Outest Privacy Policy

Last updated: August 23, 2026

1. Introduction

This Privacy Policy explains how HIKERS AND TRAILS İÇ VE DIŞ TİCARET LİMİTED ŞİRKETİ operates Outest and collects, uses, stores, transfers, discloses, and protects personal data.

In this Privacy Policy:

For users in Türkiye, we act as the data controller under Turkish Personal Data Protection Law No. 6698, commonly known as the KVKK.

Where the European Union or European Economic Area data-protection rules apply, we act as the controller under Regulation (EU) 2016/679, known as the General Data Protection Regulation or GDPR.

By accessing or using Outest, you acknowledge that you have read this Privacy Policy. Where consent is required by law, we will request it separately and clearly.

This Privacy Policy does not replace specific notices that may be shown when a particular feature is activated, such as location recording, camera access, notifications, or optional analytics.


2. Data Controller Information

Data controller and Service operator

HIKERS AND TRAILS İÇ VE DIŞ TİCARET LİMİTED ŞİRKETİ

Registered address:

HIKERS AND TRAILS İÇ VE DIŞ TİCARET LİMİTED ŞİRKETİ

Cumhuriyet Mah. D-100 Karayolu Cad. ADM Konaklama Sitesi Outlet Park AVM No: 374 İç Kapı No: 63

Büyükçekmece, İstanbul 34500

Country: Türkiye

Privacy and support email: support@hikersandtrails.com

Website: outestapp.com

Account-deletion page: https://outestapp.com/delete-account.html


3. Scope of This Policy

This Privacy Policy applies to personal data processed through:

It does not apply to independent websites, applications, services, or businesses that may be linked from Outest but are operated under their own privacy policies.


4. Personal Data We Collect

The personal data we collect depends on the features you use, the permissions you grant, your device, and how you interact with Outest.

4.1 Account and identity information

When you create or manage an Outest account, we may collect:

We do not ask users to publish their legal name unless required for a specific feature or legal reason.

4.2 Authentication information

When you register using an email address and password, authentication is managed through our authentication infrastructure.

Passwords are not available to Outest in readable form. Authentication providers store password-related credentials using security controls designed for authentication purposes.

When you use Sign in with Apple or Google Sign-In, we may receive information authorized by you and supplied by that provider, such as:

Apple may provide a private relay email address when you choose to hide your email. Apple and Google independently process information according to their own terms and privacy policies.

4.3 Precise location and trail data

Outest uses location information to record hiking activities and provide route-related functionality.

When you deliberately start an active hike or trail-recording session and grant the required permission, we may collect:

Location may continue to be collected while an active recording session is running, including when the application is temporarily in the background, where permitted by your device settings and operating-system permissions.

Outest does not intend to collect continuous location information when:

You control location access through your device settings. Disabling location permission will prevent or limit trail recording and other location-dependent features.

4.4 Hiking and activity information

We may process activity information generated from your trail recording, including:

With your permission, Outest integrates with Apple Health and Google Health Connect. Depending on your device and the feature you use, Outest may read step counts, distance, active energy, workout information, speed or pace information, and heart-rate samples, and may write a completed hiking workout, walking or running distance, active energy burned, and heart-rate samples. Outest does not request diagnoses, clinical records, or unrelated health categories from those services.

Daily distance, pace, active-energy, and heart-rate details displayed in the Movement area are processed on your device. If you use step challenges or step-based rewards, Outest stores your daily step total, goal, source, and board-sharing choice in your private account record so the challenge or reward can operate and recover across sessions. That record is not shown on the board unless you separately choose to join; when you join, Outest shares the step contribution and limited profile details needed to display it.

When you record and save a hike, Outest may store a private hike-health summary in your account, such as average and maximum heart rate, calories, steps, duration, effort score, and time in heart-rate zones. Those summaries are restricted to your account.

If you provide an optional weight, Outest stores it in your private profile settings and uses it to improve activity-calorie estimates. Outest does not display your date of birth, weight, or private hike-health summaries on your public profile.

Hiking and activity data may nevertheless reveal information about an individual’s movements, routines, or physical activity. We therefore treat it as personal data when it is linked to a user or device.

4.5 User-generated content

When you participate in Outest’s social or community functions, we may collect and process content you choose to provide, including:

Do not upload content containing personal information about another person unless you are permitted to do so.

Public content may be viewed, copied, photographed, recorded, or reshared by other users. Outest cannot fully control how another user handles information that you voluntarily make public.

4.6 Photos, videos, audio, camera, microphone, and media-library access

When you choose to take, record, or upload media, Outest may request permission to access:

We use this access only to enable the feature you selected, such as creating a profile photo, attaching media to a post, adding photographs to a trail, recording a trail voice note, or submitting a voice question for transcription.

Media files may contain metadata, including creation date or location information. Where technically feasible and appropriate, we may limit unnecessary metadata processing. You should review sensitive metadata before sharing media publicly.

4.7 Social interactions

We may process information about your interactions, including:

We use this information to operate the social features, show relevant activity, enforce community standards, and protect users.

4.8 Usage and product-interaction information

We may collect information about how the Service is used, such as:

We use this information for Service operation, troubleshooting, security, and product improvement.

We do not currently use personal data for third-party behavioral advertising or sell personal data.

4.9 Device, network, and technical information

We or our service providers may process:

We use this data to deliver the Service, maintain compatibility, investigate errors, protect accounts, and improve reliability.

4.10 Crash and diagnostic data

We use Sentry for error monitoring and crash diagnostics.

Depending on the error and our technical configuration, Sentry may receive:

We aim to configure diagnostic tools to avoid collecting unnecessary content. Users should not include highly sensitive personal information in free-text areas.

4.11 Map and geospatial service information

Outest uses Mapbox and related mapping technology to display maps, route information, geographic content, and location-based features.

When map features are used, Mapbox may process technical or location-related information necessary to deliver map tiles and related services, potentially including:

Mapbox acts under its own contractual and privacy obligations. Its processing may occur outside Türkiye or the user’s country.

4.12 Push-notification data

When you enable push notifications, we may process:

Notifications may concern:

You can disable notifications through Outest settings, where available, or your device settings.

4.13 Support and communications

When you contact us, we may collect:

We use this information to respond, investigate issues, keep support records, and protect the Service.

4.14 Moderation, safety, and reports

When content or conduct is reported, we may collect:

This information may be retained where reasonably necessary to maintain safety, prevent repeated abuse, establish or defend legal claims, or comply with legal obligations.

4.15 Subscription and transaction information

Outest offers paid subscriptions and may offer other in-app purchases. Payments are processed by Apple, Google, or another authorized payment provider. Outest uses RevenueCat to manage subscription products, purchase status, entitlements, renewals, restorations, and related customer-support functions.

Outest may receive transaction-related information such as:

Outest generally does not receive complete payment-card numbers from Apple or Google.

Additional payment-related disclosures will be added if direct payment processing is introduced.

4.16 Website information and cookies

Our website may use:

Strictly necessary technologies support core functions and security. Non-essential cookies or similar technologies will be used only where permitted and, when legally required, after obtaining consent.

Further information may be provided through a separate Cookie Policy or consent-management interface.

4.17 Information from other users and lawful sources

We may receive information concerning you when:

4.18 Emergency contacts, safety contacts, live sharing, and check-ins

If you use Outest safety features, we may process:

Phone emergency contacts are used only when you manually choose to call or send an SOS text from your device; Outest does not automatically call or text those numbers. A text you choose to send can include your GPS coordinates and is processed by your device and telecommunications provider.

Automatic check-ins operate only when you enable them. Selected Outest safety contacts may receive a hike-start notification and can remove themselves. Anyone who has your active safety-link URL can view the latest location available through that link without signing in, and a recipient can forward the link. Share it only with people you trust. Disabling automatic check-ins controls future automatic activations; it does not recall a link already shared.

Only enter another person’s contact details if you are authorized to do so and have told them that Outest will store the details for your safety feature. You can edit or remove phone contacts and Outest safety contacts in the Safety contacts screen.


5. Information We Do Not Intentionally Collect

Unless a feature clearly states otherwise, Outest does not intentionally request:

Do not place such information in your profile, posts, captions, comments, messages, trail descriptions, photographs, or support requests.

Information that you voluntarily publish may incidentally reveal sensitive personal data. You are responsible for deciding what to share publicly.


6. How We Use Personal Data

We may use personal data to:

6.1 Provide and operate the Service

6.2 Personalize the user experience

We do not currently use sensitive personal data to create advertising profiles.

6.3 Maintain security and integrity

6.4 Diagnose and improve the Service

Where reasonably possible, we use aggregated or de-identified information for analysis.

6.5 Communicate with users

6.6 Comply with law and establish legal rights


7. Legal Bases for Processing

The applicable legal basis depends on the data, purpose, and jurisdiction.

7.1 GDPR legal bases

Where the GDPR applies, we rely on one or more of the following:

Performance of a contract

Processing is necessary to provide Outest under our Terms of Service, including:

Legitimate interests

We may process data where necessary for legitimate interests that are not overridden by your rights, including:

Consent

We rely on consent when required, including potentially for:

You may withdraw consent at any time. Withdrawal does not affect processing that occurred lawfully before withdrawal.

Legal obligations

We process information where necessary to meet legal obligations, respond to lawful authority requests, and retain records required by law.

Vital interests

In exceptional circumstances, we may process information where necessary to protect a person’s life or physical safety.

7.2 KVKK processing conditions

Where the KVKK applies, personal data may be processed:

Where explicit consent is required, it will be requested separately. Acceptance of this Privacy Policy does not by itself constitute consent for every processing activity.


8. Device Permissions

Outest may request operating-system permissions such as:

Location

Used for active trail recording and location-dependent map features.

Background location

Where required by the operating system, background-location access may be used only to continue a recording session deliberately started by you.

Camera

Used when you choose to capture a photograph or video.

Photos or media library

Used when you choose media to upload.

Notifications

Used to deliver activity, operational, account, and security notifications.

Permission requests will be shown through the device interface. You can manage permissions in your operating-system settings.

Withdrawing a permission may prevent the related feature from operating but should not affect unrelated features.


9. Public and Private Information

A new Outest account’s profile-visibility setting is Public by default until you enable Private profile in Settings. When you save a recorded activity, Public is also selected by default on the save screen; you can choose Private before saving. A public activity and its route can be viewed by other users under the applicable feature design. A private activity is kept out of the community feed and is available only to you through the activity feature.

Information that may be visible to others, depending on your settings and feature design, includes:

Before sharing a route publicly, consider whether it reveals:

Where available, use privacy controls or hide approximately 200 metres around sensitive start and end points before publishing.

Direct messages, phone emergency-contact details, date of birth, weight, daily health details, and private hike-health summaries are not made public through those features. A safety link is different from a public post: it is not listed publicly, but anyone holding the active link can access the latest location made available through it.

Private information is accessible only as permitted by the feature and your settings. No online system can guarantee that another user will not copy or disclose content they are permitted to view.


10. Artificial Intelligence and Automated Processing

Outest uses artificial intelligence in two distinct ways: optional features that you choose to use and mandatory safety screening that protects the community. Outest may also publish clearly labelled AI-generated or AI-assisted official posts.

Separately, Outest may use automated systems to:

10.1 Optional AI features and your choices

Premium access and consent for optional AI features are separate. Before personal data is sent to a model for one of these features, Outest asks for a specific, informed choice for that purpose. Outest uses your account ID internally to verify consent, apply feature limits, and record the request; it is not intentionally included in provider prompts. The current optional purposes and provider-facing data are:

You may refuse or later withdraw each optional choice in Settings > AI & your data or the applicable plant-research setting. Refusal does not prevent access to the core Service; it only prevents the related optional model request or research use. Withdrawal applies to future model requests and does not undo processing already completed at your request. Withdrawing plant-research participation also removes pending and approved contributions from research use while leaving your private Field Journal entries intact.

10.2 Mandatory safety moderation

Before a post or story is visible to other users, Outest sends its text and, where present, images and video thumbnails to OpenAI's moderation API, which acts as a data processor, to check for prohibited or unsafe content.

This screening is used to enforce our Terms and protect users and the Service. It is based on the performance of our agreement with you and our legitimate interest in community safety; it is mandatory and is not part of optional AI consent. Content that cannot be screened automatically remains pending and is not publicly visible until screening succeeds or an authorized reviewer handles it. Automated results may route content for human review, and material enforcement decisions may involve human review where appropriate.

10.3 Providers, labels, and processing records

Current providers are DeepInfra-hosted models and Google Gemini for the AI Trail Guide depending on the selected mode and technical configuration; DeepInfra for voice transcription; Pl@ntNet and, where a fallback is needed, Google Gemini for plant identification; Google Gemini for nature identification; and OpenAI for mandatory safety moderation. Plant-research contributions remain in Outest research systems. The in-app notice identifies the applicable purpose, data categories, and provider before any optional AI processing. If a provider or purpose materially changes, we update the applicable notice before sending personal data for that new processing.

AI-generated or AI-assisted outputs are labelled in the interface. Outest also keeps access-controlled, append-only generation records showing the feature, intended audience or account, time, provider, model, processing status, and cryptographic hashes of inputs and outputs. The generation ledger is designed to prove provenance without duplicating raw prompts, recordings, photographs, or generated answers.

Consent records include the purpose, choice, notice version, data categories, processors, language, source, and time. Each later change creates a new record rather than editing the earlier record.

10.4 Automated decisions

Unless we provide a separate notice, Outest does not make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning a user.


11. How We Share Personal Data

We do not sell personal data.

We do not share personal data with third parties for their independent behavioral advertising.

We may share information in the circumstances below.

11.1 With other Outest users and the public

Information is shared according to:

When you create and share a safety link, you direct Outest to make the latest shared location available to anyone presenting that link’s random token while the share remains active. Outest does not make the link searchable, but we cannot prevent a recipient from forwarding it. Registered safety contacts may also receive the related hike-start notification through Outest’s notification infrastructure.

11.2 Service providers and processors

We engage providers that support Outest, including:

These providers may process information only to provide their services, under their contractual terms, legal obligations, and applicable privacy documentation.

11.3 Legal and safety disclosures

We may disclose data when reasonably necessary to:

We review requests for legal validity where permitted.

11.4 Corporate transactions

If Outest or its business is involved in a merger, acquisition, financing, reorganization, asset transfer, or sale, relevant information may be disclosed to professional advisers and transaction participants subject to appropriate confidentiality and legal safeguards.

Users will be informed where required by law of a change affecting the controller of their personal data.

11.5 With your direction or consent

We may disclose information where you instruct us to do so or give valid consent.


12. International Data Transfers

Outest is operated by a company established in Türkiye. Some service providers may process or store data outside Türkiye, the European Union, the European Economic Area, or your country of residence.

Our Supabase project is presently hosted in SouthEast Asia (Singapore)

International transfers may arise through providers such as Supabase, Sentry, PostHog, RevenueCat, Mapbox, Apple, Google, and the AI providers identified in Section 10.

Where legally required, we use an applicable transfer mechanism, which may include:

International transfer rules under Turkish law and the GDPR differ. We apply the mechanism relevant to the affected processing and jurisdiction.

Service providers may also process information in countries where their affiliates, personnel, or infrastructure are located.


13. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Service, meeting legal obligations, resolving disputes, protecting safety, preventing abuse, and enforcing agreements.

General retention principles include:

Account information

Retained while your account remains active and during the account-deletion process.

Body and health information

Date of birth and optional weight are retained with your account until changed, removed where the feature permits, or deleted with the account, subject to lawful retention requirements. Daily distance, pace, active-energy, and heart-rate details displayed in Movement remain on your device. Daily step-challenge or reward records are retained with your account until deleted with the account or no longer needed for the feature. Private hike-health summaries stored by Outest are retained with the related recorded activity until you delete that activity or your account, subject to backups and lawful retention requirements.

Trails and user content

Retained while your account remains active or until you delete the relevant content, subject to backups, moderation records, legal obligations, and content that has been lawfully reshared or incorporated into another user’s interaction.

Location records

Recorded location data is retained as part of the trail record until:

Emergency contacts, safety contacts, and live-share records

Contact and safety relationships are retained until you or the recipient removes them or the related account is deleted. Access through a safety link ends when the share becomes inactive or expires. The underlying link, location-update, and delivery records are retained only while reasonably needed to operate the feature, maintain security and abuse-prevention records, resolve disputes, or meet legal obligations, and are deleted with the account unless a lawful exception applies.

Support communications

Retained for a reasonable period to respond to requests, maintain support history, and establish or defend legal rights.

Security and moderation records

May be retained after account deletion where reasonably necessary to prevent fraud, address serious abuse, maintain platform safety, comply with law, or establish or defend legal claims.

AI consent and provenance records

Consent receipts and processing records are retained for as long as reasonably necessary to demonstrate your choices, document model processing, investigate security or compliance issues, and establish or defend legal claims. The provenance ledger stores metadata and cryptographic hashes rather than duplicate copies of raw prompts, recordings, photographs, or generated answers.

Plant research contributions

Confirmed plant contributions are retained for expert review and model research only while your separate research choice remains active and the contribution remains necessary. If you withdraw, pending and approved contributions are marked as withdrawn from research use; your private Field Journal record remains until you delete it or your account.

Diagnostic data

Retained according to our diagnostic settings and service-provider configuration, then deleted or aggregated when no longer needed.

Transaction records

Retained as required by tax, accounting, consumer-protection, or other applicable laws.

Backups

Deleted data may remain in encrypted or access-restricted backups for a limited period until backups are overwritten according to our backup cycle. Backup data is not restored for ordinary business use except when needed for disaster recovery, security, or legal obligations.

Where there is no fixed legal period, we determine retention based on:


14. Account and Data Deletion

You may request account deletion:

  1. Through the account settings inside the Outest application; or
  2. Through https://outestapp.com/delete-account.html without needing the application installed; or
  3. By contacting support@hikersandtrails.com from the email associated with your account.

We may take reasonable steps to verify identity and prevent unauthorized deletion.

Account deletion means deleting the account and associated personal data that we are not legally or legitimately required to retain. Temporary suspension, deactivation, or disabling does not constitute deletion.

Following a valid deletion request:

Some information may remain visible where:

Apple requires applications supporting account creation to allow users to initiate account deletion inside the app. Google Play also requires qualifying apps to offer in-app deletion and an external web method through which users can request deletion.


15. Your Privacy Choices

You may control your information by:

Revoking location permission will prevent new location collection but will not automatically delete previously recorded routes. Previously recorded data can be deleted separately through the relevant feature or account-deletion process.


16. Rights Under the KVKK

Individuals whose personal data is processed under the KVKK may have the right under Article 11 to:

Requests may be submitted using legally permitted methods, including in writing or through another method recognized under KVKK procedures.

Contact:

HIKERS AND TRAILS İÇ VE DIŞ TİCARET LİMİTED ŞİRKETİ

Cumhuriyet Mah. D-100 Karayolu Cad. ADM Konaklama Sitesi Outlet Park AVM No: 374 İç Kapı No: 63

Büyükçekmece, İstanbul 34500

Türkiye

support@hikersandtrails.com

A request should include enough information to identify the requester, describe the requested right, and verify the relationship to the relevant data.

KVKK requires controllers to provide an information notice and establishes data-subject rights and formal methods for submitting requests.


17. Rights Under the GDPR

Where the GDPR applies, and subject to applicable conditions and exceptions, you may have the right to:

Access

Receive confirmation of whether we process your personal data and obtain a copy and related information.

Rectification

Correct inaccurate data and complete incomplete data.

Erasure

Request deletion where there is no longer a lawful basis for processing.

Restriction

Request that processing be limited in qualifying circumstances.

Data portability

Receive certain data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible.

Objection

Object to processing based on legitimate interests, including relevant profiling.

Where data is processed for direct marketing, you may object at any time.

Withdraw consent

Withdraw consent where processing is based on consent, without affecting prior lawful processing.

Automated decisions

Request protections relating to qualifying decisions based solely on automated processing that have legal or similarly significant effects.

Complaint

Lodge a complaint with the competent supervisory authority, particularly in the EU or EEA country where you live, work, or believe an infringement occurred.

To submit a request, contact support@hikersandtrails.com.

We may verify your identity before fulfilling a request. We generally respond within the period required by applicable law. Requests may be limited or refused where permitted by law, including where they adversely affect another person’s rights, are manifestly unfounded, or are excessive.

The GDPR establishes transparency duties, lawful processing requirements, data-subject rights, security obligations, and international-transfer requirements.


18. Security

We use technical and organizational measures intended to protect personal data, including where appropriate:

No electronic transmission, storage system, or security measure is completely secure. We cannot guarantee absolute security.

You are responsible for:

Security concerns may be reported to support@hikersandtrails.com.


19. Personal Data Breaches

Where we become aware of a personal data breach, we will investigate and take steps appropriate to the nature and risk of the incident.

Where legally required, we will notify:

Notifications will be made according to applicable legal requirements.


20. Children’s Privacy

Outest is not intended for children under 13 years of age, and we do not knowingly permit children under 13 to create accounts.

In countries where a higher minimum age applies to independent consent for online services, a parent or legal guardian may need to provide valid authorization.

Parents or guardians who believe a child has provided personal data without appropriate authorization should contact support@hikersandtrails.com.

After appropriate verification, we will take reasonable steps to delete the child’s account and personal data, subject to applicable legal requirements.

Hiking routes may involve physical risk. Outest is not a substitute for parental supervision, professional guidance, safety preparation, or emergency services.


21. Location and Outdoor-Safety Notice

Trail and location information may be inaccurate, incomplete, outdated, or affected by:

Privacy controls do not make outdoor activity safe. Users should independently assess routes, weather, laws, closures, physical ability, equipment, and emergency planning.

Outest is not an emergency-location service and should not be relied upon to contact emergency services or guarantee rescue.


22. Third-Party Links and Services

Outest may contain links to third-party websites, businesses, maps, content, or services.

A third party may collect information when you interact with its service. Outest does not control independent third-party privacy practices.

Review the third party’s privacy policy before supplying personal data.


23. No Sale or Behavioral Advertising

Outest does not currently:

If these practices materially change, we will update this Privacy Policy and obtain consent where required.

For Apple privacy disclosures, data is considered “tracking” under Apple’s rules in certain circumstances involving linking data from an app with third-party data for targeted advertising or advertising measurement. Outest does not currently engage in such tracking.


24. Changes to the Service

As Outest develops, we may introduce features such as:

Before materially different data processing begins, we will update this Privacy Policy, provide feature-specific information, and request permission or consent where required.

This policy should not be interpreted as stating that every listed future feature is currently available.


25. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

The “Last updated” date will show when the latest version became effective.

Where changes are material, we may provide notice through:

Where consent is legally required for a new purpose, continued use alone will not replace valid consent.


26. Language

This Privacy Policy may be made available in English, Turkish, and other languages.

Where required by law, users will receive information in an appropriate language. In the event of an inconsistency between translations, the version designated by Outest as controlling will apply to the extent permitted by law, without limiting mandatory rights.

For the Türkiye launch, a complete Turkish version is published alongside this English version.


27. Contact and Privacy Requests

For questions, complaints, requests, or concerns about personal data, contact:

HIKERS AND TRAILS İÇ VE DIŞ TİCARET LİMİTED ŞİRKETİ

Registered address:

Cumhuriyet Mah. D-100 Karayolu Cad. ADM Konaklama Sitesi Outlet Park AVM No: 374 İç Kapı No: 63

Büyükçekmece, İstanbul 34500

Türkiye

Email: support@hikersandtrails.com

Website: outestapp.com

Account deletion: https://outestapp.com/delete-account.html

Please include:

Do not send passwords or unnecessary identification documents by ordinary email.