We do not sell personal data, and routes, searches and saved places are never used to advertise to you.
Privacy Policy
Privacy,
without the fog
Your route is a request, not a diary.
Effective 22 August 2026Route coordinates answer the request. The service logs no coordinates and keeps no record of where you have been.
Crash reports and usage data are separate opt-ins under Settings, Privacy. Both start off, and neither contains where you ride.
Who is responsible
45weg is made and run by one individual developer established in the Netherlands, working alone and not through a company. That person is the controller responsible for the processing described in this policy, and hallo@45weg.nl reaches them directly. Ask at that address for the controller's name and postal address and we will give them to you; a supervisory authority receives them on request as well.
The General Data Protection Regulation (GDPR) and Dutch law apply. The Dutch supervisory authority is the Autoriteit Persoonsgegevens.
What we collect
Account and sign-in
You do not need to register or provide your name or email address to use 45weg. The app creates a pseudonymous installation identity when it first opens so requests can be authenticated. Firebase Authentication processes a user identifier, authentication tokens, sign-in timestamps, IP address, user agent and security information. App attestation also processes an app-integrity token and related security information so the service can reject requests that do not come from a genuine installation. These are personal data even though the identifier does not directly state your name.
You can register an account, and the only additional feature it provides is keeping your saved places when you move to a new phone. If you do, Firebase Authentication also processes the sign-in method you chose, your email address and your display name where one is available. If you sign in with Google or Apple, that provider processes the sign-in under its own privacy terms; Sign in with Apple lets you hide your email address, and 45weg works normally if you do. Creating an account keeps the identity you already had, so the places you saved before it stay yours.
Location and guidance
With your permission, the app reads your precise location, heading, speed and the timestamps that go with them, so it can draw where you are and guide you turn by turn. It asks for one permission, While Using the App, and never for the always-on kind. While guidance is running it keeps reading your location with the screen off, which is what the location indicator iOS shows during a ride is telling you. Background location use stops when you stop guidance. The app may still read location while you use the map if you have granted permission. You can withdraw the permission at any time in your device settings; guidance stops working and the rest of the app keeps working.
Location is read on the device. It leaves the device only in the route requests described next, and it is never written to a file on our servers.
Route requests
Planning a route sends your starting point, destination, any further waypoints, the vehicle class you selected, your powertrain answer where the road rules depend on it, and your language to the 45weg routing service. Protected requests carry your authentication token so the service knows the request comes from a signed-in rider.
The service uses those details to compute the answer and then discards them. Its request log holds a request identifier, the HTTP method, the path, the status code and how long the request took. It holds no coordinates, no query strings and no request bodies, so no route history is built anywhere in the service.
Shared map links
When you share a map link into 45weg from another app, the share sheet writes the link into a storage area shared between 45weg and its share extension on your device, and the app then sends that link to the 45weg service to be read. The service follows the link at the map provider that issued it, which at present means Google, Apple or OpenStreetMap, to reach the coordinates or place name behind a shortened URL. That provider sees a request from our server rather than from your device.
The link is used to answer the one request and is not stored. Links to hosts other than those map providers are refused rather than followed.
Search and maps
Searching for a place sends your search text, your language and, when available, a nearby coordinate so that results near you rank first. Those searches go to Photon, the open-source geocoder operated by komoot GmbH in Germany, and for Dutch address searches to PDOK, the public geo-service of the Dutch government. Choosing a point on the map to identify it sends that coordinate to the same services. The map itself is loaded from OpenFreeMap, which receives the requests needed to deliver the style, tiles, fonts and symbols for the part of the map you are looking at.
All three receive the ordinary connection data that comes with any internet request, including your IP address and user agent. Map data comes from OpenStreetMap contributors.
Saved and recent places
Saving places needs an account, because that is the only way they can survive a new phone. Saved places are stored in Cloud Firestore under your account and nowhere else: nothing about them is written to your phone, so deleting the app leaves none of them behind. A saved place holds the name you gave it, its latitude and longitude, an address and place name where one was found, its position in your list and the time it was last changed. A separate private record notes which saved places you marked as Home and Work.
Recent destinations, your selected vehicle, your language and your other app preferences stay on the device and are not copied to the service. They go when you delete the app, and they need no account.
Optional crash reports
Crash reporting is off by default. You can choose to turn it on under Settings, Privacy and turn it off there at any time. Crash reporting is not needed to plan or follow a route.
Firebase Crashlytics collects a report when the app crashes: what failed, where in the code, which app version and what kind of device and operating system it was, with a timestamp and an identifier for your installation.
Crash reports do not contain where you ride. No route, coordinate, address or search term is sent with a report, and reports are not joined to your account or saved places.
Optional usage data
Usage measurement is also off by default and has its own switch under Settings, Privacy. If you turn it on, Google Analytics for Firebase receives automatically generated information about app launches, sessions and engagement, the app version, device model, operating system, language, timestamps, and an app-instance identifier. Google may derive an approximate region from connection information.
No route, precise location, destination, address, search term or saved place is sent to Analytics. Analytics is not joined to your registered account. 45weg does not use an advertising identifier, advertising features or cross-app tracking.
What is kept on your phone
The app keeps a little information in its own storage on your device: the installation identity and app-integrity token that authenticate your requests, your privacy choices, your selected vehicle, your language, your recent destinations, and the map link the share extension hands over. Reading and writing that needs no permission from you, because article 11.7a, paragraph 3 of the Dutch Telecommunications Act excepts storage that is strictly necessary to deliver the service you asked for, and none of it works without this.
The app-instance identifier that usage measurement needs is not covered by that exception. That is why usage data has its own switch, stays off until you turn it on, and is the one thing here we ask you before storing. Deleting the app removes what is kept on the device.
Website and support
This website is static and sets no advertising or analytics cookies. Firebase Hosting and the network in front of it process your IP address, request information, user agent, timestamps and security logs to serve the pages. If you email us, we receive your address, your message and anything you attach to it.
Why we use it, and on what basis
To provide the service you asked for. Your account, saved places, route requests, shared links, searches and guidance are processed to perform our agreement with you under article 6(1)(b) GDPR. Providing this data is a contractual rather than statutory requirement. An account is optional; without location and route details, navigation cannot work, and without account details, cloud-saved places cannot work.
To keep the service working and safe. Request logs, authentication checks and abuse prevention are processed for our legitimate interests under article 6(1)(f) GDPR, namely running a reliable service and protecting it and its riders from misuse. Those logs deliberately hold no coordinates, which keeps the interference with your privacy low.
To answer you. Support correspondence is processed to handle your message, under article 6(1)(b) or, where you are not writing about your own account, article 6(1)(f) GDPR.
Optional crash reports and usage data. If you turn either one on, we process that category on the basis of your consent under article 6(1)(a) GDPR. Each has a separate switch, is unnecessary for navigation and excludes routes, precise locations and searches.
You can withdraw either consent at any time by turning that switch off under Settings, Privacy. Withdrawal does not affect processing that was lawful before you withdrew it, and turning one category off does not change the other.
Where processing rests on our legitimate interests, you may object at any time under article 21 GDPR. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is needed for legal claims.
Who receives data
45weg uses the following providers, each receiving only what its role needs:
Google Ireland Limited and Google LLC, for Firebase Authentication, App Check, Cloud Firestore, Crashlytics, Google Analytics for Firebase and Hosting. Cloudflare, for delivery and protection of the routing API. OpenFreeMap, for map style and tiles. komoot GmbH, for Photon place search. PDOK, the geo-service of the Dutch government, for Dutch address search. Apple for app attestation, and Apple or Google when you choose their sign-in. The map provider that issued a link you share into the app, when that link is followed.
For services where Google or Cloudflare processes data on our behalf, it is bound by the data-processing terms required by article 28 GDPR: to act only on our instructions and for no purpose of its own, to protect what it receives to the same standard this policy sets out, to keep it confidential and to secure it. We give personal data to no third party that does not meet that standard. Apple and Google act independently for their own sign-in services.
OpenFreeMap, komoot for Photon search, PDOK, Apple or Google when you use their sign-in, and the provider behind a shared map link may determine their own purposes and retention for the request they receive. Their privacy notices apply to that independent processing.
We do not sell personal data, we do not share it with data brokers, and we do not use routes, searches or saved places for advertising. We disclose data to public authorities only where a legal obligation requires it.
International transfers
PDOK is operated in the Netherlands and komoot GmbH is established in Germany.
Google, Cloudflare and other recipients may process data outside the EEA, including in the United States. Where chapter V GDPR requires a transfer mechanism, we use an applicable European Commission adequacy decision, including the EU-US Data Privacy Framework for a certified recipient, or the European Commission's Standard Contractual Clauses with appropriate supplementary measures. Map and shared-link requests should be treated as potentially leaving the EEA.
You may ask us for a copy of the safeguards that apply to a given transfer.
How long we keep data
A registered account is kept until you delete it, and saved places are kept until you delete them or that account. Deleting either removes it from the service at once; Firebase Authentication then finishes removing the account from its live and backup systems within 180 days. A pseudonymous installation identity is kept while it is needed to authenticate use of the service and until it is erased following a valid rights request or the service is closed. Deleting the app does not itself send an erasure request to the service providers.
45weg does not retain route coordinates, shared links or search terms after answering the request. Service request logs contain no request body, query string or coordinates and are rotated when no longer needed to operate, secure or establish legal claims concerning the service. Independent map, search, identity and link providers apply their own retention periods.
Crash reports are retained by Firebase Crashlytics for 90 days. User-level Analytics data is retained for the period set on the Firebase property, which for a property of this kind is at most 14 months; ask us and we will tell you the period in force. Aggregated reporting may remain after user-level data is deleted. Support correspondence is kept while needed to answer you and afterwards only for as long as reasonably necessary to establish what was agreed or to handle a legal claim.
Your rights
Subject to the conditions and exceptions in the GDPR, you can ask for access, correction, erasure, restriction of processing and, where applicable, a portable copy of data you provided. You can object to processing based on legitimate interests and withdraw consent. These rights are set out in articles 15 to 22 GDPR.
Email hallo@45weg.nl. We may ask for information necessary to verify your identity or control of the relevant account. We respond without undue delay and normally within one month. We may extend by up to two months where permitted, and will explain the extension within the first month. Requests are free unless the GDPR permits a reasonable fee or refusal because a request is manifestly unfounded or excessive.
You may complain to a supervisory authority, including the Autoriteit Persoonsgegevens in the Netherlands or the authority where you habitually live, work or believe an infringement occurred. You also have the right to a judicial remedy.
Account deletion
You can remove individual saved places at any time. To delete a registered account and its saved places, open Settings, choose Account, tap Delete account and confirm. The app reports whether deletion succeeded. After deletion, the app creates a new pseudonymous installation identity so routing can continue without registration.
Deleting the app normally removes its preferences, recent destinations and Analytics app-instance identifier from that device, but does not by itself delete a registered account, saved places, Analytics data already received, or other provider records. The rights section explains how to request erasure of other personal data.
No automated decisions, no profiling
Nothing here decides anything about you automatically, and no profile of you is built. That is what article 22 GDPR is about, and it does not arise here.
Route calculation is automated, but it is a computation about roads and vehicle classes rather than an assessment of you. Which roads it opens or closes depends on the vehicle class you selected and on Dutch traffic law, never on anything personal.
Children
45weg is intended for people aged 16 or older, and an account may only be created by someone aged 16 or older. We do not knowingly accept consent for optional crash reporting from a child. If you believe a child has provided personal data, email hallo@45weg.nl and we will delete it.
Security
We use measures appropriate to the risk, including encrypted connections, authentication for protected requests, access controls and request logging that excludes coordinates, query strings and request bodies.
No online service can promise absolute security. If a breach is likely to result in a high risk to your rights and freedoms, we will inform you as article 34 GDPR requires.
Changes to this policy
We update this policy when the service or the law changes. The effective date at the top always shows the current version. Where a change materially affects how your data is used, we will bring it to your attention in the app or by email before it takes effect, and where the change needs your consent we will ask for it.
The other document