Applies to the Walkabout app for Android and iOS (com.ubiquicore.walkabout) and to this website.
Version 1.0 · effective 21 August 2026.
Walkabout reads your location on your phone, uses it on your phone, and stores it on your phone. It is never sent to us, because there is no account, no server to hold it and no code in the app that would send it. There are no adverts, no analytics, no crash reporting and no third-party trackers of any kind.
The app makes two kinds of network request. It downloads offline map packs from our own server. And, if you use the weather and stargazing features, it asks a forecast service what the weather is doing near you — sending a rounded, approximate location, never your exact position. Nothing else about you reaches anyone at any point: no account, no device identifier, no advertising ID, no analytics.
Walkabout is made and published by UbiquiCore Limited, based in the United Kingdom. For anything in this policy, including any request about your data, write to hello@walkabout.fit.
Where this policy uses "we", it means UbiquiCore Limited. Where it uses "the app", it means Walkabout installed on your phone.
Walkabout asks for location permission the first time you tap the locate-me button or start a walk, never on launch. On Android it asks only for foreground location; the background-location permission is deliberately removed from the app so that it cannot be granted at all. On iOS it asks only for "While Using the App". Recording continues with the screen off because the app runs a visible foreground service (Android) or a background activity session started while you were looking at it (iOS) — not because it holds a permission to follow you around.
Location fixes from the phone's GPS and barometer are processed entirely on the device: filtered, turned into distance, pace and climb, drawn on the map and written to a database in the app's private storage. No coordinate is transmitted anywhere by the app.
The app uses a third-party location library (tracelet, Apache-2.0) to talk to the operating system's location services. It is configured to do the minimum: its own network sync is switched off, its address lookup ("turn this coordinate into a street name", which would be a network call per fix) is switched off, its separate location database is switched off, and its logging — which would otherwise write coordinates into log files — is switched off.
All of the following lives in Walkabout's private app storage on your device. None of it is uploaded by the app.
| What | Why |
|---|---|
| Recorded walks and their GPS track points | So a walk exists after you finish it |
| Saved and planned routes | So you can walk them again |
| Downloaded region packs | The offline map, terrain, paths and place-name index |
| Progress: points, badges, streaks, explored areas | The app's gamification, computed on device |
| Your settings and preferences | Theme, units, text size, Wi-Fi-only downloads |
| An optional profile: body weight and a fitness answer | Better time and effort estimates. Both optional, both stay on the device |
We keep this data for as long as you keep the app. We do not set a retention period on it because we do not hold it — you do. Deleting the app removes all of it. Downloaded map packs can also be deleted individually inside the app.
Walkabout's data sits in the app's normal private storage, which means your phone's own backup system may include it in a backup to your cloud account — Android Backup to your Google account, or iCloud Backup on iOS — if you have that turned on. That copy is made by your operating system, goes to your own account, and is governed by Google's or Apple's terms rather than ours. We never see it. If you would rather your walk history were not backed up, turn off backup for Walkabout in your phone's settings.
Region packs — the offline maps — are files we host. When you open the offline maps screen, the app fetches a catalogue file (catalog.json) from our pack host, and when you download a region it fetches the pack files, resuming partial downloads where needed. Everything is plain HTTPS GET requests for files at fixed addresses. The requests carry no identifier of you, your device or your walks — no account, no device ID, no advertising ID, no analytics token, no query parameters about you.
Our pack host is packs.walkabout.fit. Like any web server it necessarily sees, for each request: your IP address, the file you asked for, the time, and standard connection details your device sends to fetch a file. We have configured that host to keep no request logs at all, so these details exist only for as long as it takes to send you the file.
An IP address can be personal data under UK data protection law, which is why it is described here rather than glossed over. We do not use it to identify you, do not link it to any other data, do not build a profile from it and do not share it with anyone for their own purposes.
The weather, the walking-window scores and Tonight Mode need a forecast, and a forecast has to come from somewhere. So when those features are switched on, the app asks a forecast service what the weather is doing near you.
It sends an approximate location, not your position. Before anything leaves your phone, your coordinates are rounded onto a grid of roughly two to three kilometres. What the forecast service receives is that grid square — the same square for everybody standing anywhere in it, and the same square whether you are at your front door or a mile up the lane. It is deliberately too coarse to say where you are, and it costs nothing in accuracy, because weather models work at seven to twenty-five kilometres anyway.
The request also carries the list of weather measurements the app wants and the name of the forecast model. It carries no account, no device identifier, no advertising ID, no analytics token and nothing about your walks. Like any web server, the forecast service necessarily sees the IP address the request came from.
During development and testing this is Open-Meteo’s public service. Before the app is sold we move it to a server of our own, so that the only two places your phone talks to are both ours.
None of the astronomy leaves your phone. Sunrise, sunset, twilight, the moon, the meteor calendar — all of it is worked out on the device from the date and your position, with no request to anybody. That is why Tonight Mode still works in a field with no signal.
If you turn the conditions features off in Settings, the app makes no forecast request at all.
The app has no permission to know where you are while it is closed, and never asks for one. The daily weather notification, if you turn it on, is worked out for the area you were last in — or a home area you choose — and the notification itself says which. It is not a live reading of where you are at seven in the morning, and it could not be.
The app also checks whether your connection is Wi-Fi or mobile data. That check asks the operating system and involves no network request; it exists solely so the "download over Wi-Fi only" preference can work.
On iPhones, iOS itself hands the app occasional battery and performance reports (Apple's MetricKit). Those reports are delivered by the operating system, stay in the app's storage, and are not uploaded.
| Permission | Used for |
|---|---|
| Location (precise or approximate, while using the app) | Showing where you are and recording a walk. Approximate is enough for the blue dot if that is all you grant. |
| Notifications | The ongoing notification that keeps a recording alive with the screen off. |
| Foreground service (location) — Android | Recording while the phone is in your pocket, without background-location permission. |
| Internet and network state | Downloading map packs, and knowing whether you are on Wi-Fi. |
| Motion / barometer | Measuring climb from air pressure, which is far more accurate than GPS altitude. Optional; the app works without it. |
Notably absent: background location, contacts, photos, microphone, phone, calendar, exact alarms and the advertising ID. Where a bundled library declared a permission we do not use, it is removed from the build rather than justified.
Most privacy policies for location apps are written for apps that collect location. This one is not, so it is worth being precise rather than reassuring.
The only personal data we act as a controller for is the request data our pack host necessarily receives when your phone downloads a map file (section 4): your IP address and which file you asked for.
Our lawful basis for that is legitimate interests (UK GDPR Article 6(1)(f)) — we cannot deliver a file to a device without its address, and being able to tell abuse from normal traffic keeps the service running for everyone. We have weighed this: the data is the minimum a web request cannot function without, it is not combined with anything else, it is not used to profile or to identify anybody, and it is held for no longer than stated in section 4. It is at least arguable that Article 6(1)(b) (performance of a contract) also applies once you have bought the app; we rely on legitimate interests because it is the basis that holds regardless of whether you have.
Your location history, your walks, your routes and your progress are personal data — and, because they say something about your physical activity, arguably health-related data too. We never receive any of it. It is created on your device, used on your device and stored on your device, under your control. There is no copy on our side to disclose, to correct or to delete, and no third party we could have passed it to.
We are not trying to use that as a loophole. It is the design: the reason we can say we do not process your location is that we built an app that cannot.
Rules on storing information on your equipment (the Privacy and Electronic Communications Regulations in the UK, and their equivalents elsewhere) also apply to apps, not only to website cookies. Everything Walkabout stores on your phone — your walks, your settings, your downloaded maps — is strictly necessary to provide the service you explicitly asked for. There is no analytics storage, no advertising storage and no non-essential storage of any kind, which is why the app never shows you a consent banner: there is nothing for you to consent to beyond the operating-system permission prompts, which you control and can withdraw at any time in your phone's settings.
You have the rights to access, rectification, erasure, restriction, objection and portability, and the right not to be subject to automated decision-making. Walkabout makes no automated decisions about you and does no profiling.
In practice: for everything on your phone, you exercise those rights directly — the data is in your hands, and uninstalling the app erases it. For the request data at our pack host, write to hello@walkabout.fit. Be aware that we usually cannot connect an IP address to a person, so we may not be able to find "your" records without more information than it would be sensible for you to give us — and we will not ask you for extra personal data just to run a search.
Nothing about you is transferred by us, because nothing about you is collected by us beyond the request data in section 4. Map packs are served through a content-delivery network, which means the request may be answered by a server outside the UK, whichever is nearest to you. That is a file being sent to you rather than data about you being sent abroad.
If you think we have handled your data badly, please tell us first at hello@walkabout.fit. You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or by phone on 0303 123 1113. If you are in the EU or EEA, you may complain to your own national supervisory authority.
Walkabout is not aimed at children and is rated for ages 13 and over. We do not knowingly collect personal data from anyone, of any age.
Two things sit between us and you that have their own privacy policies:
Beyond those, Walkabout uses no processors, no sub-processors and no third-party services.
This policy describes the app as it is built today, not as it might be. Some planned features would genuinely change the answers — sharing a live walk with someone, publishing a route for other people to walk, or optional crash reporting. If any of those ship, this policy will be updated and the change described before the release that contains them, and the Google Play data-safety declaration will be updated to match. We will not quietly start collecting something and update the wording later.
The current version and its date are at the top of this page. Material changes will be flagged in the app's release notes.
walkabout.fit is two static pages. It sets no cookies, loads no fonts, scripts, images or anything else from other domains, and runs no analytics or tracking of any kind. Our host keeps standard web-server request records for security and abuse prevention, on the same terms as section 4.