Privacy Statement
What WTFog collects, why it is needed, who receives it, and the choices available to you.
1. The short version
- Location is used when you ask WTFog to track trips, unlock fog, or provide a related feature.
- Your trips and profile are private unless you publish or share them.
- WTFog’s core systems are self-hosted in Europe. Specialist providers handle maps, stores, notifications, purchases, diagnostics, ads, and optional Editor analytics.
- WTFog does not sell personal data or send your account UUID, email, or name to Firebase Analytics.
- You can export data and request reset or account deletion in the app’s Privacy settings.
2. Who is responsible
Nyordre AS, organization number 934 974 670, Liankollen 11, 4638 Kristiansand, Norway, is the controller for WTFog’s processing unless a provider is identified as an independent controller.
Contact our privacy contact at support@wtfog.no. Put “Privacy” in the subject line and do not send passwords, identity documents, or precise trip files unless we provide a safe way to do so.
3. What we use data for
Depending on the feature, WTFog relies on performance of the service contract, your consent, legal obligations, or legitimate interests in security, support, fair play, and reliable operation. Device permission is not itself a legal basis. Owner and legal review must approve the final allocation before publication.
- Account and legal records
- Email, username, profile details, authentication provider, session information, and Terms acceptance/Privacy acknowledgment are used to create and secure an account. Passwords are salted and hashed; WTFog cannot read them.
- Location, motion, trips, and fog
- Precise and background location, timestamps, accuracy, altitude, speed, heading, and motion signals are used to show position, record trips, unlock fog, calculate statistics, support recovery, and protect fair play. Location is private unless you publish or share it.
- Your activity and content
- Trips, imports, exports, Editor changes, saved places, searches, profiles, photos, posts, comments, reactions, groups, competitions, chat, and reports are used to provide the feature you chose. Messages and media are visible to their intended participants; published material follows the audience shown in the app.
- Purchases, access, and advertising
- Product, receipt, entitlement, subscription, gifted or earned access, ad-consent choices, ad interactions, and reward confirmations are used to provide and restore access, prevent fraud, and meet accounting duties. Personalized advertising and advertising identifiers are used only where permitted by your choices and device settings.
- Support, recovery, and notifications
- Support messages, account-recovery details, tracking evidence, review notes, push tokens, and notification preferences are used to answer requests, recover eligible activity, deliver notices, resolve disputes, and prevent abuse.
- Diagnostics and product measurement
- App version, device and operating-system details, crash reports, performance information, and aggregate events help keep WTFog reliable and understand feature use. Firebase Analytics receives aggregate events and coarse properties, not your WTFog account UUID. Crashlytics may receive a pseudonymous account UUID when needed to investigate a crash or support case, but not your email or name.
- Device and Editor storage
- WTFog stores settings, caches, guest progress, tracking queues, secure sessions, and necessary Editor cookies or local storage. General cache and preferences are not universally encrypted. Authentication tokens use platform-protected Keychain or Keystore storage.
4. Providers and transfers
We share only what a provider needs for its role or what law requires. Some providers also act as independent controllers for platform accounts, billing, or advertising.
- Hetzner Online: European hosting for WTFog’s self-hosted Supabase authentication, API, Postgres database, workers, logs, encrypted backups, and Helsinki object storage. Privacy policy.
- Nordhost: email delivery in Norway/EEA. Privacy information.
- Mapbox: maps and mobile map telemetry. Mapbox may receive IP address, device/app data, and de-identified location or usage telemetry. Apple or Google—not Mapbox—provides platform geocoding used by the app. Privacy policy.
- Expo, Apple, and Google: app updates, push relay, APNs/FCM delivery, Apple or Google sign-in, stores, device services, and platform geocoding. Expo, Apple, and Google privacy information.
- RevenueCat: purchase and entitlement verification. Privacy policy and DPA.
- Firebase: Google Analytics and Crashlytics for aggregate measurement and crash investigation. Firebase privacy information.
- Google AdMob and UMP: optional ads, consent collection, and reward confirmation, subject to your choices and device controls. Google privacy policy.
- Microsoft Clarity: consent-gated interaction analytics in the Premium Editor, including masked session reconstruction. No WTFog account UUID, email, or name is intentionally sent. Microsoft Privacy Statement.
Core WTFog hosting is in Europe. Providers may process data in the United States or other countries described in their terms. Where required, transfers use an adequacy decision, approved contractual safeguards, or another lawful mechanism.
5. Your choices and visibility
- Start or stop tracking and change location, motion, notification, or advertising permissions in WTFog and device settings.
- Choose profile visibility and the audience for social or published content.
- Remove saved places, trips, posts, messages where supported, and other content through the relevant feature.
- Manage AdMob consent from Privacy settings and App Tracking Transparency on iOS.
- Accept or refuse optional Clarity analytics in the Premium Editor. Necessary authentication, security, and preference storage does not depend on analytics consent.
Clarity release blocker: Microsoft currently says Clarity should not be used for services targeting people under 18. Because WTFog allows accounts from age 13, Clarity must remain disabled until WTFog removes it or adopts an enforceable, legally reviewed solution.
6. Retention and deletion
- Account data, private trips, fog, saved places, and social data normally remain until you remove them, reset activity data, or delete the account.
- Published trips may remain after deletion under an anonymized “Deleted user” identity.
- Legal acceptance records are append-only while the account exists and are deleted with the account.
- Encrypted database backups use a rolling 30-day cycle. Deleted data disappears as the relevant backup expires.
- Resolved tracking-recovery artifacts are scheduled for deletion after 30 days; minimal outcome information may remain for support, integrity, or legal claims.
- Firebase documents 90-day retention for Crashlytics reports and identifiers.
- Microsoft documents 30 days for Clarity playback data and 9 months for heatmaps and favorited sessions.
- Temporary uploads, processing queues, logs, support records, billing records, analytics, ads, and provider data follow operational, contractual, or legal periods. Exact WTFog settings for these items must be owner-confirmed before publication.
Deletion removes data from active systems according to these periods. We may retain limited information where law requires it or where necessary to establish, exercise, or defend a legal claim.
7. Young users and fair-play review
WTFog accounts are not for children under 13. Norway’s current information-society consent threshold is 13. Contractual capacity and purchase authorization are separate, so a parent or guardian may still need to authorize use or a purchase.
WTFog can use automated and manual signals to flag impossible movement, duplicate rewards, suspicious imports, recovery conflicts, fraud, or unsafe content. A signal can limit an affected result or refer it for review; it should not be the sole basis for a significant decision where applicable law requires human involvement. You can ask support to review an account, recovery, moderation, or fair-play action.
8. Your rights
Depending on the law and circumstances, you can ask for access, correction, deletion, restriction, portability, or an objection to processing, and you can withdraw consent for future processing. You can download a user-data export or request deletion in Settings → Privacy, or contact support@wtfog.no. We may need to verify the request and may limit it where law protects other people, security, confidential logic, or legal claims.
You may complain to:
DatatilsynetPostboks 458 Sentrum
0105 Oslo, Norway
Complaint information
9. Changes
We may update this Statement when the service, providers, or law changes. The current version and effective date appear at the top. Material changes will be announced when required. The contractual rules for WTFog are in the Terms of Service.