Privacy Policy

Last updated: 27 June 2026

Tassie Abels is developed and operated by Isle Works ("we", "us", "our"). This policy explains what information we collect, how we use it, and your rights regarding your data.

1. Information We Collect

Account information

When you create an account, we collect your name, username, email address, and optionally a profile photo. If you create a managed account for a family member, we also collect their name and username — no email address or date of birth (see Section 5).

Activity data

We store the summit logs you create, including date, start time, duration, distance, steps, elevation gain, weather conditions, gear notes, and any written notes or ratings you add.

Social data

We store friend connections, group memberships, partner links, and the comments and likes you post on community summit logs. If you choose to add optional social media handles or a website link to your profile (for example Instagram, Strava, Facebook, TikTok, YouTube), these are stored and displayed publicly to other users — they are entirely optional, and you should only add them if you are happy to be found.

Community visibility

When community features are turned on (the default), your summit logs, comments, profile, and leaderboard position may be visible to other users in the public activity feed and leaderboard. You can turn community features off at any time in Profile → Privacy, which keeps your activity visible only to your friends, groups, and family. Managed accounts appear in the public community — the leaderboard and activity feed — like any other account, but cannot send or receive friend requests.

Subscription data

If you purchase a premium subscription, we store your subscription expiry date in your account record. Payment processing is handled entirely by Apple App Store or Google Play — we never see or store your payment details.

Notification tokens

If you grant permission for push notifications, we store a device token (FCM token) in your account record to deliver notifications such as friend requests, likes, and comments. This token is removed from our servers when you log out or revoke notification permission. Summit reminders you set for planned trips are scheduled and stored on your device and delivered locally — they are not sent through our servers.

Health data (Apple HealthKit / Google Health Connect)

With your explicit permission, Tassie Abels reads the following data from your device's health store:

This data is read solely to pre-fill fields in the summit log form. Health data is never uploaded to our servers, never shared with third parties, and never used for advertising. It is processed on-device and discarded after the form is populated.

2. How We Use Your Information

We do not use your information for advertising or sell it to any third party.

3. Third-Party Services

Tassie Abels uses the following services, each with their own privacy policies:

4. Data Retention

Your account data is retained for as long as your account is active. You can permanently delete your account and all associated data at any time from Profile → Account → Delete Account. Deletion is immediate and cannot be undone.

A manager who removes a managed-account link retains an archived record of that link for 30 days to allow recovery. After 30 days, the archive entry is automatically deleted. Your account cannot be deleted while you are an active manager of a managed account, or within the 30-day recovery window of a removed managed-account link.

5. Managed Accounts, Family Members & Children's Privacy

Creating a managed account

You must be at least 13 years old to create your own Tassie Abels account. Any user may also create a managed account for a family member and log summits on their behalf — for example a parent for their child, or one adult for another family member who doesn't use the app themselves. The person who creates a managed account is its manager.

Before a managed account is created, we present a screen that clearly explains what data is collected and how it is used. If the family member is a child, the manager must confirm they are the child's parent or legal guardian and give their informed consent. This confirmation is recorded against the manager's account.

Data collected for managed accounts

When creating a managed account, the manager provides the family member's name and username. The family member's summit logs, progress, and any notes entered by the manager are also stored. Managed accounts do not require an email address, and we do not collect a date of birth. A managed account can later be upgraded to a full, self-managed account by adding and verifying an email address.

How managed-account data is used

Managed-account data is used to track and display the family member's hiking progress. Like any other account, a managed account's display name and summit logs may appear in the public community — the leaderboard and activity feed — which contain no sensitive personal information. A managed account cannot send or receive friend requests or start social interactions itself; its public summits can, however, receive likes and comments from other users like any other post. A manager can turn community visibility off for a managed account at any time.

Manager controls

The manager has full administrative control over a managed account, including the ability to:

Co-managers and partner linking

When two accounts are linked as partners, each may choose to share their managed accounts with the other. Both then have full access to all shared managed accounts. Sharing is opt-in at the time of linking and can be adjusted independently by each manager.

Reporting concerns

If you believe a managed account has been created for a child without appropriate parental consent, or for an adult without their knowledge, please contact us and we will investigate and remove it promptly.

6. Content Moderation

We reserve the right to moderate user-generated content to maintain a safe and respectful community. Specifically, authorised Isle Works staff may:

Users may report content using the in-app reporting tools. Reports are reviewed by our moderation team. We will take reasonable action but cannot guarantee a specific outcome or timeframe.

7. Internal Access to User Data

Authorised Isle Works staff may access account information when it is necessary to:

Access is restricted to the minimum information needed for the task. Staff cannot access your password (passwords are hashed by Firebase and are never visible to us), payment details, or health data. Access is logged and is not used for marketing, advertising, or any purpose beyond operating and supporting the service.

For managed accounts, access is additionally limited to resolving manager-related support requests or responding to safeguarding concerns.

8. Your Rights

You have the right to:

Residents of the European Economic Area, United Kingdom, and other jurisdictions with applicable data protection laws may have additional rights including the right to data portability and the right to object to processing. Contact us to exercise these rights.

9. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by updating the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.

10. Contact

Questions or concerns about this privacy policy? Visit our support page.

Like the app? Buy me a coffee ☕