Pocket Atlas records where you walked so it can give you stickers for it. Your walks are private by default. Your photographs stay on your phone unless you share them. We do not sell anything to anyone, we do not carry advertising or third-party analytics, and you can take everything with you or delete all of it from inside the app.
Pocket Atlas is made by Savvas Pythakakis. Contact: [email protected]. We are the data controller for everything described here.
On your phone, always, and this is the copy that matters:
On our servers, in Frankfurt, so the passport survives a lost phone:
Location is the whole app. It is used to notice you have arrived somewhere and to record the walk you are on. Two things about it are deliberate:
We store accuracy and speed alongside each sticker. That is used to tell a real arrival from a spoofed one before a leaderboard counts it, and for nothing else.
Your photograph is the sticker. It is stored on your phone and uploaded to private storage tied to your account. Nobody else can read it unless you share a walk that contains it. We do not analyse the contents of your photographs and we do not use them to train anything.
You do not need an account for the map, the camera or the passport — but you do need one to get past the first screen, because a passport nobody can recover dies with the phone it was on. The app signs you in anonymously at first launch, and then asks for an email address.
There is no third-party login and never will be. No Google, no Apple, no Facebook. We email you a six-digit code; there is no password to make and none to forget, and no other company is told that you use this app. Signing in with the code links the anonymous identity the app already gave you — it does not replace it, and nothing collected beforehand is lost.
We store the address, and we use it for exactly two things: sending you a sign-in code, and knowing which passport is yours. We do not email you anything else. There is no newsletter and no announcement list.
There is one place in the app that keeps a count, and this section exists because it would be dishonest to bury it in a list.
When you sign in, the app records that each step happened: the screen was shown, a code was sent, a code was wrong, a name was taken, it finished. It is nineteen named events, it is ours, it goes to the same Frankfurt database as everything else, and it exists so we can see where people get stuck on the one screen they cannot skip.
None of it carries anything you typed. Not the address, not the code, not the handle. Where a reason is recorded it is a word we chose — no_at for an address with no @ in it, offline for a code that could not be sent — and the column it goes in is constrained by the database to short lowercase words, so an address could not be written there even by mistake. The events are attached to your account, which means they are in your export and they are deleted with it.
Nothing else in the app is counted. There is no screen-view tracking, no session recording, and no third-party analytics SDK anywhere in the binary.
Landmark names, coordinates and descriptions come from Wikidata (CC0), OpenStreetMap (ODbL) and Wikimedia Commons, each credited in the app. Nothing about you goes back to them.
Under the GDPR you may see, correct, export or delete your data, and object to how it is handled. Three of those are buttons in Settings rather than a request you have to make:
Pocket Atlas is not directed at children under 13 and we do not knowingly collect their data.
Until you delete them. There is no automatic expiry, because a passport whose early pages vanished would not be a passport. Detailed walk routes are the one exception: they are simplified after a period, since the exact line adds nothing once the walk is over and its precision is the part worth losing.
If this policy changes in a way that affects what happens to your data, the app will say so rather than quietly updating a web page.