Information you provide
Account information: email address, display name, and password. Passwords are stored as salted bcrypt hashes; we never see or store your plaintext password.
Profile preferences: units, notification settings, biometric unlock preference, and app settings.
Summit-log content: date and time you summited a peak, the peak and optional trail or road, notes, tags, and related sync metadata.
Journal photos: photos you attach remain on your device and, if you enable iCloud Sync, in your private iCloud container. Epicrest does not upload journal photos to our servers.
Subscription receipts: if you subscribe to Epicrest Pro, we receive and verify the receipt issued by Apple. We do not receive your payment card information.
Information collected automatically
Device location, only when you grant permission, is used to show nearby peaks, calculate distance and bearing, estimate offline packs, and enable AR features. Precise foreground coordinates are processed on device and sent to our servers only transiently to query the peak database; we do not store your location history.
Elevation and heading, only when you grant permission, are used by AR and altimeter features and are processed on device.
API request logs include method, URL path, response status, request duration, and anonymized IP for debugging, monitoring, and abuse prevention. Request logs are retained for 30 days.
Device metadata such as iOS version, app version, and device model may be used to investigate crashes and compatibility issues.
Information we do not collect
- We do not collect journal photos on our servers.
- We do not track you across other apps or websites.
- We do not run third-party advertising SDKs or sell personal information. Epicrest Pro subscriptions are the primary way the app is funded.
- We do not access your Photos library beyond images you explicitly pick or capture inside Epicrest.
- We do not collect precise background location.
How we use your information
- To provide the service, including peak discovery, logging, account sync, and payment entitlement checks.
- To improve the app by diagnosing crashes, measuring feature usage in aggregate, and understanding which mountain-data workflows need more work.
- To communicate about account, service, security, and material product updates.
- To detect and prevent abuse or misuse.
Who we share data with
We do not sell personal information. We share limited data with providers used to deliver Epicrest: Apple for CloudKit, StoreKit, and Sign in with Apple; OpenStreetMap and Overpass for public peak and trail data; Open-Meteo for weather; and infrastructure providers for hosting, database, caching, monitoring, and email delivery. We may disclose information if required by law or to protect user safety.
Your iCloud data
When iCloud Sync is enabled, journal entries and photos synchronize to your personal iCloud account using Apple's CloudKit service. The iCloud copy lives in your private iCloud container, and Epicrest backend systems cannot retrieve journal photos from iCloud. Disable sync in-app to keep future changes local to your device.
Your rights and choices
Access and export: request a copy of account data we hold through the support form.
Deletion: delete your account from Profile → Security → Delete Account or contact support. Server-side account records and metadata are permanently removed. Device-local data is removed by deleting the app. iCloud-synced journal data remains in your iCloud until you remove it from iCloud Settings.
Location: disable location access any time in iOS Settings. Epicrest continues to work with reduced functionality.
Notifications: manage notification settings in-app or in iOS Settings.
Security
- Passwords are stored as salted bcrypt hashes.
- Network traffic uses HTTPS/TLS.
- Authentication tokens are stored in the iOS Keychain.
- Production access is restricted to authorized personnel.
No system is perfectly secure. Use strong, unique passwords and enable biometric unlock where appropriate.
Children
Epicrest is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact support and we will remove it.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app and by email where available. The Last updated date indicates when changes were last made.
Contact
Questions about privacy? Use the support form.