and never if you only ever use the route library — and you can review or revoke it at any time in the Health app, under Sharing → Apps.

When the app writes to Health

Normal use is read-only: opening the app, browsing your workouts, viewing routes and profiles, and exporting tracks never change anything in Health.

There are exactly two actions that do, and both are ones you start yourself:

  • Importing a GPX file saves a new workout, with its route and distance, into Apple Health. The app asks for write permission at that point — not at launch — and only then.
  • Deleting a workout from inside the app removes that workout and its route from Apple Health. This cannot be undone, and the app warns you before doing it.

The app never modifies workouts it did not create, and never touches any other Health data.

Your Location

The Routes tab can show where you are on a saved route. This is off until you tap the locate button, and it stops as soon as you leave that screen — the app never follows you in the background and never asks for "Always" access.

Your position is used on the device to work out the nearest point on the route, so the elevation profile can follow you and the app can tell you how far off the route you are and which way it lies. It is not recorded, not added to any route, and not transmitted anywhere.

If you turn on "turn with the phone", the compass is read as well, so the map can rotate as you do. That reading stays on the device too, and stops with everything else when you leave the screen.

You can revoke it at any time in Settings → Privacy & Security → Location Services.

Your Routes

Routes you import are stored in the app's own storage. They are not written to Apple Health — a route is a path, not something you performed — so importing one asks for no Health permission at all. Deleting a route removes it from the app and touches nothing else.

Imported routes sync across your own devices through iCloud, using the app's private iCloud container — so a route added on your iPhone appears on your iPad. They travel inside your iCloud only, never to us or any third party, and this is covered by Apple's privacy policy. If you are signed out of iCloud, routes simply stay on the one device. The six bundled example routes are not synced — they are seeded on each device from the app itself.

Downloading Routes

Routebox can fetch a catalog of downloadable example routes — and the route files themselves — from the project's public wiki on GitHub. This happens only when you open the download browser from the Routes tab, never in the background. These are ordinary requests for public files: GitHub receives the request (including your device's IP address, as any web server does) and serves the files, which is covered by GitHub's privacy statement. No account, and nothing about you, your workouts or your routes, is sent — the app only downloads. A route you download is saved to your library like any other import.

Notes, Ratings and Difficulty

Notes, the rating and the difficulty you set for a workout are kept in the app's own storage, keyed to the workout. Apple Health has no field for them, so they are not written to Health, and they are not included in exported GPX or KML files.

These three small items sync across your own devices through iCloud key-value storage, part of the Apple Account you are already signed in to. They travel inside your private iCloud — never to us, and never to any third party — so the same note or rating shows on your iPhone and iPad. This uses Apple's iCloud and is covered by Apple's privacy policy. If you are signed out of iCloud, or have iCloud Drive turned off, they simply stay on the one device. Clearing a note or rating removes it from your devices.

Importing Files

When you import a GPX file, the app reads the file you pick and nothing else. It has no access to the rest of your files.

Maps

Displaying a route draws map tiles from Apple Maps. As with any map, Apple receives the map area being viewed in order to serve those tiles. This is handled by Apple's MapKit framework and is covered by Apple's privacy policy.

Several buttons hand a single point to the Apple Maps app: the start or the end of a workout as a pin, and the start or the end of a saved route as a directions destination. Only that one coordinate is passed, and only for the button you tap. Your route itself is never sent.

When you ask for directions, Apple Maps works out the way there from your position. That happens inside Maps, using the location permission you have given Maps — this app neither reads nor passes your position for it.

Nothing is sent to Google. Earlier versions could hand a coordinate to Google Maps; that was removed, and no coordinate now leaves the device for anyone but Apple Maps.

Exporting Tracks

Exporting a workout as GPX or KML writes the file to a temporary folder inside the app's own storage. The file leaves your device only if you choose to send it somewhere using the system share sheet — for example to another app, to Files, or by email. Where it goes then, and what that recipient does with it, is up to you.

Sharing Your Information

We do not share your information with any third parties, because we never have it in the first place. Data leaves your device only in ways you control: a coordinate to Apple Maps when you tap one of those buttons, an exported track through the share sheet, and your own notes, ratings, difficulty and imported routes syncing through your private iCloud to your other devices. None of it comes to us, and where an export goes is entirely your choice.

Changes to This Policy

If this policy changes, the new version will be published on this page with an updated effective date.

Contact

Questions about this policy are welcome at info@nowhereman.eu. See also the Support page.