Privacy in the field

Privacy policy.

This policy explains how Backcountry Tracker handles information when you record, upload, share, view, and delete a track.

Effective August 14, 2026

Who operates the service

This policy covers the Backcountry Tracker Android app, its server, and its private web track viewer.

Questions can be sent to support@backcountrytracker.com.

Information the service handles

Track information

When you track a route, the app handles precise latitude and longitude points and their capture times. A point may also include altitude and horizontal accuracy when your device supplies them. You may give a track a name.

Information on your Android device

Tracks, location points, upload state, and related app settings are stored in an on-device Room database. Location points are saved locally before upload is attempted so tracking can continue through a network outage. The app's local database is excluded from Android cloud backup and device-to-device transfer.

Server and network information

Uploaded track information is stored by Backcountry Tracker on Cloudflare infrastructure. Cloudflare may process information ordinarily associated with serving internet requests, such as IP address, network and protocol details, request time, and request metadata. Backcountry Tracker does not add advertising or analytics services.

When information is sent and how it is used

The app contacts Backcountry Tracker when you create or start a track or request another server-backed track action. Location points are collected and queued only after you choose to start tracking. Uploads use encrypted HTTPS. Capture and upload happen independently, so points may remain queued on the device and be sent later when a connection is available.

While a track is active, location capture may continue when the app is minimized, closed from view, or the screen is off. Android displays a persistent foreground notification while this tracking service is active.

The service uses track information to accept and retain your reports, retry uploads safely, display the track to holders of its private viewer link, calculate viewer-side route summaries, and export the track when requested.

No accounts or public directory. Backcountry Tracker does not provide user accounts, a public profile, a public track directory, ads, or analytics.

Private links and service providers

Capability-based viewer links

Each track has a private viewer link that acts as a capability: anyone holding the link can access that track without an account or an additional password. The server stores cryptographic hashes of capability tokens rather than the plaintext capability tokens. This reduces the usefulness of a database copy by itself, but it does not make a shared or exposed link harmless.

Share a viewer link only with people you trust. A recipient can forward it, store it, or open it through systems outside Backcountry Tracker's control.

Cloudflare

Cloudflare provides the Worker, database, and network infrastructure used to operate the service. It may process the uploaded data and the IP, network, and request metadata needed to deliver and protect requests.

Map tile providers

The Android app and private web viewer can request map tiles from OpenStreetMap, Esri World Imagery, and OpenTopoMap. When a map is opened, moved, or downloaded for offline use, the selected provider can receive the device or viewer's IP address, browser or app-related request metadata, the Backcountry Tracker origin where applicable, and requested tile coordinates. Those tile coordinates can reveal the geographic area being viewed or downloaded. These providers handle that information under their own terms and privacy practices.

Raw recorded track points, write tokens, and private viewer tokens are not intentionally included in map tile requests. However, requested tile coordinates identify the map area and may approximate the device or route location.

Retention and deletion

Tracks and their location points remain on the server until you delete them through the app. In-app deletion removes the server track and its points and removes the track's local data.

After server deletion, Backcountry Tracker retains a minimal, non-location deletion replay marker containing the track ID, a hash of its write token, and the deletion time. This marker allows a repeated authenticated deletion request to succeed safely if the original response was lost. It does not contain the track's points, name, or plaintext token.

Information may remain temporarily in infrastructure backups or operational systems according to a provider's normal lifecycle, and copies shared or exported by other people are outside Backcountry Tracker's control.

Your choices

  • You decide whether to grant Android precise-location permission and whether to start tracking. Without precise location, the core recording feature cannot work.
  • You can stop tracking to stop new location capture. Already queued points may continue to upload so the recorded track can finish synchronizing.
  • You choose a track name, capture and upload intervals, and whether and with whom to share a private viewer link.
  • You can delete a track in the app to remove its server track and points and its local data, subject to the minimal deletion replay marker described above.
  • You can use Android settings to revoke location permission or clear all app storage. Clearing local storage alone does not delete a track already uploaded to the server; use in-app track deletion first if you want the server copy removed.

Security and practical limitations

Backcountry Tracker uses HTTPS for data in transit and separates track-writing and track-viewing capabilities. Capability tokens are designed to be difficult to guess, and stored server values are hashed. These measures reduce risk but cannot guarantee absolute security.

Treat a viewer link like a key. Anyone who obtains it can view the associated precise location history. Link access does not currently expire automatically, and the service does not provide end-to-end encryption that prevents the server infrastructure from processing track data.

Device compromise, malware, screenshots, exported files, link forwarding, browser history or synchronization, insecure recipient devices, and provider or network failures can expose information. Delayed or failed connectivity can also make the web viewer incomplete or out of date. Backcountry Tracker is not an emergency, rescue, or guaranteed live-location service.

Policy changes and contact

This policy may be updated as the service changes. The effective date at the top identifies the current version. Material changes will be reflected on this page.

For privacy questions or requests, contact support@backcountrytracker.com. Because the service has no user accounts, include only enough information to explain your question; do not email a private viewer link or precise location data unless it is necessary.