Bænkle privacy policy
Draft. Written by Claude, to be reviewed and completed by the operator (see docs/legal/README.md). Placeholders are in [[double square brackets]]. This is not legal advice. The German version is authoritative; this is a translation.
Last updated: [[publication date]]
This policy covers the Bænkle app for iOS and Android and the web app at https://baenkle.app. Bænkle is a private, non-commercial project: no ads, no paid features, no analytics or tracking services.
1. Controller
[[First and last name]]
[[Street and number]]
[[Postcode and city]]
[[Country]]
Email: kontakt@baenkle.app
No data protection officer has been appointed, because the legal requirements for one are not met.
2. In short
• You can find benches, plan and share walks and report content without an account.
• You only need an account to contribute benches, photos and texts, keep favorites, and sync walks between devices.
• We don't keep a location history. Your location is used only on your device, to center the map or set a start point.
• We store positions only when you save them as content yourself: a bench, a favorite or a synced walk. A walk's start point is often your home; keep that in mind when you sync.
• Photos are stripped of metadata (including GPS data) on your device before upload and again on the server.
• You can delete your account in the app at any time and export your data as a file.
3. What we process, and when
3.1 Without an account
Map, benches and photos. The app loads bench data from tiles.baenkle.app, photos from photos.baenkle.app and base-map tiles directly from OpenFreeMap (tiles.openfreemap.org). This necessarily transmits your IP address, the time, the requested address and information about the app or browser. We don't analyse this data or link it to anything. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is delivering and securing the service.
Server logs. Our server (api.baenkle.app) writes technical logs with a request id, the function called, the status code and the duration. We never log tokens, precise coordinates or IP addresses. Cloudflare keeps these logs for a few days [[check Workers Logs retention, currently about 3 days on the free plan]]. Legal basis: Art. 6(1)(f) GDPR (debugging and security).
Place search. When you search for a place, the app sends your search text and the current map view to our server. The server forwards the search text and the map center to the Photon search service (komoot GmbH). It doesn't pass on your IP address or account data. Results are cached briefly, without any link to you. Legal basis: Art. 6(1)(b) GDPR.
Routes. When you plan a walk, the app sends its waypoints to our server, which has openrouteservice (HeiGIT gGmbH) compute the route. Again, neither your IP address nor your account data is passed on. Routes are cached briefly by their waypoints (rounded to about 5 metres), without any link to you. Waypoints are never logged together with identifiers. Legal basis: Art. 6(1)(b) GDPR.
Abuse protection. To limit abuse, we count requests to search, routing and reports per device. For this we derive a keyed hash from your IP address, using a key that changes every day. The IP address itself is never stored, and the hash can't be linked back once the day is over. Legal basis: Art. 6(1)(f) GDPR (protecting the service and its free quotas).
Reports without an account. You can report benches, photos or users without an account. We store the reason, an optional comment, the time and the daily hash described above. Please don't put personal data in the comment. Legal basis: Art. 6(1)(f) GDPR (moderation) and, for illegal content, Art. 6(1)(c) GDPR together with the Digital Services Act.
Data kept only on your device. The app stores settings such as filters and appearance, drafts, and walks saved only on this device in your device's (or browser's) storage. This data doesn't leave your device unless you sync or share it.
Location. With your permission, the app reads your location while you use it, to center the map or set a start point. Your location isn't sent to us except as part of a route request you start yourself, and it isn't stored. You can withdraw the permission at any time in your device settings.
Sharing and GPX export. When you share a walk, the route is contained in the link itself. We don't store shared walks. Anyone with the link sees the waypoints, including a start point that may be your home. GPX files are created on your device.
3.2 With an account
Sign-in. Sign-in is provided by Clerk (Clerk, Inc., USA). Clerk processes your email address, sign-in codes, session data, IP address and device information to sign you in and prevent abuse. If you sign in with Google or Apple, Clerk receives your email address and, depending on your settings, your name from that provider, whose privacy policy also applies. [[Remove while Google and Apple sign-in are not enabled.]] Legal basis: Art. 6(1)(b) GDPR.
In our own database we keep only: your Clerk user id, your display name (initially a random nickname you can change), your role, the version of the terms you accepted, a ban flag if any, and timestamps. Your email address stays with Clerk.
Contributions. Benches, additions to OpenStreetMap benches, photos, titles and descriptions you contribute are shown publicly with your display name. For benches we store the position you give. Legal basis: Art. 6(1)(b) GDPR.
Photos. The app resizes photos before upload, converts them to JPEG and removes all metadata, including GPS position and camera data. The server checks the format and removes metadata a second time. Photos are stored under unguessable addresses and served publicly. The app uses the camera and photo library only when you add a photo, and only with your permission.
Confirmations, favorites, synced walks, blocks. When you confirm a bench as "still here" or "gone", save a favorite, sync a walk or block another user, we store this with your account. Favorites and walks contain positions and are visible only to you. Legal basis: Art. 6(1)(b) GDPR.
Reports with an account. When you report content while signed in, we store who reported it, so that repeated reports can be recognised. Only the operator, as moderator, sees the reporter.
Moderation. To enforce the terms, the operator can hide, restore or delete content and ban accounts. Every such action is logged. Hidden photos are moved to non-public storage. Legal basis: Art. 6(1)(f) GDPR (a safe and lawful service) and Art. 6(1)(c) GDPR (obligations under the Digital Services Act).
3.3 Web app: cookies and browser storage
The web app sets no tracking cookies. When you sign in, Clerk sets cookies that are strictly necessary for sign-in. Settings and walks saved only on this device live in your browser's storage. Neither needs consent (Section 25(2) no. 2 TDDDG), because both only provide the function you asked for.
3.4 Email
If you write to kontakt@baenkle.app, the message is forwarded by Cloudflare Email Routing to the operator's mailbox and kept there until your request is dealt with, unless the law requires keeping it longer. Legal basis: Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR for requests about your account.
4. Recipients and processors
Service: Cloudflare, Inc. (Workers, D1, R2, CDN, Email Routing)
Purpose: Hosting the app, server, database, photos and bench data; email forwarding
Location: USA; processing also in data centers worldwide
Basis for transfers outside the EU: EU-US Data Privacy Framework; standard contractual clauses
Service: Clerk, Inc.
Purpose: Sign-in and account management
Location: USA
Basis for transfers outside the EU: EU-US Data Privacy Framework [[verify certification]]; standard contractual clauses
Service: HeiGIT gGmbH (openrouteservice)
Purpose: Route computation (waypoints only, no identifiers)
Location: Germany
Basis for transfers outside the EU: –
Service: komoot GmbH (Photon)
Purpose: Place search (search text and map center only)
Location: Germany
Basis for transfers outside the EU: –
Service: OpenFreeMap
Purpose: Base map, loaded directly by your device (IP address, requested map tiles)
Location: [[verify operator and hosting]]
Basis for transfers outside the EU: [[verify]]
Service: Google Ireland Ltd. / Apple Distribution International Ltd.
Purpose: Sign in with Google or Apple, only if you choose it
Location: Ireland (parent companies in the USA)
Basis for transfers outside the EU: EU-US Data Privacy Framework
Service: Apple and Google as app store operators
Purpose: Downloading and updating the app; the stores are responsible for this themselves
Location: –
Basis for transfers outside the EU: –
Service: Expo (650 Industries, Inc.)
Purpose: Delivering app updates
Location: USA
Basis for transfers outside the EU: EU-US Data Privacy Framework [[verify]]
Data processing agreements under Art. 28 GDPR are in place with Cloudflare and Clerk [[accept the Cloudflare and Clerk DPAs and confirm here]]. openrouteservice and Photon receive no personal data that identifies you.
Your data is never sold or used for advertising.
5. How long we keep data
• Account data, favorites, synced walks and blocks: until you delete them or your account.
• Photos: until you delete them, delete your account, or they are deleted for moderation reasons. The server deletes abandoned uploads after one day.
• Benches and texts you contributed: stay after account deletion, shown as from a "former contributor", with no link to you (see the terms of use).
• Confirmations and reports: stay after account deletion as moderation signals, with no link to you.
• Daily hashes for abuse protection: can't be linked back after the day ends.
• Server logs: a few days (see 3.1).
• Moderation log: [[set a period, e.g. 3 years]].
6. Deleting your account and exporting your data
In the app, under Account → Your data, you can:
• export all data Bænkle stores about you as a JSON file (Art. 15 and Art. 20 GDPR);
• delete your account. This deletes your profile, favorites, synced walks, blocks and photos (including the image files) and your Clerk account. Benches and texts stay, anonymised; confirmations and reports stay with no link to you. Walks saved only on your device stay there until you remove the app.
You can also ask for deletion by email to kontakt@baenkle.app.
7. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Write to kontakt@baenkle.app.
You can also complain to a data protection supervisory authority, for example the one where you live or the one responsible for the operator: [[state data protection authority for the operator's place of residence]].
8. No obligation, no automated decisions
You don't have to provide any data to browse benches and plan walks. Contributing requires an account with an email address. There is no automated decision-making within the meaning of Art. 22 GDPR. Content is hidden automatically when several registered users report it; the operator reviews such cases and can reverse them.
9. Children
Bænkle isn't aimed at children under 16. Only people aged 16 or over may create an account.
10. Changes
We update this policy when the app or the law changes. The current version is at https://baenkle.app/privacy [[set the address once the page is linked]].