Munro Planner

Privacy policy

This policy is written the same way Munro Planner is built — plainly. The short version: no ads, no selling of data and no third-party analytics. Your location normally stays on your device unless you deliberately turn on live sharing or connect a service such as Strava.

Last updated 27 August 2026

Who we are

Munro Planner is developed and operated by Simon Grogan, who is the data controller responsible for the personal data described in this policy. For anything in this policy, contact Simon via the contact page.

The short version

What the app collects, and why

Using the app without an account

The app fetches forecasts, route scores, map tiles and similar data from our server. Like almost every internet service, those requests include standard technical information (your IP address and device type) in short-lived server logs used for security and to keep the service running. We don't use this to identify or profile you.

Approximate and precise location data

Munro Planner accesses approximate location, and precise GPS location when you grant that permission, to provide its mapping, navigation, recording and safety features. While you are using the app, it uses location to show your position on the map, find nearby routes, guide you along a route, calculate progress and distance, warn when you move off route, record a walk, and optionally log a Munro when you reach its summit. If you grant only approximate location, features that need an accurate position may be less reliable or unavailable.

Location in the background. If you deliberately start phone walk recording, live location sharing, or phone takeover of an active watch recording, Munro Planner can continue to access precise location in the background, including while the phone or watch screen is off, the screen is locked, or the app is closed or not in use. Background access is needed to keep the active track or live position up to date. It is used only for those active features and stops when you end the walk, stop recording or turn live sharing off. Android and iOS require you to grant the relevant location permission, and you can withdraw it at any time in your device settings. The app does not access background location for advertising, marketing or general analytics.

Current map and navigation positions are primarily processed on your device. GPS points from a recorded walk are stored on your device so you can view the route and walk statistics; you can delete a recorded walk in the app. They are not included in account logbook sync. If you deliberately use “Sync with phone” in the signed-in website route planner, that planned GPX route is held in your account's delivery inbox for up to 30 days so each signed-in phone can receive it. Location is not sold or shared with advertisers.

When location or route coordinates leave your device. Precise fixes are transmitted to Munro Planner's server while live sharing is active. To suggest a useful name for a recorded walk, the app can send up to seven representative points from that track to our place-name service; they are used to return nearby feature names and are not added to your account. Online map, elevation, terrain and route-weather requests send the viewed area or relevant route coordinates to Munro Planner's service or the mapping/data provider needed to return that content. Those requests are not labelled with your Munro Planner account or an advertising identifier, although the receiving service also sees standard request information such as IP address. When you choose to upload a walk to Strava, its GPX track and the details shown in the confirmation screen pass through our server to Strava. When you export or share a GPX, it is sent only to the app or person you choose. A paired phone and watch also exchange location and recorded-track points to provide navigation, recovery and a single saved walk.

Location access is optional. You can decline the permission and continue using features that do not need your position. You can stop an active recording or live-sharing session in the app, and you can change or remove location permission at any time in your device settings.

Live location sharing

If you deliberately enable live sharing, the app transmits precise location fixes to Munro Planner's server, including in the background while the sharing session is active, so that people with your link can see your latest known position. You choose whether the link shows only that position or also the breadcrumb track recorded during the active sharing session. You can separately choose to share available device status, such as battery level, projected battery time, charging state, connection type and the mobile network selected in Settings.

A permanent link is memorable and may be guessed or forwarded, so it should be treated as public while sharing is active. The private credential used by the app to update your position is separate and is not placed in the public link. By default, the last position, breadcrumb and selected device status remain visible for up to 24 hours after a walk ends. You can turn this off before sharing, and starting another shared walk removes the previous one sooner. Live sharing depends on GPS, battery and data coverage and is not an emergency or rescue service.

Live sharing also has an on-by-default performance option that helps improve battery life and reliability. If left on, we keep a separate account-free summary containing the device family, whether a phone or watch supplied and uploaded the last fix, session duration, number of shared points, and available start/end battery readings. It contains no account identifier, email, link token, route, coordinate, network provider or exact walk time. You can turn this off in More sharing settings. We use these summaries only to compare reliability and battery performance across app and device types.

Wear OS health and fitness data

On a Wear OS watch, with your permission, Munro Planner uses Android Health Services and the watch's sensors to read heart rate, daily step count, daily calories burned and daily floors climbed. Passive readings can be received in the background, including when no walk is being recorded, so the watch's statistics pages stay current. During a walk you start, current readings are added to recorded GPS points and used for live watch statistics and the saved walk summary, including steps and average and maximum heart rate. An optional Continuous heart rate setting reads the heart-rate sensor more frequently during an active recording.

Wear OS asks separately for foreground health permissions and, on supported versions, permission to read health data in the background. You can decline or revoke these permissions in the watch's app or health-permission settings. Without them, the related statistics are unavailable, but mapping, route guidance and other features continue to work.

Health and fitness readings are stored locally on the watch and mirrored to your paired phone while a walk is being recorded so the app can preserve the track and show its summary. Munro Planner's live-location service does not receive heart rate, steps, calories or floors; it receives only the location-derived walk progress and optional device status described above. Health and fitness data is not used for advertising, profiling or sale. It is shared with another service only when you deliberately export or share a recorded GPX file, or choose to upload that recording to Strava; exported GPX data may include heart-rate, step, calorie and floor readings.

Recorded health and fitness readings remain part of the locally stored walk until you delete that walk in the app. They are not included in account logbook sync and are not retained on Munro Planner's server.

Drive times

If you use drive times, the departure point you type in (a postcode, town or city) is sent to our server to calculate journey times to route start points. Results are cached by place, not by person, and your departure point is not linked to your identity or account.

Accounts and logbook sync

Creating an account is optional, and exists so your logbook can sync across devices. If you create one, we store:

Your derived walking profile is included only while you are using a signed-in account. You can delete your account at any time from inside the app (More → Account). Deletion is immediate and permanent — it removes your account, sessions, derived walking profile and synced logbook from our server. You can also follow the account deletion instructions if you cannot access the app.

Subscriptions and gifts

Subscriptions are purchased through the Apple App Store or Google Play. Apple or Google handle the payment; we never receive your card details. We receive confirmation of your subscription status so the app can unlock supporter features. Website gift purchases are processed by Stripe. We store the purchaser and recipient details needed to fulfil and manage the gift, including names, email addresses, delivery choice, message and payment status, but Stripe handles the card details. Gift codes are stored as secure hashes — we keep only enough to validate a redemption.

Feedback and logbook imports

If you send feedback through the app, we keep the message (and your email, if you choose to include it) so we can read and act on it. If you use the logbook import feature — uploading a spreadsheet, notes or a saved web page — the content you upload is processed to build your logbook entries. Where automatic interpretation is needed, the uploaded content may be processed by an AI service (Google Gemini) solely for that purpose; it isn't used for anything else. To identify failed or incorrect imports, a signed-in import also creates a limited diagnostic record linked to your account: the app or website used, parser route, counts matched, added, duplicated or unmatched, any short error message, and the identifiers of entries added to the shared logbook. We do not retain the uploaded file, its filename or ascent notes in this diagnostic record.

Strava

If you choose Connect Strava, Strava sends Munro Planner the activities, route coordinates, dates, notes and activity statistics you authorised so the app can identify Munros and show those walks back to you. This data is displayed only to the connected Strava user. It is cached on your device for no longer than seven days, refreshed only when you request an import, and removed when it expires or when you disconnect Strava. Munro Planner does not use Strava data for analytics, advertising, AI or model training.

You can withdraw access in the app with Disconnect Strava or from your Strava account. Disconnecting revokes the connection and removes the cached Strava walks from the app. Strava may collect API usage data when Munro Planner uses its service, as described in Strava's own privacy and API policies.

What the website collects

munroplanner.com doesn't use analytics or marketing cookies. The site is served through Cloudflare, which may set strictly necessary cookies for security. If you use the contact form, your name, email address and message are emailed to us (delivered via Mailgun) so we can reply — they're not stored in a database.

Third parties we rely on

ServiceWhat it does
Apple App Store / Google PlayApp distribution, payments and subscription management.
StripeProcesses card payments for annual gift purchases on the website. We do not receive your full card details.
Ordnance SurveyLicensed OS mapping and place-name results. Requests are made through our service and may contain the map area, route area or representative walk points needed to return the requested content.
Thunderforest / OpenStreetMap contributorsProvides the optional free map. Tile requests reveal the area being viewed and standard request information such as IP address, but are not labelled with your Munro Planner account.
Open-Meteo / Amazon Web Services public terrain tilesProvides fallback route-weather or elevation data where used. Requests contain the route area or terrain-tile coordinates needed to return that data and standard request information such as IP address.
CloudflareServes and protects the website.
MailgunDelivers email from the contact form and gift purchases.
Google GeminiInterprets logbook files you choose to import — only when you use that feature.
StravaConnects, imports or uploads activities only when you choose a Strava action.
Awin / Snaptrip / Cottages.comOpens an accommodation search only when you choose a cottage link. The link carries the selected base, dates, party filters and non-personal campaign/test context, but not your Munro Planner account, logbook or precise device location. Awin and the chosen accommodation provider may set their own affiliate cookies after you open the link, under their own privacy notices.

Most weather, wildlife and route data is gathered and processed on our own server. Where an online map, place-name, elevation or fallback weather request needs an area or route coordinate, it is handled as described in the location section and table above.

How long we keep things

Account and logbook data are kept while your account exists and removed when you delete it. Logbook-import diagnostic records are removed after 90 days, or sooner if the account is deleted. Recorded GPS walks, including any associated heart-rate, step, calorie and floor readings, are stored on your devices until you delete the walk in the app. Strava activity data is cached for no longer than seven days and is removed sooner if you disconnect. By default, precise live-sharing locations, breadcrumbs and selected device status are kept on our server for no more than 24 hours after the walk ends and are removed sooner when another shared walk starts; you can turn this retention off before sharing. Minimal session records without precise location are removed after 30 days and are used only to operate and troubleshoot live sharing. Account-free performance summaries are removed after 90 days. Server logs are short-lived and rotate automatically. Feedback is kept as long as it's useful for improving the app.

Our lawful basis for service improvement

We rely on legitimate interests to create the limited, account-free performance summaries described above so we can improve live-sharing reliability and battery life. We minimise and separate the fields, exclude locations and identifiers, retain them for 90 days, and provide an easy opt-out in the same sharing settings. You can also object or ask us to remove information by using the contact page.

Security

All traffic between the app, the website and our server is encrypted (HTTPS). Passwords and session tokens are stored hashed. No method of storage is perfectly secure, but we deliberately keep the amount of personal data we hold small.

Your rights

Under UK data protection law (UK GDPR) you can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. The fastest route for deletion is in the app itself (More → Account → delete account); the account deletion page explains both in-app deletion and how to request deletion without the app. For anything else, use the contact page. You also have the right to complain to the Information Commissioner's Office.

Children

The app is not directed at children under 13, and we don't knowingly collect personal data from them.

Changes to this policy

If this policy changes in any meaningful way, we'll update this page and the date at the top. Nothing in a future version will quietly start selling your data — that isn't what this app is for.