Last updated: August 2, 2026
Map Tools: Fake GPS & Trails Disclosure Notice on Processing of Personal Data (Under the Personal Data Protection Law No. 6698)
Data Controller: Abdulkadir ER Contact: akillisletme@gmail.com
1. Introduction This disclosure notice has been prepared in accordance with Article 10 of the Personal Data Protection Law No. 6698 ("KVKK") to inform you about how your personal data is processed during your use of Map Tools: Fake GPS & Trails ("the App").
2. Personal Data Processed
A. Data Processed Locally on Your Device: • Mock location coordinates you set within the App • Favorite locations you save and associated notes • Joystick starting positions • Saved routes and PRO route waypoints (with speed/altitude/dwell parameters) • Human behavior simulation settings • Scheduled location settings • Smart Shield rules (package name ↔ location profile mappings) • The foreground app's package name held in memory by Smart Shield (via Usage Access — PACKAGE_USAGE_STATS) (not written to disk, not logged) • Photo GPS Editor: local editing of EXIF location metadata of the photo the user explicitly picks, and saving a new copy to the device gallery • Recorded walk tracks (Walk mode): sequences of latitude, longitude, altitude, and timestamp • Unfinished recording drafts (temporary track records kept on the device during a recording to guard against crashes) • Home widget and floating widget slot settings • Map and interface preferences • Vehicle favorites, unit preference, accent color, and daily usage (quota) counters • Language, theme, usage/consent status
Real location data. The location permission is used for two purposes: (1) centring the map and verifying the mock-location setup, and (2) sampling your real GPS track only while you are recording a walk that you started yourself. In that case latitude, longitude, altitude and a timestamp are stored on your device. This data is never sent to our servers; it stays on your device until you delete it or uninstall the app. Recording continues with the screen off and while the App is in the background; a persistent notification is shown throughout, and recording ends only when you stop it.
IMPORTANT: All of the above data is stored solely on your device using local storage (HydratedBloc, SharedPreferences, and the on-device SQLite database). This data is never transmitted to any server or third party.
B. Data Processed Through Third-Party SDKs: • Google Maps SDK: May process data in accordance with Google's own privacy policy during map display. We do not access or receive this data. • Firebase Remote Config: Only receives a configuration request to check the minimum app version. No personal data is transmitted. • Firebase Crashlytics: Only active on release builds when the CRASHLYTICS flag is enabled. May process technical crash data such as app version, package name, device model, OS version, crash time, error logs, and stack traces. Name, email, phone, contacts, messages, user content, and saved locations are never knowingly collected. • Cloud Firestore (read-only): Only reads the app_meta/changelog document to display the "What's New" (changelog) text. No user data is written or uploaded to Firestore; only during the read request may standard connection metadata such as the IP address be processed under Google's own policies.
3. Personal Data We Do Not Process We explicitly do not collect, process, store, or transmit: • Any transmission of your real GPS location to our servers (the location permission is used on-device only; track data collected while recording a walk stays on your device — see Section 2/A) • Device identifiers (IMEI, Android ID, Advertising ID) • IP addresses • Usage statistics, behavioral data, or analytics (no analytics SDK including Google Analytics or Firebase Analytics is included) • Personal identification information (name, email, phone, etc.) • Financial or payment information • Biometric data • Communication data (contacts, SMS, call logs) • Screen content, typed text, messages, passwords (with the Usage Access permission, Smart Shield reads only the package name of the foreground app and does not read screen content) • The list of your installed apps (read locally for the Smart Shield app picker only; the list is never sent off the device) • Your photos or photo metadata (Photo GPS Editor only accesses the single photo the user picks and performs no background photo scanning) • Advertising SDK or ad profiles (no advertising network is integrated)
Note: Only when Firebase Crashlytics is enabled, technical data such as crash stack, device model, and OS version is processed; see Section 6 below for details.
4. Purposes of Data Processing Limited local data processing serves the following purposes: • Providing the App's core mock location functionality (Basic Mock, Joystick, Route, Pro Route, Human Simulation) • Storing your favorite locations, routes, and simulations for convenient reuse • Detecting the foreground app's package name via Smart Shield (Usage Access / PACKAGE_USAGE_STATS) and automatically starting the user-defined location profile (fully local, no screen content is read) • Editing the EXIF GPS metadata of a photo the user explicitly picks via the Photo GPS Editor (local operation, a new copy is saved to the device gallery) • In Walk mode, sampling your real GPS track and storing it on your device only while you are recording a walk that you started; writing a temporary draft to protect the recording against crashes; drawing a heat map and an altitude profile from your recordings; and following a saved track while you walk it, alerting you when you drift away from it (all of these run on the device; no location data is transmitted) • Triggering scheduled mock locations via the scheduler (AlarmManager; RECEIVE_BOOT_COMPLETED is required to re-register after reboot) • Quick control via the floating widget and home widget • Remembering your app preferences and consent status • Checking the required minimum app version via Firebase Remote Config • Monitoring app stability and diagnosing crashes via Firebase Crashlytics (release builds only, when enabled)
5. Legal Basis for Data Processing • KVKK Article 5/2-c: Processing is necessary for the performance of the App's functionality accepted by the user • KVKK Article 5/2-f: Legitimate interests of the data controller (app version check for security and compliance) • KVKK Article 5/1: Your explicit consent obtained through the in-app consent mechanism for general use of the App
6. Data Transfer • Domestic Transfer: No personal data is transferred to any domestic third party. • International Transfer: We do not directly transfer personal data internationally. The following third-party services may process technical data through Google's global infrastructure: - Google Maps SDK: map-tile requests (IP address etc. subject to Google's own policies) - Firebase Remote Config: configuration requests such as app version and device locale - Firebase Crashlytics: only on release builds and when enabled, crash stack, device model, OS version, and app version are sent to Google; no personal identifier is included - Address search (Geocoding): the place-name query you search on the map is resolved into coordinates via the Android system geocoder (over the internet; the backend resolver may be Google). Only the search text you type leaves the device; it is not stored or used for profiling - Cloud Firestore (read-only): the app_meta/changelog document is read to display the "What's New" (changelog) text. Read-only; no user data is written or uploaded • We do not access or control the raw data in these communications; the data is subject to the relevant provider's own privacy policies. • We do not sell, rent, or share any data with data brokers or third parties.
7. Data Retention Period • Local Data: All data stored on your device is retained until you clear the app data from Android Settings or uninstall the App. The App does not use device backup (android:allowBackup="false"); therefore deleted data — including your recorded walks — cannot be recovered. • Server-Side Data: Since we do not collect any data, we do not retain any data on servers. • You always have full control over your data.
8. Your Rights Under KVKK Article 11 You have the right to: a) Learn whether your personal data is being processed b) Request information about the processing if your personal data has been processed c) Learn the purpose of processing your personal data and whether it is used in accordance with its purpose d) Know the third parties to whom your personal data has been transferred domestically or abroad e) Request rectification if your personal data has been processed incompletely or inaccurately f) Request deletion or destruction of your personal data under the conditions stipulated in Article 7 of KVKK g) Request notification of rectification and deletion operations to third parties to whom your personal data has been transferred h) Object to the emergence of a result against you through the analysis of processed data exclusively by automated systems i) Claim compensation if you suffer damage due to unlawful processing of your personal data
To exercise any of these rights, please contact: akillisletme@gmail.com We will respond to your request within the legally required 30 days.
9. Data Security Measures We implement the following measures to protect your data: • All data is stored locally on your device, eliminating server-side breach risks • No unnecessary data collection, minimizing exposure risk • The App does not require internet access for core functionality (only for map tiles and version check) • We follow the principle of data minimization, collecting only what is strictly necessary
10. Changes to This Notice This disclosure notice may be updated periodically. Changes will be reflected in the "Last Updated" date. Significant changes will be communicated through an in-app notification.
11. Governing Law This disclosure notice is governed by the laws of the Republic of Turkey, primarily the Personal Data Protection Law No. 6698.
12. Related Detailed Information Pages This KVKK notice is a summary. The following pages provide more detailed information on the related topics: • Permissions and Data Use — why each Android permission is requested • Usage Access Disclosure — how Smart Shield works and what it does not do • Third-Party Services — Google Maps + Firebase family list • Data Deletion — how to delete local data
— Change Note (September 2, 2026): An optional account (sign-in with Google or email) was added to the App. The statement "The App does not require account creation, sign-in, or personal profile creation" was corrected: anonymous use continues and signing in is optional; if you sign in, only account information is stored on our servers, while content data (routes, walks, favorites, settings) stays on your device. A pointer to the Data Deletion page for account removal was added.
Change Note (August 2, 2026): Updated for Walk mode. The statement in Section 3 that "your real GPS location is used only for local map centering and mock setup validation" was corrected, as it presented the scope of the permission as narrower than it is; the second purpose of the location permission (sampling the real GPS track while the user records a walk they started) was written explicitly into Section 2/A. Recorded walk tracks (sequences of location + altitude + timestamp), unfinished recording drafts, and quota counters were added to the processed-data categories; walk recording, the heat map, the altitude profile, and route following were added to the purposes in Section 4; a notice that no device backup is made (allowBackup=false) was added to Section 7. The statement that location data is never sent to our servers remains unchanged. The App was renamed from "Location Simulator – Mock GPS" to "Map Tools: Fake GPS & Trails"; all references in this document were updated. Page URLs are unchanged.
Change Note (June 21, 2026): Updated for the v2.1.0 release. It was reflected that Smart Shield now uses the Usage Access permission (PACKAGE_USAGE_STATS) instead of the Accessibility Service; the "android:canRetrieveWindowContent" reference was removed and the related disclosure link was updated to the Usage Access Disclosure page.
Change Note (June 1, 2026): Updated for the v1.7.0 release. The read-only use of Cloud Firestore (app_meta/changelog) was explicitly added to the third-party SDK list (Section 2) and the data-transfer section (Section 6).