LEGAL · PRIVACY POLICY

Tornante · Privacy Policy

Effective date: 3 August 2026 · Version 2.0

Tornante is built to keep your data on your phone. This policy explains, in plain language, what the App does and does not do with your data. Data controller: Diego Bianchi, hello@tornanteapp.com.

The short version

  • No account, no sign-up, no advertising, no analytics, no trackers.
  • Your location is never transmitted. GPS is processed on the phone to time the spoken pacenotes; nothing sends it anywhere. The single exception is entirely in your hands: if you write to us and leave the diagnostic run log attached, that log contains the GPS trace of your drive.
  • The App goes online only to prepare a stage: building it, searching for a place, drawing the map, checking the weather. While you drive, it makes no network requests at all.

What the App processes, and where

DataWhere it is processedLeaves the device?
GPS position, speed, heading during a runOn the device onlyNo
Diagnostic run log of each drive (GPS fixes, calls)Stored on the device; newest 20 keptOnly if you attach one to a message
Stages you create/import (routes, names, elevation)Stored on the device (local database)No
App settings (look-ahead, volume, units, language)Stored on the deviceNo
Start/finish/via coordinates when you pick a route on the mapSent to our servers to compute the road pathYes, only these points, only while building the stage
A place name you type into searchSent to the OpenStreetMap Foundation’s public search serviceYes, only the text you type
A stage’s coordinates when you open its detail screenSent to Open-Meteo for the local forecastYes, only those coordinates
Map preview tiles while you set up a stageStandard tile requests to the map tile providerYes (standard web request)

Network requests in detail

Building a stage. When you create a stage by picking points on a map, the App sends only the coordinates you tapped to our own servers (under tornanteapp.com, operated by the Developer), which compute the road path and return the road’s shape. If our servers are unreachable, the same query may be sent as a last resort to a public third-party map-data service so that stage creation still works.

Elevation and weather. Where elevation data is not bundled with the App, elevations along the road are fetched from Open-Meteo (Copernicus GLO-90 data). Open-Meteo also provides the small weather summary shown on a stage’s detail screen: opening that screen sends the stage’s coordinates to fetch the local forecast.

Searching for a place. If you search for a place or address by name, the text you type is sent to the OpenStreetMap Foundation’s public search service to turn it into coordinates.

Maps. Map preview tiles are fetched from CARTO; if you choose the Earth (satellite) map view, imagery tiles are fetched from Esri instead.

Service status. If you open the service-status screen in Settings, the App pings the services above to check whether they are reachable. These pings carry no data about you.

None of these requests include identifiers, an account, or any history; they are used only to compute the response, are not profiled or linked to you, and are not retained beyond ordinary short-lived technical logs. As with any internet request, the operator of a service sees your IP address. No request of any kind is made while you drive.

Location permission

The App asks for location permission (“While Using”, optionally “Always” for screen-off/pocket use) solely to time the pacenotes during a run. Location is used in real time and is never transmitted or used for any other purpose. A diagnostic run log (GPS fixes, the calls played, GPS-lost events) is written on the phone for each drive so that problems can be investigated; the newest 20 are kept, they are never uploaded, and you can read or delete them at any time under Settings → About → Run logs. You can revoke the location permission in iOS Settings; the App then works in replay mode only.

Feedback you send us

Sending feedback opens your own mail app with a message addressed to hello@tornanteapp.com. Nothing is transmitted in the background: you see the message and send it yourself, and you can cancel at any point.

Whatever you include reaches the Developer: your message, the email address you send from, any screenshots you attach, and, unless you switch the attachment off, the most recent diagnostic run log, which contains the GPS trace of that drive. Turn the attachment off if you would rather not share it. If your mail app is unavailable or you cancel, the report stays in a local outbox on your phone until you choose to send it; it is not uploaded. Reports are used only to answer you and to fix the App, never for marketing, never shared with anyone.

What the App does NOT do

  • No collection of personal data by the Developer: no accounts, no user database; our servers answer each request and store nothing about you.
  • No analytics or crash-tracking SDKs, no advertising, no fingerprinting.
  • No background uploads of any kind: the only information that reaches the Developer is a message you compose and send yourself.
  • No sale or sharing of any data with anyone.

Beta builds (TestFlight)

If you take part in a beta, those builds are distributed through Apple TestFlight, and Apple provides the Developer with anonymised crash logs and basic beta statistics under Apple’s TestFlight terms and privacy policy. This is Apple’s collection, governed by Apple’s policies; the App itself adds no telemetry.

This website (www.tornanteapp.com)

This section covers the Tornante website only. The App itself remains analytics-free, as described above.

  • Vercel Web Analytics runs on every page. It is cookieless: it counts visits in aggregate (page, country, device type) using no cookies, no persistent identifiers, and no cross-site tracking, so it requires no consent.
  • Google Analytics 4 runs only if you accept the cookie banner. Until you accept, no Google script is loaded and no request is sent to Google. If you accept, Google Analytics (provided by Google Ireland Ltd.) sets cookies to measure how the site is used: pages visited, session counts, approximate location derived from your IP address (GA4 does not log or store the IP itself). We use this data only in aggregate, to understand which pages matter; advertising features, ad personalisation, and data sharing with other Google products are disabled.
  • Your choice is stored in your browser (localStorage), not on a server. You can change or withdraw it at any time via “Cookie preferences” in the site footer, which stops measurement immediately, or by clearing the site’s browser data.

Your rights (GDPR)

Because the App stores your data only on your device and the Developer holds no personal data about you, most GDPR requests (access, rectification, erasure) are satisfied directly on your phone: deleting a stage, a run log, or the App itself removes the data. If you have written to us, you may ask us to delete that correspondence and anything attached to it. For anything else, contact hello@tornanteapp.com. You also have the right to lodge a complaint with your supervisory authority (in Italy: the Garante per la Protezione dei Dati Personali).

Changes

Material changes to this policy will be shown in the App and reflected in the effective date above.