Datenschutzerklärung · Lost in the Woods
Stand: 3. August 2026 · Verantwortlich: Beda Foehn (foehnetics), Luzern, Schweiz · Kontakt: foehnetics@gmail.com
Kurz
Lost in the Woods teilt den Standort einer kleinen Gruppe auf Zeit. Es braucht kein Konto, keine E-Mail-Adresse, keine Telefonnummer und keinen Namen. Standorte werden auf dem Gerät verschlüsselt, bevor sie den Server erreichen; der Server speichert sie als unlesbare Blobs und besitzt den Schlüssel nicht. Die Gruppe löscht sich selbst, wenn ihre Zeit abgelaufen ist.
Es gibt keine Werbung, keine Analyse-Werkzeuge, kein Tracking und keine Weitergabe an Dritte zu Werbezwecken.
Was verarbeitet wird
Standortdaten
Die App erhebt deinen Standort, solange du das Teilen in einer Gruppe aktiv gestartet hast — auch bei ausgeschaltetem Bildschirm, sichtbar durch eine dauerhafte Benachrichtigung.
Standortdaten verlassen das Gerät ausschliesslich verschlüsselt. Die Koordinaten werden mit einem Gruppenschlüssel verschlüsselt, den nur die Mitglieder der Gruppe besitzen. Der Server speichert einen encrypted_payload und kann ihn nicht lesen. Der Schlüssel wird nie an den Server übertragen: er reist im Fragment des Einladungslinks oder im QR-Code, also in dem Teil, den Browser und Server nicht mitsenden.
Nachrichten und Fotos
Nachrichten und Fotos einer Gruppe werden ebenso auf dem Gerät verschlüsselt. Der Server speichert verschlüsselte Blobs. Ein Foto trägt optional die Position, an der es aufgenommen wurde — verschlüsselt wie alles andere.
Was der Server im Klartext sieht
Ehrlichkeitshalber, weil Ende-zu-Ende-Verschlüsselung nicht alles verbirgt:
- Anzeigename. Standardmässig ein automatisch erzeugtes Pseudonym („Stiller Luchs"). Du kannst ihn ändern — der gewählte Name liegt im Klartext auf dem Server, weil die Gruppe ihn lesen können muss. Wähle entsprechend.
- Gruppenname, Ablaufzeitpunkt und Einladungs-Token.
- Mitgliedschaft: wer mit wem in welcher Gruppe ist, seit wann.
- Zeitpunkt und Häufigkeit der Standortmeldungen (nicht ihr Inhalt).
- IP-Adresse, technisch unvermeidbar bei jeder Verbindung.
Die Aussage „zero-knowledge" in dieser App bezieht sich auf Standortdaten, Nachrichten und Fotos — nicht auf die obige Liste.
Konto
Die Anmeldung ist anonym. Es entsteht eine zufällige Kennung ohne E-Mail-Adresse, Telefonnummer oder Namen. Ein Gerätewechsel oder eine Neuinstallation ist ein neues Konto — die App sichert nichts in ein Cloud-Backup (allowBackup="false").
Was auf dem Gerät bleibt
- Gruppenschlüssel im verschlüsselten Systemspeicher des Geräts.
- Zwischenspeicher für Nachrichten und noch nicht gesendete Standorte.
- Kartenkacheln, damit die Karte ohne Empfang funktioniert. Öffentliches Kartenmaterial, kein Personenbezug.
Verlässt du eine Gruppe oder läuft sie ab, werden Schlüssel und Zwischenspeicher lokal gelöscht.
Wie lange
- Wegpunkte werden gelöscht, sobald sie älter sind als die von der Gruppe gewählte Spurdauer (1–48 Stunden). Ein Auftrag räumt stündlich auf.
- Abgelaufene Gruppen werden samt Mitgliedschaften, Standortmeldungen und Nachrichten gelöscht; der Auftrag läuft alle fünf Minuten. Ab dem Ablaufzeitpunkt ist ohnehin nichts mehr lesbar.
- Fotos werden stündlich aus dem Speicher entfernt, sobald ihre Gruppe weg ist. Bis dahin sind sie nicht lesbar, weil der Lesezugriff eine lebende Gruppe voraussetzt.
Es gibt keine Aufbewahrung „für später". Ein abgelaufener Ausflug hinterlässt nichts, womit sich ein Bewegungsprofil bilden liesse.
Wer sonst beteiligt ist
- Supabase (Datenbank, Authentifizierung, Speicher) — Serverstandort eu-west-1 (Irland). Erhält ausschliesslich das oben Beschriebene.
- swisstopo (
wmts.geo.admin.ch) — liefert die Schweizer Landeskarte. Beim Laden von Kacheln sieht der Dienst die IP-Adresse und den betrachteten Kartenausschnitt. Es werden keine Positionen der Gruppe übermittelt. - MapTiler — dasselbe für Karten ausserhalb der Schweiz.
- Cloudflare — liefert die Website
lostinthewoods.appaus: diese Erklärung und die Seite, die ein Einladungslink zeigt. Öffnet jemand einen Einladungslink, ohne die App installiert zu haben, sieht Cloudflare dabei die IP-Adresse und das Einladungs-Token aus der Adresse. Den Gruppenschlüssel nicht — der steht hinter dem#und wird von Browsern nie an einen Server gesendet. Ist die App installiert, öffnet Android sie direkt, und es geht überhaupt keine Anfrage hinaus.
Deine Rechte
Du kannst eine Gruppe jederzeit verlassen, das Teilen jederzeit beenden und die App deinstallieren — Letzteres entfernt alle lokalen Daten samt Schlüssel.
Einschränkung, offen benannt: eine anonyme Kennung lässt sich derzeit nicht aus der App heraus löschen. Sie enthält keine personenbezogenen Angaben, aber sie bleibt bestehen. Für eine Löschung schreib an foehnetics@gmail.com.
Änderungen
Änderungen dieser Erklärung werden hier mit neuem Datum veröffentlicht.
Privacy Policy · Lost in the Woods
As of 3 August 2026 · Controller: Beda Foehn (foehnetics), Lucerne, Switzerland · Contact: foehnetics@gmail.com
In short
Lost in the Woods shares a small group's location for a limited time. It needs no account, no email address, no phone number and no name. Locations are encrypted on the device before they reach the server; the server stores unreadable blobs and does not hold the key. A group deletes itself when its time is up.
There is no advertising, no analytics, no tracking, and no sharing with third parties for advertising purposes.
What is processed
Location data
The app collects your location while you have actively started sharing in a group — including with the screen off, shown by an ongoing notification.
Location data leaves the device only in encrypted form. Coordinates are encrypted with a group key held only by the group's members. The server stores an encrypted_payload it cannot read. The key is never sent to the server: it travels in the invite link's fragment or in the QR code — the part browsers and servers do not transmit.
Messages and photos
Group messages and photos are likewise encrypted on the device; the server stores encrypted blobs. A photo optionally carries the position where it was taken, encrypted like everything else.
What the server does see in the clear
Stated plainly, because end-to-end encryption does not hide everything:
- Display name. By default a generated pseudonym ("Stiller Luchs"). You may change it — a chosen name is stored in the clear, because the group has to be able to read it. Choose accordingly.
- Group name, expiry time and invite token.
- Membership: who is in which group with whom, and since when.
- Timing and frequency of location updates (not their content).
- IP address, unavoidable for any connection.
"Zero-knowledge" in this app refers to location data, messages and photos — not to the list above.
Account
Sign-in is anonymous: a random identifier with no email address, phone number or name. A new device or a reinstall is a new account — nothing is put into a cloud backup (allowBackup="false").
What stays on the device
- Group keys in the device's encrypted system storage.
- Caches for messages and for location updates not yet sent.
- Map tiles, so the map works without signal. Public cartography, not personal data.
Leaving a group, or a group expiring, deletes its key and caches locally.
For how long
- Waypoints are deleted once older than the group's chosen trail duration (1–48 hours); an hourly job removes them.
- Expired groups are deleted together with memberships, location updates and messages, by a job running every five minutes. Nothing is readable past the expiry time in any case.
- Photos are removed from storage hourly once their group is gone. Until then they are unreadable, because read access requires a live group.
Nothing is retained "for later". An expired trip leaves nothing from which a movement profile could be built.
Who else is involved
- Supabase (database, authentication, storage) — hosted in eu-west-1 (Ireland). Receives only what is described above.
- swisstopo (
wmts.geo.admin.ch) — serves the Swiss national map. When tiles are fetched it sees the IP address and which part of the map is being viewed. No group positions are transmitted. - MapTiler — the same, for maps outside Switzerland.
- Cloudflare — serves the
lostinthewoods.appwebsite: this policy and the page an invite link shows. If someone opens an invite link without the app installed, Cloudflare sees the IP address and the invite token from the address. Not the group key — that sits after the#, which browsers never send to a server. With the app installed, Android opens it directly and no request leaves the device at all.
Your choices
You can leave a group at any time, stop sharing at any time, and uninstall the app — which removes all local data including keys.
A limitation, named openly: an anonymous identifier cannot currently be deleted from within the app. It holds no personal details, but it persists. For deletion, write to foehnetics@gmail.com.
Changes
Changes to this policy are published here with a new date.