Graveller
← Back to map

Privacy Policy

Last updated: 22 July 2026

This policy explains what personal data Graveller ("we", "the service") collects, why, who it is shared with, how long it is kept, and the rights you have over it. Graveller is aimed at cyclists in the EU and processes data about an EU region, so we treat the EU General Data Protection Regulation (GDPR) as applying.

Data controller: Michael Oppitz, Dreihausgasse 26/8, 1150 Vienna, Austria. Questions or requests about your data: privacy@graveller.app.

What we collect and why

When you create an account

  • Email address - to identify your account, let you log in, and send password reset links. (Legal basis: performance of a contract - providing you an account.)
  • Password - stored only as a salted bcrypt hash; we never store or can read your actual password.
  • Display name - shown publicly next to any ratings, comments, and photos you post.

When you contribute

  • Ratings, star ratings, condition flags, and comments - displayed publicly on the relevant segment alongside your display name. (Legal basis: your consent, given by choosing to post.)
  • Photos - displayed publicly on the segment you attach them to. When you upload a photo we re-encode it and strip its embedded metadata (EXIF, including any GPS coordinates and timestamp) before storing it, so that data isn't published. Please still avoid photos whose visible content reveals a location you'd rather keep private (such as your home).
  • Favorites and ridden logs - private to your account; used only to show you your own saved and ridden segments.

If you connect your OpenStreetMap account (optional)

  • Your OpenStreetMap display name and an OAuth access token, stored encrypted at rest, so you can submit tag-edit suggestions to OpenStreetMap under your own OSM identity. You can disconnect at any time from your account settings, which deletes the stored token.

Automatically, to run the service

  • A session cookie - an encrypted, signed cookie that keeps you logged in (about 14 days). It is strictly necessary for the service to function and is not used for advertising or tracking.
  • IP address - used transiently, in memory, only for rate-limiting to prevent abuse. It is not written to our database or used to profile you. (Legal basis: our legitimate interest in keeping the service available and secure.)
  • Password reset tokens - a hashed, single-use token with a short expiry, kept only until used or expired.

We do not use advertising, third-party analytics, or tracking cookies, and we do not sell your data to anyone.

Who your data is shared with

  • OpenStreetMap - only content you explicitly confirm. If you leave a note or confirm a tag-edit suggestion, that submission (and, for edits, your OSM identity) becomes a public, permanent part of OpenStreetMap. Your Graveller ratings are never sent to OSM automatically.
  • Email provider - password reset emails are sent via a transactional email provider (Resend, Inc.); your email address is shared with them only to deliver those messages.
  • Map tile providers - your browser loads base-map tiles and fonts directly from OpenFreeMap (built on OpenMapTiles) and terrain tiles from an AWS-hosted open dataset; those providers see standard web request information (including your IP) as part of serving the map.
  • Place search - the "search for a place" box queries OpenStreetMap's Nominatim service through our server, so your search text (not your account) reaches Nominatim.
  • Hosting / infrastructure - netcup GmbH (servers in a data centre in Vienna, Austria), who processes data on our behalf to run the servers and database.

How long we keep it

Account data and your contributions are kept until you delete your account. Photos that are reported and hidden by moderation are moved to a quarantine area and kept for up to 90 days so a moderator can finish reviewing them, then permanently deleted. Database backups, which include your data, are kept for recovery; until a backup is rotated out, a deleted account may still be present in it.

Your rights

Under the GDPR you can:

  • Access and export your data, and have inaccurate data corrected.
  • Delete your account yourself at any time from your account settings. This permanently removes your account, ratings, comments, photos, favorites, and ridden logs, detaches any connected OSM account, and recalculates affected segment ratings without your contributions. (Photos already hidden for moderation follow the 90-day retention above.) Note that any edits you already submitted to OpenStreetMap live in OpenStreetMap and are governed by OSM's own privacy policy.
  • Withdraw consent, object to processing, or lodge a complaint with your data protection authority (in Austria, the Datenschutzbehörde / Data Protection Authority).

To exercise a right that isn't self-service, contact privacy@graveller.app.

Changes

If this policy changes materially, we'll update the date above and, where appropriate, notify account holders.