Last updated: September 20, 2026
How It Went turns a multi-day trip into a short film, and is published by CodeUX.design e.U. (Austria). This policy covers the iOS, Android and macOS apps and this website at howitwent.app.
The app works on your tracks, your photographs and your video. All of it is the kind of thing a privacy policy usually exists to explain the sharing of. None of it is shared. Your files are read on your device, the film is rendered on your device, and neither your material nor the film is ever sent to us or to anyone else. The app makes three kinds of network request and no others: it downloads map tiles when you ask it for a map; it sends a handful of counters about how the app performed, which are on unless you turn them off and carry nothing about your rides; and it uploads its own log if you press the button that does that, which nothing else triggers. All three are described below.
You pick three kinds of file, through your device's own file picker:
The app keeps its own copy of these inside its private storage, so that a tour is still there when you reopen it. Those copies stay on the device. Your originals are left where they are.
Everything the app works out from them — which day was which, where a photograph belongs on the track, what the film cuts to and when — is worked out on the device and written to a project file beside the copies.
There is no analytics SDK, no crash reporting, no advertising, no account and no sign-in. Nothing reads your activity files, your photographs, your video or your finished film back out of the app to anywhere. We cannot see any of it, and there is no code in the app that could send it.
A film can be drawn over a map, and those map tiles are downloaded when you tap Load map. Nothing is fetched until you do. The tiles are kept afterwards, so opening the same route again draws its map without downloading it. If the kept copy turns out not to cover your route, the app fetches a newer one without asking a second time.
The app asks howitwent-api.codeux.dev which build to use and
downloads it from our storage at Hetzner,
cux-hiw.fsn1.your-objectstorage.com. If none of our builds can
be read, it falls back to build.protomaps.com. Elevation comes
from mapterhorn.com. Those last two are not us. A request for
tiles necessarily describes roughly which part of the world your
route crosses, because that is what selects the tiles, so every one
of these hosts, ours included, can infer the general area of a ride, at the
resolution of a map tile rather than of your track. Your activity file is
never sent, and neither is any position out of it.
The app sends a small set of counters — how often each fallback ran, how exports finished, how long they took — to a collector we run. This is on unless you turn it off, and the switch is in Settings, under Diagnostics. Turning it off stops it immediately and for good.
It used to be off until you switched it on. We changed that because the counters are how we find out that an export is failing on a phone we do not own, and almost nobody finds a switch that is off by default — so the app was effectively telling us about one device. What we send did not change when the default did: it is the same counters, to the same collector, shared with nobody.
What it sends is counts and an identifier we generate for your installation, which is not a device ID and is not connected to anything else. It carries no positions, no file names, no tour names and no paths. Nothing about a particular ride is recoverable from it.
The legal basis is our legitimate interest in finding out that the app is broken on hardware we do not own (GDPR Article 6(1)(f)). The switch is how you object: turning it off stops the collection, and you do not have to give a reason or write to us first. We keep the counters for the five most recent app versions and delete older ones.
We do not sell or share any of it, and never have — not your material, not the counters, not to anyone, for any purpose.
Separately from the counters, Settings → App diagnostics has two buttons. One hands the app's log to your device's share sheet, so you can send it wherever you like. The other uploads it to the same collector, so you can give us a link instead of an attachment. Neither happens unless you press it — there is no timer, no send at launch, and no retry.
The log is what the app wrote about itself while it ran: what it loaded, how long things took, what failed. It is more than the counters, and the difference is worth stating plainly. It contains file paths from your device, and a file path often contains your name. It can also carry the name of a tour and the address a map was fetched from. It does not contain your rides, your photographs, your clips or your films.
We do not keep an uploaded log longer than 90 days. If you want one gone sooner, write to the address below and say roughly when you sent it; we will find it and delete it.
It requests no location permission on any platform, and it does not use your device's location services. Every position it draws comes out of the files you chose to hand it — which is to say, out of a trip you already recorded, on purpose, on something else.
Photographs and clips arrive through the system file picker, which gives an app access to exactly the files you select and nothing else. The app never requests permission to browse your photo library, and cannot.
The one Photos permission it does ask for is permission to add — and only when you save a finished film to your camera roll. That is a deliberately narrower request than the read access it would need to look around, and the app is built so that it cannot be widened by accident.
Deleting a tour in the app deletes the project file and the copies of the activity files, photographs and clips it was holding. Deleting the app removes everything it ever stored. Neither touches your originals, and neither touches a film you already saved to your camera roll — those are yours, in your own storage, and the app does not reach back into them.
Visiting this site writes an ordinary web server access log entry: IP address, browser user agent, the file requested and the time. This is used only to operate and secure the site, is not combined with anything else, is never used to profile visitors, and is kept for a short period before being discarded. The legal basis is our legitimate interest in running a working, secure website (GDPR Article 6(1)(f)).
These pages load no third-party fonts, scripts or advertising.
Under the GDPR you may request access to, correction of, or erasure of your personal data, and may object to or request restriction of its processing. In practice this concerns four things and no others: the server logs described above; the visit records our own analytics server holds for the front page; the counters and installation identifier held by our collector, unless you switched diagnostic counts off; and any app log you chose to upload. Write to the address below and we will find and delete them. Everything else the app holds stays on your device, where we cannot reach it and you can delete it yourself by deleting the tour or the app. You also have the right to lodge a complaint with a supervisory authority — in Austria, the Datenschutzbehörde.
The app is not directed at children, and we do not knowingly collect personal data from anyone, of any age.
Until this update, this page said that the app made no network requests at all, and promised that map tile fetching would be described here before any version that did it was released. The map tile fetch shipped to testers before this page was updated, so that promise was not kept. It is described above now, and nothing about your rides, photographs or films was sent in the meantime — what changed is that the app can request map tiles and report counters.
Since then, diagnostic counts became on-by-default rather than off-by-default. Nothing about what they contain changed, and nothing about your rides, photographs or films is in them or ever has been. If you already have the app and had ever set this either way, your setting was left exactly as it was — the new default applies where there was nothing to keep, and an existing choice changes only when you change it.
And uploading a log became something you can do. The button was there before this update but only a developer could reach it; now anyone can, beside the one that shares the same file through your own share sheet. Nothing sends by itself, and what a log contains is described above — including that it carries file paths, which often carry your name.
The commitment stands for anything else: if a future version collects or transmits something, we will update this page, and the date above will change.
Questions about this policy or your data: hello.howitwent@codeux.design