Controller
The controller responsible for data processing within the meaning of the DSGVO is Ebrahim Seyfi (Geschäftsbezeichnung „Senorit"), Seeschwalbentwiete 23, 22119 Hamburg, privacy@glenby.de. Full provider details can be found in the Legal notice.
End-to-end encryption
Content you share with friends (photos, notes about places) is encrypted on your device before it reaches our servers. Only the recipients you choose can decrypt it. We store exclusively the encrypted content and hold no key to it.
What stays visible: metadata
End-to-end encryption makes the content of your messages and photos unreadable to us, but not the fact that communication is happening at all. To deliver messages we necessarily process metadata: who sends to whom, timestamps, and delivery/read status. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (performance of the usage contract); the retention period follows the lifetime of your account, see the Retention period section. In addition to the DSGVO, the telecommunications secrecy under § 3 TDDDG protects both the content and the closer circumstances of your communication and binds us as a provider of an interpersonal telecommunications service.
What data we process
- Account
- Glenby can only be used with an account; there is no local-only mode. It covers your email address, display name, friend code and progress. We store the password exclusively as a hash, never in plain text; if you sign in with Google, an identifier for your Google account takes its place.
- Username
- The name you chose, when it was last changed, and whether you want to be findable by it. With that setting off, nobody can find you by name.
- Profile details
- Optional answers on pace, terrain, distance, experience and availability, plus an avatar motif, a short intro and answers to the profile prompts. They exist to suggest something you and a friend would both enjoy.
- Location
- When you complete a task, your approximate location is captured once as proof and stored with the completion. No background tracking, no movement profile.
- Home region
- A coarse region plus when it last changed, so the app can tell when you are travelling. A region, not a precise place.
- Safe-return check-in
- If you arm one, we store until it expires the time you chose, the contact you chose and your last position, that position only end-to-end encrypted for that one person and unreadable to us. The legal basis is your consent. The feature is not an emergency service.
- Emergency card and SOS
- Blood group, allergies, conditions and emergency contacts are health data under Art. 9 GDPR. They are stored encrypted on your device alone, never reach our servers and are in no backup. The legal basis is your explicit consent under Art. 9(2)(a) GDPR. An SOS sends the same encrypted location report as an expired check-in, only immediately; impact detection reads the motion sensors on the device only. Neither is an emergency service.
- Shared content
- Photos and notes about places, stored exclusively end-to-end encrypted. We hold no key to it.
- Video calls
- 1:1 video calls are transmitted directly between devices (WebRTC, encrypted) and are not recorded. Cloudflare acts solely as a TURN relay to broker the connection.
- Billing
- For a paid subscription, our payment provider Stripe processes the payment data. We ourselves store only the identifier needed for contract administration and the plan status.
- Friends and notifications
- Friend code, connections, and, if you enable reminders, a push token. If you arrive through an invite link, also who invited you and whether that referral has already been rewarded.
- Technical data
- Minimal data for operation and security, such as session and device identifiers and synchronization timestamps. Plus the period you chose after which an unused account is deleted automatically.
Location
When you complete a task, your location (GPS) is captured once as proof of authenticity and stored together with the completion. There is no background tracking and no movement profile. Your location is therefore not a special category of personal data within the meaning of Art. 9 DSGVO; the processing is based on Art. 6 Abs. 1 lit. b and lit. f DSGVO.
Services we use (processors)
Encrypted content and account data are processed by the following services:
| Service | Purpose | Location / transfer basis |
|---|---|---|
| Cloudflare Inc. (USA) | Database and application logic (D1, Workers): accounts, chat metadata, entitlements. Storage of end-to-end encrypted photos and voice notes (R2), chat delivery (Durable Objects), call connection brokering (TURN). Hosting of this website (glenby.de), delivered through the Cloudflare network, with access logs. Transactional email delivery through Cloudflare Email Service (email address, display name, message content), no marketing emails. | Database location hint: Western Europe, with no read replicas in other regions (no contractually guaranteed EU jurisdiction); requests are processed at the nearest Cloudflare data centre. Shared content reaches Cloudflare only as ciphertext. Transfer based on the EU-US Data Privacy Framework and the Cloudflare Customer DPA with Standard Contractual Clauses. |
| Cloudflare Web Analytics (Cloudflare, Inc., USA) | Anonymous measurement of load times and page views on glenby.de, only with your consent (cookie banner). Processes browser performance data, the visited and referring page, and the browser type. No cookies, nothing stored on your device. | According to Cloudflare, the IP address is discarded at the nearest data centre and not stored. Transfer based on the EU-US Data Privacy Framework and the Cloudflare Customer DPA with Standard Contractual Clauses. |
| Cloudflare Turnstile (Cloudflare, Inc., USA) | Protection of the forms on glenby.de against spam and automated attacks. Processes technical data such as IP address, browser and device information and interaction signals, no form contents. | Transfer based on the EU-US Data Privacy Framework and the Cloudflare Customer DPA with Standard Contractual Clauses. |
| Stripe Payments Europe Ltd. (Ireland) / Stripe Inc. (USA) | Payment processing for Glenby+ subscriptions: email address, name, payment data. | Transfer based on the EU-US Data Privacy Framework. |
| Google LLC (USA) | Google account sign-in (Google Sign-In: email address, name, profile picture), push notification delivery (Firebase Cloud Messaging, device token), map rendering (Google Maps SDK, direct device connection), app integrity checks (Play Integrity), crash reports (Firebase Crashlytics, only after opt-in in the app, off by default). Optional chat backup into the hidden app folder (appDataFolder) of the user’s own Google account: off by default, the “drive.appdata” permission only, contents end-to-end encrypted before upload. | Transfer based on the EU-US Data Privacy Framework. |
| Norwegian Meteorological Institute (MET Norway) | In-app weather forecast (api.met.no, Locationforecast) and, if you switch them on, official severe weather warnings in Norway (MetAlerts). | Device IP address and location coarsened to roughly 1 km are sent directly from the device. Data licensed under NLOD 2.0 and CC BY 4.0. |
| Deutscher Wetterdienst (Germany) | Official severe weather warnings for your location in Germany (maps.dwd.de), if you switch them on. | No third-country transfer. Device IP address and coarsened location are sent directly from the device. Data under the German GeoNutzV ordinance and CC BY 4.0, source: Deutscher Wetterdienst. |
| National Weather Service / NOAA (USA) | Official severe weather warnings for your location in the USA (api.weather.gov), if you switch them on. | Device IP address and coarsened location are sent directly from the device, and only while you are there. Data free to use for any purpose. |
| HeiGIT gGmbH (Germany) | Walking-route routing (openrouteservice). | Coarsened coordinates, relayed through our server; the device never contacts the service directly. |
| Overpass API instances (Germany/Austria, community-run) | Place and POI data. | Server-side queries without any user identifier. |
| Wikimedia Foundation (USA) | Place information and reference photos. | Server-side queries without any user identifier. |
| Hugging Face, Inc. (USA) | One-time download of the offline speech model for voice notes as text and for voice commands where the system has no offline recogniser. | No content or account data is transmitted. |
We have the necessary agreements under Art. 28 DSGVO in place with all processors named.
Data sources
Map data, routes and photos in the app come from open sources such as OpenStreetMap and Wikimedia Commons - the purpose and role of each service is listed above under "Services we use". Information about animals and plants at a place additionally comes from the GBIF database (Global Biodiversity Information Facility, gbif.org), a worldwide network of museums, institutions and citizen-science projects. We only use records published under CC0 or CC BY, crediting the publishing institutions as the source. This data is not linked to any person and contains no information about you.
Transfers to third countries
Some of the services we use are based, or process data, outside the EU/EEA. Our database runs with Cloudflare. Cloudflare, Stripe, and Google are based (also) in the USA and are certified under the EU-US Data Privacy Framework, which the EU Commission has recognized as providing an adequate level of protection (Art. 45 DSGVO). All transfers to third countries take place exclusively on one of the bases provided for in Art. 44 ff. DSGVO. The full, continuously updated list is above under "Services we use".
Content you share with others (photos, voice notes, notes) leaves your device only end-to-end encrypted. Even though the encrypted ciphertext sits on servers outside the EU, nobody except the recipients you chose can read the content, not us and not the respective hosting provider.
Screening for harmful content on the device
Before a photo is encrypted and shared, the app screens it directly on your device for clearly harmful content. This screening runs locally - no images are uploaded for it. More on this on the Security & Transparency page.
Voice commands and voice notes as text, on the device
Voice commands ("Sag es Glenby") and turning voice notes into text run entirely on your device. Speech recognition is done by your Android system's offline recogniser (Google, Android 12 and later) or, where that is missing, by a local speech model inside the app; understanding the command is done by a small model inside the app. Audio, recognised text and command never leave your device and are not stored by us. A command that touches safe-return, SOS or your location always waits for your confirmation. If the offline recogniser is missing or you request transcription, the app downloads a speech model (about 57 MB) once from Hugging Face, Inc. (USA), only after you agree; your IP address is transmitted, no content or account data (see "Services we use"). Legal basis: Art. 6(1)(b) GDPR.
Crash reports
- Purpose
- Error analysis and stability improvement of the app.
- Data
- App version, operating system version, device model and device state (free storage, for example), the crash report (stack trace), and a random Crashlytics installation ID. No link to your Glenby account. Google necessarily processes your device IP address on receipt; it does not become part of the report. Messages, photos and voice notes are never included.
- Legal basis
- Art. 6 Abs. 1 lit. a DSGVO (consent). The feature is disabled by default (opt-in); you enable it yourself in settings and can disable it again there at any time using the same toggle, with effect for the future.
- Recipients
- Google LLC (Firebase Crashlytics, USA).
- Storage
- A crash report is first created only on your device and is only transmitted the next time the app starts. On the server, crash reports are kept for a maximum of 90 days; we store a maximum of 5,000 reports in total, with older ones automatically overwritten.
Statutory reporting duty
If there is reasonable suspicion of a serious crime - in particular depictions of the sexual abuse of children - we are required under Art. 18 of Regulation (EU) 2022/2065 (Digital Services Act) to inform the competent law enforcement authority. The central reporting body in Germany is the Bundeskriminalamt as the central office under § 13 DDG in conjunction with § 2 BKAG. Only the content concerned is, in this case, excluded from end-to-end encryption and secured with a separate key that only the automated, official reporting channel can open. No one at Senorit sees this content in plain text.
Cancellation and withdrawal function
- Purpose
- Receiving and automatically carrying out statutory declarations under § 312k BGB (cancellation) and § 356a BGB (withdrawal).
- Data
- Name, email address, contract details, and the time of the declaration.
- Legal basis
- Art. 6 Abs. 1 lit. b and lit. c DSGVO.
- Recipients
- Payment processing (Stripe), database and email delivery (Cloudflare).
- Storage
- For evidentiary purposes, for the duration of the statutory retention periods.
Adventures and invitations
When you start an adventure, we store its content, checked steps and start, update and completion times in your account. Checking a step is your own report, not GPS verification. Your device can keep encrypted offline copies of the last six opened adventures with progress. Companion invitations connect an adventure with the inviting account and, if accepted, the accepting account. Their links are valid for 14 days; expired invitations are deleted by the daily cleanup. Share an invitation link only with your intended companion. Public previews show none of your account or location data. Optional discovery notes, selected details and photos stay on your device and are removed on sign-out or account change. They are not part of the server export or cloud backup. You can export notes through the share menu. A memory card can include a photo you select, its title, date and public adventure link; notes and precise coordinates are excluded. Photos can contain visible location landmarks. The adventure and invitation records stored in your account provide the requested feature (Art. 6(1)(b) GDPR), are included in your export and are deleted with your account.
Usage and payment overview
For internal totals on usage and payment, we count existing task, session and adventure records. Starting an adventure can also store the general source of its link, such as “first-discovery” or a campaign name, without an advertising identifier. We keep an updated summary of the first and latest payment confirmed by Stripe, payments during the last 28 complete days after refunds, and the trial period and contract status. Granted access does not automatically count as a purchase. The purpose is to understand use of the service and its economics; the legal basis is our legitimate interest under Art. 6(1)(f) GDPR. You can object to this analysis by contacting privacy@glenby.de. It adds no advertising cookies, movement profiles or access to private messages. Account summaries are exportable and removed on account deletion; legally required payment records at the payment provider are unaffected.
iOS waitlist
- Purpose
- If you sign up on the download page for the iOS launch, we send you a confirmation email and then exactly one message once the app is available for iPhone. Nothing else happens with your address: no newsletter, no advertising, no sharing.
- Data
- Email address, the time of sign-up and of confirmation, a random confirmation code, and the note that the sign-up came through the website. Your IP address is evaluated in memory only, for the abuse limit, and is not stored.
- Legal basis
- Art. 6(1)(a) GDPR (consent). The sign-up only takes effect once you click the link in the confirmation email (double opt-in). You can withdraw your consent at any time with effect for the future - an informal message to legal@glenby.de is enough and we delete the entry.
- Recipients
- Cloudflare (database, email delivery and website hosting). How each is classified, and the basis for the transfer, is set out above under "Services we use".
- Retention
- If you do not confirm the sign-up, the confirmation link stays valid and we delete the entry automatically at the latest twelve months after sign-up. We send no reminder in the meantime. Confirmed sign-ups are deleted after the launch message, or immediately on withdrawal.
Legal bases
- Art. 6 Abs. 1 lit. b DSGVO - provision of the app, its features, and the paid contracts.
- Art. 6 Abs. 1 lit. a DSGVO - consent for push notifications and for optional crash reports; revocable at any time.
- Art. 9 Abs. 2 lit. a DSGVO - express consent for the meet-people feature, to the extent it may involve special categories of personal data.
- Art. 6 Abs. 1 lit. f DSGVO - operation, security, and abuse prevention.
- Art. 6 Abs. 1 lit. c DSGVO - statutory reporting and cooperation duties.
Retention period
Content and account data are stored for as long as your account exists; upon deletion they are removed (see account and data deletion). If a statutory report under Art. 18 DSA has been triggered for a piece of content, that content remains excluded from deletion for the duration of the official proceedings; the legal basis for this is Art. 17 Abs. 3 lit. b DSGVO.
Your rights
You have the right to access (Art. 15 DSGVO, first copy free of charge), rectification, erasure (Art. 17 DSGVO), restriction of processing, data portability, and objection (Art. 15-21 DSGVO), as well as the right to withdraw any consent given at any time with effect for the future. The app offers an export and a deletion function directly in the settings; see account and data deletion. Requests at any time to privacy@glenby.de.
Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority, generally the authority of the German federal state (Bundesland) where you reside.
Technical error reports on this website
- Purpose
- Detecting and fixing technical errors on glenby.de, maintaining safe and stable operation.
- Data
- Automatically captured JavaScript error messages and violations of our Content Security Policy (CSP reports). No cookies, no user identifier; IP addresses are not stored.
- Legal basis
- Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in a secure and error-free operation of the website). Since no cookies are set and no recognition takes place, no consent under § 25 TDDDG is required for this.
- Recipients
- Internal operations system, database (Cloudflare).
- Storage
- For abuse-prevention reasons we accept a maximum of 500 reports within 24 hours. The retention period is 90 days, after which reports are automatically deleted.
Cloudflare Web Analytics
With your consent we use Cloudflare Web Analytics, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. It shows us how fast our pages load and which pages are viewed. For this, your browser loads a script from static.cloudflareinsights.com. It reads performance data through the browser's Performance API, such as load times, the visited and the referring page and the browser type, and sends it to Cloudflare.
No cookies are set and no data is stored on your device. Cloudflare builds no user profiles and does not track you across websites. Your IP address is transmitted for technical reasons. According to Cloudflare it is discarded at the nearest data centre and not stored.
The legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw your consent at any time with effect for the future through the cookie settings.
Cloudflare is certified under the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR). A data processing agreement with Standard Contractual Clauses is also in place. More information: https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile
To protect our forms against spam and automated attacks we use Cloudflare Turnstile, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you open a form, Turnstile checks in the background whether the request comes from a human. This processes technical data such as IP address, browser and device information and interaction signals. Turnstile does not read form contents and uses the data solely for this security check.
The legal basis is our legitimate interest in preventing abuse and spam under Art. 6(1)(f) GDPR. The access to information on your device this requires is strictly necessary for the secure operation of the form (§ 25(2) no. 2 TDDDG).
Cloudflare is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). A data processing agreement with Standard Contractual Clauses is also in place. More information: https://www.cloudflare.com/turnstile-privacy-policy/
Notice for users in the United States
Glenby is operated from Germany and follows the GDPR. We grant the rights described here to everyone, wherever they live. For California, additionally: we do not sell or share personal information within the meaning of the CCPA, and we receive nothing in return for it. You can review, export or delete your data yourself at any time in the app under “Your data” or through our deletion page; questions go to privacy@glenby.de.
Do Not Track: we collect no information about what you do on other websites or in other apps, neither ourselves nor through any third party via Glenby. Because we do not carry out that collection at all, there is nothing a browser “Do Not Track” signal could change.