fonskii — Privacy Policy

Last updated: July 7, 2026

1. Overview

fonskii is a ski and altitude tracking app for iOS and Android that records altitude, speed, distance, and vertical during your sessions. This policy explains what data fonskii collects, how we use it, and the choices you have.

App: fonskii
Provider: fonszi Kft. ("Fonszi," "we," "us," "our")
Contact: dev@fonszi.com

This is the product-specific policy for fonskii. For the full company-wide policy, including detailed GDPR and CCPA disclosures that apply across all Fonszi products, see our main Privacy Policy.

2. Accounts and Sign-In

fonskii uses a Fonszi account managed by our backend at api.fonszi.com. We collect:

  • Email address — required for account creation and login.
  • Display name — user-provided, shown to friends in Buddy Sessions.
  • Profile photo — optional, uploaded to our server.
  • Authentication tokens — stored securely on your device (Android: EncryptedSharedPreferences; iOS: Keychain).

Single-device sessions: a stable device identifier is sent at login to enforce single-device sessions (Android: ANDROID_ID; iOS: a randomly generated app UUID). We do not collect advertising identifiers (IDFA/GAID).

Deleting your account: You can permanently delete your account and all associated data from within the app (Profile › Delete account). Deleting your fonskii account does not affect your account on other Fonszi apps.

3. Location Data

  • GPS coordinates (latitude, longitude, altitude) and barometric pressure are collected only while a tracking session is active to compute speed, distance, altitude, and vertical.
  • Session tracks and metrics are stored locally on your device and are never uploaded to our serversunless you explicitly share them (e.g., Strava export).
  • During Buddy Sessions (real-time location sharing with friends), your GPS coordinates are streamed to our server for the duration of the session only (typically 2–4 hours) and are automatically deleted when the session ends.

4. Other Data We Collect

4.1 Session Data (Local Only)

  • Tracking sessions (start time, duration, distance, elevation gain/loss, speed, GPS track) are stored locally on your device.
  • You can export sessions as GPX files or share summary cards.

4.2 Analytics Data (Anonymous)

  • Firebase Analytics collects anonymous usage data such as app opens, screen views, and feature usage. This data cannot identify you personally.
  • Firebase Crashlytics and Fonsitor (our own error-monitoring tool) collect crash and runtime-error reports with device model, OS version, and screen context. No personal information is included.

4.3 Advertising (Free Tier Only)

  • Free-tier users see ads served by Google AdMob (interstitials after sessions, occasional banners).
  • Pro users do not see ads.
  • iOS App Tracking Transparency (ATT): On iOS, fonskii presents Apple's ATT prompt before any advertising identifier is accessed. If you decline, only contextual (non-personalized) ads are served. You can change this any time in Settings › Privacy & Security › Tracking.
  • Android: You can opt out of personalized ads in Settings › Privacy › Ads. fonskii does not collect or share your advertising identifier.

4.4 Billing and Subscriptions

fonskii Pro is available as a one-time lifetime purchase. Subscription status is managed by RevenueCatand linked to your Fonszi account. Purchase tokens from the Apple App Store or Google Play Store are forwarded to RevenueCat for validation. We never receive or store your payment card details — those are handled entirely by Apple or Google.

5. Maps, Weather, and Trail Data

  • Google Maps (Android) and Apple MapKit (iOS) display maps and may collect data under their own privacy policies.
  • Open-Meteo receives your approximate coordinates (latitude/longitude) to provide weather during tracking. No user ID is sent.
  • Overpass API (OpenStreetMap) receives geographic bounding boxes to load piste and lift data for trail maps. No user ID is sent.
  • Strava export is user-initiated: when you choose to share a session, the GPX file is sent to Strava via their API.

6. Data We Do NOT Collect

  • Phone number or physical address
  • Contacts or address book
  • Camera or microphone access (profile photo upload is user-initiated)
  • Browsing or search history
  • Health or biometric data (a "biometric login enabled" flag, if set, is stored locally only)
  • Financial data or payment details
  • Advertising identifiers (IDFA / GAID)

7. Third-Party Services

ServiceData ReceivedPrivacy PolicyFirebase Analytics (Google)Anonymous events, device infoFirebase / GoogleFirebase Crashlytics (Google)Crash reports, device infoFirebase / GoogleGoogle AdMob (Google)Device info, ad impressionsGoogle AdsRevenueCatPurchase tokens, subscription statusRevenueCatOpen-MeteoApproximate coordinatesOpen-MeteoOverpass API(OpenStreetMap)Geographic bounding boxesOverpass APIGoogle Maps / Apple MapKitMap viewport, tile requestsGoogle / AppleStrava (optional)GPX file (user-initiated)StravaFonsitor (Fonszi)Error messages, screen context, device infoFirst-party (see this policy)Apple App Store / Google PlayPurchase & subscription dataApple / Google

8. Permissions PermissionPlatformPurpose

Location (Fine & Coarse)Android & iOSGPS-based trackingForeground Service (Location)AndroidTracking during a sessionBackground LocationAndroidContinued tracking with screen offHigh Sampling Rate SensorsAndroidPrecise barometric pressureNotificationsAndroid & iOSTracking status, buddy invitesInternetAndroid & iOSMaps, resort data, authentication

All permissions are requested at runtime. You can revoke any permission through your device settings.

9. Data Storage and Security

  • Session data is stored locally on your device in a database protected by OS-level file permissions.
  • Account data (email, display name, avatar) is stored on our backend (api.fonszi.com) over encrypted HTTPS connections.
  • Authentication tokens are stored in platform-specific secure storage (EncryptedSharedPreferences on Android, Keychain on iOS).
  • Buddy session location data is ephemeral — automatically deleted when the session ends (2–4 hours maximum).

10. Data Retention

DataRetentionHow to deleteSession tracking dataUntil you delete itDelete in app or uninstallAccount dataUntil account deletionIn-app account deletion (within 30 days)Avatar imagesUntil you remove or delete accountIn-app profile settingsFirebase Analytics14 months (Google default)Opt out via device settingsCrash reports90 days (Fonsitor), retained by Google (Crashlytics)Automatic expiryBuddy session data2–4 hoursAutomatic expiry

11. Children's Privacy

fonskii is not directed at children under 13, and we do not knowingly collect personal data from them. In the European Economic Area, the applicable minimum age may be higher (up to 16, depending on the country). If you believe a child has provided us with personal data, contact us and we will delete it.

12. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. In particular, you can:

  • Delete your account and all associated data via in-app account deletion;
  • Delete session data at any time within the app;
  • Export your data as GPX files;
  • Opt out of personalized advertising via your device settings (or the iOS ATT prompt);
  • Revoke permissions through your device's system settings.

For full details of your rights under GDPR and CCPA/CPRA, see our main Privacy Policy. To make a request, email dev@fonszi.com.

13. Changes to This Policy

We may update this policy from time to time. Changes are posted here with an updated "Last updated" date. For material changes, we will provide additional notice (e.g., in-app). Continued use of the app after changes take effect constitutes acceptance.

14. Contact Us

If you have questions about this privacy policy:

Email: dev@fonszi.com
Website: https://fonszi.com