Privacy Policy
How CoordKit handles your location, your saved points and everything else.
Effective 12 September 2026·Last updated 12 September 2026
The short version. CoordKit reads your location to show you your coordinates. That location is processed on your device. The points, measurements and photos you save stay on your device — there is no CoordKit account and no CoordKit server holding your data. A coordinate leaves your device only when a feature you used needs an answer from someone else: a map tile, a place search, an address, or a ground elevation. We never send your location to our analytics.
1. Who we are
CoordKit ("the app", "we", "us") is published by Dewmina Udayashan. This policy explains what the app does with information about you, and applies to the CoordKit mobile application on iOS and Android. It does not apply to the App Store or Google Play themselves, which have their own policies.
For the purposes of the UK and EU General Data Protection Regulation, Dewmina Udayashan is the data controller for the limited processing described below.
2. What CoordKit collects
The table below is the complete list. Anything not in it, the app does not collect.
| Category | What it is | Where it goes |
|---|---|---|
| Precise location | GPS/GNSS latitude and longitude, altitude, heading, speed and the accuracy of the fix, while the app is open | Processed on your device. Shared with third parties only for the specific features in §3. |
| Saved points & measurements | Coordinates, labels and notes you choose to save | Stored only on your device. |
| Stamped photos | Photos you take in the app, with coordinates, elevation and time written into the image and its EXIF metadata | Saved to your device's photo library. Never uploaded by us. |
| Search queries | Text you type when searching for a place | Sent to Google Places to return results. |
| Usage & diagnostics | Which screens and tools are opened, whether onboarding finished, app version, device model, OS version, language, and crash reports with stack traces | Firebase Analytics and Crashlytics (production builds only). |
| Purchase status | Whether a subscription or lifetime purchase is active, its store transaction identifiers, and a randomly generated app user identifier | RevenueCat, Apple and Google. |
CoordKit has no accounts. We never ask for your name, email address, phone number or a password, and we do not have a server that stores your points.
3. How your location is used
Location is the product: the app exists to tell you where you are and what that place is called in six coordinate formats. It is requested as "while using the app" only. CoordKit does not track you in the background, and does not request background or "always" location permission.
Your coordinate is transmitted off the device in exactly four situations, each of them a feature you chose to use:
- The map. The area you are looking at is sent to Google Maps so it can return tiles to draw.
- The address. The coordinate under the crosshair is sent to the device's own geocoding service — Apple's on iOS, Google's on Android — to turn it into a street address.
- Ground elevation. The coordinate is sent to Open-Meteo's public elevation API to look up terrain height. It is rounded to roughly an 11-metre grid before it is sent, and cached, so panning the map does not stream your exact position.
- Place search. What you type, plus a location bias, is sent to Google Places.
Your location is never included in analytics events, crash reports or advertising requests, and is never sold or shared for marketing.
4. What stays on your device
Saved points, measurement sessions, your settings, unit and format preferences, and the photos you stamp are written to local storage on your phone. They are not synchronised, not backed up by us, and not readable by us. If you delete the app, that data is deleted with it — so export anything you want to keep first.
When you export points to GPX, KML or CSV, or share a coordinate, the file goes wherever you send it through your device's share sheet. At that point it is governed by whichever app or service you chose.
5. Third-party services
These are the only third parties that receive anything, and what each one gets:
| Service | Purpose | Receives | Policy |
|---|---|---|---|
| Google Maps SDK | Map display | Viewed map area, device and network data | policies.google.com/privacy |
| Google Places | Place search | Search text, location bias | policies.google.com/privacy |
| Apple / Google geocoding | Coordinate → address | The coordinate being read | apple.com/legal/privacy · Google |
| Open-Meteo | Terrain elevation | A coordinate rounded to ~11 m | open-meteo.com/en/terms |
| Firebase Analytics & Crashlytics (Google) | Usage measurement, crash diagnostics | Pseudonymous app instance ID, device and app metadata, event names, crash traces | firebase.google.com/support/privacy |
| RevenueCat | Subscription management | Anonymous app user ID, store receipts, entitlement status, country | revenuecat.com/privacy |
| Apple App Store / Google Play | Billing | Your purchase, handled entirely by the store | Store policies |
Analytics and crash reporting run in production builds only; development builds report nothing.
6. Advertising and tracking
CoordKit shows no advertising, and contains no advertising software. There is no ad SDK in the app, no ad network receives anything about you, and no advertising identifier (IDFA or Android Advertising ID) is read or requested. CoordKit never shows Apple's App Tracking Transparency prompt, because there is nothing in it that would track you.
CoordKit does not track you across other companies' apps or websites, and has no capability to do so. If that ever changes, this policy will be updated and your consent obtained before any such feature ships.
We do not sell or share personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, and we have never done so.
7. Purchases and subscriptions
CoordKit Pro is sold as a subscription or a one-time purchase through the App Store or Google Play. Your payment details never reach the app or us — the store handles payment and tells us only whether an entitlement is active.
We use RevenueCat to validate store receipts and keep your purchase working across reinstalls and devices signed into the same store account. RevenueCat identifies your install with a randomly generated identifier that is not linked to your name or email.
8. Why we are allowed to process this (UK/EU)
- Performance of a contract — location, map, address, elevation and search processing. Without them the app cannot do the thing you installed it for.
- Legitimate interests — aggregate usage measurement and crash diagnostics, to keep the app working and decide what to build. The data is pseudonymous and excludes your location.
- Consent — device permissions (location, camera, photo library, motion). You can withdraw any of these at any time in your device settings.
9. How long anything is kept
- On your device — until you delete the item, clear the app's data, or uninstall the app.
- Analytics — retained by Firebase for up to 14 months, then deleted automatically.
- Crash reports — retained for up to 90 days.
- Purchase records — kept for as long as your entitlement is active plus the period the stores and tax law require.
- Requests to third parties (map, address, elevation, search) — we keep no log of them at all; each provider's own retention applies.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, port, or object to the processing of your personal data, and to complain to your data protection authority.
Because CoordKit holds your points and photos on your device only, most of these you can exercise directly and immediately:
- Access and portability — export your saved points to GPX, KML or CSV from the library.
- Deletion — delete individual points in the app, or uninstall the app to remove everything local.
- Stop location processing — revoke location access in iOS Settings or Android app permissions. The map still works; you simply lose "where am I".
- Analytics — limit app analytics in your device's privacy settings, or contact us to request deletion of the data associated with your install.
For anything you cannot do yourself, write to support@dewmina.dev and we will respond within 30 days. We will never charge you for exercising a right, and we will not discriminate against you for doing so.
11. International transfers
The providers listed in §5 operate globally, so data sent to them may be processed outside your country, including in the United States. Where required, those transfers rely on the European Commission's Standard Contractual Clauses or an equivalent approved mechanism, as set out in each provider's own policy.
12. Children
CoordKit is a general-audience utility and is not directed at children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Security
All network requests use HTTPS. Data on your device is protected by your device's own storage protections and passcode. No system is perfectly secure, but the strongest protection here is structural: there is no CoordKit account and no CoordKit database of your locations to breach.
14. Changes to this policy
If this policy changes materially — in particular, if a new processor is added — we will update the "Last updated" date and, for significant changes, tell you in the app before the change takes effect.
15. Contact
Questions, requests or complaints: support@dewmina.dev.
© 2026 Dewmina Udayashan. CoordKit and this policy are provided for the CoordKit mobile application. Apple and App Store are trademarks of Apple Inc. Google, Google Play, Google Maps and Firebase are trademarks of Google LLC.