Privacy policy
Last updated: October 8, 2026
What data Corally keeps, why and for how long. No advertising or selling data. We measure usage with first-party metrics, without third-party analytics services.
Controller
Miguel Ángel Llorente Carmona, tax ID [pending: tax ID (NIF)], [pending: address]. For any privacy matter: [pending: contact email].
What data we process and why
- Account: name, email, password (stored as a hash, never in plain text), language, preferences, the date you accepted the use notice and, if you sign in with Google or Apple, that account's ID, your email and your name (with Apple, only if you share it). To provide the service (legal basis: the contract you accept when you sign up).
- Routes and checks: start, finish and waypoints, the GPX files you upload, the routes computed and the ones you save. To compute, display and export them (basis: the contract).
- Mobile app and notifications: if you install the app and allow notifications, each phone's push notification identifier, its system (Android or iOS) and the app version; and the routes you send yourself from the website to “Received”. To notify you on your phone when a route arrives and show it in the app (basis: the contract).
- App navigator: your GPS position is processed on the phone to guide you and never leaves it, except when you ask to recalculate the route: then we send your position and the point of the route you are at to compute the new route, which is stored as another route of your account. Voice directions are read by the phone itself. To guide you (basis: the contract).
- Navigator with the screen off (if you enable it): GPS keeps running in the background while guiding, with the “always” location permission and, on Android, a fixed system notification. The position is still processed on the phone and is only sent when recalculating. It stops when you leave the navigator.
- Offline maps and routes (app): the regions and routes you download are kept only on your phone, and you delete them from «Offline maps». For a route's map we build on our server a file with the map around the route, without your account data and with a name that can't be guessed; it's deleted if nobody asks for it in 30 days.
- Recorded rides (if you record): the GPS points with their time and altitude, on the phone and, when uploaded, in your account (“Recorded”), private and only for you; used to view, export and analyse them. Deleted when you delete them or with the account (basis: the contract).
- Track ratings («Check tracks», only for administrator and field tester accounts): the track, the difficulty you observe, whether you rode it or saw it from outside, your tags and note, the photo if you take one (shrunk and stripped of its metadata, including the location stored by the camera), your position, accuracy, heading and speed when you rate it, the time, your rider profile and, if you were recording, the ride. To validate and improve the difficulty calculation (basis: your voluntary participation as a tester). They are kept on the phone until there is a connection; they are private: only you and the administrators see them.
- App crash reports: when the app fails, the phone's model and system, the app version and the technical error, without your name, email, position or routes (they are cleaned on the phone before being sent). To find and fix bugs (basis: legitimate interest).
- Waiting list: your email and, if you give them, your name, your bike and where you usually ride, and your language. To tell you when there is an invitation (basis: your consent, which you can withdraw at any time).
- Reports from the trail (when available): position, time, track, your note and any photo you send. To correct the difficulty and warnings for those tracks (basis: your consent when you send it). Your position is not published linked to you.
- Technical data: IP address, an anonymous identifier in a cookie to count the allowance without an account (daily and last 7 days), and error logs. To keep the service working and secure and to prevent abuse (basis: legitimate interest).
- Usage metrics: pages and actions in Corally, visit origin (referring domain and campaign or link tags), approximate country, region and city, language, mobile or desktop device, browser and operating-system family, and whether the visit looks like a bot (from the browser or because it comes from a data-centre network). To understand what works and improve the app (basis: legitimate interest). Metrics do not store your IP, precise coordinates, emails or free text you enter. Location and network name come from local GeoIP databases; we do not send your IP to a geolocation service.
What data we process and why
- Account: name, email, password (stored as a hash, never in plain text), language, preferences, the date you accepted the use notice and, if you sign in with Google or Apple, that account's ID, your email and your name (with Apple, only if you share it). To provide the service (legal basis: the contract you accept when you sign up).
- Routes and checks: start, finish and waypoints, the GPX files you upload, the routes computed and the ones you save. To compute, display and export them (basis: the contract).
- Mobile app and notifications: if you install the app and allow notifications, each phone's push notification identifier, its system (Android or iOS) and the app version; and the routes you send yourself from the website to “Received”. To notify you on your phone when a route arrives and show it in the app (basis: the contract).
- App navigator: your GPS position is processed on the phone to guide you and never leaves it, except when you ask to recalculate the route: then we send your position and the point of the route you are at to compute the new route, which is stored as another route of your account. Voice directions are read by the phone itself. To guide you (basis: the contract).
- Navigator with the screen off (if you enable it): GPS keeps running in the background while guiding, with the “always” location permission and, on Android, a fixed system notification. The position is still processed on the phone and is only sent when recalculating. It stops when you leave the navigator.
- Offline maps and routes (app): the regions and routes you download are kept only on your phone, and you delete them from «Offline maps». For a route's map we build on our server a file with the map around the route, without your account data and with a name that can't be guessed; it's deleted if nobody asks for it in 30 days.
- Recorded rides (if you record): the GPS points with their time and altitude, on the phone and, when uploaded, in your account (“Recorded”), private and only for you; used to view, export and analyse them. Deleted when you delete them or with the account (basis: the contract).
- App crash reports: when the app fails, the phone's model and system, the app version and the technical error, without your name, email, position or routes (they are cleaned on the phone before being sent). To find and fix bugs (basis: legitimate interest).
- Waiting list: your email and, if you give them, your name, your bike and where you usually ride, and your language. To tell you when there is an invitation (basis: your consent, which you can withdraw at any time).
- Reports from the trail (when available): position, time, track, your note and any photo you send. To correct the difficulty and warnings for those tracks (basis: your consent when you send it). Your position is not published linked to you.
- Technical data: IP address, an anonymous identifier in a cookie to count the allowance without an account (daily and last 7 days), and error logs. To keep the service working and secure and to prevent abuse (basis: legitimate interest).
- Usage metrics: pages and actions in Corally, visit origin (referring domain and campaign or link tags), approximate country, region and city, language, mobile or desktop device, browser and operating-system family, and whether the visit looks like a bot (from the browser or because it comes from a data-centre network). To understand what works and improve the app (basis: legitimate interest). Metrics do not store your IP, precise coordinates, emails or free text you enter. Location and network name come from local GeoIP databases; we do not send your IP to a geolocation service.
How long
- Unsaved routes are deleted after 90 days; unsaved checks after 30.
- What you save in “My routes” and your account data: while you have an account.
- Track ratings and their photos: while you have an account or until you delete them.
- Phones with notifications: linked to an active session. They stop receiving new notifications when that session is signed out, expires or is revoked, or when you delete your account. Confirming sign-out requires a connection. Notifications already sent may arrive later. Routes in “Received”: until you remove them or delete your account (they don't expire while they're there).
- Waiting list: until you get access or ask to leave.
- App crash reports: 30 days at most.
- Error logs: 30 days. Backups: a few weeks, on rotation.
- Usage metrics, including account-linked activity: the configured retention period (contact the controller). Periodic maintenance deletes expired data. Backups retain data until rotation and never contain the daily salt.
How we measure visits
Without an account, we use a hash of the IP and user agent with a random daily salt. It recognizes visits and unique visitors for that day; the salt is deleted at the UTC day boundary and excluded from backups. We do not follow anonymous visitors across days. A new visit starts after inactivity (30 minutes by default).
With an account, pages and actions are associated with your user to understand usage and return visits over time. Signing in or creating an account may associate the current anonymous visit with it. Only administrators can view this history.
We do not store cookies, localStorage or sessionStorage for measurement. The anonymous quota cookie is not used for metrics. Data stays in our database, without external analytics scripts or pixels.
How long
- Unsaved routes are deleted after 90 days; unsaved checks after 30.
- What you save in “My routes” and your account data: while you have an account.
- Phones with notifications: linked to an active session. They stop receiving new notifications when that session is signed out, expires or is revoked, or when you delete your account. Confirming sign-out requires a connection. Notifications already sent may arrive later. Routes in “Received”: until you remove them or delete your account (they don't expire while they're there).
- Waiting list: until you get access or ask to leave.
- App crash reports: 30 days at most.
- Error logs: 30 days. Backups: a few weeks, on rotation.
- Usage metrics, including account-linked activity: the configured retention period (contact the controller). Periodic maintenance deletes expired data. Backups retain data until rotation and never contain the daily salt.
Who we share it with
We do not sell or hand over your data. Corally runs on its own server in Spain and backups go to another machine of our own. Some third parties are involved as follows:
- Google, only if you choose “Sign in with Google”: you identify yourself on its page or in Google's window on your phone and it returns your email and name.
- Apple, only if you choose “Sign in with Apple”: you identify yourself with your Apple account and it returns your ID and email (see “Sign in with Apple” below).
- Map providers (OpenFreeMap, Spain's National Geographic Institute and Mapterhorn): your browser or the app requests map images from them directly, so they see your IP like any website you visit. We do not give them your routes.
- OsmAnd and DMD2: when you send a route, the app downloads the GPX through a signed link that expires in one hour.
- Google Play and the App Store: if you install the app from them, Google or Apple process your store account and the download as controllers, under their own policies. They only give us aggregated install and crash statistics, with no data that identifies you. If you join an app test, we give your email to Google or Apple to invite you.
- Expo (650 Industries, Inc.), only if you use the app with notifications: it delivers notifications to your phone through Google (Android) and Apple (iOS). It receives the notification identifier and the notification text (the route's name and distance), which it doesn't keep beyond delivering it; it logs the IP address and basic request data for about 30 days.
- Sentry (Functional Software, Inc.), only in the app: it receives the crash reports described above, without personal data or positions, to help us fix them.
Transfers outside the EU
If you use “Sign in with Google” or “Sign in with Apple”, Google or Apple may process data in the United States under the EU-US Data Privacy Framework; the same applies to Google Play and the App Store when you install the app. Some map providers may serve images from outside the EU. App notifications go through Expo (United States) and Google's and Apple's notification services. App crash reports are processed by Sentry, which may do so in the United States under the EU-US Data Privacy Framework.
Your rights
You can ask to access, correct, delete or take your data, object to or restrict its use, and withdraw your consent by writing to [pending: contact email]. If you think we have not handled it properly, you can complain to the Spanish Data Protection Agency (aepd.es).
In “My account”, downloading your data includes your retained activity and deleting the account removes its linked metrics. You can object to processing based on legitimate interest by writing to [pending: contact email]. Without an account, we cannot locate your visits once the daily salt is gone.
Age
You must be at least 14 to create an account.
Security
Encrypted connection (https), passwords stored as hashes, sessions in a protected cookie on the website and, in the app, with a token kept in the phone's secure storage, and restricted server access.
Cookies
We only use technical cookies. Details are in the cookie policy.
Changes
If we change this policy in a significant way, we will announce it on the website.
Sign in with Apple
If you choose Apple, we receive your account identifier and verified email, which may be a hidden relay address. We receive your name only if you share it. We encrypt and store the token needed to revoke access when you delete your account; it is not shared with other users. Apple processes authentication data under its privacy policy.
Optional photos
When you tap “View photo”, your browser contacts Wikimedia Commons and, where needed, Wikidata. These services receive your IP address and the place or photo reference; we do not send your route or account details. Photos do not load until you request them.