Summited

Privacy policy

Effective 30 September 2026

The short version

Summited is a local-first app. The logbook on your phone is the source of truth, and the app works without an account. If you create an account, your rounds back up to our servers so you can restore them and share them with the people you choose.

We do not run ads, we do not use analytics or advertising trackers, and we never sell your data. We only share it with the services that run the app, listed below.

Who we are

Summited is built and run by Michael Hutchinson, a sole developer based in the United Kingdom. He is the data controller for the personal data described here. For anything in this policy, email support@summited.app.

Using Summited without an account

You can log summits without signing in. Your rounds, notes and photos then stay in the app's database on your phone and are not sent to us. Uninstalling the app removes them.

Your account

Accounts are optional. If you create one, we store the following in Supabase, hosted in London:

Your rounds

When you are signed in, each summit you log syncs to your account: the summit, the date, any notes, and any photo you attach. Photos are resized on your phone before upload, and a small thumbnail is made on your phone too, so lists and grids load quickly.

Photos and avatars are kept in private storage. There is no public link to them: the app fetches them through short-lived signed URLs, and only for people allowed to see them.

When a round comes from a Strava activity, a GPX file you import, or a companion tag, we also keep where it came from: the source, the Strava activity ID or the member who tagged you, and how close the route passed to the summit. This helps us check that summit detection is accurate. It is never shown to other members in the app.

Who can see what

Your handle, display name, avatar and follower counts are visible to other signed-in members, so they can find you and send a follow request. Other members can search for you by handle or display name.

If your profile is public, any signed-in member can see your rounds, notes, photos, bio, and the cheers and comments on your days. If it is private, only followers you approve can see them.

Blocking someone hides your profile content from each other and removes any follow between you.

Social features

If you use the social side of Summited, we store what you do there so it can be shown to the right people:

Notifications

If you allow notifications, your phone gives us a push token, which we store against your account. Pushes are sent through Expo's push service, which passes them to Google Firebase Cloud Messaging on Android or the Apple Push Notification service on iOS. A push contains the notice itself, for example who cheered your day.

We also keep a history of your notifications for the inbox in the app. Read notifications are deleted after 90 days, and all notifications after 180 days. Records of push delivery attempts are deleted after 30 to 90 days. Signing out removes this phone's push token.

Strava

Connecting Strava is optional. If you connect it, we ask for permission to read your activities, including ones you have marked private on Strava, so we can suggest summits you crossed.

Your phone reads your activity list and each candidate activity's GPS track straight from Strava, and works out the summits on the device. The tracks never reach our servers. The only things kept from that process are the summit and the date of each suggestion you confirm, plus the private provenance described above (the Strava activity ID and match distance).

Your Strava tokens are held in secure storage on your phone, not on our servers. To connect, the app uses a small service we run on Vercel at summited.app that swaps the one-time Strava code for tokens and refreshes them. It holds our Strava app secret and passes your tokens straight back to your phone without storing them.

Disconnecting Strava in Settings tells Strava to revoke our access, deletes the tokens from your phone, and removes any suggestions you have not confirmed. You can also revoke access at any time from your Strava settings. Summits you already confirmed stay in your logbook.

Your location

Location is optional. If you allow it, the app uses your phone's location to show the nearest hills and your position on the map. Your location is used on the phone only and is never sent to our servers. The map itself is drawn by Google Maps on Android and Apple Maps on iOS, which work under Google's and Apple's own privacy policies.

Weather

Hill pages show a forecast from Open-Meteo. The app sends Open-Meteo the coordinates of the hill you are looking at, never your own location.

Crash reports

We use Sentry, in its EU region (Germany), to learn about crashes and errors. A report includes technical details such as the error, the app version, your phone model and operating system, and the steps leading up to the error. Sentry is set not to collect personal information by default and not to store IP addresses, web addresses in reports are stripped of their query strings, and requests to Strava are left out entirely. A few reports about account deletion include your internal account ID so we can finish removing your files.

Our server jobs also send Sentry alerts about their own health. These do not contain your content.

Summited Pro

Summited Pro, when it is available, is a subscription sold through the App Store or Google Play. Apple or Google take your payment, and we use RevenueCat to check your subscription. We receive your subscription status, such as which plan is active and when it renews or ends, never your card or payment details.

Who processes your data

We never sell your data. It is processed only by these services, each under terms that limit what they may do with it:

International transfers

Your account and rounds are stored in the UK. Some of the services above are based in the United States or process data there, including Expo, Google, Apple, Vercel, Strava and RevenueCat, and Sentry may use US sub-processors. Where personal data leaves the UK, we rely on UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where the provider is certified) or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

Our lawful bases

Under UK data protection law (the UK GDPR and the Data Protection Act 2018), we rely on:

How long we keep it

Deleting your account

You can delete your account in the app: Account, then Settings, then Delete account at the bottom. This deletes your account and everything attached to it on our servers, apart from reports, which are kept as moderation records: open reports until they are resolved, and resolved ones for 90 days after the account is deleted. Rounds stored on your phone stay on your phone until you uninstall the app. If you no longer have the app, you can ask us by email. Full details are at summited.app/delete-account.

Children

Summited is not for children under 13, and you must be 13 or over to create an account. If you believe a child under 13 has created an account, email support@summited.app and we will delete it.

Your rights

Under UK data protection law you have the right to access your data and get a copy of it, to have it corrected, to have it erased, to restrict or object to how we use it, and to have it moved to another service. Where we rely on consent, you can withdraw it at any time.

To use any of these rights, email support@summited.app from the email address on your account. We will reply within one month. We may ask you to confirm your identity first.

If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk or on 0303 123 1113.

Security

All traffic between the app and our servers is encrypted. Every table in our database has access rules so members can only read what privacy settings allow, your sign-in session is encrypted on your phone, and the app never holds keys that could bypass those rules.

Changes to this policy

If this policy changes in a way that matters, we will update this page and the effective date at the top, and let you know in the app before the change takes effect.