Privacy policy

DIY Walking Challenges is operated by ITP Digital LLC. This page explains what the Android app keeps on your phone, what you may choose to share, and what outside services process.

Walking and location data

Health Connect and the app's local recording provide steps and distance. These observations and your height, if you enter it, stay in the app's private storage on your phone. The app does not upload raw health observations or height to its race servers or send them in advertising requests. Android app backup is disabled for the private health database and settings. An explicit .walkbackup export leaves out raw health observations, credentials, height, and purchase entitlement.

Google Maps is optional. When you view a Google map, Google's Maps SDK receives map requests and technical data. If you grant location access, the map can show your position or center a new route near you. These editor fixes are not saved as a walking track. A route may separately require GPS tracking; tracking starts only when you tap Start GPS tracking. Raw GPS fixes and tracks stay in memory and are not stored or shared. Credited distance and session information are stored locally. Shared progress on a real GPS route may reveal your approximate whereabouts to other racers.

Races, friends, and shared routes

Cloud races and Friends are optional. When you use them, the selected Firebase server receives an anonymous authentication ID, participant or account ID, nickname and optional small icon, and the room or friend information needed to show standings and invitations. Shared race data includes credited and aggregate distance, not raw health readings or GPS fixes. A friend profile may include aggregate distance, medals, and race statistics. Public leaderboard visibility is a separate opt-in.

You can use the built-in community server or a private server selected by you or a race organizer. A private server's owner controls that Firebase project, its access and retention. If you choose to host a route pack, its route content and artwork are uploaded to the selected private server; the built-in community server does not accept hosted packs. Anyone given a valid hosted link and matching server configuration may request access while the share is open. Files already downloaded by others cannot be recalled by the app.

Artwork generation

If you request AI artwork, the selected image server receives your short prompt, artwork type and model choice. A reference image is sent only when you select one and confirm your right to use it. The request does not include health observations, progress, Firebase credentials, advertising identifiers, or payment details. The built-in server uses Cloudflare Workers AI and does not intentionally save prompts, reference images, or generated images; Cloudflare processes the request under its own practices. A custom image server may process or retain inputs differently. The app stores artwork you choose locally, and you may later share it in a route, backup, or hosted pack.

Reports about generated images go to the server that made them and include a generation request ID, an opaque validation token, a report category, optional details, and a server-specific pseudonymous client identifier. They do not resend the prompt, reference image, or generated image. The built-in server uses Cloudflare Workers and its D1 database to process and store report records: a report reference, generation request ID, hashed client identifier, category, optional details, timestamps, alert delivery state, and review outcome. The owner accesses report details through private authenticated review tools.

The built-in server uses Resend to send report alerts to the owner's mailbox. The message body contains only a count and an opaque report reference; it does not contain report details, the client identifier or its hash, prompts, or images. Resend also processes the sender and recipient email addresses and delivery information. The owner's review target is within 48 hours of receipt, with investigation and changes to safeguards when warranted. This is a human review target, not a guaranteed response deadline.

The report retention policy schedules database records for deletion once they reach 90 days after original receipt. Daily cleanup removes the report and its associated alert retry and review state; repeat submissions do not reset the original receipt time. Service failures or a cleanup backlog can delay deletion. This database cleanup does not delete notification email copies or providers' own records. A custom image server's owner controls its report handling and retention.

The built-in server keeps limited diagnostic records for failed image generation, with cleanup after 30 days on later failure writes.

Advertising and Pro

Ads support the free app. Advertising depends on your app version: released version 2.17.111 (156) uses Google AdMob. Upcoming version 2.17.112 (157), when released, selects Unity LevelPlay with Unity Ads and ironSource (including the ironSource exchange) and retains AdMob behind an internal build switch. Only the selected provider initializes or requests ads, with no automatic fallback. In LevelPlay versions, the app offers personalized or contextual ads, with separate unchecked adult and device-access confirmations before initialization. Personalized ads use your permission to personalize; contextual ads decline personalization and restrict sale or sharing. Both LevelPlay choices require device access and may process data for delivery, measurement, attribution and fraud prevention. Contextual does not mean data-free. Withheld or withdrawn device-access permission keeps LevelPlay advertising blocked. We apply this LevelPlay device-access choice worldwide without collecting location to infer exemptions.

The LevelPlay dialog names ITP Digital LLC, Unity LevelPlay, Unity Ads and ironSource/its exchange and links this policy, Unity's privacy policy and advertising choices. Sale/share restriction starts on for personalized choices and stays on for contextual ads. Pro removes ads without advertising prompts. The separate developer APK permanently disables advertising. These choices do not create or change a Pro purchase.

In LevelPlay versions, open Settings > Privacy and cookie settings to review or change choices, or withdraw saved device-access permission. Reviewing choices pauses requests and invalidates cached ads. Cancel restores only a valid current choice. Earlier LevelPlay v1/v2 records, including "decline all ads," remain unchanged and blocked until you explicitly choose under the new disclosure. The migration message explains that contextual ads still require device access. The app saves device access, personalization, adult confirmation, sale/share restriction, disclosure version and network contract privately on your phone. Missing, outdated or unavailable permission blocks LevelPlay ads. Withdrawal stops new requests and sends restrictive SDK signals; an ad already displayed may finish.

Released AdMob versions and builds that select AdMob internally use Google's User Messaging Platform (UMP) for applicable regional consent messages and privacy options. Settings > Privacy and cookie settings is available when that flow requires it. Google Mobile Ads can process IP address (which can estimate general location), app interactions, diagnostics and device/account identifiers for advertising, measurement and fraud prevention under Google's privacy policy and applicable choices; see Google's UMP guidance and SDK data disclosure. These AdMob versions follow Google's regional flow, rather than the LevelPlay device-access choice. UMP choices are not treated as LevelPlay permission.

In LevelPlay versions, with explicit device-access permission, Unity LevelPlay, Unity Ads and ironSource/its exchange may store or access device information and collect/share advertising/device identifiers, IP-derived approximate location, device/app information and advertising interactions. LevelPlay collects diagnostics; Unity Ads also shares diagnostics. Unity Ads 4.21.0 additionally discloses collection/sharing of personal identifiers (User IDs) for app functionality and purchase history for advertising and analytics. These are SDK-reported practices: the app does not supply an optional network user ID, profile or Google Play purchase token/history to the advertising layer. Unity's disclosure does not identify the purchase-history payload or source. Data supports ad delivery, measurement, app functionality and fraud prevention; personalized ads also use it to select ads for you. See the Unity Ads disclosure, LevelPlay disclosure, Unity's app-user privacy policy and advertising choices. If Acquire Optimization is enabled, Unity also collects and shares app usage times for advertising, analytics and fraud prevention. The LevelPlay build excludes Ad Quality. No optional network user ID, segment or custom targeting is supplied. The app does not include Firebase Analytics, and ITP Digital LLC does not sell app data.

The advertising layer receives no walking, Health Connect, height, route, journey progress, nickname, profile or race data. Pro and developer do not initialize advertising SDKs or request advertising consent. Onboarding, review suppression, screen safety, lifecycle and frequency rules also gate ad requests and display.

Banners are limited to eligible reviewed publisher journey overviews. Fullscreen ads require an eligible natural break, current privacy permission and content checks, with a five-minute foreground grace period, ten minutes between displays, two per session and four per rolling day. Ordinary navigation, custom/imported content, builders, progress viewing, overlays, permission prompts and failed/cancelled actions do not trigger fullscreen ads. Pro suppresses ads. The separately supplied developer build disables advertising SDK initialization, requests and advertising consent permanently.

The optional Google Play remove_ads purchase removes banners and fullscreen ads. Google Play handles payment and account information. The app uses the product and ownership information needed to grant or restore the ad-free benefit; it does not receive card details or include the entitlement in a portable backup.

Clearing data and requests

Removing app data clears information held on that phone and may discard its anonymous Firebase credential. It does not by itself delete records already held by a Firebase server or copies saved by other people. Leaving an open race removes your cloud member record. Closing a race keeps its aggregate standings as read-only server history; removing a saved closed race from your phone removes only that local copy. Friend and hosted-route records may also remain on the selected server until separately removed. The app does not promise automatic deletion of shared cloud records after a fixed period.

For a privacy question or deletion request about the built-in services, email diywalkingchallenges@gmail.com. Tell us which feature and server you used and enough information to identify the record; please do not email raw health records, passwords, or private keys. Requests involving a private Firebase or image server may need to go to that server's owner. We can review a request, but cannot guarantee removal of another person's downloaded copy or data controlled by a private-server owner.

For Unity advertising privacy or deletion requests, contact DPO@unity3d.com. Unity's policy also describes the Data Privacy icon within ads. Provider records retained for security or legal reasons may remain. These are request routes, not a promise that clearing app data deletes every remote record.

Other providers

Unity processes advertising data in LevelPlay versions through LevelPlay, Unity Ads and ironSource/its exchange under its app-user privacy policy and explains advertising privacy choices. Google processes AdMob/consent data in released AdMob versions and internally selected AdMob builds, along with Maps and Play purchases, under its privacy policy. Firebase hosts optional shared data on the selected project. Cloudflare processes requests to the built-in artwork service and stores its report database under its privacy policy. Resend processes report notification emails under its privacy policy. Providers' practices may include technical connection data such as IP addresses.