Privacy Policy
Last updated: July 27, 2026
Overview
ZYRNTOPO is an offline mapping app for backcountry travel, field work, and search and rescue. We are committed to protecting your privacy. This policy explains what data the app collects, how it is used, and your rights.
Data Collection
The core ZYRNTOPO app does not collect, transmit, or store personal data on servers operated by us. The one exception is the optional ZYRNTOPO Pro account, described in its own section below. Some optional online features contact third-party map, weather, elevation, routing, or search providers directly from your device. In summary:
- The only usage data collected is an anonymous install ping — a random device identifier the app generates locally, the app version, and the platform (web or Android). It contains no personal information and no location, is not linked to any account, and is never used for advertising or shared. See Anonymous Usage Analytics below.
- No personal information is sent to servers operated by us, except the email and password you provide if you create an optional ZYRNTOPO Pro account, and anything you choose to type into a feedback report. See Feedback and Bug Reports below.
- No account or sign-up is required to use the core app.
- No cookies are used for tracking purposes.
Anonymous Usage Analytics
To understand how many people use ZYRNTOPO — including those who never create an account — the app sends a single, minimal, anonymous usage ping to our own service (api.zyrntopo.com) roughly once per day. This ping contains only:
- a random identifier the app generates and stores on your device the first time it runs (it is not derived from your device, hardware, phone number, advertising ID, or any account, and you can clear it at any time by clearing the app's data);
- the app version; and
- the platform —
androidorweb. The Windows and Linux desktop builds run the same web build inside a desktop shell, so they report asweb; we cannot tell a desktop install from a browser tab, and we do not try to.
That is the entire payload. It contains no personal information, no location, no map activity, and no account link. We use it only to count installs, active devices, and which app versions are in use. It is never used for advertising, never sold, and never shared. The request reaches our server over HTTPS; your IP address is visible to the server for that connection (as with any web request) and is used only to prevent abuse — it is not stored alongside the ping. This is the only telemetry the app sends; there are no third-party analytics SDKs, cookies, or advertising trackers in ZYRNTOPO.
Feedback and Bug Reports
If you send feedback — from Settings → Help & Support → Send feedback in the app, or from the form at zyrntopo.com/feedback — that report is sent to our own service (api.zyrntopo.com) and stored there so we can act on it. This is entirely optional and never automatic; nothing is sent unless you write a report and press Send.
A report contains:
- What you wrote, and the category you picked. Please do not include anything sensitive — treat it like an email to a stranger, because that is effectively what it is.
- Your email address, only if you type one. It is optional, is used solely to reply to you about that report, and is never added to a mailing list.
- App details — version, platform, operating system, and whether Pro is active. The app shows you this exact line before you send and you can untick it or edit it out.
- The anonymous install identifier described above, when sent from the app. It is used only to limit how many reports one device can send per day, and is not linked to any account.
A report does not include your location, your map objects, your tracks, or your account password. Your IP address is visible to the server for the connection and is used only for rate limiting — it is not stored with the report. If you write a report while offline, it is held on your device and sent when you are back in service; you can discard it by clearing the app's data before that happens.
Reports are readable only by us. They are never sold, shared, or used for advertising. If you want a report of yours deleted, email grangedevgroup@gmail.com and tell us roughly when you sent it and what it said, and we will remove it.
Local Data Storage
All app data — including map objects, settings, gear lists, and team rosters — is stored locally on your device using browser storage (IndexedDB / localForage). Map tiles viewed are cached locally using the Cache API for improved performance.
Where that lives depends on how you run ZYRNTOPO: inside your browser's profile for the web app, in the app's private storage on Android, and in the desktop app's own data folder — %APPDATA%\ZYRNTOPO on Windows, ~/.config/ZYRNTOPO on Linux. Uninstalling the desktop app deliberately leaves that folder in place, so saved maps and offline tiles survive an uninstall or a version change; delete the folder yourself if you want it gone. None of it is transmitted to us, and none of it is recoverable by us if you lose the device.
Network Requests
The app makes network requests to third-party services to load maps and optional field context. These providers may receive standard request information such as your IP address, browser or Android WebView user agent, referrer/origin where applicable, timestamp, and the requested URL. Map tile URLs contain tile coordinates for the area being viewed; weather, elevation, route-planning, and search requests may include the map/GPS coordinates or search query needed to answer that request.
Third-party services used by online features may include:
- OpenStreetMap (tile.openstreetmap.org)
- OpenTopoMap (tile.opentopomap.org)
- OpenFreeMap — vector basemaps (tiles.openfreemap.org)
- VersaTiles — vector basemaps (tiles.versatiles.org)
- Esri ArcGIS (server.arcgisonline.com)
- CartoDB (basemaps.cartocdn.com)
- Wikimedia Labs — Hillshade (tiles.wmflabs.org)
- OpenSnowMap (tiles.opensnowmap.org)
- BLM GIS (gis.blm.gov)
- USFS (apps.fs.usda.gov)
- Mapterhorn DEM (tiles.mapterhorn.com)
- Nominatim Geocoding (nominatim.openstreetmap.org)
- BRouter routing (brouter.de)
- Open-Meteo / OpenTopoData / Open-Elevation for weather and elevation lookups
- NWS Weather (forecast.weather.gov)
The app also contacts ZYRNTOPO's own static endpoints (hosted on Cloudflare) to check whether a newer app version is available and to sync the optional community points-of-interest database. These are plain file downloads and contain no personal data about you; as with any web request, the host receives standard information such as your IP address, user agent, and timestamp.
GPS / Location Data
If you grant location permission, the app accesses your device's GPS to display your position on the map, record tracks, follow routes, and provide navigation features. Location is accessed only while the app is in use (foreground) — the app does not access your location in the background. Location data is stored locally on your device unless you export it, share it with a Team Sync session, or use an online feature that needs coordinates, such as weather, elevation, routing, or map/search requests. Before the system location prompt is shown, the app displays a disclosure explaining this use.
Microphone
If you grant microphone permission, the app can record short voice messages (up to 60 seconds) for use in the Team Sync chat feature. The microphone is requested only at the moment you start recording a voice note. Voice messages are transmitted directly to other connected team members in the same session via the active sync transport (P2P, LAN, or Reticulum mesh). They are not sent to any server operated by us, not stored on external systems, and are not retained after the session ends.
Photos
You can attach a photo to a map waypoint. Photos are chosen through your device's standard file / photo picker (which may offer your camera) — the app itself does not request camera permission and never accesses the camera directly. Attached photos are stored locally on your device within the app's data storage. They are never uploaded to any server or shared externally without your explicit export action.
Team Sync and Peer Location Sharing
When you join a Team Sync session, your device's GPS coordinates and shared map objects are sent to other connected team members in that session. Depending on the transport you choose, this data may travel peer-to-peer, through a WebRTC signalling provider, through a LAN WebSocket bridge, or through a Reticulum mesh bridge. It does not pass through any server operated by us. Team Sync is opt-in — you must explicitly start a session and share a session code or QR code with others to connect. No location data is retained by us after the session ends.
ZYRNTOPO Pro Accounts and Licensing
The core app is free and needs no account. ZYRNTOPO Pro — an optional one-time purchase that unlocks the advanced features — does use an account, and it is the one place ZYRNTOPO stores personal data on a server we operate. If you never create a Pro account, none of this applies to you.
When you create a ZYRNTOPO Pro account, we run a self-hosted account and license service (at api.zyrntopo.com) that stores:
- Your email address, encrypted at rest, used to sign in, to send password-reset and purchase-confirmation emails, and to tie your Pro license to you.
- A hashed password — we use a one-way hash (Argon2id) and never store your password in readable form.
- Your Pro license status and the signed license token issued to your account.
We do not require your name, phone number, or address, and we do not sell or share this information. Your Pro license is verified on your device using a public key built into the app, so once Pro is active it keeps working with no signal and without contacting our server.
Payments. Purchases are handled by a third-party payment processor (such as Lemon Squeezy) or by the app store you bought from. You enter your payment card details with that processor — they are never seen or stored by us. The processor shares back only what we need to grant your license, such as your email and confirmation that payment succeeded.
Your control. From the account page you can change your email or password, transfer your Pro license to another account, download a copy of everything we hold about you, or close the account. Exactly what closing does is set out in the next section.
Deleting Your Account and Data
You can delete your ZYRNTOPO account yourself, at any time, from zyrntopo.com/account → Close account & delete data. It is confirmed with your password and takes effect immediately — there is no support ticket and no waiting on us. That page works in any browser, so uninstalling the app first does not strand your data, and you can reach it from within the app under Settings ▸ Account & ZYRNTOPO Pro.
Closing an account:
- revokes your Pro entitlement and every licence token issued to the account;
- deletes every sign-in session, signing out all your devices;
- deletes any pending email tokens — password resets and address confirmations; and
- erases the profile fields we hold, including any phone number you added.
Two things survive, and we would rather say so plainly than let you discover it:
- A closed record keyed to your email address. The address stays encrypted and we keep a one-way index of it. This is what stops a closed account from immediately re-registering as a brand-new one and re-claiming Pro that was refunded or transferred away. It is not used to contact you and is not used for anything else.
- Payment records for any purchase — order reference, amount, date. We and the merchant of record are required to keep these for tax and accounting purposes, typically for several years under applicable law. They contain no card details; we never had those.
If you want the remaining record erased rather than closed, email grangedevgroup@gmail.com from the address on the account and ask. We will erase everything that law does not require us to keep, and tell you what stayed and why.
None of this touches what is on your device. Maps, tracks, waypoints, photos and notes were never on our servers, so closing an account cannot reach them, and the app carries on working as the free version.
How Long We Keep Things
The account service holds as little as it can for as short as it can. Concretely:
- Account record (encrypted email, password hash, Pro status) — for as long as the account is open, then as described above.
- Sign-in sessions — expire 30 days after sign-in; expired rows are deleted automatically.
- Password-reset and email-confirmation tokens — deleted the moment they are used, and in any case when they expire.
- Licence tokens — the ten most recent per account are kept as a support and audit trail; older expired ones are deleted.
- Security log (sign-ins, failed sign-in attempts, account changes, with the IP address that made them) — 180 days, then deleted. We keep it to investigate account takeover and abuse.
- Anonymous install pings — an install that has not pinged for 400 days is deleted. These rows carry only the random identifier, app version and platform; they are not linked to any account.
- Feedback reports — kept until we have dealt with them, then 365 days, so a report is still on hand when the bug it describes is finally fixed. A report we have not read yet is never deleted on a timer. Ask us and we will delete yours sooner.
- Encrypted database backups — a rolling 14 nightly backups, encrypted at rest. A closure or erasure is applied to the live database immediately; the backups age out within two weeks, and we do not mine them.
Where Your Data Is Processed
The account and licence service runs on a single virtual server we rent and administer ourselves, hosted in the United States with Contabo Inc. This website and its assets are served by Cloudflare Pages. We do not use a third-party analytics, advertising, CRM or data-broker service, so there is no other place your account data goes.
If you are in the EEA, the UK or Switzerland, using ZYRNTOPO Pro means your account data is transferred to and stored in the United States. Where that transfer needs a safeguard under UK or EU data-protection law, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our hosting provider, together with encryption of the data in transit and of identifying fields at rest.
How We Protect It
- All traffic to
api.zyrntopo.comand to this site is HTTPS only, with HSTS. - Passwords are stored as Argon2id hashes — a one-way function. We cannot read your password, and neither can anyone who steals the database.
- Email addresses and phone numbers are encrypted at rest; lookups use a separate one-way blind index, so the plain address is never stored in an indexable form.
- Sign-in is rate-limited and throttled per account and per IP address to blunt credential-stuffing.
- Backups are encrypted before they leave the machine.
- Your Pro licence is verified on your device against a public key compiled into the app, so normal use of Pro sends nothing to us at all.
No system is perfectly secure. If you find a vulnerability in ZYRNTOPO, email grangedevgroup@gmail.com — we would much rather hear it from you than read about it later.
Your Privacy Rights
Why we are allowed to process what little we hold. Where the UK or EU GDPR applies, our legal bases are: performance of a contract for the account, licence and purchase data that make Pro work; legitimate interests for the security log, sign-in throttling and the anonymous install count, where our interest in keeping the service working and unabused is balanced against data that identifies you as little as possible; legal obligation for payment and tax records; and consent where your device asks for it, such as location or microphone permission, which you can withdraw at any time in your system settings.
Rights you can exercise. Wherever you live, you can ask us to:
- Access what we hold — the account page's Download my data button returns it immediately, in JSON.
- Correct it — you can change your email address and phone number yourself.
- Delete it — see Deleting Your Account and Data.
- Port it — the same export is a machine-readable copy you can take elsewhere.
- Object to or restrict processing based on legitimate interests, and to withdraw consent for a device permission at any time.
If you are in California or another US state with a privacy law (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana), you have rights to know, delete, correct and obtain a portable copy of your personal information, and to be free from discrimination for exercising them. To be unambiguous about the categories those laws care about: we do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not process it for targeted advertising or profiling. There is no advertising in ZYRNTOPO, and no advertising identifier is collected. We have never received a "sale" of your data because there is no buyer and no product.
How to exercise any of them: use the account page, or email grangedevgroup@gmail.com from the address on the account. We answer within 30 days, and we do not charge for it. If we cannot verify that a request comes from the account holder we will say so rather than hand data to a stranger.
If you think we have handled your data badly, please tell us first — but you also have the right to complain to your data-protection authority: the ICO in the UK, your national supervisory authority in the EEA, or your state Attorney General in the US.
App Stores and Platform Disclosures
Where ZYRNTOPO is distributed through a store, that store requires its own machine-readable privacy declaration. Those declarations describe the same practices as this policy, and this policy is the authoritative version:
- Google Play — our Data safety declaration reports that the app collects an anonymous app-usage identifier, and that account email and purchase data are collected only if you create a ZYRNTOPO Pro account; that data is encrypted in transit; and that account deletion is available at zyrntopo.com/account, as Google Play's account-deletion policy requires. Location is used in the foreground only, never collected by us, and never sent to our servers.
- Apple App Store — ZYRNTOPO is not published on the App Store yet. When it is, the App Privacy labels will mirror this policy, in-app account deletion will be available as guideline 5.1.1(v) requires, and this section will name any Apple-specific data flow.
- Microsoft Store — the Windows build is currently distributed from this site as a direct download. If we publish it to the Microsoft Store, this policy is the privacy policy linked from that listing, as the Microsoft Store's requirements provide.
The desktop builds are ordinary applications: they do not phone home beyond the anonymous ping described above, do not auto-update themselves, and contain no telemetry SDK.
Third-Party Services
The app does not integrate with any third-party analytics, advertising, or social media services.
The website may load basic presentation assets from third-party CDNs, including Google Fonts and Font Awesome, and may link to Google Play. Those providers may receive standard request information such as your IP address, browser user agent, referrer, and timestamp when your browser requests their assets or opens their links. These services are not used by us for analytics or advertising.
The homepage shows an approximate local weather chip. To do this, your browser makes a request to an IP-geolocation service (ipwho.is) to estimate your city from your IP address, and to a weather service (Open-Meteo) for current conditions near that location. This runs in your browser, the result is not stored, and it is used only to display the weather chip — not for analytics or advertising. The account and Pro pages communicate with our license service (api.zyrntopo.com), described above.
Children's Privacy
ZYRNTOPO is a backcountry and search-and-rescue tool built for adults. It is not directed to children, we do not market it to them, and it contains no advertising, no social features open to strangers, and nothing designed to hold a child's attention.
We do not knowingly collect personal information from children under 13, consistent with the US Children's Online Privacy Protection Act (COPPA). In the EEA and UK, where a child must be 16 — or the lower age their country sets, never below 13 — to consent to online services on their own, the same applies at that age. A ZYRNTOPO Pro account requires the ability to enter a binding contract, which a child does not have.
If you are a parent or guardian and believe a child has created an account, email grangedevgroup@gmail.com and we will close it and erase the data promptly, at no cost and without arguing about it. Note that a child using the free app on a family device creates no account and sends us nothing but the anonymous install ping, which contains no personal information.
Changes to This Policy
We may update this policy — for example when we ship on a new platform or add a feature that touches data. Changes appear on this page with a new "last updated" date. If a change materially affects how we handle personal data we hold about you, we will give notice before it takes effect: in the app, by email to accounts affected, or both, as required by law and by the app stores' policies. The version published when you use the service is the one that applies.
Contact
ZYRNTOPO is built and operated by Grange Dev Group, which is the data controller for the account and licence data described in this policy. Questions about this policy, a privacy request, or a report of a security problem all go to the same place: grangedevgroup@gmail.com. We aim to reply within 5 business days, and within 30 days for a formal data request.