Privacy Policy — Real World Completionist

Last updated: 25 May 2026

This policy explains what personal data Real World Completionist ("the app") handles, on what legal basis, where it goes, how long it is kept, and what your rights are. It is written to satisfy Article 13 of the EU General Data Protection Regulation (GDPR) as well as comparable disclosure obligations in other jurisdictions.

For the legally-required publisher and contact details (Impressum / § 5 DDG), see the separate Impressum page.

Controller

The data controller within the meaning of Art. 4(7) GDPR is the publisher named in the Impressum linked above. Contact for privacy-related questions: realworldcompletionist@pm.me.

Data Protection Officer

We have not appointed a Data Protection Officer (DPO). Under Art. 37 GDPR and § 38(1) BDSG, designation of a DPO is only mandatory where, inter alia, the controller's core activities consist of large-scale regular and systematic monitoring of data subjects (Art. 37(1)(b) GDPR), the large-scale processing of special categories of data (Art. 37(1)(c) GDPR), or at least 20 persons are permanently engaged in automated processing of personal data (§ 38(1) BDSG). None of these conditions apply to this single-developer, server-less application.

For privacy-related enquiries, please contact the data controller directly via the channels listed at the bottom of this policy.

Summary

What data the app processes

Precise location (GPS)

Areas, sessions, and routes you create

Background location

Storage on your device (§ 25 TDDDG)

Some of the data described above — your settings, your saved areas, your session history, and the app's local SQLite database — is stored on your device's local file system. Under § 25 Abs. 1 of the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG, the German implementation of the ePrivacy Directive), accessing or storing information on a user's terminal device generally requires the user's explicit consent.

We rely on the strictly-necessary exemption in § 25 Abs. 2 Nr. 2 TDDDG: the storage operations performed by the app are unbedingt erforderlich to provide the telemedia service you have expressly requested by installing and using the app — without storing your areas and session history on the device, the core completionist functionality cannot work. No data is stored on your device for analytics, profiling, advertising, or any purpose other than delivering the app's functionality.

What data leaves your device, and when

The app contacts two third-party services. Each is contacted only at specific moments, and each receives only the data described below. The app does not send either of these services your identity, your full session history, your saved areas, or any account information — there is no account.

1. Overpass API (overpass-api.de)

2. OpenFreeMap (tiles.openfreemap.org)

Neither of these services is run by us. We do not control what they log, but we send them only the minimum data required for the feature you triggered.

International transfers

The servers operated by the third parties listed above may be located within or outside the European Economic Area (EEA). The data the app sends in each call (bounding-box coordinates for Overpass; tile coordinates for OpenFreeMap) is technical map-data, not personal data within the meaning of the GDPR once detached from your IP address. Your IP address is briefly visible to OpenFreeMap at request time. No adequacy decision (Art. 45 GDPR) or supplementary safeguard (Art. 46 GDPR) is required for the transfer of non-personal map coordinates; the IP address exposure is incidental to ordinary HTTP and is governed by each service's own policy. See the linked operator pages above.

What data we collect ourselves

None. We do not operate any server that receives data from the app. There is no analytics SDK, no crash-reporting SDK, and no advertising SDK that exfiltrates data. We have no user-account system and therefore no user list, no email database, and no usage profile.

How long data is kept

Your rights under the GDPR

You have the following rights regarding the personal data processed during your use of the app:

If you wish to exercise any of these rights against us in writing, contact us via the contact form, by email at realworldcompletionist@pm.me, or at the postal address in the Impressum.

Permissions the app requests

You may revoke any of these permissions through your device's system settings at any time. The app degrades gracefully (no tracking, no map tiles) rather than crash.

Children's privacy

The app does not knowingly target users below the age of 13 (US) / 16 (EU, depending on the Member State). The app has no account system and collects no profile data, so it neither knows nor needs to know a user's age. If you believe a child has used the app and you have a privacy concern as their parent or guardian, please contact us at the email above.

Changes to this policy

If we change this policy, the Last updated date at the top changes too. Material changes are additionally noted in the in-app changelog (Settings → About → What's new) so you have a chance to review them.

Open-source attributions

Contacting us

You can reach us through any of the following channels:

If you use the contact form, the form is provided by Tally (Tally BV, Antwerp, Belgium), which acts as our processor under Art. 28 GDPR. Tally receives the data you enter and forwards it to us by email; details of Tally's own processing are in their privacy policy. The lawful basis for processing the data you submit via the form is your consent (Art. 6(1)(a) GDPR), obtained through the consent checkbox on the form itself, and — where applicable — Art. 6(1)(b) GDPR for messages relating to the use of the app. We delete form submissions once your enquiry has been handled, in any case at the latest six months after receipt, unless a statutory retention obligation requires longer storage.