Skip to content
balise
sec · privacy

Privacy policy

Updated 17 August 2026

Balise is an application for topographic mapping and route planning, for macOS and for iOS. This policy describes the data the application handles, what leaves your devices and what does not. In short: we run no server that could receive your tracks, and the only thing that moves them between devices is iCloud sync on your own Apple Account.

What this policy covers

It applies to the Balise applications for macOS and for iOS, and to this site, balise.mgcrea.io. It does not cover third-party sites or services you might reach by following a link from the application or from this site.

In brief

  • No account with us, no sign-up, no user profile.
  • No telemetry, no automatic crash reports, no trackers.
  • Your tracks, your points and your projects are files in your own folder, readable without the application.
  • Sync between your devices runs through the private iCloud database on your Apple Account. We have no access to it.
  • The only hosts the application contacts are the ones that publish the maps:data.geopf.fr in France, basemap.nationalmap.gov andelevation.nationalmap.gov in the United States, and www.refuges.info only if you turn the mountain-hut overlay on. None of those servers is ours.

The data the application handles

Your routes, your waypoints and your notes are stored locally, in Balise's application container. Import and export are in GPX, an open format: what you produce stays readable by any other tool, including if you uninstall Balise.

iCloud sync

If you use Balise on more than one device, your library — tracks, waypoints and routes — syncs through CloudKit, into the private database of your Apple Account. Three consequences, better read than guessed at:

  • That data is then stored at Apple, under your account. This transport and storage fall under Apple's privacy policy, not ours.
  • We have no access to it. The database is private and tied to your Apple Account; there is no console, no key and no technical means by which we could read it.
  • Nothing is shared between accounts. There is no public library, no route sharing, no profile, and no social feature of any kind.

If iCloud is unavailable, or if you have turned it off for Balise, the application keeps a local library and carries on working normally: nothing is lost, and nothing leaves.

The network requests, and what they contain

Balise contacts map providers only, and only for what you asked to see:

  1. Map tiles. When you pan the map, the application requests the tiles for the area on screen. The Géoplateforme therefore sees the coordinates of the requested tiles and the IP address they were requested from, as any web server would. We see none of it: the request goes from your device to IGN, with nothing in between.
  2. Geocoding and elevation. A place search sends the text you typed to IGN's geocoding service; an elevation profile sends the coordinates of the route's points to the elevation service. Again directly, with no API key and without passing through us.

There is no Balise server. We cannot collect what we have nowhere to receive.

The local cache

Tiles already displayed are kept on your disk to avoid requesting them again. That cache is purely local, and is emptied from the application's settings on the Mac. Layers whose licence does not permit redistribution are never cached offline — that is a licensing constraint, enforced in the code, layer by layer.

The map data

The mapping comes from IGN's Géoplateforme, under the Licence Ouverte / Etalab 2.0. Each source's attribution, with its update date, is shown in the application and carried into the GPX files it exports.

The App Store

If you install Balise from the App Store, Apple handles the purchase, the download and, where applicable, the aggregated and anonymous statistics Apple makes available to developers. That falls under Apple's privacy policy rather than ours, and gives us access to neither your identity nor your data.

This site

This site is static. It uses no advertising cookies and no third-party scripts beyond the visitor statistics described below. The maps on the home page load their tiles directly fromdata.geopf.fr, exactly as the application does; that is one of only two external hosts the page contacts. Your light or dark theme choice is kept in your browser's local storage and is never transmitted.

One cookie exists, balise-lang. It is written only when you click FR or EN, it contains nothing but those two letters, and its job is to stop us sending you to the other language on your next visit. It identifies nobody and is read only by this site. Without it, the language offered on a first visit is inferred from the preferences your browser declares, and nothing is stored.

Visitor statistics

This site counts visits with Cloudflare Web Analytics, so we know which pages are read. It is part of the website only — it is not in the Balise app, and it never sees anything from the app.

It sets no cookie and stores nothing on your device. No identifier is kept between page loads, no localStorage, and no fingerprinting of your browser or IP address. A visit is counted by looking at whether the page you came from was on this site, not by recognising you. Because nothing is written to or read from your device, this needs no consent banner under the ePrivacy Directive (in France, Article 82 of the loi Informatique et Libertés), and there is none.

Sent on each page view: the page address, the address you came from, your browser and operating system, your screen size, and page load timings. Cloudflare derives an approximate country from your IP address and does not pass the address itself to us. We see aggregate totals only — never a profile, never an individual, and never anything across other websites. Our lawful basis is legitimate interest in understanding how our own site is used; Cloudflare acts as our processor under its Data Processing Addendum. Any content blocker, or a browser Do Not Track setting, stops the script loading.

Children

Balise is not directed at children and knowingly collects no data about them — for the simple reason that it collects data about nobody.

Changes to this policy

Any change will be published here with a new update date. A change that widened what the application sends over the network would be announced in the release notes, not only here.

Contact

Any questions about this policy: support@mgcrea.io.

Feedback form

The app collects nothing; this website has one page that does — thefeedback form, and only when you choose to fill it in and press send. Balise itself never sends feedback: it opens a web address in your browser and stops.

We receive what you typed — the subject and the details — and your email address if you chose to give one. The address is optional; leave it blank and the report is anonymous, and we will still read it.

Opening the form from inside the app (Help → Send Feedback) also fills in four technical facts: your Balise version, your macOS version, your Mac's model identifier, and your language. They arrive in the web address itself, so you can read them in your browser's address bar before anything is sent, and the form shows them as ordinary editable fields you can change or clear. That is the entire list — never your username, and never a track or file name.

Submissions are stored in a Cloudflare D1 database hosted in Western Europe and emailed tosupport@mgcrea.io so we can reply. We keep them fortwelve months, then delete them. Never used for marketing, never sold, never shared. The form sets no cookie, and your IP address is not stored, and nothing in the code that handles your submission ever reads it.