Privacy policy
Effective: 7 October 2026
This page explains in plain words what data Strolly processes, why, for how long, and what you can do yourself.
Who is responsible?
Simon Steindl, Währinger Straße 146, 1180 Vienna, Austria
Email: [email protected]
Your account
On first launch, Strolly quietly creates an anonymous account. It has only a random ID, no name and no email address. Your progress is tied to it.
With "Save your progress" you link the account to Apple or Google. Then we store the provider's ID, your email address and your name. For Google, Strolly shows your profile picture. The address of the picture sits with Firebase Authentication, and we do not store the picture ourselves.
Sign-in runs through Firebase Authentication by Google.
What we process and why
- Recorded walks: When you start a recording with "Go", Strolly uses your precise location. Recording continues with the screen locked. Android shows a notification for it, iOS shows the location indicator. When you finish, the app uploads the recording: positions with time, accuracy, altitude and speed, start, end and pauses, plus operating system and app version. The server works out which streets you have walked and deletes the raw data afterwards. What stays is the counted track (without timestamps), time and distance. On your phone, the copy is deleted as soon as the server is done.
- Location for Home: So that Strolly can show you places and stories near you, your phone rounds your location to about 100 m. It sends it in a request header, not in the address of the request. Our server rounds it again, never writes it to logs and does not store it.
- Connections (only if you set them up): Strava, Garmin and COROS. We store your ID at the provider and the access keys, which stay on our server and never on your phone. We fetch activities on foot (walking, hiking, running), older ones too: date, duration, distance, elevation, device name and GPS track. Cycling and other activities are discarded, and so are activities far outside Vienna. We do not fetch heart rate or other health values.
- What Strolly works out from that: walked streets, how much of your Grätzl and districts you have explored, discovered places, famous faces met, badges, streaks, stats and recaps. That is the game.
- Routes: routes you plan or save in Plan. Your route requests are also cached for a short time.
- Visitor mode (only if you choose "I'm visiting"): a trip with the time you have, your interests and optional trip dates, where you are staying as a starting point rounded to about 100 m, and the day plans generated from it (places and times only, no coordinates of yours). We delete the base and the day plans within 24 hours after the trip ends, and you can remove them sooner with "End trip". "Delete trip" removes the whole trip; your stamps, walks and badges stay. The offline package lives only on your phone and is deleted 7 days after the trip. Trip data is part of your data export and is deleted with your account.
- Notifications (only if you agree): the device identifier for push (token), operating system, app version, language and which kinds you want. We also keep a log of which kind was sent when, so that we do not message you too often.
- Crash reports: If the app crashes or hits an error, Strolly sends a report to Google's Firebase Crashlytics. It holds the technical trace of the error (stack trace), device model, operating system, app version, a Firebase installation ID and the random ID of your account. It holds no email address, no name, no location, no walks and no text you type. Reports are always on, except in development builds. The legal basis is our legitimate interest in a stable app (Art. 6(1)(f) GDPR).
- Feedback (only if you send it): your text, the app version, the operating system, the device model (Android only) and the language. You see these details before you send. If you attach an image, you pick it yourself and it goes along. No location, no walks. Only the author reads feedback.
- On your phone: language, units and your progress through the intro. This stays on the device.
- Photos: Strolly does not access your photos or your camera. Only if you attach an image to feedback yourself does exactly that image go along. The photos in the app come from Wikimedia Commons; we serve them ourselves and credit author, source and licence on each.
The legal basis is performing our agreement with you (Art. 6(1)(b) GDPR): Strolly cannot work without this data. For location and notifications your consent also applies (Art. 6(1)(a) GDPR), which you can withdraw at any time in your operating system.
No tracking, no ads
Strolly contains no analytics tools, no ads and no third-party trackers. We never sell your data. Our server keeps technical logs to find errors (legitimate interest, Art. 6(1)(f) GDPR). They hold no coordinates, access keys, email addresses or plain user IDs. Google Cloud also keeps its own request logs (time, address of the request, IP address). The server also keeps anonymous daily totals of how many people use Strolly and which steps they take (sums with no link to a person; numbers under 5 are not stored).
Who else sees something
- Google Cloud processes everything on our behalf: Firebase Authentication, Firebase Crashlytics, Firestore, BigQuery, Cloud Storage and Cloud Run. A data processing agreement is in place.
- Apple and Google (sign-in) are responsible for their own accounts. Only the sign-in data goes to them.
- Strava, Garmin and COROS are responsible for their own data. Strolly only reads there and writes nothing back. Only you see the data from your connections.
- Google (FCM) and Apple (APNs) deliver notifications. They get the text and a link, nothing more.
- Map tiles and photos are loaded by the app from our space on Google Cloud Storage. Label fonts are loaded on iOS from protomaps.github.io (GitHub Pages); on Android they are inside the app. Your profile picture is loaded from Google. These providers see your IP address while doing so, but no account and no Strolly data.
Where your data lives
Cloud Run, BigQuery and Cloud Storage run in the EU region Frankfurt (europe-west3). Firestore and Firebase Authentication also run at Google.
This website
The website strolly.online sets no cookies, uses no analytics and loads nothing from third parties: fonts and images are on the same server. It is hosted by Cloudflare, which technically has to process your IP address to deliver the page. We keep no logs of our own about this and store no visitor data.
How long we keep data
For as long as your account exists, unless it says otherwise here:
- Raw data of a recording: deleted once it is processed. Leftovers after 7 days at the latest.
- Technical server logs: kept for up to 14 days, then deleted.
- Anonymous accounts: deleted when you have not used them for 12 months, and at once when you sign out without saving your progress. An anonymous account with Strava connected stays until you delete it yourself.
- Push tokens: deleted on sign-out, on account deletion and when the provider reports them invalid. A token unused for 60 days is deleted before the next notification. The send log is kept for 8 weeks.
- Data export: the link works for 15 minutes, the file is deleted after one day.
- Feedback: deleted after 12 months, and at once with the account. It is part of the data export, including an attached image.
- Single walks: You can delete any walk. It then counts for nothing and is never shown again. We delete its route. So that it does not come back through a connection, we keep only the provider's ID and a coarse fingerprint (start time, duration, length) as a marker until you delete your account.
- Delete account: everything is deleted immediately and for good, markers included. There is no waiting period and no recovery. Only a deletion note with the random ID and the time stays for up to 30 days, so that late jobs do not create anything new. Backups at Google are then overwritten automatically: for the database and files after up to 14 days, for the sign-in data in Firebase after up to 180 days.
When you disconnect Strava, Garmin or COROS, we revoke our access at the provider and delete the access keys. You decide whether the walks already imported stay or are deleted. If you delete them, we recalculate your map, badges and stats.
If Strava, Garmin or COROS end the access themselves, your walks stay at first. Strolly then asks you whether they should stay or be deleted.
Your rights
- Access and portability: Settings → Export my data gives you a file (JSON) with everything we store about you, except the access keys.
- Erasure: Settings → Delete account. We revoke our access at Strava as part of it. Disconnect Garmin and COROS first under Settings → Connections, otherwise you can only revoke their access there yourself.
- Withdrawal: Settings → Connections, notifications in the same menu, and location in your phone's settings.
- Rectification: your name and email come from Apple or Google and are changed there.
You also have the right to restrict processing and to object. Write to us at [email protected].
Complaints
You can complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde): Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
Security
All connections are encrypted (HTTPS) and the stored data is encrypted too. Every request for your data needs you to be signed in, and nobody can see anyone else's data. Only our server can read the access keys for Strava, Garmin and COROS.
Age
Strolly is meant for people aged 16 and over.