Privacy

Last updated 16 August 2026. Short version: no account, no email or phone number required to use it, no analytics, no advertising, and your location stays on your phone unless you choose to send it.

The Sunshine Coast Trail app is designed to work offline. It has no advertising or analytics SDK. Community participation uses an anonymous installation identifier; a first name is optional and no email address or phone number is required.

Location

If the user chooses Enable Location, the app requests foreground location access. It uses the device coordinate, reported accuracy, and timestamp locally to estimate a nearby trail marker and draw the user's position. Foreground fixes are not retained as a history unless the user separately starts Trip Recording.

Background trip recording

Trip Recording is off by default and starts only when the user taps Start. The app then requests background (“Always”) location access and stores precise coordinates, timestamps, and available accuracy, altitude, speed, heading, and mock-location flags while the app is in the background or the screen is locked. Recording continues until the user stops it or the operating system interrupts it.

The resulting track is stored only in the app's local storage. It is not uploaded. The user can export it as a GPX through the system share sheet or permanently delete it from the Trip Recording screen.

Sharing

Sharing is initiated by the user. Shared text includes the raw GPS coordinate, reported accuracy when available, capture time, and an explicitly approximate marker kilometre. A GPX export contains the recorded track and its raw location fields. The operating-system share sheet sends that data only through the recipient or service selected by the user; those recipients and services have their own privacy practices.

Family Sharing is separately opt-in. A manual update is sent only through the system share sheet and may include the GPS detail selected by the user. A private follow link contains only feed posts and hut check-ins deliberately published by the hiker; it does not upload a raw GPS fix or complete background recording. A follow page may be stale and is not live tracking or an emergency-monitoring service.

Community plans and trail feed

Hut-night plans may contain an optional first name, where the hiker says they are travelling from, a photo, hut, calendar night, party size, direction, sleeping preference, and planned-or-arrived status. Feed posts may contain an optional first name, where the hiker says they are travelling from, a photo, category, text, one or more fixed condition tags (a short list per category — for example "Bridge out" or "Bear sign"), a flowing-or-dry tap for a water source, a reply to another post, approximate marker kilometre, and time. Raw GPS coordinates are not automatically attached to feed posts.

On a ride-share or lost-and-found post only, a hiker may choose to type a public contact detail — a phone number, email address, or social handle — so another hiker can reach them. The composer warns at the point of typing that this is public, seen by every synced device, and cannot be unpublished once someone has it; leaving it blank and using replies instead is always an option.

These records are saved locally first. When community synchronization is connected, queued records are sent to the community service so other hikers can see them. Until a successful sync is shown, the app labels resulting counts as device-only.

Data stored on the device

Display, units, direction, planning, destination, and Trail Mode preferences may be stored locally. The anonymous community identifier, optional first name, hut plans, feed posts, pending sync operations, and family-sharing choices are also stored locally. The anonymous edit credential is kept in iOS Keychain or the Android Keystore-backed encrypted store, not beside ordinary preferences. Trip recordings remain local until the user deletes them or uninstalls the app. The offline map and trail data ship with the app.

Data not otherwise collected

The app never requests contacts, health data, or a legal name, and never asks for an email address or phone number to use it — there are no accounts. The one exception is the optional public contact field described above: if a hiker chooses to type a phone number, email address, or handle onto a ride or lost-and-found post, that is their deliberate, visible choice at the moment of posting, not something the app asks of them. It has no advertising profile or usage analytics. A connected community service receives only the community and family-sharing fields described above. Data is not sold or shared for advertising.

A public web copy, support contact, retention period, community moderation process, and service-operator details must be completed before synchronized community features ship. The App Store privacy answers must match the production service configuration.