Privacy Policy for Conquer
Last updated: 30 July 2026
Effective date: 30 July 2026
Table of contents
- Who we are
- Scope of this policy
- Summary at a glance
- The personal data we collect
- Location data and device sensors
- How and why we use your data
- Information that is visible to other users
- Photos you upload
- Push notifications
- Analytics and diagnostics
- Payments and subscriptions
- Who we share your data with
- International data transfers
- How long we keep your data
- Security
- Your rights
- California privacy rights
- Children's privacy
- Cookies and local storage
- Automated summit verification
- Changes to this policy
- How to contact us
1. Who we are
Conquer ("Conquer", "we", "us", "our") is a gamified mountain-hiking application that lets you discover, plan and record peak ascents.
The data controller responsible for your personal data is:
Vegard Nygård
Damsgård 31C, 4318 Sandnes
Norway
Email: conquerapp@proton.me
The data controller decides why and how your personal data is processed and is responsible for it under the EU/EEA General Data Protection Regulation (GDPR), the Norwegian Personal Data Act (personopplysningsloven) and the other laws referenced in this policy.
2. Scope of this policy
This policy explains what personal data we collect, why we collect it, who we share it with and what rights you have. It applies to:
- the Conquer mobile application for iOS and Android; and
- the conquerapp.no website and any related online services
(together, the "Service").
By using the Service you acknowledge the practices described here. If you do not agree with this policy, please do not use the Service.
3. Summary at a glance
| Question | Short answer |
|---|---|
| What is the most sensitive data we collect? | Your precise location, including in the background while you are recording an ascent — and, if you switch on the safety beacon, your live position shown on a public tracking page to anyone you give the link to. |
| Do we sell your personal data? | No. We never sell your data and never use it for cross-app advertising. |
| Do we use your data to show you ads? | No. Conquer contains no advertising. |
| Can other people see my data? | Some of it — see Section 7. Your username, level, achievements, conquests, leaderboard standing and any photos you upload are visible to other users. |
| Can I get a copy of my data, or delete my account? | Yes — both can be done from inside the app at any time. See Section 16. |
| Is the Service for children? | No — you must be at least 13 years old (or older where your country requires it). |
This summary is for convenience only and does not replace the full policy below.
4. The personal data we collect
4.1 Data you give us
- Account data — your email address (used to sign in), your password, and a username and/or display name. Passwords are never stored in plain text: we keep only a salted scrypt hash, which is mathematically infeasible to reverse.
- Profile and settings — language, theme, map style, home location (optional) and other preferences you choose.
- Content you create — conquest plans, direct messages to friends, friend requests, duo/group trip invitations, and photos you capture or upload.
- Support communications — the contents of any message you send us.
- Safety contacts — if you use the safety beacon, the name, phone number, email address and relationship label ("Mom", "Partner") of the people you choose to be alerted about your hikes. This is personal data about them, so please add someone only if they have agreed to it — see Section 5.
If you use Conquer without signing up ("continue as guest"), we still create an account for you so your progress, photos and settings can be saved. It holds no email address and no password until you choose to sign up, and you can delete it from the app in the same way as any other account.
4.2 Data we collect automatically when you use the Service
- Location data — see Section 5.
- Device sensor data — barometric-pressure / altitude readings used to measure your altitude and elevation gain (see Section 5).
- Activity data — the peaks you summit, ascent routes, timestamps, points, levels, streaks, achievements and other in-app progress.
- Device and technical data — device model, operating system and version, app version, language, approximate location derived from your IP address, IP address, and unique identifiers needed to deliver app updates and push notifications.
- Diagnostics — see Section 10.
4.3 Data we receive from third parties
- Sign-in providers — if you sign in with Google or Apple, that provider sends us your name, email address and a unique account identifier. If you use Apple's "Hide My Email" feature, we receive a private relay address instead of your real email.
- App stores — when you purchase a subscription, Apple or Google confirms your subscription status and gives us a transaction identifier (but not your payment card details — see Section 11).
We do not collect special categories of data (such as health, religious or political data) and we ask that you do not submit such data through the Service.
5. Location data and device sensors
Location is the most sensitive data Conquer handles, so we describe it separately.
Precise location. With your permission, Conquer accesses your device's precise GPS location to:
- show you nearby peaks and your "local mastery" progress;
- guide you during an ascent; and
- verify that you reached a summit.
Background location. During an active conquest (a recording session you have started), Conquer continues to access your location in the background — that is, while the app is minimised or your screen is off. This is necessary because a hike takes hours and we must record your route and confirm you reached the top even when you are not looking at your phone. Background location is used only during an active conquest and stops when the session ends.
Route traces. While you record an ascent, we keep the sequence of location fixes that make up your route (your "trace"). Besides drawing your route and verifying your summit, we use these traces — in de-identified, aggregated form, with rest stops and sensor noise removed — to learn how long peaks typically take to climb, so we can show realistic trip-time estimates for every peak, including ones you have never climbed. This model is built by combining many users' traces; it is not used to track you as an individual.
Home location. You may optionally set a home location. We use it to find peaks near you, and we convert those coordinates into a city or area name using a third-party place-name lookup service (see Section 12).
Device sensors. Conquer reads your device's barometric-pressure / altitude sensor during an ascent to measure your altitude and elevation gain (your trip statistics). Your summit itself is verified by GPS (see Section 20).
Safety beacon — live location sharing. If you start a safety beacon,
Conquer records your position for the whole session — including in the
background — and publishes your latest position on a public tracking page at
a secret link (conquerapp.no/track/…). This is separate from an active
conquest: a beacon runs even when you are not recording an ascent.
Anyone holding that link can open the page without an account and see your live position on a map, your display name and profile picture, the peak you are heading for, how long you have been out, your phone's battery level, and a timeline of the trip; they can also send you a message through the page. You decide who to send the link to, but anyone they forward it to can see it too, so share it only with people you trust. Each beacon link stops working automatically 12 hours after the beacon starts, and you can end a beacon at any time from the app. Search engines are instructed not to index tracking pages.
Safety contacts and alerts. You can save a small number of safety contacts in the app. When you start a beacon, miss a check-in, are overdue, end a trip, or trigger SOS, we send those contacts a message by SMS, email or push notification containing your name, the peak, your last known coordinates and the tracking link. SMS is sent through the messaging providers listed in Section 12.
A safety contact's details are personal data about a person who may not use Conquer. Please add someone only if they have agreed to it — you are responsible for telling them that their name and contact details are stored in Conquer so we can alert them on your behalf. We use their details for nothing else: no marketing, no profiling, no sharing with anyone but the messaging providers needed to deliver the alert. We keep them only while they stay in your list, and delete them when you remove the contact or delete your account. If you are a safety contact and want your details removed, ask the person who added you to delete you in the app, or write to us at conquerapp@proton.me and we will remove you.
Your control. Location and motion access are controlled by your device's permission settings. You can turn them off at any time in your device settings. If you turn off location, summit verification and nearby-peak features will not work; if you turn off motion access, your altitude and elevation statistics will not be available. The rest of the app will continue to function.
6. How and why we use your data (legal bases)
Under the GDPR we must have a lawful basis for each use of your data. The table below sets out what we do and why.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and operate your account; provide core features | Account data, activity data | Performance of a contract |
| Verify summit ascents and record your climb statistics | Precise/background location, sensor data, activity data | Performance of a contract |
| Social features (friends, direct messages, leaderboards, group trips) | Account data, content, activity data | Performance of a contract |
| Show weather forecasts and safety alerts for hikes you plan | Plan details, location of the planned peak | Performance of a contract; legitimate interest in hiker safety |
| Run the safety beacon: share your live position on a tracking page and alert your safety contacts | Precise/background location, beacon session data, your display name and photo | Performance of a contract (you switch the beacon on) |
| Send beacon and SOS alerts to your safety contacts | Your safety contacts' names and contact details | Legitimate interest in hiker safety (yours and theirs); vital interests in a genuine emergency |
| Send push notifications you have enabled | Push token, plan and activity data | Consent (you enable notifications) |
| Process subscriptions and purchases | Subscription status, transaction identifier | Performance of a contract |
| Analyse and improve the Service; fix bugs | Usage analytics, diagnostics, device data | Legitimate interest in improving the Service |
| Estimate how long ascents take (trip-time estimates) | De-identified route traces (rest stops removed), route distance and elevation | Legitimate interest in improving the Service |
| Keep the Service secure; detect fraud and summit "spoofing" | Location, sensor data, device data, account data | Legitimate interest in protecting the Service and its users |
| Respond to your support requests | Support communications, account data | Legitimate interest; performance of a contract |
| Comply with legal obligations | Any relevant data | Legal obligation |
Where we rely on consent, you may withdraw it at any time (this does not affect processing that already took place). Where we rely on legitimate interest, you may object — see Section 16.
7. Information that is visible to other users
Conquer is a social app. The following information is visible to other users:
- your username, display name, level and profile frame;
- your conquests, achievements and statistics;
- your standing on friends, regional and global leaderboards (which are based on points and streaks);
- photos you upload (see Section 8); and
- direct messages, which are visible to the friend you send them to.
In addition, while a safety beacon is running, your live position, display name, profile picture and trip details are visible to anyone holding the tracking link — including people who do not use Conquer and have no account (see Section 5).
Please consider what you share. Do not put information in your display name, messages or photos that you would not want other users to see.
8. Photos you upload
When you capture a summit photo or contribute a photo to a peak's gallery, that photo becomes publicly visible — it can be seen by other users and may be served on the public conquerapp.no website, attributed to your display name.
To protect you, we automatically remove embedded metadata (such as EXIF GPS coordinates, capture timestamps and device information) from photos before we store them. This means the precise location and device fingerprint that your camera writes into a photo file are stripped out and are not published.
Do not upload photos that contain anything you do not want to be public. You can ask us to remove a photo at any time (see Section 16).
9. Push notifications
If you enable notifications, Conquer sends push messages such as weather updates and safety alerts before a planned conquest, streak reminders, and social notifications (for example, a friend request or a direct message).
To deliver these, your device is assigned a push token, which is routed through Expo's push service and through Apple's (APNs) or Google's (Firebase Cloud Messaging) notification systems. Weather information is obtained from a third-party weather service using the location of the peak you plan to climb.
You can turn push notifications off at any time in your device settings.
10. Analytics and diagnostics
We use Sentry, a crash- and performance-monitoring service, to detect and fix crashes, errors and performance problems in the app. Sentry processes crash reports, performance traces, and device and app information (such as device model, operating system and app version), associated with your account identifier so we can trace an issue back to the affected session. Crash reporting runs only in released builds of the app.
We also use PostHog to understand how people use Conquer — which screens are opened, where new users get stuck, and which features matter — so we can improve the app. PostHog records product-usage events (such as "opened a peak" or "completed a conquest") together with your public username (the pseudonymous tag shown to other users in the app) and a few coarse attributes (for example your level, app language, and whether you have a Pro subscription), linked to your account identifier. We run PostHog on its European (Frankfurt) infrastructure, so this data stays in the EU/EEA, and it is configured not to collect your IP address.
To see where the app confuses people, PostHog can also capture session replays: a series of snapshots of your screen inside Conquer only, while the app is open and in use. Everything you type and all photos are masked on your device (replaced with placeholders) before anything is sent — a replay shows which screens are visited and which buttons are pressed, never your typed text or your pictures. Replays are stored on the same European infrastructure and are deleted automatically after about a month. We keep your precise location and personal details (such as your email address) out of analytics events.
Because a replay is a picture of your screen, a replay of the map screen also shows the part of the map you were looking at, which can indicate roughly where you were at the time. We never attach your coordinates to an analytics event.
We use this analytics and diagnostics data only to keep Conquer stable and to improve it. We do not use it to sell your data, for advertising, or for cross-app tracking, and the app contains no advertising SDKs. Our lawful basis is our legitimate interest in operating and improving the Service; you can object at any time (see Section 16).
11. Payments and subscriptions
Conquer offers an optional paid subscription ("Conquer Pro").
When you subscribe, your payment is processed by the Apple App Store or Google Play, depending on your device. These stores handle your payment information under their own privacy policies. We never receive or store your payment card details — we only receive confirmation of your subscription status and a transaction identifier.
We verify your subscription status directly with the Apple App Store or Google Play using the transaction information they provide; we do not use a third-party subscription-management provider. Refunds and billing disputes are handled by Apple or Google.
12. Who we share your data with
We share personal data only as described below. We do not sell your personal data.
12.1 Service providers ("sub-processors")
We use trusted third parties to run the Service. They may process your data only on our instructions and only to provide their service to us.
| Provider | What they do for us | Where they process data |
|---|---|---|
| Railway | Application hosting and backend infrastructure | United States |
| Turso | Database hosting (your account, activity and social data) | United States |
| Cloudflare | Photo storage and content delivery | United States / global |
| Resend | Sending sign-in and service emails | United States |
| Expo (650 Industries, Inc.) | App delivery, over-the-air updates, push-notification routing | United States |
| Mapbox, Inc. | Interactive maps and 3D terrain | United States |
| MapTiler AG | Map tiles (topographic maps) | Switzerland |
| OpenStreetMap Foundation | Map tiles and place-name lookup (geocoding) | United Kingdom / EEA |
| Apple Inc. | Sign in with Apple; App Store payments; iOS push delivery | United States / EEA |
| Google LLC | Sign in with Google; Google Play payments; Android push delivery | United States |
| Sentry (Functional Software, Inc.) | Crash and performance diagnostics | United States |
| PostHog, Inc. | Product analytics (how the app is used) | European Union (Germany) |
| Twilio Inc. | Sending SMS alerts to your safety contacts | United States |
| GatewayAPI A/S | Sending SMS alerts to your safety contacts (backup provider) | Denmark |
| Gravitystorm Ltd (Thunderforest) | Map tiles for the optional Thunderforest map styles | United Kingdom |
| Microsoft (Azure Maps) | Satellite map imagery | European Union / global |
| Open-Meteo | Weather forecasts for peaks and planned trips | European Union |
Some of these providers (notably the map providers) receive your IP address and the area of the map you are viewing directly from your device when you use the Service.
Satellite imagery and weather forecasts are requested by our server instead of by your device, so Microsoft and Open-Meteo receive the map area or the peak's coordinates but not your IP address. The SMS providers (Twilio and, as a backup, GatewayAPI) are used only for the safety beacon. They receive your safety contact's phone number and the text of the alert, which includes your name, the peak, your last known coordinates and the tracking link.
12.2 Other sharing
- With other users — as described in Section 7.
- Social platforms — if you choose to share a photo or achievement card to a third-party platform such as Instagram, Facebook or Snapchat, that content is handed to the platform you choose, under its privacy policy. This only happens when you actively choose to share.
- Legal reasons — we may disclose data where required by law, to comply with legal process, or to protect the rights, safety or property of Conquer, our users or the public.
- Business transfers — if Conquer is involved in a merger, acquisition or sale of assets, your data may be transferred as part of that transaction; we will notify you of any such change.
13. International data transfers
Some of our providers are located outside Norway and the EEA, mainly in the United States. When we transfer your personal data outside the EEA, we rely on appropriate safeguards recognised under the GDPR, which may include:
- Standard Contractual Clauses approved by the European Commission;
- the EU–US Data Privacy Framework (where the provider is certified); and/or
- an adequacy decision for the country concerned.
You can request more information about these safeguards using the contact details in Section 22.
14. How long we keep your data
- Account and activity data is kept for as long as your account is active.
- When you delete your account (which you can do in the app), we delete or irreversibly anonymise your personal data: your email address, display name and home location are scrubbed and your sign-in sessions are ended. Anonymised, non-identifying records (for example, aggregate peak statistics) may be retained.
- Public photos you uploaded are removed on account deletion or on request.
- Route traces from your ascents are kept while your account is active and are deleted when you delete your account. The de-identified, aggregated model learned from them — which cannot identify you — may be retained.
- Staying signed in. Your sign-in session does not expire on a timer — you stay signed in on a device until you sign out, reset your password, or delete your account. This is deliberate: for a guest account the session is the only key to your progress, so a timed sign-out would strand it. Signing out, or resetting your password, ends the session everywhere.
- Password-reset links expire after 1 hour and can be used only once.
- Safety-beacon data. A tracking link stops working 12 hours after the beacon starts. The session record — the positions it logged, the alerts sent and any messages exchanged on the tracking page — is kept while your account is active and deleted when you delete your account.
- Safety contacts are kept until you remove them or delete your account.
- Backups are kept on a short rolling cycle and then overwritten.
- We may keep certain data longer where a law requires it or to establish, exercise or defend legal claims.
15. Security
We take reasonable technical and organisational measures to protect your data, including encryption of data in transit (HTTPS), storage of sign-in tokens in your device's secure storage, access controls, and salted scrypt hashing of passwords so that we never store or transmit your plaintext password.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal-data breach that is likely to present a risk to you, we will notify you and the relevant supervisory authority as required by law.
16. Your rights
If you are in the EEA, Norway or the United Kingdom, you have the following rights in relation to your personal data:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your personal data deleted ("right to be forgotten").
- Restriction — ask us to limit how we use your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time.
- Not be subject to solely automated decisions that produce legal or similarly significant effects (see Section 20).
How to exercise your rights. You can export your data and delete your account directly inside the Conquer app at any time. For any other request, or if you need help, contact us at conquerapp@proton.me. We will respond within one month; this may be extended by two further months for complex requests, in which case we will tell you.
Right to complain. If you believe we have not handled your data correctly, you may lodge a complaint with the Norwegian Data Protection Authority:
Datatilsynet
Postboks 458 Sentrum, 0105 Oslo, Norway
Website: datatilsynet.no
You may also complain to the supervisory authority in your own EEA country.
17. California privacy rights
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you additional rights.
Categories of personal information we collect include: identifiers (such as email and account ID); internet and app activity; precise geolocation; photos and other visual information; and inferences drawn from your activity. We collect these for the business purposes described in Section 6.
You have the right to know what personal information we collect, to delete it, to correct it, and to opt out of the sale or sharing of your personal information. We do not sell your personal information and we do not "share" it for cross-context behavioural advertising. We will not discriminate against you for exercising your rights.
To exercise these rights, contact us at conquerapp@proton.me or use the in-app export and account-deletion tools.
18. Children's privacy
The Service is not directed to children under 13 years of age, and you must be at least 13 to create an account. In some countries the minimum age is higher (for example, 16 in parts of the EEA); you must meet the minimum age that applies where you live.
We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided us with personal data, please contact us and we will delete it.
Mountain hiking carries real-world risk. Conquer is not a substitute for proper preparation, and minors should hike only with appropriate adult supervision.
19. Cookies and local storage
In the app, Conquer stores data on your device (such as your secure sign-in token and cached content) so that the app works and loads quickly. This storage is necessary for the app to function.
On the website, we use a small number of cookies that are either strictly necessary or set by your own choice: a session cookie that keeps you signed in, and preference cookies that remember settings you pick — such as language, colour theme, map style and interface options — for up to a year. We do not use advertising or cross-site tracking cookies, and we do not use cookies to build a profile of you. Because these cookies are either strictly necessary or set only when you choose a setting, no consent banner is required for them.
Website analytics. To understand how the conquerapp.no website is used (for example, which pages are viewed and which "Download on the App Store" buttons are clicked), we use PostHog in a strictly cookieless mode: it sets no cookies and stores nothing on your device, and we run it on PostHog's European (Frankfurt) infrastructure. Instead of an identifier stored on your device, visits are counted using a pseudonymous, daily-rotating hash, so we cannot recognise you from one day to the next and cannot build a long-term profile of you. Because nothing is stored on or read from your device, this does not require a cookie-consent banner; our lawful basis is our legitimate interest in understanding and improving the website, and you can object at any time (see Section 16).
20. Automated summit verification
When you submit a conquest, Conquer automatically decides whether to approve it by comparing your GPS position and GPS altitude against the peak's known location and elevation. This is done to prevent cheating.
This automated check does not produce any legal effect or similarly significant effect on you — at most it determines whether a single conquest is recorded. If you believe a conquest was wrongly rejected, you can contact us and a person will review it.
21. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top. If the changes are material, we will give you notice through the app or by email before they take effect. We encourage you to review this policy periodically.
22. How to contact us
For any question about this policy or your personal data, or to exercise your rights, contact the data controller:
Vegard Nygård
Damsgård 31C, 4318 Sandnes
Norway
Email: conquerapp@proton.me