Privacy Policy

Effective September 5, 2026

Glassing is a backcountry map. It shows you where you stand, records where you walked, and keeps the marks you make on the land. Where you hunt, hike and ski is nobody's business but yours. This policy says what happens to that information — every flow, including the ones that are inconvenient to admit — rather than reserving rights nobody intends to use.

Glassing — the iOS app, the watch app, and the web map at glassing.app — is published by Glassing, LLC, a Delaware limited liability company. Write to privacy@glassing.app if anything below is unclear.

The short version

What stays on your phone

Signed out, nothing you record leaves the device. Your position, your tracks, your waypoints, your photos, your notes and your recent searches live in the app's own storage.

These stay on the phone whether or not you sign in:

Drawing a map still contacts map servers — see "Map data and the servers behind it" — but nothing you have recorded is part of those requests.

Signing in

Sign in with Apple is the only sign-in Glassing offers. The app sends Apple's identity token, and an authorization code when Apple supplies one. Nothing else goes with it.

From the verified claims inside that token the server stores a stable Apple identifier and, when Apple provides one, an email address — which is Apple's private relay address if you chose Hide My Email. The account row also records the date it was made. The authorization code is exchanged with Apple for a refresh token, stored as Apple issued it, which exists for exactly one purpose: revoking Glassing's access to your Apple Account when you delete your Glassing account.

What syncs

Signed in, five kinds of record sync to your account:

What What it contains
WaypointsCoordinates, elevation, name, notes, symbol, timestamps
TracksEvery recorded position: coordinates, elevation, time, accuracy, speed, heading
RoutesThe line you drew and its points
TripsTitle, notes, dates, and the place name the app gave it
PhotosThe picture itself, a caption, where and when it was taken, and which waypoint or trip it belongs to

That is the whole list of what syncs, and the server enforces it — a sixth kind of record has nowhere to sync to. Settings, layer choices, downloaded maps and recent searches do not sync. The only other thing the server keeps for your account is the share links you have made, described under "Sharing a link".

Each record reaches the server as an id, a timestamp and a block of JSON. The server checks that the block is a JSON object and how big it is, and stores it as text. It never reads a field inside it, never indexes it, and no feature anywhere depends on its contents.

Sharing a link

On the web map you can make a share link for a waypoint, route, track or trip. Nothing is published until you do.

The app does not make share links today.

Location and motion

The app asks for location While Using the App. It never asks for Always.

Three things keep the receiver running with the screen off, and the first two show the blue indicator in your status bar the whole time:

Location draws your position, measures distance and bearing to anything you tap, records a track you asked for, and places a photo. Nothing else.

Motion is read on the device. While a recording runs, Glassing reads the motion coprocessor to decide how hard the GPS receiver has to work — walking means fixes, standing still means fewer — and reads the barometer to sharpen the elevation on the track. When you stop a recording, it asks iOS for the activity history of the past week to notice a drive you forgot to stop recording. The coprocessor's readings and the week's history stay on the phone. The barometer's contribution becomes part of each track point's elevation, so, signed in, it syncs with the track like every other number on that point.

Off-route alerts are local notifications. Glassing has no push certificate, mints no device token, and no notification is ever composed on a server. The alert is marked time-sensitive so it can break through a Focus.

Health

Finishing a recording writes one hiking workout to Apple Health: its start and end, the pauses, the distance, the elevation ascended, and the route.

Photos

Three paths, and they behave differently:

The app has no access to your photo library. iOS shows its own picker and hands over only the picture you chose.

Photo files are stored in Cloudflare R2. The picture travels through Glassing's server on its way to the bucket and is never opened there. Downloading one answers with a short-lived signed link, valid for five minutes; the server never reads a photo's EXIF or makes a thumbnail.

Purchases

Glassing sells one subscription, through the App Store. Apple processes the payment, and Glassing never sees a card, a bank account, or a billing address.

Three things do reach Glassing's server, and they exist so a renewal Apple reports two years from now finds the right account:

Apple's own notifications record an identifier, a type and an environment, so a retry of the same renewal is recognized as a retry. Those rows carry no account.

The trial is one per account. The date a trial started is written once and never cleared, so a converted or lapsed trial still counts as used. Deleting the account deletes that date with everything else.

An offer code you redeem is Apple's; it reaches Glassing as a transaction like any other and stores nothing about you beyond the row above.

Stripe is not in use. Nothing in the app or on the server takes a payment.

Land ownership

Some of what Glassing draws is about other people. The Ownership overlay is off until you turn it on. With it on, tapping private ground shows what a county assessor's tax roll records about that parcel: the county, the acreage, the number of taxlots, and — for some timber and industrial owners — a link to their own access rules.

No private individual is ever named. Where the roll's owner of record is a company, the card names the company, because a company's name is how you find its access rules. Where the owner is a person, the card names nobody. In that person's place it shows the parcel's own street address — the number and the street, a fact about the ground and not a way to reach anybody. There is no unit, no city and no ZIP, because the card is answering where this ground is and not where somebody lives.

If a parcel is yours and you want what the map says about it taken down, write to privacy@glassing.app.

Map data and the servers behind it

Drawing a map means asking for tiles. Working from a downloaded map asks nobody: the tiles come off your own phone and no server is contacted at all.

Online, these requests go out from the app:

The web map reads its archives from tiles.glassing.app, a storage bucket of Glassing's with nothing in front of it, and its search and account requests from glassing.app.

Four requests carry coordinates rather than tile numbers, and are worth naming one by one:

None of the four is written down. The access log records the path a request hit, never its query string and never its body, so search terms and coordinates do not land in it.

Glassing updates downloaded maps without a tap, on Wi-Fi and only while the phone is charging. The whole check refuses cellular and Low Data Mode outright — including the up to 64 KB of the coverage index it reads to find out whether anything changed — and a map downloads only when that map actually moved.

A parcel can carry a link to its owner's website. Following it is a visit to their site, under their rules, and Glassing asks before opening one.

Requests to USGS and to Amazon show those servers your IP address and which tiles you asked for, which is a rough indication of where you are looking. Glassing does not control them, they receive no account and nothing you recorded, and their operators' policies apply to their logs.

Importing a file on the web map

When you import a GPX, KML or KMZ file on the web map, the names of the places in it are sent to Glassing's server, which asks a hosted language model on Amazon Web Services to propose an icon for each name that the file did not give one. The names go verbatim; no coordinates, notes, dates or account go with them, and the answer is a list of icon names. Neither Glassing nor Amazon keeps the names, and the model is not trained on them.

The phone does this without a server: the app reads the names on the device, and they never leave it.

The web map at glassing.app

The web map is the same account and the same data, in a browser. Signed in, you can see, create, rename, annotate, color, file and delete waypoints, routes, tracks and trips; move a pin; redraw a route; import GPX, KML and KMZ files; export anything as GPX; add and view photographs; make and revoke share links; and delete the account. Recording a track is the phone's job, and the web map does not do it.

Signing out clears the token locally first, whether or not the network agrees.

The watch app

The watch shows the recording, the map around it, your pins and the way to a target. It reads its own compass for heading and nothing else: the watch has no GPS of its own and makes no network requests. Position, pins and map frames come from the phone over Apple's device-to-device link, and commands — start, pause, drop a waypoint — go back the same way.

Diagnostics

Settings → Share Diagnostics builds a zip and hands it to the share sheet. Nothing uploads it, and it goes only where you send it.

It contains a copy of your whole library — every waypoint, route, track and trip, which means your full coordinate history — plus Apple's performance and crash payloads, the app's own frame-timing ledger, and four facts about the build: app version, build number, iOS version, and when the zip was made. It carries no account identifier, because the library holds none, and no photos.

Read that as the warning it is: the zip is your marks. Send it to somebody you trust with them.

What Glassing does not collect

Servers and logs

Glassing's server writes one line per request: the time, the method, the path, the status, how long it took, and the client IP address. No request body and no response body is ever logged. Errors add a class, a message and a stack trace, which is code rather than anything about you. Two kinds of security event add a line of their own: a retired session key being presented again, which names the session and the account it belonged to, and a Sign in with Apple exchange that Apple refused.

The proxy in front of the server keeps no access log for it. When the server behind the proxy is unreachable, the proxy's error log records the request it could not deliver, including its path and headers, so a query string can appear there during an outage and nowhere else.

Downloading offline maps contacts the server without an account, so those requests appear in the log the way sync requests do — an address and a path, no coordinates.

Access logs rotate by size: the oldest lines drop as new ones arrive, and nothing is archived anywhere else.

Two providers process data on Glassing's behalf. Amazon Web Services hosts the sync service, its database and its backups, renders the Fresh overlay, and serves the model that names icons; Cloudflare serves the website, the map tiles and the photo files, sits in front of the server, and sees IP addresses and request paths the way any web host does. Both act as processors and neither is permitted to use your data for its own purposes.

No third-party error tracker is configured, and no account exists at one.

Security

No system is perfect, and this policy will not pretend otherwise. What you store is not encrypted at rest with a key only you hold. Encrypting it that way would be better, and if it ships this policy will say so.

How long things are kept

Deleting your account

Settings → Account → Delete Account, or the account panel on the web map. It removes your account record, your synced waypoints, routes, tracks, trips and photos, every photo file stored for you, your sessions, every share link you made, and your entitlement row. Glassing's access to your Apple Account is revoked with Apple in the same operation.

Deletion is immediate in the live database. It is not a request in a queue and it is not reversible: the data is gone from the live systems before the app says it worked. Encrypted database backups are kept for seven days on a rolling schedule; a deleted account's rows age out of them within that window, and nothing is restored from a backup except to recover the whole service.

Two other things do not go, and both are worth saying plainly:

Deleting your account does not touch your phone. Everything you recorded stays in the app, and the app keeps working without an account. Delete the app to remove it from the phone. The workouts in Health are yours and stay in Health.

Signing out is the smaller version: it ends the session on this phone and on the server, and your account and its data are waiting when you sign back in.

You can export your waypoints, routes and tracks as GPX at any time, with or without an account. They are yours, in a format any other app reads.

Your rights

Wherever you live, you can ask what Glassing holds about you, correct it, delete it, or have it handed over in a portable form. Write to privacy@glassing.app for an answer within 30 days. Most of it needs no asking: GPX export is your data, and account deletion is in the app.

If a parcel is yours and you want what the map says about it taken down, the same address takes that request.

Glassing does not sell personal information and does not share it for cross-context behavioral advertising. There is nothing here to opt out of.

Children

Glassing is not directed to children under 13, and collects nothing knowingly from them. Write to privacy@glassing.app if you believe a child has created an account and it will be deleted.

Changes

If this policy changes in a way that affects what is collected or what is done with it, the effective date above moves and the change is listed under "What changed". Nothing new starts being collected quietly.

What changed on September 5, 2026

What changed on September 4, 2026

Read from the code again, twelve days on, this version adds or corrects:

What changed on August 23, 2026

Read from the code rather than the roadmap, this version adds or corrects:

Contact

Glassing, LLC — privacy@glassing.app