Privacy Policy
Effective September 5, 2026
Glassing is a backcountry map. It shows you where you stand, records where you walked, and keeps the marks you make on the land. Where you hunt, hike and ski is nobody's business but yours. This policy says what happens to that information — every flow, including the ones that are inconvenient to admit — rather than reserving rights nobody intends to use.
Glassing — the iOS app, the watch app, and the web map at glassing.app — is published by Glassing, LLC, a Delaware limited liability company. Write to privacy@glassing.app if anything below is unclear.
The short version
- The app works fully without an account, and without one nothing you record leaves your phone. No sign-up wall.
- Signing in syncs your own data to your own account. That is the only reason accounts exist.
- Glassing does not sell your data, share it with data brokers, or use it for advertising. The app carries no analytics or advertising tools of any kind.
- There are no heatmaps. Your tracks are never pooled with anyone else's, for any purpose, including Glassing's own.
- Nobody at Glassing looks inside what you store. Waypoints, routes, tracks, trips and photos are stored as opaque data; the server does not read them, index them, or analyze them. The one exception is a file you import on the web map, whose place names are sent to a model to suggest icons — see "Importing a file on the web map".
- Nothing is published unless you publish it. A share link you make shows one record to whoever holds the link. Nothing else is ever visible to anyone but you.
- Some of what the map draws is about other people. The Ownership overlay, which is off until you turn it on, shows what a county tax roll records about private ground. No private individual is named. See "Land ownership".
- Health data stays on your phone. A finished recording writes a workout to Apple Health. Glassing never reads it back and never sends it anywhere.
What stays on your phone
Signed out, nothing you record leaves the device. Your position, your tracks, your waypoints, your photos, your notes and your recent searches live in the app's own storage.
These stay on the phone whether or not you sign in:
- Your recent searches — eight strings, clearable.
- Apple's performance and crash reports. Glassing subscribes to MetricKit, and the reports are written to app storage and stay there. Nothing uploads them. Settings → Support → Share diagnostics report packages them for you to send, Delete diagnostics data erases them all, and deleting the app removes them.
- Motion and barometer readings. See "Location and motion" below.
- The hiking workouts written to Health. See "Health" below.
- Your name, if Apple provides it. Sign in with Apple hands back a full name on the first authorization; the app keeps it locally and never puts it in a request.
Drawing a map still contacts map servers — see "Map data and the servers behind it" — but nothing you have recorded is part of those requests.
Signing in
Sign in with Apple is the only sign-in Glassing offers. The app sends Apple's identity token, and an authorization code when Apple supplies one. Nothing else goes with it.
From the verified claims inside that token the server stores a stable Apple identifier and, when Apple provides one, an email address — which is Apple's private relay address if you chose Hide My Email. The account row also records the date it was made. The authorization code is exchanged with Apple for a refresh token, stored as Apple issued it, which exists for exactly one purpose: revoking Glassing's access to your Apple Account when you delete your Glassing account.
What syncs
Signed in, five kinds of record sync to your account:
| What | What it contains |
|---|---|
| Waypoints | Coordinates, elevation, name, notes, symbol, timestamps |
| Tracks | Every recorded position: coordinates, elevation, time, accuracy, speed, heading |
| Routes | The line you drew and its points |
| Trips | Title, notes, dates, and the place name the app gave it |
| Photos | The picture itself, a caption, where and when it was taken, and which waypoint or trip it belongs to |
That is the whole list of what syncs, and the server enforces it — a sixth kind of record has nowhere to sync to. Settings, layer choices, downloaded maps and recent searches do not sync. The only other thing the server keeps for your account is the share links you have made, described under "Sharing a link".
Each record reaches the server as an id, a timestamp and a block of JSON. The server checks that the block is a JSON object and how big it is, and stores it as text. It never reads a field inside it, never indexes it, and no feature anywhere depends on its contents.
Sharing a link
On the web map you can make a share link for a waypoint, route, track or trip. Nothing is published until you do.
- A share link shows that one record to whoever opens it — its name, its notes, and every coordinate in it — with no account and no sign-in. Photographs are never included.
- You choose how long it lives: a day, a week, thirty days, or until you revoke it. Revoking is immediate, and no cache anywhere is allowed to keep the answer.
- The server keeps the link, what it points at, when it expires, and when you revoked it. Deleting your account deletes every link you made.
- A link pasted into a message is fetched by that messaging service, which sees the record's name and where it is, the way it does with any link. The page itself tells search engines not to index it.
The app does not make share links today.
Location and motion
The app asks for location While Using the App. It never asks for Always.
Three things keep the receiver running with the screen off, and the first two show the blue indicator in your status bar the whole time:
- A recording you started, until you stop it.
- Following a route, so an off-route alert reaches you with the phone in your pack.
- A one-shot fix for the watch, when the watch asks where you are.
Location draws your position, measures distance and bearing to anything you tap, records a track you asked for, and places a photo. Nothing else.
Motion is read on the device. While a recording runs, Glassing reads the motion coprocessor to decide how hard the GPS receiver has to work — walking means fixes, standing still means fewer — and reads the barometer to sharpen the elevation on the track. When you stop a recording, it asks iOS for the activity history of the past week to notice a drive you forgot to stop recording. The coprocessor's readings and the week's history stay on the phone. The barometer's contribution becomes part of each track point's elevation, so, signed in, it syncs with the track like every other number on that point.
Off-route alerts are local notifications. Glassing has no push certificate, mints no device token, and no notification is ever composed on a server. The alert is marked time-sensitive so it can break through a Focus.
Health
Finishing a recording writes one hiking workout to Apple Health: its start and end, the pauses, the distance, the elevation ascended, and the route.
- Glassing reads nothing of yours from Health. The authorization request asks for write access and lists no read types at all. The one query Glassing makes looks only for a workout it wrote itself, so it does not write the same hike twice.
- Health data never leaves your phone. It goes into your own Health store, and no sync path, no server request and no export touches it.
- It is not shared with third parties, and not used for advertising, marketing, or data mining. Health data serves one purpose: the workout record you asked for by pressing Stop.
- Deleting your Glassing account does not touch it. Those workouts are yours, held by iOS. Delete them in Health; revoke write access in Settings → Health → Apps.
Photos
Three paths, and they behave differently:
- A photo taken inside Glassing is saved without GPS coordinates in the image file. Where it was taken is kept in the photo's own record, from the app's fix, so you can move or remove it like any other mark.
- A photo added from your library on the phone is stored exactly as it is, which means it keeps whatever location its original camera wrote in. Signed in, that photo syncs with that information in it. A photo added on the web map is re-encoded to fit a screen on the way in, and the re-encoding leaves the original camera's data behind.
- A photo shared out of the app leaves without the camera's location. The GPS block, every camera maker note, the body and lens serial numbers and the camera-owner name are stripped from the outgoing copy every time, and so are the IPTC and XMP blocks a photo editor can mirror a location into. Nothing to switch on, and your own copy is untouched. What stays is the picture, the moment, the exposure, the make and model, and which way up it goes.
The app has no access to your photo library. iOS shows its own picker and hands over only the picture you chose.
Photo files are stored in Cloudflare R2. The picture travels through Glassing's server on its way to the bucket and is never opened there. Downloading one answers with a short-lived signed link, valid for five minutes; the server never reads a photo's EXIF or makes a thumbnail.
Purchases
Glassing sells one subscription, through the App Store. Apple processes the payment, and Glassing never sees a card, a bank account, or a billing address.
Three things do reach Glassing's server, and they exist so a renewal Apple reports two years from now finds the right account:
- An app-account token — a random identifier this install generates, kept in app storage, and attached to every purchase. It identifies a purchase, not a person, and unlocks nothing on its own.
- A signed transaction, posted once after a purchase so the account is current without waiting for a webhook. It is verified and discarded. No receipt body is stored.
- One entitlement row — status, plan, source, expiry, and the two identifiers Apple joins a purchase by. A row, not a ledger: no history of past transactions is kept, and it decides one thing only, whether saving is permitted.
Apple's own notifications record an identifier, a type and an environment, so a retry of the same renewal is recognized as a retry. Those rows carry no account.
The trial is one per account. The date a trial started is written once and never cleared, so a converted or lapsed trial still counts as used. Deleting the account deletes that date with everything else.
An offer code you redeem is Apple's; it reaches Glassing as a transaction like any other and stores nothing about you beyond the row above.
Stripe is not in use. Nothing in the app or on the server takes a payment.
Land ownership
Some of what Glassing draws is about other people. The Ownership overlay is off until you turn it on. With it on, tapping private ground shows what a county assessor's tax roll records about that parcel: the county, the acreage, the number of taxlots, and — for some timber and industrial owners — a link to their own access rules.
No private individual is ever named. Where the roll's owner of record is a company, the card names the company, because a company's name is how you find its access rules. Where the owner is a person, the card names nobody. In that person's place it shows the parcel's own street address — the number and the street, a fact about the ground and not a way to reach anybody. There is no unit, no city and no ZIP, because the card is answering where this ground is and not where somebody lives.
- It comes from public county records. Glassing redraws them on a map and adds nothing. Mailing addresses, phone numbers and email addresses are never requested from the county and are not in the map, and neither is the city or ZIP of a parcel's own address.
- It is not collected from you and not joined to you. The overlay streams from Glassing's server like any other online layer; tapping a parcel sends nothing to anyone.
- It is in a downloaded map on the same terms. A downloaded map carries the parcels under it exactly as the streamed overlay draws them: the same records, the same withheld names, so the radio being off changes nothing about what is shown or who is named.
- Glassing cannot be searched by owner and never will be.
- Rolls lag. What a parcel card says can be years behind what the county recorded.
If a parcel is yours and you want what the map says about it taken down, write to privacy@glassing.app.
Map data and the servers behind it
Drawing a map means asking for tiles. Working from a downloaded map asks nobody: the tiles come off your own phone and no server is contacted at all.
Online, these requests go out from the app:
- Glassing's own server (
sync.glassing.app), for satellite and hybrid imagery, contours, streamed terrain, the coverage index, and a version check on launch. No account is needed, and none of these requests carries one. - The United States Geological Survey (
basemap.nationalmap.gov), for the online topo base map. - A public elevation-tile archive on Amazon Web Services, for slope outside a downloaded area.
The web map reads its archives from tiles.glassing.app, a storage bucket of Glassing's with nothing in front of it, and its search and account requests from glassing.app.
Four requests carry coordinates rather than tile numbers, and are worth naming one by one:
- Place search sends your query text, and your position when the app has one, so nearby places rank first. The web map sends the center of the map instead of your position. It carries no account, even when you are signed in.
- Naming ground sends one point and asks what it is called. The app sends the center of a map you are about to download, so it gets a name instead of "Downloaded area". The web map sends the center of a group of places you are importing, so a trip gets a name, and a share page sends the location of the record it is showing. It carries no account.
- Route snapping sends the coordinate pairs of a route you are drawing, so the line follows the trail. This one carries your session, because the router is expensive. The server computes and answers; it writes nothing.
- Importing a file on the web map sends the names of the places in it, and nothing else — no coordinates, no notes, no account — so an icon can be suggested for the ones the file left bare. See the next section.
None of the four is written down. The access log records the path a request hit, never its query string and never its body, so search terms and coordinates do not land in it.
Glassing updates downloaded maps without a tap, on Wi-Fi and only while the phone is charging. The whole check refuses cellular and Low Data Mode outright — including the up to 64 KB of the coverage index it reads to find out whether anything changed — and a map downloads only when that map actually moved.
A parcel can carry a link to its owner's website. Following it is a visit to their site, under their rules, and Glassing asks before opening one.
Requests to USGS and to Amazon show those servers your IP address and which tiles you asked for, which is a rough indication of where you are looking. Glassing does not control them, they receive no account and nothing you recorded, and their operators' policies apply to their logs.
Importing a file on the web map
When you import a GPX, KML or KMZ file on the web map, the names of the places in it are sent to Glassing's server, which asks a hosted language model on Amazon Web Services to propose an icon for each name that the file did not give one. The names go verbatim; no coordinates, notes, dates or account go with them, and the answer is a list of icon names. Neither Glassing nor Amazon keeps the names, and the model is not trained on them.
The phone does this without a server: the app reads the names on the device, and they never leave it.
The web map at glassing.app
The web map is the same account and the same data, in a browser. Signed in, you can see, create, rename, annotate, color, file and delete waypoints, routes, tracks and trips; move a pin; redraw a route; import GPX, KML and KMZ files; export anything as GPX; add and view photographs; make and revoke share links; and delete the account. Recording a track is the phone's job, and the web map does not do it.
- No cookies. Glassing sets none. The session token lives in the browser's local storage, along with the account it belongs to — an identifier, and an email address if Apple shared one. The worker that relays the account API drops a cookie on the way out and a set-cookie on the way back, so neither can ever become a credential.
- No analytics, no advertising, no tracking scripts. The page loads its own code and nothing else, with one exception you have to ask for: choosing Sign in with Apple fetches Apple's sign-in script from
appleid.cdn-apple.comand opens Apple's own window. Somebody who only reads the map never loads it. - What the browser remembers stays in the browser. Your layer choices, the shape of the panel, the rows you have hidden, and, signed in, your session and account. Clearing site data clears all of it.
- Your position is drawn only if you ask for it, through the browser's own permission. It is not stored and not sent anywhere.
- 3D terrain makes the one outside request the browser makes — to the same public elevation archive on Amazon Web Services the app uses, for ground Glassing's own pyramid does not cover. It is off until you turn it on.
- The "Fresh" satellite overlay is a web feature. Each tile is rendered on demand by a small service of Glassing's on Amazon Web Services, asked for by the map page's own origin with the tile's coordinates and nothing else — no account, no session, no IP address of yours. It needs a connection, which is why it is not in the app.
Signing out clears the token locally first, whether or not the network agrees.
The watch app
The watch shows the recording, the map around it, your pins and the way to a target. It reads its own compass for heading and nothing else: the watch has no GPS of its own and makes no network requests. Position, pins and map frames come from the phone over Apple's device-to-device link, and commands — start, pause, drop a waypoint — go back the same way.
Diagnostics
Settings → Share Diagnostics builds a zip and hands it to the share sheet. Nothing uploads it, and it goes only where you send it.
It contains a copy of your whole library — every waypoint, route, track and trip, which means your full coordinate history — plus Apple's performance and crash payloads, the app's own frame-timing ledger, and four facts about the build: app version, build number, iOS version, and when the zip was made. It carries no account identifier, because the library holds none, and no photos.
Read that as the warning it is: the zip is your marks. Send it to somebody you trust with them.
What Glassing does not collect
- No analytics, no advertising, no tracking. The app contains no third-party analytics, advertising, or attribution tools. It does not use the advertising identifier and does not track you across apps or websites. Two third-party libraries ship with it — MapLibre for the map, GRDB for the database — and neither talks to anyone.
- No crash-reporting service. Apple's MetricKit, written to your phone and left there.
- No contacts, no microphone, no browsing history.
- No search history on Glassing's side.
- No payment information.
Servers and logs
Glassing's server writes one line per request: the time, the method, the path, the status, how long it took, and the client IP address. No request body and no response body is ever logged. Errors add a class, a message and a stack trace, which is code rather than anything about you. Two kinds of security event add a line of their own: a retired session key being presented again, which names the session and the account it belonged to, and a Sign in with Apple exchange that Apple refused.
The proxy in front of the server keeps no access log for it. When the server behind the proxy is unreachable, the proxy's error log records the request it could not deliver, including its path and headers, so a query string can appear there during an outage and nowhere else.
Downloading offline maps contacts the server without an account, so those requests appear in the log the way sync requests do — an address and a path, no coordinates.
Access logs rotate by size: the oldest lines drop as new ones arrive, and nothing is archived anywhere else.
Two providers process data on Glassing's behalf. Amazon Web Services hosts the sync service, its database and its backups, renders the Fresh overlay, and serves the model that names icons; Cloudflare serves the website, the map tiles and the photo files, sits in front of the server, and sees IP addresses and request paths the way any web host does. Both act as processors and neither is permitted to use your data for its own purposes.
No third-party error tracker is configured, and no account exists at one.
Security
- Everything between the app and the server travels over HTTPS. A release build refuses a plaintext server address outright.
- Your session key lives in the iOS keychain, not ordinary app storage, and never syncs to iCloud or moves in a device transfer.
- The server stores only a cryptographic hash of that key, so a copy of the database cannot be used to sign in as you.
- A session key rotates after 30 days, and a session unused for a year is deleted. Replaying a retired key ends the whole family of sessions it belongs to.
- What you sync is stored opaquely and never read.
No system is perfect, and this policy will not pretend otherwise. What you store is not encrypted at rest with a key only you hold. Encrypting it that way would be better, and if it ships this policy will say so.
How long things are kept
- Photos: deleting a photo in the app deletes the file from storage in the same sync pass. A cleanup job catches whatever a dropped connection left behind.
- Records: deleting a waypoint, route, track or trip syncs the deletion so your other devices delete it too. A marker of the deleted item stays, so sync stays consistent across devices, until you delete your account.
- Share links: until they expire or you revoke them. A revoked link's row stays, marked revoked, until you delete your account.
- Sessions: a device that has not synced for a year has its session deleted, and you sign in again the next time you use the app there. Signing out ends a session immediately. Neither deletes anything you recorded.
- Database backups: seven days, on a rolling schedule, encrypted, at the database host.
- Access logs: rotated by size, as described above.
- Your account: kept as long as it exists, because your data is the entire reason it exists. Inactive accounts are not deleted without telling you first.
Deleting your account
Settings → Account → Delete Account, or the account panel on the web map. It removes your account record, your synced waypoints, routes, tracks, trips and photos, every photo file stored for you, your sessions, every share link you made, and your entitlement row. Glassing's access to your Apple Account is revoked with Apple in the same operation.
Deletion is immediate in the live database. It is not a request in a queue and it is not reversible: the data is gone from the live systems before the app says it worked. Encrypted database backups are kept for seven days on a rolling schedule; a deleted account's rows age out of them within that window, and nothing is restored from a backup except to recover the whole service.
Two other things do not go, and both are worth saying plainly:
- Apple notification receipts — an identifier, a type and a timestamp for each notification Apple has delivered. They carry no account, no name and nothing about where you went, and they exist so a retried renewal is not processed twice.
- Access log lines already written, until they rotate out.
Deleting your account does not touch your phone. Everything you recorded stays in the app, and the app keeps working without an account. Delete the app to remove it from the phone. The workouts in Health are yours and stay in Health.
Signing out is the smaller version: it ends the session on this phone and on the server, and your account and its data are waiting when you sign back in.
You can export your waypoints, routes and tracks as GPX at any time, with or without an account. They are yours, in a format any other app reads.
Your rights
Wherever you live, you can ask what Glassing holds about you, correct it, delete it, or have it handed over in a portable form. Write to privacy@glassing.app for an answer within 30 days. Most of it needs no asking: GPX export is your data, and account deletion is in the app.
If a parcel is yours and you want what the map says about it taken down, the same address takes that request.
Glassing does not sell personal information and does not share it for cross-context behavioral advertising. There is nothing here to opt out of.
Children
Glassing is not directed to children under 13, and collects nothing knowingly from them. Write to privacy@glassing.app if you believe a child has created an account and it will be deleted.
Changes
If this policy changes in a way that affects what is collected or what is done with it, the effective date above moves and the change is listed under "What changed". Nothing new starts being collected quietly.
What changed on September 5, 2026
- No private individual is named. The Land ownership section is rewritten to the way the overlay now works: a company owner is named, a person is not, and the parcel's own street address stands in a person's place.
- Parcels are in a downloaded map again. The previous version said the overlay only streams. From this version a downloaded map carries the parcels under it, with the same records and the same withheld names as the streamed overlay.
- Automatic map updates refuse cellular outright, including the coverage-index read that starts the check. The previous version carved that read out.
- Diagnostics reports can be erased from Settings, which the previous version did not claim because a shipping build had no way to do it.
What changed on September 4, 2026
Read from the code again, twelve days on, this version adds or corrects:
- Land ownership has its own section. The Ownership overlay shows the owner a county tax roll records, and a removal address is given.
- Share links have their own section. A link you make publishes one record to whoever holds it; nothing else is ever published.
- Importing a file on the web map sends place names to a hosted model for icon suggestions. The phone does the same job on the device.
- Database backups are named, with their seven-day window, where the previous version said a deleted account existed nowhere.
- The barometer is named beside the motion coprocessor, and its contribution to a track's elevation syncs with the track.
- The web map's section matches the web map: what it can do, Apple's sign-in script, what local storage holds, where tiles come from, the browser's own location permission, 3D terrain's outside request, and how the Fresh overlay is rendered.
- One subscription. The purchase section describes a single plan, and offer codes.
- Smaller corrections: a trip's place name and a photo's caption in the sync table; the server checks a record's shape without reading it; a photo upload passes through the server unopened; Health's one duplicate-guard query; the frame-timing ledger in the diagnostics zip; the version check on launch; the 64 KB coverage-index read; the two security-event log lines and the proxy's error log; the account creation date; the refresh token stored as issued; web photos re-encoded on upload.
What changed on August 23, 2026
Read from the code rather than the roadmap, this version adds or corrects:
- Health. A finished recording writes a hiking workout to Apple Health. Nothing is read back and nothing leaves the phone. The previous version said the app touched no health data.
- Purchases. The app-account token, the signed transaction, the entitlement row, and the trial date kept once and never cleared. The previous version said no purchase information reached the server.
- The web map has accounts. It syncs the same records as the app. The previous version described it as viewing-only.
- Background location has three claimants — recording, route following, and the watch's one-shot fix — where the previous version named only recording.
- Search, area naming and route snapping are server requests carrying coordinates, now described one by one, along with what the access log does and does not record.
- Imagery, contours and terrain come from Glassing's own server now, not only from USGS and Amazon.
- Wi-Fi map updates download without a tap, on power, never on cellular.
- Diagnostics. The shared zip contains your whole library, and the policy now says so.
- The watch app has its own section: no GPS, no network.
- Log retention is described as the size-based rotation the deployment performs, replacing a 30-day promise nothing enforced.
- What survives account deletion — Apple notification receipts and unrotated log lines — is named instead of implied.
Contact
Glassing, LLC — privacy@glassing.app