App Privacy Policy

Effective date: 2026-08-26

This is an English translation provided for convenience. The German version is authoritative; where it differs from this translation, German governs.

1. Overview

RowCulus is a mobile app designed to support safer rowing by sharing session and position information between participating users.

This Privacy Policy explains what data we process, why we process it, and what choices you have.

For a short, plain-language summary intended for in-app display, see legal/privacy_policy_in_app_de_ch_main.md.

2. Who This Policy Applies To

This policy applies to users of the RowCulus mobile application on iOS and Android.

3. Data We Process

3.1 Location Data

When location sharing and an active rowing session are enabled in the app, we process your location data to provide core features such as:

  1. Showing your own boat position on the map.
  2. Sharing your position with other participants.
  3. Showing other participants on the map.

Your position is not shared with every user of the app: visibility is limited to your immediate geographic vicinity. Other participants only see your boat if they are within roughly 1 km; likewise, you only see boats near you. This limit is enforced server-side, not just hidden in the app, and updates automatically as you move.

During an enabled rowing session, location processing may continue when the app is in the background or the screen is locked, subject to your device permissions and operating-system settings. On Android, the app shows a persistent location-tracking notification while this is active. On iOS, the system may show its background-location indicator. Background tracking is intended for an active rowing session; ending the session or disabling location sharing stops position sharing. It is not intended to continue after you force-quit the app, and your operating system may stop it in some circumstances.

3.2 Session and Identity Data

The app processes session-related identifiers and profile data, such as:

  1. Session user ID.
  2. Boat ID.
  3. Boat name (if configured).

These values are used to distinguish participants and route session updates.

If you enable Anonymous Mode for a session, your boat name and boat type are omitted from position updates shared with other participants. Your boat/session identifiers and vessel category (used to keep collision-safety pairing working) continue to be processed normally.

3.3 Technical and Device Data

To operate and diagnose the service, we may process technical metadata, such as:

  1. App version and build number.
  2. Device/platform information (for example device name and phone model), only when diagnostics sharing is enabled in the app.
  3. OS type and version.
  4. Connection status and timestamps.
  5. Battery level, only when diagnostics sharing is enabled in the app.

When diagnostics sharing is enabled, we also record and retain, on our infrastructure, the full data stream for that rowing session — including your position, speed, and heading over the course of the session, together with the session and device metadata described above — for internal testing, quality assurance, and simulation purposes (for example, replaying real session data to test collision-detection behavior). This recording is not shared with other participants or disclosed outside RowCulus’s internal development and testing use, and is kept only as long as needed for that purpose rather than on a fixed schedule (see section 8).

Locale/language is used only on your device to display the app in your preferred language and is not transmitted to us or other participants.

3.4 Map Display Data

When the map is shown, your device requests map tiles (image data for the visible map area) from our tile-hosting infrastructure. These requests inherently reveal the approximate map area you are viewing (and your device’s IP address) to that infrastructure, independent of whether location sharing is enabled.

3.5 Installation Authentication and Platform Attestation

To protect the service against unauthorized or modified app installations, the app creates a device-specific cryptographic key and registers an installation identity with our authentication service. We process:

  1. A randomly generated installation ID.
  2. Device platform (iOS or Android).
  3. The installation’s public key and a fingerprint of that key. The private key remains in the device’s protected key storage and is not sent to us.
  4. Cryptographic challenges, signatures, timestamps, and short-lived access-token identifiers used to verify the installation and authorize MQTT and map-tile access.
  5. Platform-integrity evidence from Apple App Attest on iOS or Google Play Integrity on Android.

On Android, Google processes the integrity request and returns an integrity verdict that our authentication service verifies. On iOS, Apple App Attest creates the attestation and assertions used by our authentication service; we store the App Attest key identifier, public credential, receipt, validation data, and assertion counter. Apple and Google may process technical data under their own privacy terms when their platform-integrity services are used.

This authentication data is required to connect to protected RowCulus services. If registration or attestation is unavailable or unsuccessful, MQTT position sharing and protected map-tile access may not work.

3.6 Data We Do Not Intentionally Collect in This Flow

The app is not designed to collect payment card data or other financial account data.

4. How We Collect Data

We collect data:

  1. Directly from your device sensors and OS permissions (for example, location).
  2. From app configuration and runtime state.
  3. Through app-to-server messaging needed for session features.

5. Why We Process Data

We process personal data for the following purposes:

  1. To provide map/session functionality and rowing safety features.
  2. To maintain service reliability and troubleshoot issues.
  3. To secure and monitor app communications.
  4. To comply with applicable legal obligations.

6. Legal Basis (Where Applicable)

Depending on jurisdiction, processing is based on one or more of:

  1. Your consent (for example, location sharing settings/permissions).
  2. Performance of a service you request.
  3. Legitimate interests in operating a reliable and secure app.
  4. Compliance with legal obligations.

7. Sharing and Recipients

We share data only as needed to provide the service, including:

  1. Infrastructure/services used to transmit or host session messages.
  2. Infrastructure/services used to host and deliver map tiles (see section 3.4).
  3. Other participating users, only for data necessary to session visibility features (for example, shared position updates), and even then only participants within your immediate geographic vicinity (see section 3.1) — not every user of the app.
  4. Apple App Attest and Google Play Integrity, depending on your platform, to verify that the app installation and device meet service-integrity requirements (see section 3.5).

We do not sell personal data.

8. Data Retention

Current position and session messages are transmitted through the MQTT service without the MQTT retained-message feature. RowCulus does not intentionally maintain a server-side history of these messages for sessions where diagnostics sharing is not enabled. Messages may remain briefly in service memory while being delivered, and operational systems may process connection and security metadata.

If diagnostics sharing is enabled for a session, that session’s position and session data is additionally recorded on our infrastructure as described in section 3.3. This recording is retained under a purpose-bound policy rather than a fixed retention period: it is used only for internal testing and simulation, is never shared or disclosed outside that internal use, and is deleted once it is no longer needed for that purpose.

The installation ID, platform, public key, key fingerprint, verification timestamps, and iOS App Attest credential are stored in the authentication database so that an installation can continue to authenticate. They are currently retained while the installation remains registered or until the records are deleted as part of a privacy request, service maintenance, or decommissioning. Authentication challenge records contain expiry times (normally two minutes), but expired and consumed challenge records may remain in the authentication database until service maintenance removes them.

On your device, the installation ID, session identifiers, boat profiles, privacy preferences, and registration state are retained in app storage until they are replaced, reset by the app, or removed by clearing the app’s data or uninstalling the app, subject to operating-system backup behavior.

Security and infrastructure logs may contain timestamps, installation or client identifiers, request outcomes, and network metadata. They are retained according to operational log rotation, backup, security, and legal requirements. We do not intentionally log MQTT message content as part of normal broker operation.

We are refining automated deletion and fixed retention schedules during the beta. Until those schedules are implemented, you may request deletion using the contact details below. Some records may be retained longer where required for security, legal claims, or compliance with law.

9. Security

We apply reasonable technical and organizational measures to protect data against unauthorized access, loss, misuse, or alteration.

No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.

10. Your Choices and Controls

You can:

  1. Control location permissions in your device settings.
  2. Enable or disable in-app location sharing controls.
  3. Enable Anonymous Mode for a session: other participants will not see your boat’s name or boat type on their map. Your position is still shared and collision-safety detection still works normally — Anonymous Mode hides display information, it does not stop position sharing. To stop sharing entirely, end your session (see below).
  4. Start or end a rowing session; ending it stops background location tracking and position sharing.
  5. Stop using the app at any time.

Disabling location sharing may limit or disable core session features.

11. Your Rights

Depending on your location and applicable law, you may have rights to:

  1. Access your personal data.
  2. Correct inaccurate data.
  3. Request deletion of data.
  4. Restrict or object to processing.
  5. Data portability.
  6. Withdraw consent (where consent is the basis).

To exercise rights, contact us using the details below.

12. Children

RowCulus is not intended for children under the age required by applicable law without appropriate parental/guardian involvement.

13. International Transfers

If data is processed in countries other than your own, we apply appropriate safeguards where required by law.

14. Changes to This Policy

We may update this policy from time to time. We will post the updated version with a new Last updated date.

15. Contact

Controller/Operator: RowCulus.ch Email: privacy@rowculus.ch Address: Chriesibaum GmbH, RowCulus, Oberer Gubel 59, 8645 Jona, Switzerland

For privacy requests, include enough information for us to verify your request and respond.

16. App-Store Disclosures

You may also find platform-specific privacy disclosures in app store listings (for example, App Store and Google Play data safety sections). If there is any conflict, this policy governs unless mandatory platform disclosures require additional detail.

Scroll to Top