Privacy policy
DeutschLast updated: 2026-07-28.
Controller
Tim Beyer
Kolonnenstr. 8
10827 Berlin
Deutschland
Email: hello@trailvid.com
Competent supervisory authority: Berliner Beauftragte für Datenschutz und Informationsfreiheit
Overview
TrailVid creates cinematic travel animations on your device. Your trips, themes, and finished videos are created and stored locally on your device; rendering and video encoding happen on your device, not on our servers. There is no user account and no server-side database of your trip content.
The cases where data does leave your device are described individually below: the maps/routing lookup, audience measurement, sending feedback, app updates, and — on iOS only — iCloud sync and local-network streaming to an Apple TV.
Your rights
Under the GDPR you have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
Where we process data based on your consent, you can withdraw it at any time with effect for the future — the anonymous baseline measurement can be controlled in the app settings or via the notice on the website.
You also have the right to lodge a complaint with a data protection supervisory authority; the one competent for us is named above under “Controller”.
Hosting and server logs
The website, app delivery, and our API (api.trailvid.com) run on a hosting provider. When you access them, technically necessary connection data — including your IP address — is processed for delivery, security, and to limit abusive requests (rate limiting).
For sharper globe detail, the app requests imagery tiles from this first-party API. The requested tile coordinates indicate the map region currently being viewed; they are not your device’s GPS location and are not sent to Mapbox.
Cloudflare, Inc.
- Purpose
- Hosting the app, marketing site, and API; delivering close-range globe detail; security and abuse prevention.
- Data
- IP address; Request metadata (user-agent, timestamps); Requested detail tile (tile coordinates / viewed map region); Edge logs
- Legal basis
- Art. 6(1)(b) — providing the requested app function; Art. 6(1)(f) — legitimate interest in secure, functioning operation.
- Transfer
- USA — Data Privacy Framework (where certified) + Standard Contractual Clauses (SCCs).
- Retention
- Transient; edge logs on Cloudflare's rolling cycle.
Audience measurement
To improve the product and measure usage we use privacy-friendly audience measurement, processed in the EU. It is two-tier: without your consent, only a cookieless baseline runs, via a server-side, daily-rotating hash — no information is stored on or read from your device and no cross-device identifier is created. Only with your explicit consent do we enable enriched analytics with an anonymous identifier stored on your device; you can withdraw this consent at any time.
We only measure events such as “export finished” or “theme edited” — counts, formats, and durations. Your trip content (place names, titles, captions) is never captured. We do not use session replay.
PostHog, Inc.
- Purpose
- Audience measurement and error tracking to improve the product.
- Data
- Cookieless daily-rotating server hash (treated by PostHog as non-personal data); Event names and non-identifying properties (counts, formats, durations — never trip content); Exception traces; With app opt-in: an anonymous device-scoped identifier
- Legal basis
- Baseline: Art. 6(1)(f) legitimate interest (cookieless, no storage on your device). Enriched (app opt-in only): Art. 6(1)(a) consent.
- Retention
- Per the PostHog project retention settings.
Map and route data
When you search for a place or build a route for car, bus, walking, or cycling, our server fetches the required geometry from a maps provider. What is transmitted is the search term you typed or the rounded coordinates of your stops — not your IP address, because the request is made server-side.
Mapbox, Inc.
- Purpose
- Geocoding and route directions for the trip the user is building.
- Data
- Typed search text; Quantized stop coordinates (location data); End-user IP is NOT sent (the Worker proxies server-to-server)
- Legal basis
- Art. 6(1)(b) (performing the requested feature) + Art. 6(1)(f).
- Transfer
- USA — Data Privacy Framework (where certified) + Standard Contractual Clauses (SCCs).
- Retention
- Responses cached at the edge (geocoding ~7 d / directions ~30 d), keyed on normalized query/coords — no IP or user id in the cache key.
Feedback
When you send feedback in the app, your message, an optional reply email you provide, and technical diagnostics (app version, platform, screen size, user agent) are transmitted to our issue tracker so we can act on it. Nothing is sent before you tap “Send”; your trip content is not transmitted.
GitHub, Inc. (Microsoft)
- Purpose
- Receiving and acting on user-submitted feedback.
- Data
- Message text; Optional reply email; Device diagnostics (app version, platform, screen size, user-agent); No trip content; sent only on explicit submit
- Legal basis
- Art. 6(1)(a) consent / Art. 6(1)(b) handling the request.
- Transfer
- USA — Data Privacy Framework (Microsoft) + Standard Contractual Clauses (SCCs).
- Retention
- For as long as needed to handle the report.
App updates (iOS only)
The iOS app obtains program updates via an update service. This processes technically necessary data such as your IP address, the app identifier, and the version/channel.
Capgo
- Purpose
- Delivering over-the-air JS-bundle updates to the iOS app.
- Data
- Device IP; App identifier; Version/channel
- Legal basis
- Art. 6(1)(f) legitimate interest in delivering updates.
- Transfer
- Provider location and transfer safeguard are being confirmed (see the DPA checklist).
- Retention
- Short-term, for update delivery.
iCloud sync and Apple-TV streaming (iOS only)
On Apple devices, your trips, themes, and settings can sync between your devices via the private iCloud database of your own Apple account. The content resides in your own iCloud; we operate no server for this.
If an Apple TV is paired, trip and theme changes are streamed directly to that device on your local network (peer-to-peer, no external server).
Apple Inc.
- Purpose
- App Store distribution; syncing the user's trips/themes/settings across their own Apple devices (CloudKit); silent push (APNs) to trigger sync.
- Data
- Trip and theme content (in the user's own private iCloud); Push tokens
- Legal basis
- Art. 6(1)(b) — providing the feature.
- Transfer
- USA — Standard Contractual Clauses (Art. 46 GDPR) and Apple's supplementary safeguards.
- Retention
- In the user's iCloud until they delete it.
Photo import (iOS only)
If you use photo import, the app — after you grant the photo permission — reads only the metadata of your photos (location and capture time) on the device to draft a trip. The image data itself is not copied or uploaded; the analysis happens entirely on the device.
International data transfers
Some of the providers named above process data in the USA. Depending on the provider, these transfers are safeguarded by the EU-US Data Privacy Framework (where the provider is certified) and/or by Standard Contractual Clauses under Art. 46 GDPR; the basis that applies to a given provider is stated above with that provider. The Data Privacy Framework currently stands but is under legal challenge — the Standard Contractual Clauses remain in place as a standing safeguard should it fall away. You can request a copy of these safeguards from the address given above under “Controller”.
No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
Retention
Content stored on your device remains there until you delete it. Server logs and cached route responses are cached only for operation and deleted on a rolling basis. Feedback is retained for as long as needed to handle it.
Changes to this policy
We update this policy when the underlying processing changes. The version published here at the time applies.