1. Scope and controller
This policy covers the AnkerTrace Android app and its Legal & Help website. The controller for processing described as ours is Paul Wolfmajer, Forstsiedlung 20, 8074 Raaba-Grambach, Austria. Contact for support and privacy requests: support@wolfmajer.com. “Wolpa” is the developer name used in the app.
AnkerTrace has no user account or cloud logbook. Recorded GPS tracks stay on your device unless you export them. This does not mean that the app makes no external requests: online map tiles reveal the viewed geographic area, and advertising services process advertising and connection data. The sections below distinguish these activities.
2. Location and anchor monitoring
After you grant precise-location permission, the app processes latitude, longitude, position time, accuracy, speed and heading on the device. It compares the phone’s position with your chosen anchor and radius, displays the track, and detects possible drift or unreliable GPS. An explicitly started Android watch continues in the background and with the screen locked, with an ongoing service notification. Battery level and alarm-volume state are used to display readiness and battery warnings. Notification permission enables service and alarm information; audio and vibration provide alerts.
AnkerTrace does not upload recorded tracks to us or include GPS coordinates in Google ad requests. Online map requests can nevertheless reveal the area around the phone or anchor (section 4). Your operating system’s location services are separate and subject to its settings and provider policies. The app does not request contacts, microphone or photo-library access for anchor monitoring.
Processing provides the local features you request, Article 6(1)(b) GDPR. Operating-system permission is a device-access control, not blanket consent to advertising. Precise location is not legally required, but a real watch cannot start without a fresh, sufficiently accurate fix. Simulation remains available in Settings → GPS Simulator. You may stop a watch and revoke location permission in Android settings. Removing permission during a watch prevents reliable monitoring.
2a. Version checks, required updates and emergency restrictions
On launch, on return to the app and approximately every five minutes while the UI process is running, AnkerTrace requests a small version-policy file from its Legal & Help hosting infrastructure. Requests contain ordinary connection metadata (IP address, requested URL, time and client/connection information), not GPS positions, tracks, advertising identifiers or a user account. This provides compatibility and safety notices and can prohibit starting new watches with an unsupported or temporarily disabled app. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in safe, compatible app operation; necessary contractual update obligations can additionally engage Article 6(1)(b) or (c).
Only a valid response for this app replaces the last policy stored on the device. A received minimum version or emergency restriction persists without internet and has no time-based expiry. A compatible installed build satisfies the stored minimum; an emergency restriction requires receipt of a valid new policy withdrawing it. A device that has never received a restriction remains usable offline; a server cannot deliver a new restriction to a disconnected device. Network errors and malformed responses do not remove a received restriction.
A restriction prevents new watches and the app's advertising flow. A watch already running is not stopped remotely: its alarm acknowledgement and explicit stop controls stay available. Maintain independent supervision and end the watch when safe. Legal information, support, local logbook export and deletion remain available. The policy does not transmit or delete your logbook and does not change prior legal acknowledgement or advertising consent. The stored policy remains until replaced by a valid policy or app storage is removed. Hosting recipients, retention and transfer information are described in sections 6 and 8.
3. Local records, exports and deletion
The app stores radius and day/night preferences, a versioned acknowledgement of the first-run legal information, recovery information for an interrupted watch, and up to 100 completed watches. A watch contains anchor coordinates, start/end time, radius, maximum distance, a simulation label, up to 3,600 recent track points and 1,000 events. Older records or points are discarded as these limits are reached. Saved sessions otherwise remain until you delete them or clear app data. The interrupted-watch record is replaced or removed through normal watch operation or logbook deletion; monitoring is not silently restarted after a process/device restart.
Settings → Delete local logbook removes stored sessions, recovery data and the temporary exported file. First end any active watch. Preferences and the legal-information acknowledgement remain. Android → App info → Storage → Clear storage removes local app data, including preferences and consent records; uninstalling also removes the app’s private storage. Android backups are disabled for AnkerTrace. Files you have shared to other apps or recipients must be deleted there separately.
Only after you choose Share logbook as JSON does AnkerTrace write a temporary JSON file and open the system share sheet. You decide whether and where to send it. It can contain precise location history. It is replaced on the next export and removed by logbook deletion or clearing app cache/data. We do not receive an export unless you send it to us. A receiving app or recipient processes it under its own terms.
Local records and requested export support your requested features, Article 6(1)(b) GDPR. Preferences support those features; the legal-information record also serves our legitimate interest in recording which information was presented, Article 6(1)(f). Local app storage is not a guarantee against access by someone who can unlock or compromise your device.
4. Online maps and map cache
In Settings > Map style, you can select Street (OpenStreetMap, default) or Satellite (Esri World Imagery). Satellite tiles are requested directly from https://services.arcgisonline.com. Esri and its delivery infrastructure receive your IP address, tile coordinates/zoom, app User-Agent and request timing for the viewed area. Provider privacy information: https://www.esri.com/en-us/privacy/overview. The map request and local cache behaviour described below also applies to satellite imagery. Map is the default position view. When a position is available and the initial legal notice has been acknowledged, it loads tiles for the displayed area directly from https://tile.openstreetmap.org. OpenStreetMap Foundation (OSMF) and its content-delivery infrastructure receive your IP address, requested tile coordinates/zoom, app-identifying User-Agent and request timing. Tile coordinates identify a geographic area and can reveal where you or your anchor are located. Panning and zooming request other areas. Your logbook is not uploaded as a file.
These requests provide the map view, Article 6(1)(b) GDPR. OSMF also processes service requests for its own operational/security purposes under its policy. Recipient information, retention criteria, delivery infrastructure and international processing are described at https://osmfoundation.org/wiki/Privacy_Policy and https://osmfoundation.org/wiki/Services_and_tile_users_privacy_FAQ. Map data is © OpenStreetMap contributors: https://www.openstreetmap.org/copyright.
Downloaded tiles are cached locally using server caching headers. The cache is configured for approximately 500 files and cleanup of files unused for seven days; this is a cache policy, not a promise of deletion at an exact time. Clear Android app cache to remove cached tiles. There is no bulk offline-region download. Monitoring and alarms do not require map downloads. If map tiles fail to load, position, anchor circle and track remain visible without a complete map background. The map is not a nautical chart.
5. Google advertising and consent
Ad-enabled builds use Google Mobile Ads (AdMob) and Google’s User Messaging Platform (UMP). Relevant Google entities include Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, as identified in Google’s applicable service/privacy information. Google and ad partners can act as controllers for their own processing; their roles and purposes are described in the consent interface and linked terms.
The ads SDK collects/shares IP address, device/account identifiers (including advertising ID and app-set ID where available), ad views/clicks and other product interactions, and diagnostic/performance information for ad delivery, measurement/analytics and fraud prevention. IP addresses may be used to infer approximate location. AnkerTrace does not send its GPS records in ad requests. No separate analytics SDK has been added by us; this does not exclude the advertising SDK’s analytics.
Banners support the app. Rewarded videos appear only after you choose Watch video, are optional and grant 30 minutes without banners on this device after completion is confirmed. They do not unlock watch features. A local expiry timestamp stores this reward, survives restarts and is replaced on the next completed reward; clearing app data removes it. Ad presentation is suspended during an active watch. The first-run legal acknowledgement is separate from advertising consent. UMP obtains regional consent information and displays Google’s configured form where required. The app requests ads only when UMP reports that requests are permitted. Refusal does not disable monitoring, logging, simulation or export. Depending on applicable law and Google’s settings, eligible ads may be personalised, non-personalised or limited; non-personalised does not mean no personal data is processed.
Consent is the basis for advertising personalisation and other advertising processing/device access requiring consent, Article 6(1)(a) GDPR and applicable device-access law, including § 165(3) Austrian TKG 2021. Transmission or storage strictly necessary to provide an explicitly requested service may fall within the statutory exception. Permitted security/fraud-prevention processing can rely on legitimate interests under Article 6(1)(f), subject to applicable law and the recipient’s disclosures. A technical canRequestAds result does not replace applicable consent requirements.
Reopen choices through Settings → Advertising privacy options or Info → Manage advertising consent where Google makes a form available. End an active watch before opening a consent form. Withdrawing consent affects future processing, not the lawfulness of earlier processing. Android advertising-ID controls offer additional choices. UMP stores consent choices locally. Google/ad-partner retention varies by data type, purpose, consent and account settings; consult their policies and use their privacy controls or contact them for their retained data. Clearing AnkerTrace data does not itself delete data already held by these recipients.
Google privacy and advertising information: https://policies.google.com/privacy and https://policies.google.com/technologies/ads. Google partner/controller information: https://business.safety.google/privacy/. Ad partners and available purpose-specific choices are identified in the consent form. Development builds use Google test ads; those SDK/consent requests can still involve network data. Builds configured without ads do not initiate the app’s advertising flow.
6. Website, cookies and external links
The Legal & Help website and version-policy file are delivered directly through Cloudflare Pages infrastructure. Requests reveal IP address, requested URL, time, browser/client information and technical connection/error data to the hosting infrastructure. This provides pages, TLS delivery, reliability and abuse prevention, our legitimate interests under Article 6(1)(f) GDPR. Hosting retention is governed by operational/security needs and the provider’s applicable service policies; it is not determined by the app’s logbook limits.
We add no advertising, analytics trackers, marketing cookies, remote fonts or embedded maps to these legal pages. This is not a claim that the hosting infrastructure stores nothing. The public pages require no login. Hosting/provider information: https://www.cloudflare.com/privacypolicy/.
App legal links open your browser. Following an external link sends ordinary request metadata to that destination, whose privacy terms apply. The feedback button opens your email app with a draft; it does not automatically send a message. No GPS export is attached automatically.
7. Support correspondence
If you email us, we receive the contact details, message and attachments you choose to provide through the email services involved. Incoming mail for wolfmajer.com is routed through IONOS mail servers. Provider privacy information: https://www.ionos.de/datenschutzerklaerung/en. We use them to respond, investigate issues and handle rights requests, Article 6(1)(b), Article 6(1)(c) for legal obligations and/or Article 6(1)(f) for service support and defence of legal claims as applicable. Please send only data needed for the request and avoid precise tracks unless relevant.
We retain correspondence while needed to resolve the request and follow-up, and longer only where legal retention obligations or the establishment/exercise/defence of claims require it. Access should be limited to those who need it for those purposes. You can request deletion; an applicable obligation or legal claim can limit immediate deletion. Our email infrastructure and any service provider supporting that correspondence are recipients within that purpose.
8. International transfers and safeguards
Google, OSMF’s delivery infrastructure, Cloudflare and correspondence providers may process data outside the EEA. The safeguards depend on the service, recipient and destination: an applicable adequacy decision under Article 45 GDPR, or Article 46 safeguards such as Standard Contractual Clauses and supplementary measures where required. The EU–US Data Privacy Framework applies only where the recipient and processing are actually covered; we do not assert that every recipient is covered. See the service policies above or contact us for information and, where applicable, a copy of safeguards relating to processing for which we are responsible.
9. Your rights and complaints
Where the legal conditions apply, you have rights of access, rectification, erasure, restriction and portability under Articles 15–20 GDPR. You may object to processing based on legitimate interests under Article 21 for reasons relating to your situation, and to direct marketing at any time. You may withdraw consent at any time for the future. There is no fee for an ordinary rights request. We may request proportionate information to verify identity where needed.
Send requests to support@wolfmajer.com. We respond without undue delay and normally within one month. Where GDPR permits an extension for complexity or volume, we inform you within that month of the reason and the extended period. We cannot retrieve device-only records remotely; use the local export and deletion functions for those records. This does not limit your rights concerning data we or relevant recipients actually hold.
You may complain to a supervisory authority, including in your habitual residence, workplace or place of an alleged infringement. In Austria: Österreichische Datenschutzbehörde, https://www.dsb.gv.at/.
10. Children, automated decisions and changes
AnkerTrace is designed for people responsible for anchoring a vessel and is not directed at children. We do not knowingly solicit children’s contact information or location exports. Contact us if you believe a child has sent personal data to us. No age-verification claim is made by this policy.
We do not use GPS records for profiling or automated decisions producing legal or similarly significant effects under Article 22 GDPR. Drift calculations are local safety-assistance alerts. Advertising recipients may use profiling as described in their consent/privacy information; this is separate from the local drift calculation.
Material changes are published under a new legal version and presented in the app. Earlier acknowledgement records remain separate; an app update itself does not constitute agreement or advertising consent. Installed builds link to their pinned version; the undated website routes show the current notice. Changes to this notice do not retrospectively create consent or waive your rights.