Privacy Policy
"10 000 pas" app (Android and iPhone): last updated on
8 September 2026. Lire cette politique en français.
10 000 pas is a walking app that suggests a fresh loop every day, sized
to the steps you still need to reach your daily goal. It is designed to work
without an account: your walking data stays on your phone. The app is funded
by occasional ads, described below, shown only with your consent where the
law requires it. This policy applies to the Android and iOS versions.
Location data
- Your location is used to compute the loop of the day and to follow
your progress during an active walk. Outside a walk, no tracking takes
place.
- To generate a route, the start coordinates (and the destination for a
one-way route) are sent to our routing server anonymously: no account, no
name, no advertising identifier. They are kept only in the technical cache
and the logs described under "Technical data".
- During a walk, the GPS track is processed and stored only on your
phone. It is never transmitted.
- Background tracking exists only during a walk you started. It is
shown by a persistent notification on Android and by the system
background location indicator on iPhone. It stops with the walk.
- When you use the address search field, the text you type and the
coordinates of the displayed map area are sent to the Photon service
(komoot GmbH, Germany), only to suggest matching addresses. We keep none
of it on our server; the last five selected addresses are stored only on
your phone so they can be suggested again.
Health data (Health Connect, Apple Health and step sensor)
- The app reads only your step count: through Health Connect on
Android, through Apple Health (HealthKit) on iPhone, or through the
phone's motion sensor. It writes nothing to Health Connect or Apple
Health.
- This data is used exclusively to show your daily progress, fill your
walking diary and statistics, and size the suggested loop.
- It is stored only on your phone. It is never sent to our servers or
to third parties, never sold, and never used for advertising or
marketing.
- You can revoke access at any time: on Android in Health Connect or
the phone settings; on iPhone in Settings, Health, Data Access and Devices
(and Settings, Privacy and Security, Motion and Fitness for the sensor).
The app remains usable.
Technical data
- A random installation identifier accompanies route requests, only to
limit abuse (a per-device quota of route computations). It is linked to
no identity and changes with every reinstall.
- At each launch, the app reports an opening to our server with that
same random identifier, only to count users and openings per day. Only
anonymous daily totals are kept; no profile, no per-device history.
- Our server is hosted by Cloudflare. Its technical logs, kept for at
most seven days to diagnose failures, contain for each request the
installation identifier, the rounded start coordinates (about ten metres
of precision), the requested distance and the outcome of the computation,
along with the usual metadata of any web request (IP address, country,
device type). They serve no other purpose.
- No third-party analytics tracker is embedded. The only advertising
tool is the Google AdMob SDK, described below.
Advertising (Google AdMob)
- The app occasionally shows interstitial ads served by Google AdMob,
for example when regenerating a route. The first route generation of the
day is always ad-free.
- To serve these ads, the Google Mobile Ads SDK may collect technical
data: the device advertising identifier, IP address, device information
and interactions with ads. Google processes this data under its
privacy policy.
- In the European Economic Area and the United Kingdom, no data is used
for advertising without your explicit choice: a consent form (GDPR) is
shown at launch. You can decline; less personalised or limited ads may
then be shown.
- On iPhone, the app additionally asks for Apple's tracking permission
(App Tracking Transparency) before the first ad, after the consent form.
If you decline, ads remain non-personalised and the advertising
identifier is not accessible. Google may also measure installs coming
from an ad through SKAdNetwork, Apple's attribution mechanism, which does
not reveal your identity.
- Your health data (step count) and your GPS tracks are never shared
with the ad network.
- You can reset your advertising identifier or opt out of ad
personalisation at any time: on Android in Settings, Privacy, Ads; on
iPhone in Settings, Privacy and Security, Tracking.
In-app purchases and unlock codes
- The premium unlock (unlimited route generations) is bought through
Google Play or the App Store. Payment is handled entirely by the store: we
receive neither your name, nor your email address, nor your payment
details.
- To activate the unlock, the app sends our server the proof of
purchase issued by the store (Google Play token or App Store transaction).
The server verifies it with Google or Apple, then attaches the premium
status to your installation identifier. Only that status and its date are
kept; the proof of purchase is not stored, and only the transaction number
appears in the technical logs.
- An unlock code entered in the app is sent to the server, which
records which installation identifier used it so that it can only be used
once.
Third-party services
To work, the app relies on services that receive technical requests (IP
address included, as with any online service):
- OpenRouteService (HeiGIT) and
Overpass (OpenStreetMap): route and point-of-interest
computation, through our server, which forwards only anonymous
coordinates.
- OpenFreeMap: map display, contacted directly by the
app to load tiles.
- Photon (komoot GmbH, Germany): address search
autocompletion (OpenStreetMap data), contacted directly by the app with
the typed text and the displayed map area.
- Google AdMob: ad delivery, under the conditions
described in the "Advertising" section above.
- Google Play and App Store (Apple): in-app purchase
processing and proof-of-purchase verification, under their own privacy
policies.
- Cloudflare: hosting of our server and its technical
logs.
Contact form
- The website's contact form asks for a first name, an email address
and a message. This information is used only to reply to you.
- It is kept on our server for at most twelve months, then deleted
automatically. You can ask for earlier deletion by email.
- A copy of each message may be forwarded to a private notification
channel reserved for the app's author, so that no request is missed.
- The visitor's IP address is used to limit the number of submissions
per day; that counter is deleted automatically after 48 hours.
Retention and deletion
Retention periods, by storage location:
- On your phone: walking history, recorded walks,
recent address searches, settings and premium status are kept until the
app is uninstalled (or its data cleared), which deletes them permanently
and immediately.
- On our servers: we keep no account and no profile.
Start coordinates sent for route computation are kept only in an anonymous
technical cache: 24 hours for routes, 7 days for points of interest, then
deleted automatically. Quota and opening counters tied to the random
installation identifier are deleted automatically after 48 hours; only
anonymous daily totals (number of openings and generated routes) are kept
beyond that. Technical logs are deleted after at most seven days. The
premium status (paid or code unlock) attached to the installation
identifier is kept as long as needed to provide that unlock.
- At Google AdMob: data collected for advertising is
kept by Google for the periods described in its
retention
policy; we have no access to it and keep no copy.
- Health Connect and Apple Health: data held by these
platforms remains managed by them and by your other apps.
- Deletion on request: write to us (contact below) to
have the server data tied to your installation identifier deleted,
including the premium status.
Children
The app is not directed at children under 13 and collects no data that
could identify them.
Changes
Any change to this policy will be published on this page, with its
update date.
Contact
For any question about your data:
contact@10000pas.app