Huella · FRANKITO Trading Co.
Effective 21 August 2026 · Applies to the Huella iOS app
Everything you record stays on your phone. Huella has no account system, no analytics, no ads, and no trackers. Exactly two things ever touch the network, and both are named below.
Every walk you record — the route, every GPS point, barometric elevation, pace, voice notes, landmark pins, imported routes, trips — is written to a local database on your phone. There is no sign-in, because there is no server holding your data to sign in to.
We cannot see your walks. Not “we promise not to look” — there is no copy anywhere for us to look at.
Recording a walk never requires either. With no signal, recording, history, stats and GPX export all work in full — that is the app’s founding rule. Features that genuinely need a connection (live terrain measurement in the AR view) say “no signal” plainly instead of failing quietly.
| Permission | Used for |
|---|---|
| Location | Recording your route, including with the screen off during a walk. Your location is written to the on-device database and nowhere else. |
| Motion & Fitness | The barometer, for accurate elevation gain, and motion activity, to pause recording automatically when you stop moving. |
| Microphone | Voice notes on the trail, recorded only while you hold the button. Stored on-device with the walk. |
| Camera | The AR horizon view that names peaks and measures terrain. Camera frames are rendered on screen and never stored or transmitted. |
Each permission is requested only when you first use the feature that needs it, and the app works without any you decline — you just lose that one feature.
An optional backup-and-sync feature may come later. If it does, it will be opt-in, off by default, and recording will never require it — local-first is an architectural rule in this app, not a marketing line. This policy will be updated before any such feature ships.
Open an issue on the Huella repository — the same place the app’s source lives.