Privacy Policy
Last updated: 22 July 2026
The short version
- hejje works fully offline. You can use it without an account and without sending anything to us.
- When you create an account, your activities and routes are end-to-end encrypted on your phone before they sync — we cannot read them.
- We show no ads, use no third-party analytics or tracking SDKs, and we never sell your data.
- The AI features run entirely on your device. Your data is never sent to any AI or cloud service for them.
1. Who we are
hejje ("hejje", "we", "us") is a privacy-first fitness tracking app for recording runs, rides and walks. It is built and operated by an independent individual developer. This policy explains what data the app handles, what (if anything) leaves your device, and the choices you have.
For any privacy question or request, contact hejjetracker@gmail.com.
2. Offline-first, account optional
hejje is designed to work entirely on your device. You can install it, record activities, view your history and use the analytics without ever creating an account or connecting to the internet. In that mode, no activity data leaves your phone.
Creating an account is optional — but it is also what turns on sync. As soon as you register, hejje automatically syncs your data to our servers so it is backed up and can be restored on another device. Everything synced this way is end-to-end encrypted on your device first (see section 4), so we still cannot read it. If you never create an account, the sections below about our servers simply do not apply to you.
The social features — following other people — are a further optional step you take from within the app; they are not switched on just by registering.
3. What data hejje handles
Depending on which features you use, the app processes:
- Activity data — the runs, rides and walks you record: GPS route, distance, duration, pace/speed, elevation, and step count.
- Location data — GPS coordinates collected only while you are actively recording an activity, including in the background so tracking continues with the screen off.
- Media — photos and videos you choose to attach to an activity.
- Profile — a display name and optional profile/banner images, if you create an account.
- Goals & settings — training goals and app preferences you set.
- Account & device information — if you enable sync: a cryptographic key pair generated on your device, a device name, and technical details used to keep your account secure (see section 6).
4. End-to-end encryption
When you enable sync, your activity data is encrypted on your device before it is uploaded, using keys that are generated on and stay on your device. This includes your activity summaries, your GPS routes, and any photos or videos attached to an activity. We store only the encrypted result and cannot decrypt or read it.
You are given a one-time recovery key when you create your account. It is the only way to restore your encrypted data onto a new device. Because we never receive your keys, if you lose your recovery key we cannot recover your encrypted data for you. Please store it somewhere safe.
5. What our servers can see
To make accounts, sync and following work, a small amount of information is not end-to-end encrypted and is readable by our server. We keep this to the minimum needed:
- Your public profile — your display name, follower/following counts, and your public key. These let other people find and follow you.
- Profile and banner images — if you set them, these images are stored unencrypted so they can be shown to people who view your profile. Do not use an image as a profile picture if you would not want it visible to other hejje users.
- Device and security information — a device name, the user agent, your IP address, and last-seen time. These are used to authenticate your devices, apply rate limits, and protect your account from abuse.
- Social graph — follow requests and follow relationships between accounts, so requests can be delivered and accepted.
Your encrypted keys are also held on the server in a form that is itself encrypted with your recovery key, purely so you can restore your account — we cannot unlock it.
6. Media storage
Photos and videos you attach to activities, and your profile/banner images, are stored using Cloudflare R2 object storage on our behalf. Activity media is uploaded encrypted and cannot be read by Cloudflare or by us. Profile and banner images, as noted above, are stored unencrypted so they can be displayed.
7. On-device AI
hejje's AI features run a language model entirely on your device. Your activities and any questions you ask are processed locally and are not sent to us, to Cloudflare, or to any third-party AI provider.
8. Importing from Strava
If you choose to import your history from Strava, you do so by providing an export file that you download from Strava yourself. hejje does not connect to your Strava account and has no access to Strava beyond the file you hand it. Imported activities are then treated exactly like activities you recorded in hejje.
9. App permissions
The app requests only the permissions its features need:
- Location (including background) — to record your route during an activity; background access lets tracking continue when the screen is off or the app is in the background.
- Physical activity / step counter — to count steps during a recording.
- Notifications & foreground service — to show the ongoing tracking notification and to keep recording, syncing, or importing running reliably in the background.
- Run at startup — so an interrupted recording can resume after your device restarts.
- Photos / media access — only when you pick a photo or video to attach.
You can review and revoke these at any time in your device's system settings.
10. Who processes data for us
We use a small number of infrastructure providers, acting on our instructions:
- Hetzner — hosts the server that stores your encrypted vault and public profile.
- Cloudflare (R2) — stores media as described in section 6.
We do not use advertising networks or third-party analytics/tracking services, and we do not sell or rent your data to anyone.
11. Data retention & deletion
Data recorded on your device stays there until you delete it or uninstall the app. If you use sync, your encrypted data and public profile remain on our servers until you delete them. You can delete individual activities at any time, and you can request deletion of your account and associated server-side data by emailing hejjetracker@gmail.com.
12. Your rights
Depending on where you live (for example under the GDPR or CCPA), you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Because your activity data is end-to-end encrypted, much of it is already accessible only to you. For anything on our servers, contact hejjetracker@gmail.com and we will respond within a reasonable time.
13. Children
hejje is not directed at children and is not intended for use by anyone under the age of 13 (or the minimum age required in your country). We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be highlighted where practical.
15. Contact
Questions, requests, or concerns about your privacy? Email hejjetracker@gmail.com.