This policy describes what data the Etappa app processes, for what purpose, and on what legal basis – based on the actual source code. New features only appear here once they are really in the code; until then they are explicitly marked "planned". What arises when you visit the website getetappa.com is described in section 3.13.
1. Controller
Patrick Voelz
Plauer Str. 3
19395 Ganzlin
Germany
support@getetappa.com
For privacy questions, please contact me at the email address above.
2. Principle
Etappa is built without its own server. There is no sign-up with Etappa, no user account with me, and no transmission of your trip data to me. Your trips, stages, payments, documents and settings live on your device (SwiftData) and — if you use iCloud sync — additionally in your own private iCloud account. I have no access to it.
Etappa uses no analytics, tracking, or advertising SDKs and builds no usage profile. There is no tracking in the sense of Apple's App Tracking Transparency framework.
Automated decision-making within the meaning of Art. 22 GDPR or profiling does not take place — every rule notice the app shows (e.g. a night gap, a due payment) is a hint for you to assess yourself, never an automated decision with legal effect on you.
Entering your trip data is voluntary but required to use the corresponding feature — no stages, no timeline; no payment plan, no due-date reminders. Location, camera, and notification access are likewise voluntary: without them, only the dependent extra features stop working (e.g. arrival notifications without location access), the rest of the app stays usable.
3. What data Etappa processes, and why
3.1 Trip data (stages, payments, to-dos, vehicle profile, travelers)
Titles, dates, places, amounts, notes and similar information you enter yourself for your trip. Purpose: the app's core function — planning and tracking a trip. This data stays on your device, or, with iCloud sync turned on, in your private iCloud database. It is not transmitted to me.
Travelers: no date of birth is stored, only an age group. First names are optional; without them, the people in your home are called “Adult 1”, “Child 1” and so on. IDs/documents: Etappa stores, at most, the document type, expiry date, nationality and which person it belongs to — never an ID number — and there is no requirement to scan or store an ID at all.
3.2 Location
Etappa asks for "While Using" access to
- one-time translate your current location into an address for your home profile (setup), and
- detect when you arrive at a stage so it can show you the booking reference and access codes.
Etappa asks for "Always" access only when you turn on arrival notifications — that is the only way iOS can detect an arrival by geofence while the app is closed. Without arrival notifications turned on, it stays at "While Using".
The one-time home address lookup and the automatic distance/driving-time calculation use Apple's map services (see 3.3) — for those, the coordinate involved leaves the device toward Apple, not toward me. The geofence monitoring for arrival notifications itself runs on the device via iOS; there is no Etappa server that receives your location, and Etappa builds no movement profile.
Only the address derived from your location is stored, not the location itself, as your home (on your device; with iCloud sync or when sharing your home, also in your iCloud account and with invited participants). You can change or delete it at any time in Settings.
3.3 Apple Maps (MapKit, location services)
For address search when creating a stage, automatic calculation of distance and driving time between stages, nearby-place suggestions, the "Look Around" preview, and converting coordinates into countries/addresses, Etappa sends your search text or the relevant coordinates to Apple's map service. No names, booking references, or other trip data are transmitted — only search text or coordinates. This automatic calculation can be turned off in Settings.
If you deliberately share a route via the share button (e.g. to the Tesla app or Google Maps), the opened maps link transmits the start and destination coordinates (and, for Google Maps, possibly a few intermediate route points) to Google or Apple Maps — this only happens when you explicitly tap it, never automatically.
3.4 Local notifications
Arrival notifications, change notifications for shared trips, and similar reminders are local notifications (UserNotifications) triggered by your own device. There is no push delivery of my own via a server; the silent pushes that trigger change notifications for shared trips run over Apple's CloudKit (see 3.6).
3.5 Photo/camera — meter readings and inventory text recognition
Meter readings (consumption): The photo you take as evidence of a meter reading with the camera (camera only, no photo library) is stored as a JPEG locally on your device (an app-owned folder) — it serves as your proof and does not leave the device (except via iCloud sync into your own iCloud account; Etappa does not sync meter photos themselves, see 3.6).
Inventory text recognition: When filling in an inventory entry, you can have a photo (camera or photo library) taken or picked to pull text from it. Text recognition runs entirely on-device via Apple's Vision framework, with no network call. Only the recognized lines of text are carried into the form; the photo itself is discarded afterwards and not stored. For an ID, Etappa reads the type, expiry date, nationality and first name; a recognized date of birth is used only in the moment to assign the ID to an adult or a child and is not stored. The ID number is not read. Etappa only takes over the recognized first name if you confirm it. Etappa does not request its own photo-library permission for this — PhotosPicker runs in a process separate from the app.
3.6 iCloud/CloudKit and sharing
Etappa syncs your trip data between your own devices via your private iCloud database by default (iCloudSyncEnabled, default on). Without an iCloud account or without a network connection, Etappa keeps working locally without any change, nothing is lost. Your trip data is encrypted in transit and at rest on Apple's servers, within your own iCloud account — I have no access to it, as is the case for any app using Apple's CloudKit service.
A single trip or your whole home profile can also be shared with other people via iCloud (CKShare), with the role "editor" or "viewer":
- Whoever is invited to your home sees the home profile, all inventory entries (without their photos and notes — those stay on the respective device), and all trips that live in the home — in full, including booking references, access codes, and payment details.
- Whoever is invited to a single trip sees that trip in full (booking references, codes, payments); of the home's inventory entries, only short notes travel along (type and country, e.g. "Austria vignette"), never photos or notes.
- Changes are distributed between devices via silent push notifications; participants additionally get a visible, local notification (e.g. "Anna changed "Summer at the Baltic Sea"", without further content) — switchable off under Settings → On the Road.
Your data is always encrypted in transit and at rest on Apple's servers — not end-to-end encrypted, not even for individual fields. Apple can technically access this data to the extent required to provide the service, unless you have enabled Advanced Data Protection for iCloud. Reviewing "Advanced Data Protection for iCloud" in your device's iCloud settings is a sensible thing to do.
This policy is updated whenever sharing is extended, and the app points this out before you use such a feature for the first time (e.g. the notice at the sharing entry point: "Everyone you invite sees the whole trip, including booking references and codes.").
3.7 Exchange rates (European Central Bank)
For currency conversion, Etappa fetches a public, non-personalized rate file from the European Central Bank once per calendar day (https://www.ecb.europa.eu/stats/eurofxref/eurofxref-daily.xml, a plain GET request, no sign-in, no API key). This transmits no trip, amount, or personal data whatsoever — only a public file is retrieved; technically unavoidable, as with any network request, is that your device's IP address reaches the ECB. The most recently fetched rate table is cached locally so conversion also works offline.
3.8 Settings (UserDefaults)
Etappa stores app settings (e.g. "arrival notifications on/off", appearance, muted rule hints) in UserDefaults — locally, in Etappa's own app container, with no onward transmission.
In addition, Etappa stores a single value in the iCloud key-value store of your own iCloud account (NSUbiquitousKeyValueStore): whether setup has been completed on one of your devices (yes/no). This lets another device with the same Apple ID wait for your data instead of asking you to set up again. No content, addresses or trip data are stored there.
3.9 Feedback and diagnostic log
Via Settings → Help and Information → "Send Feedback" you can prepare an email to me, support@getetappa.com. Before anything is sent, the app or the mail app shows you the text: app version, build, system version and device type are included automatically — you write your own message on top, no trip data is included. If you write to this address, I process your email address and the content of your message in order to reply; I delete the history once your request is resolved, at the latest after one year.
Before sending, you can additionally check a box to attach a diagnostic log (default: on, with a preview of its content before anything is attached). It lives exclusively locally on your device (Application Support folder, excluded from the iCloud backup), rolling over at most 7 days and 1 MB, and contains exclusively technical, anonymous entries: timestamps, app/system version, device model, language/region, event type (e.g. app launch, view opened, action performed), errors with domain/code and the location in the code, storage and sync errors (CloudKit error code, sync state), permission status for notifications/location, setting states, counts (number of trips/stages/documents, shared yes/no, role), durations of slow operations, and a crash/hang hint via Apple's MetricKit. Never included: trip titles, addresses, codes, booking references, names, or any other trip data — the interface simply does not allow that kind of content in.
The log is never transmitted automatically or in the background, only when you attach it to a feedback email. In Settings → Help and Information you can remove it at any time via "Delete diagnostic log".
3.10 TestFlight (beta testing)
If you install Etappa via TestFlight, Apple automatically collects crash logs and usage data and makes them available to me in App Store Connect — Apple controls this, not Etappa; an opt-out in iOS Settings does not apply here. If you send feedback via TestFlight (text, screenshot), your name and email address from the TestFlight invitation may be sent along, unless you joined via a public link. This data is used only for troubleshooting and app improvement, is not passed on to third parties, and is not linked to your trip data in the app. Details: Apple, "TestFlight & Privacy" (apple.com/legal/privacy/data/en/test-flight/).
3.11 Flight search (Google Flights)
For an open flight stage, Etappa offers a "Search flights" button. It opens a prefilled search on Google Flights in your browser — only when you tap it, and only after you tap "Search" in a dialog. The dialog first states which details go to Google: departure place and destination airport, the date of the outbound flight (and of the return flight if a return stage exists), and the number of travelers (the number only, no names). With "Cancel", nothing is opened and nothing is transmitted. The choice is not remembered; Etappa asks every time. Etappa itself transmits nothing in the background and sends no request to Google; the details are contained in the link that is opened, and reach Google only when your browser loads the page. The search contains no tracking or partner parameters, and Etappa earns nothing from it. What Google does with the details is governed by Google's privacy notices.
3.12 Sharing or pasting bookings, booking confirmation, links (draft, not yet published)
You can hand a booking confirmation to Etappa via “Share” (text from an email, an email file, PDF, image or screenshot, Wallet pass, calendar file) or take it over in Etappa with “Paste booking” from the clipboard (text, image or PDF). You can also share a link (e.g. from Safari) to Etappa.
- Recognition on-device: Etappa reads dates, times, provider, booking reference, places and amounts using fixed rules; text in images and in PDFs without a text layer is recognized on-device by Apple's Vision framework. There is no network call and – apart from the test switch below – no AI involved, and the content does not leave your device. Etappa treats text in a confirmation only as data, never as instructions.
- What Etappa does not keep: Emails, text, images, screenshots and Wallet passes are only read and then discarded. Etappa keeps the text read from them only until you have saved or cancelled in the preview sheet (see “Text until you decide”). From a Wallet pass, Etappa takes neither your name nor seat nor barcode.
- Booking confirmation as PDF: If you share (or paste) a PDF, Etappa attaches the file to the stage when you save, so you can open, share or print it at any time. The file stays on this device only in the app's storage (“complete” file protection). It is not synced via iCloud. Like all app data, it is included in your device backup until Etappa deletes it. Etappa deletes it automatically 30 days after the end of the trip (checked when the app starts), together with the stage or trip, and whenever you delete it yourself.
- What others see: Members of your home or participants of a shared trip only see a note on the stage: file name, size, a checksum (SHA-256, to recognize the same file), the date, the device type (iPhone/iPad), a random identifier of this installation and your short name from the participant list – never the content. This note is synced via iCloud like the rest of the trip data (3.6) and stored there as an encrypted field. Others can ask you for the file through Etappa; that request is also just a note (name, device, time). Only you send the file itself, with “Send” via the iOS share sheet (e.g. AirDrop or Messages) – Etappa does not upload it anywhere. Unanswered requests expire after 30 days.
- Vignettes and toll receipts: If Etappa recognizes a vignette in the shared document (e.g. the registration confirmation of an e-vignette), it does not create a stage but an entry in your Documents. Only the country, validity, licence plate and vehicle category are taken over – not the order or receipt number, the vignette's ID, payment details or names. The licence plate belongs to the vignette and is synced with your home like your other documents (3.6, as an encrypted field); the vehicle category is put in the entry's note, which stays on the device. Like a booking confirmation, the PDF stays on this device only, with the entry in Documents. Members of your home only see the note “Receipt is with …” (the same details as above, never the content) and can ask you for the file; only you can send it. Etappa deletes the PDF 30 days after the validity ends (without a stated end, 400 days after it was filed), with the entry, and whenever you delete it yourself.
- Links: Etappa only keeps the address and – if Safari provides it – the page title. Etappa never loads the page, neither in the extension nor in the app; only “Open booking” opens it in your browser.
- Pages from Safari: When you share a page from Safari, Safari also gives the extension the visible text of the page. Etappa reads it only on your device to recognize what it is and – if you choose a type under “What is this?” – to read the matching details from it. Afterwards it is deleted; at most the details you save and the link are kept. Etappa does not read the page's source code, cookies or values in form fields.
- PDF in Safari: If Safari is currently showing a PDF (it has no page text), the Safari script passes the data of exactly this displayed document to the extension (at most 10 MB). This is not a download by Etappa: the extension itself does not access the network; Safari has already loaded the document and usually serves it from its cache. The PDF is handled like a shared PDF (see “Booking confirmation as PDF”).
- Text until you decide: So that Etappa can read the details from the same text after “What is this?”, the extension stores the text it read (page text, email or shared text, at most 200,000 characters) next to the recognized details in the folder shared by the app and the extension (App Group, on this device only, “complete” file protection, not in iCloud). Etappa collects it when it opens, deletes the file and keeps the text only in memory until you have saved or cancelled; then it is gone. The text never becomes part of your trip data and is never synced.
- Handover to the app: The share extension stores the recognized details, the text it read, a shared PDF or images whose text the app still has to read, and links in a folder shared by the app and the extension on your device (App Group, “complete” file protection) and then opens Etappa, as far as iOS allows it. Etappa collects them when it opens and deletes the files; details that are not collected are discarded after seven days. Images are deleted once they have been read.
- Clipboard: Etappa only reads it when you tap “Paste booking”; iOS asks for permission itself.
- AI recognition (test builds only, experimental): In TestFlight builds and builds installed from the development environment, Etappa additionally uses Apple's on-device language model (the “FoundationModels” framework, requires Apple Intelligence). From build 17 the switch for this is on from the start; you can turn it off at any time under Settings → Development, and that choice is kept. It reads the same text as the rules (email, page and PDF text, text recognized in images) – on the device only. Etappa calls neither a server nor Apple's Private Cloud Compute for this. Etappa checks every value from the model against the text, discards anything that does not appear in it word for word, and shows the rest as an “AI suggestion”; the model can still be wrong. To evaluate it, Etappa keeps an “import evaluation” on the device – without document content and without field values, only field names, source (rule/AI), confidence level, whether you kept or changed a value, the run time, and the mode and reason of the AI run as codes (“complete” file protection, not synced via iCloud). It leaves the device only if you choose “Share evaluation”, and you can delete it at any time. The App Store version does not have this switch.
- Nothing is saved until you confirm: You see everything in a preview and can change every field. Only when you tap “Save” do the details become part of your trip data and are then treated like it (3.1), including iCloud sync (3.6).
3.13 This website (getetappa.com)
The Etappa website at getetappa.com consists of static pages (home page, support, imprint, this policy). It is hosted by Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Les Acacias (Geneva), Switzerland. The domain, name resolution (DNS) and the mailbox of the support address are also set up there. According to its own statements, Infomaniak runs its data centres exclusively in Switzerland and processes the website's data on my behalf (processing on behalf of a controller under Art. 28 GDPR).
- Server logs: When you open the website, the web server records your IP address and the usual connection data (e.g. date and time, the page requested, details of your browser) in access and error logs, as technically necessary to deliver the pages and to protect the service against abuse. According to its own statements, Infomaniak keeps these logs for at least 7 days; older entries cannot be restored afterwards. I can view them in my Infomaniak customer area and use them only for troubleshooting and to fend off abuse, not to analyse your behaviour.
- Legal basis: Art. 6(1)(f) GDPR. My legitimate interest is providing the website securely and reliably. You can object under Art. 21 GDPR (section 9).
- Switzerland: The data is processed in Switzerland. There is an adequacy decision of the European Commission for Switzerland (Art. 45 GDPR), so your data is adequately protected by EU standards there. No transfer to the USA or any other third country takes place for the website. Infomaniak's privacy notices: https://www.infomaniak.com/en/legal/confidentiality-policy
- No cookies, no tracking: The website sets no cookies, uses no analytics or advertising services, and loads no fonts, scripts or images from third parties; all files come from the website itself. Links to other sites (e.g. to TestFlight at Apple) only lead there when you click them; the notices of that provider then apply.
4. What Etappa does not do
- No analytics or tracking SDKs, no ad network, no sale of data.
- No access to Contacts or Calendar (Etappa uses an Apple building block for address formatting from the map service — this is not use of your address book).
- Etappa itself does not automatically send crash reports: the anonymous diagnostic log from section 3.9 only ever reaches me by email and only on your own action. Via TestFlight, section 3.10 additionally applies — there Apple collects crash and usage data automatically, outside my control.
- No ID numbers, no dates of birth.
5. Technical and organizational measures
In short: your data lives in iOS's own app sandbox, additionally protected by your device lock and iOS's own device encryption; transmission to iCloud runs over transport encryption (TLS). In Settings → Security you can additionally turn on an optional privacy shield for access codes and booking references via Face ID / Touch ID (default: off) — this is explicitly only a shield against prying eyes on an unlocked device, not its own encryption and not a replacement for the device lock itself.
6. Legal bases (Art. 6(1) GDPR)
- (b) contract / pre-contractual measure: processing of the trip data you enter, insofar as it belongs to the app's core function.
- (a) consent: location access, notifications, and camera access — each via the iOS system prompt, revocable at any time in device settings.
- (f) legitimate interest: technically necessary requests such as the daily ECB rate fetch — my legitimate interest here is providing you with current exchange rates and a functioning app, without any relevant personal data of yours being involved. An objection under Art. 21 GDPR is practically moot here, since no personal data of yours is processed; you can still turn off the automatic conversion in Settings at any time. Also (f): the technically necessary processing of the IP address in the host's server logs when you open the website (section 3.13).
7. Recipients
- Apple as the provider of iOS, Apple Maps/MapKit, iCloud/CloudKit, UserNotifications and TestFlight — each within the scope of the functions described in section 3. Apple processes this data as an independent controller under its own privacy notices.
- Google, if you deliberately open a Google Maps link to share a route (section 3.3) or open the flight search after confirming in the dialog (section 3.11).
- The European Central Bank only as the source of the publicly retrieved rate file (section 3.7).
- Infomaniak Network SA (Switzerland) as the host of the website, the domain and the support mailbox (section 3.13) – this concerns the website and support emails only, not the app.
- No other recipient. In particular, no data is passed on to advertising networks, analytics providers, or other third parties.
Third country: Apple also processes data in the USA; this is based on the EU Standard Contractual Clauses and/or Apple's own privacy notices on international data transfers (apple.com/legal/privacy/). For Infomaniak (Switzerland) the adequacy decision of the European Commission applies (section 3.13). The European Central Bank is based in the EU, so this question does not arise there.
8. Retention
Trip data remains stored until you delete it in the app or uninstall the app (with iCloud sync on, also until you remove it there). Meter-reading photos remain until you delete them. Kept booking confirmations (PDF, section 3.12) are deleted by Etappa 30 days after the end of the trip, vignette receipts 30 days after their validity ends (without an end, 400 days after they were filed), requests for them after 30 days. The ECB rate table is overwritten on each successful daily fetch. Settings remain until you change them or uninstall the app. The diagnostic log (section 3.9) holds at most 7 days, or until you delete it; I delete a support email once your request is resolved, at the latest after one year.
9. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21), as well as the right to withdraw consent at any time with effect for the future (Art. 7(3)) — e.g. location or notification access via iOS settings. Since your trip data lives on your device or in your own iCloud, you can exercise most of these rights directly in the app or via your iCloud settings (e.g. delete a trip, remove a document).
You also have the right to lodge a complaint with a data protection supervisory authority, in particular with the Landesbeauftragter für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern (responsible for my registered address in Ganzlin), or in the member state of your habitual residence, place of work, or the place of the alleged infringement.
10. Children
Etappa is intended for adults planning a trip. Traveling children are recorded in the data model only with a name and age group, not a date of birth; they cannot be granted editing rights in the app.
11. Changes to this policy
If what data Etappa processes changes, this policy will be updated accordingly and the date at the top will be adjusted.