Privacy, explained

What stays on your phone, and what leaves it

Walkable has no account and no copy of your walking history. This page says that in full: what is kept on the device, the few moments something is sent, and what happens when you deliberately share.

The short version

There is no Walkable account, so there is no profile, no login and no server-side copy of your walks to look up. Your walking history lives in the app’s own private storage on your phone. A handful of things do go out — a map has to be fetched, a planned route may need calculating, and a few features exist only because they send something — and every one of them is named below with the moment it happens.

This page is a plain-language reading of the full policy. Where the two differ, the privacy policy is the document that governs.

Part one

What stays on your phone

Everything Walkable records about your walking is kept in the app’s own private storage — the area of the device other apps cannot read. It is not synced, and there is no account it could be synced to.

  • Your walks — the GPS route, distance, duration, pauses and step count.
  • Photos, videos and voice notes you attach to a walk.
  • Moods, titles and notes you add to a walk.
  • Places you pin, and the reminder times you set.
  • Goals, streaks and your learned walking rhythm.
  • Your local profile name and picture — local, in the sense that it has nowhere else to be.
  • Guided trails you have walked, and routes friends have shared with you.
  • Your companion, everything it has walked with you, and your conversation with it — every message, and everything it remembers about you.
  • Your settings, including which suggestions you allow.
  • Cached map tiles and downloaded offline map data.

Walkable contains no advertising, analytics, crash-reporting or tracking SDKs. There is no Firebase, no ad network and no third-party analytics library in the app.

No account, and nothing to log in to

Walkable requires no account, no sign-up, no email address and no password. There is no Walkable user database. We do not hold a profile, a login, or a copy of your walking history on our servers — which means there is no account for us to look up, export or hand over.

Location is recorded only while you are walking

Recording starts only when you tap to start a walk, and a notification stays visible for as long as it runs. It stops when you finish or discard the walk. Your recorded routes are saved on your phone; they are not uploaded anywhere unless you use one of the optional features in part two.

There is one exception, and it is entirely your choice: Auto Walk Detection. It is off by default, and turning it on is the only thing that makes Walkable ask for Android’s background location permission. With it on, Walkable uses your phone’s physical-activity information to notice when you start walking, and only then uses your location — to measure the distance and record the route — showing a notification for as long as it records, exactly as a walk you started by tapping. Between walks it holds no location access at all: no GPS, no background service, no periodic check of where you are. Switch it off in Settings and Walkable goes back to recording only when you tap.

It stays until you remove it

Walkable does not expire, rotate or automatically delete your walking data. It remains on your phone until you delete individual walks, use Settings → Delete my Walkable data, clear the app’s storage in Android Settings, or uninstall the app. Deleting from the phone cannot be undone, because there is no server copy to restore from.

Walkable also opts out of Android’s automatic backup and of device-to-device transfer. Your walks, places, notes and photos are not copied into Google’s system backup, and are not carried across by the “copy from your old phone” flow. The ways your data reaches a new phone are the ones you choose.

Part two

What leaves your phone, and exactly when

This is the complete list. The first three happen because a map, a route or the weather cannot be produced without asking for them. One — talking to your companion — arrives switched on and can be switched off. The rest do not happen at all unless you turn them on.

  • Map tiles

    Whenever you look at a map

    Walkable draws maps from OpenStreetMap tile servers. Asking for a map square necessarily tells the tile server which squares you are looking at. A downloaded routing region does not change this — it holds routing data, not map pictures. Tiles you have already looked at are cached on the phone and are not fetched again.

  • Route planning happens on your phone

    Nothing sent

    Every time — nothing is sent

    Planning a route runs entirely on your phone, using the map data already on it. The start point and the distance you asked for are not sent anywhere. Walkable used to be able to ask a routing server when it had no local map data; that server was retired in July 2026 and the online path is switched off in every build you can install.

  • Weather

    Once, at the start of a walk

    Current conditions are requested from Open-Meteo using coordinates rounded to about one kilometre. Your exact position is not sent.

  • Encrypted Google Drive backup

    Optional

    Only after you set it up

    Off until you switch it on. Your walks are encrypted on the phone and then copied into the private app-data folder of your own Google Drive. There is a section on this below, because the trade it asks of you is real.

  • Live sharing

    Optional

    Only if you start it during a walk

    Your position is sent to a relay so that anyone holding the link can follow along. The link expires by itself, sharing stops when the walk ends, and you can stop it at any time. Nothing is shared unless you start it.

  • Route sharing, and handing a walk to a watch

    Optional

    Only if you use them

    Sharing a route with a friend, or passing a walk to a paired watch, sends that route through a relay so the other device can pick it up. These transfers are short-lived and contain the route only.

  • In-app help

    Optional

    Only if you write to us

    If you ask a question through the in-app help, the text of your message is sent to our support service so it can be answered. Please do not put anything in a support message that you would not want us to read.

  • Talking to your companion

    On by default

    When you send a message, and once a day at most if it speaks first

    Your companion's replies are written by an AI model that is not on your phone, so a conversation is a request. It sends what you typed, the name it calls you by, what it remembers of earlier conversations, your walking totals as plain numbers, and the language you read the app in — never your coordinates, your route, your photos, or any individual walk, including the one you are on. The conversation is stored on your phone, and “Forget our conversations” erases it. Settings → Talk with your companion switches the whole thing off.

  • Adding a companion

    Optional

    When you download one

    Companions are not built into the app: you pick one and Walkable downloads it from our own file host. Like any download, that tells the server which file was asked for. It carries no account, no identifier and nothing about your walks.

  • Opening a route in Google Maps

    Optional

    Only if you tap it

    Tapping “Open in Google Maps” hands the route over to Google Maps, which is then governed by Google's own privacy policy.

None of these carries a Walkable account, because there is no Walkable account to carry. The two that need to recognise a returning device — in-app help and the companion conversation — carry a random installation id, which is generated on the phone, is not taken from its hardware, and exists so that abuse can be rate-limited. VorreiX does not retain personal data from any of them: route-planning requests are processed to return a route and are not used to build a profile, weather lookups use rounded coordinates and are not retained by us, live-sharing sessions and route or watch transfers are short-lived and expire by themselves, a support message is kept only as long as it takes to answer you, and a conversation with your companion is answered and not stored — what is kept is the counter that limits how many messages a day one installation may send.

The one that is worth reading twice

The encrypted Drive backup, and how it differs from the local-first default

Walkable’s default is simple: your walks are on your phone and nowhere else. That default has an obvious cost — lose the phone, lose the walks — and the backup exists to answer it without giving up the promise.

  • It is off until you set it up. The local-first default is what you get if you never open that screen.
  • It goes into your Drive, not ours. Walkable copies your walks into the private app-data folder of your own Google Drive — a folder only Walkable can reach, not your documents and not your photo library.
  • It is encrypted on the phone before it leaves. Google stores a file it cannot open: not your routes, not your coordinates, not your notes, and — if you switch on Include photos & audio — not your photos, videos or voice notes either. Each media file is sealed individually and named so that the folder does not reveal which walks contain photographs.
  • The key is yours. The file is locked with a key generated on your phone, which is itself locked by a recovery key shown to you once, at setup. Walkable never stores or transmits that recovery key — not on the phone, not in your Drive, and not on any server, because no VorreiX server is involved in this at all. It exists only where you put it.
  • You can change your mind. Replace the recovery key at any time from Settings → Cloud backup — the backup stays where it is and the old key stops working immediately. Delete the backup at any time, in every state, including before it is set up and when this phone cannot read it.

If you lose the recovery key, your backup can never be opened

Not by you, not by us, not by Google, and not in response to any legal demand. This is the same fact as “encrypted so that nobody else can read it”, stated in the direction that costs something. Write the recovery key down somewhere you will still have it after the phone is gone.

Deleting your data on the phone deliberately does not touch the Drive backup, so that clearing a device never silently reaches into your Google account — delete it separately under Backup. And anything sitting in your Drive remains subject to Google’s privacy policy, which is precisely why what we put there is unreadable.

Part three

What happens when you share

Sharing in Walkable is always something you do, never something that happens in the background. Each kind works differently, and it is worth knowing which is which.

The Community is a separate, public place — and you type into it

The Walkable Community lives on this website, in a browser. It is not part of the app, and it is not connected to it: the app has no account, so there is nothing for a post to be attached to. Your walks are never uploaded to the Community, and there is no mechanism by which they could be. A Community post contains what somebody deliberately wrote into a form — the text, the broad place they optionally gave, and a display name they chose. There is no social feed in the app, no public profile, no leaderboard and no follower list.

If you do post, please leave out anything you would not want a stranger to read: an exact home address, a live location, or private medical information. Visit the Community

Live sharing shows where you are, while you are walking

If you start it, your position goes to a relay so that whoever holds the link can follow along. The link expires by itself, sharing ends when the walk ends, and you can stop it at any moment. It is the one feature that shares your position as it changes, which is why it never starts on its own.

Sharing a route shares the route, and nothing else

Sending a route to a friend, or handing a walk to a paired watch, passes that route through a relay so the other device can pick it up. These transfers are short-lived and contain the route only — not your history, and not your other walks.

Handing a route to Google Maps hands it to Google

“Open in Google Maps” does exactly what it says: from that tap onwards, the route is in Google’s app, under Google’s own policy.

Reporting something your companion said sends that message

Holding a message down offers Report this message. It hides the message from your conversation and sends that message, with the reason you picked, to us — so that a person reads it rather than a model. Nothing else about you travels with it, and reports are kept, because a report is a request to look at something.

Writing to support shares what you write

A support message is read by a person so it can be answered, and it is kept only as long as that takes. Please do not include anything in it you would not want us to read.

Removing everything

Settings → Delete my Walkable data permanently removes, from that phone, every walk with its route, distance and times; the photos, videos and voice notes saved on your walks; your saved places and reminders; your goals, streaks and learned rhythm; your local profile name and picture; your companion, your conversation with it and everything it remembered about you; and your settings. It leaves downloaded offline map data, which contains nothing about you, and it leaves your Drive backup, which you delete separately.

There is a narrower control for the conversation alone: Forget our conversations, in the chat’s own menu, deletes every message and everything your companion remembers about you, and keeps your companion.

Because there is no account and no server copy of your walking history, there is normally nothing for us to delete on your behalf. To ask about something we do control — a support message you sent us, for instance — or for written confirmation of any of the above, email Automat4ed@gmail.com. We respond within 30 days.

The full document

This page is a reading of the privacy policy, not a replacement for it. The complete version — including data retention, the permissions Walkable asks for and why, children, and how changes are published — is the one to rely on.

Read the full privacy policy

Walk without signing in

Walkable is free, works without an account, and keeps your walking history on your phone.

Install fromGoogle Play

Android, in early access. There is no iPhone version yet. Read the guides