1. Who publishes this app
FitMapped is developed and published by Jason Gleman, an individual based in the Netherlands. For the purposes of the EU General Data Protection Regulation (GDPR), Jason Gleman is the data controller for this app — but as you'll see below, there is very little data to control, because it never leaves your device.
You can reach me at privacy@hotwaffles.lol.
2. What FitMapped does
FitMapped reads your workout route history from Apple Health and draws it as a personal heatmap on a map. The longer or more frequently you've traveled a route, the brighter it glows. It also shows summary statistics (total distance, top speeds, workout counts, locations) derived entirely from the data already on your device.
That's the entire app. It does not do anything else with your data.
3. What data FitMapped processes
FitMapped processes the following data, only on your iPhone:
- Apple Health workout data, with your explicit permission: workout type, start and end times, distance, and — where available — the GPS route and associated metadata (speed, elevation) recorded by Apple Watch or your chosen workout app.
- Your current location and heading, optionally and only while the app is in use, if you grant location permission. This is used solely to display your position on the map (the standard blue dot), to orient the map to the direction you're facing, and to center the map on you when you tap the location button. Your location is never saved to disk, never added to any database, and never transmitted off the device. Nothing is derived from it beyond what's drawn on screen while you're looking at the map.
- App preferences such as your distance unit (km or mi), active filters, and whether you've completed onboarding. These are stored in the standard iOS preferences system on your device.
FitMapped does not request or access: your name, email, phone number, photos, contacts, calendar, microphone, camera, advertising identifier, device identifier, or any information about your iPhone beyond what the operating system needs to draw the app.
4. Where that data lives
All workout data that FitMapped reads from Apple Health is cached in a local SQLite database stored in the app's Application Support directory on your iPhone. This location is not backed up to iCloud by default. Map imagery shown in the Locations browser is cached in the app's Caches directory, which iOS manages and clears as needed.
No data from FitMapped is ever transmitted to any server operated by me, because I do not operate any servers. There is no "FitMapped cloud." There is no account to sign up for. There is no data for me to lose, leak, or be compelled to hand over.
5. Apple services FitMapped relies on
Although FitMapped itself does not make any network calls, it uses a few Apple-provided frameworks that may contact Apple's own services on your behalf. Any such contact is governed by Apple's privacy policy, not mine. I do not see or receive any of this traffic.
- Apple HealthKit — used to read your workout history with your permission. HealthKit access is entirely on-device.
- Apple MapKit — used to render the map. MapKit downloads map tiles from Apple and, when you view the Locations browser, uses Apple's reverse-geocoding service to turn coordinates into place names (e.g. "Amsterdam, North Holland"). These requests are made by iOS, sent directly to Apple, and contain no information about you beyond the coordinates being displayed.
- Apple CoreLocation — used, with your permission, to show your current position and heading on the map while you are viewing it. CoreLocation provides this information to the app on-device; it is not transmitted anywhere by FitMapped.
- Apple crash reports — if you have "Share with App Developers" enabled in iOS Settings → Privacy & Security → Analytics & Improvements, Apple may include FitMapped in anonymized crash and performance reports that are delivered to me through Apple's App Store Connect. These reports contain only technical information about the crash (stack traces, device model, OS version). They never contain your workout data, your location, your identity, or anything else personally identifying. You can turn this off at any time in iOS Settings.
6. What FitMapped does not do
As of the current version of the app, FitMapped does not:
- Upload, transmit, or copy your HealthKit or location data off your device.
- Sell, share, or rent your data to anyone.
- Embed third-party analytics SDKs, tracking pixels, advertising SDKs, or crash reporters other than Apple's own.
- Show advertisements.
- Require an account, email address, phone number, or any sign-up.
- Use your Advertising Identifier (IDFA) or request App Tracking Transparency permission.
This is both how the app works today and the intent with which I built it. I have no current plans to add tracking, analytics, advertising, data sharing, or a sign-up requirement. If any of that ever changes in a future version — for example, to support a feature that genuinely requires an account — I will update this policy and the effective date, and update the "App Privacy" details on the App Store listing before shipping the change. You will see the new disclosures before you install the update, and anything that requires a new permission (such as App Tracking Transparency) will also prompt you at runtime.
One commitment here does not depend on my future plans: your HealthKit data will not be used for advertising, marketing, or data mining. This is required by Apple's HealthKit rules for every app that uses the framework, and applies as long as FitMapped uses HealthKit at all.
7. Your rights under GDPR
Because FitMapped stores no personal data on any server I operate, I have no data about you to access, export, correct, or delete on your behalf. You exercise your rights directly on your device:
- Right of access — open the app. What you see is all the data FitMapped has. The source (Apple Health) is accessible in the iOS Health app at any time.
- Right to rectification — edit or delete the workout in the Apple Health app. FitMapped will reflect the change the next time it syncs.
- Right to erasure — uninstall FitMapped. iOS removes the app's entire data container, including the SQLite cache and all preferences. Nothing is left behind.
- Right to restrict processing — revoke the app's HealthKit permission in iOS Settings → Health → Data Access & Devices → FitMapped.
- Right to data portability — your HealthKit data can be exported at any time from the Apple Health app (Profile → Export All Health Data).
- Right to object — same as restriction or uninstallation above.
If you believe your rights under GDPR have been violated, you have the right to lodge a complaint with the Dutch Data Protection Authority, Autoriteit Persoonsgegevens.
You may also contact me directly at privacy@hotwaffles.lol with any question about this policy.
8. California residents (CCPA / CPRA)
FitMapped does not collect, sell, or share personal information as defined by the California Consumer Privacy Act. There is no "Do Not Sell or Share My Personal Information" link because there is no selling or sharing to opt out of.
9. Children
FitMapped contains no content inappropriate for any age and does not knowingly collect information from anyone, including children. The app reads workout data from Apple Health, and the use of Apple Health on a child's device is governed by Apple's Family Sharing and screen-time controls. FitMapped itself neither knows nor cares about the age of its users, because it is not collecting data about any of them.
10. Changes to this policy
If this policy ever changes, I will update the effective date at the top of this page, and — if the change is material — I will update the "App Privacy" section of the App Store listing accordingly. Because FitMapped does not collect email addresses, I cannot notify you directly. The current version of this policy will always be available at hotwaffles.lol/fitmapped/privacy.html.
11. Governing law
This privacy policy is governed by the laws of the Netherlands. Any dispute arising from or related to it falls under the exclusive jurisdiction of the competent courts in the Netherlands, without prejudice to any mandatory consumer-protection rights that apply to you under the law of your own country of residence.
12. Contact
Questions, concerns, or data-protection requests: privacy@hotwaffles.lol
Jason Gleman · Netherlands