This page covers the website and the current development app. Public account registration and cloud backup are not yet available. For operator and contact details, see the legal notice.
Who and what this covers
This privacy policy describes the Placeloader Android app (application ID com.placetimeline, formerly Dwell) and this website. It explains the data handled by the current development version and identifies features whose production services are not yet available.
Axenta GmbH, Lange Gasse 65, 1080 Wien, Austria, is the operator and controller for information processed by Placeloader. Contact us at office@axenta.at. See the legal notice for registration and contact details.
Data on your device
With location permission and tracking enabled, Placeloader processes precise location, arrival and departure events, timestamps, saved place names and coordinates, visits, and time-at-place summaries. This includes background location when the app is closed or not in use.
You may add notes, tags, and corrections. Tracking settings, permissions, and diagnostic state help the app explain interruptions. If you enable route logging, the app collects more frequent location samples to show routes between places.
Location history is stored in an encrypted local database by default. The app uses this information to build your timeline, identify visits, calculate summaries, and display history and trends.
Permissions and choices
Background tracking requires your permission. You can keep tracking off, pause it in the app, or change location access in Android Settings. Limiting permissions may prevent background visits from being recorded.
Route logging, place suggestions, route snapping, and encrypted cloud backup are separate settings. Turning off a connected feature stops future requests from that feature; it does not recall information already sent.
Accounts and cloud backup
Account and encrypted backup services are undergoing testing before public launch. The following describes the account service and the information processed when you use these features during testing.
If you create an account, the app sends your email, authentication information, and associated device/account identifiers to the configured authentication service. The account server stores a salted password hash and uses expiring, single-use email links for verification, reset, and web deletion. Cloud backup requires a verified email. Transactional emails are sent through MXroute from noreply@placeloader.com. MXroute receives the destination email address and the verification, password-reset, or deletion message, including its time-limited action link. Account deletion removes account records, sessions, linked device credentials, and the active encrypted snapshot. Do not reuse production credentials with a development server.
If you enable cloud backup, your device encrypts the backup using a key derived from your recovery phrase before sending it. The server receives encrypted content and the identifiers and request metadata needed to handle the backup. The recovery phrase is not sent to the service. Losing it can prevent recovery of encrypted backups.
Disabling backup stops new uploads and clears the cached encryption key. Device credentials remain for the account until sign-out or account deletion. It does not guarantee deletion of remote backups. The account service stores one encrypted snapshot per account, replaced by your next successful upload. Account records and the latest snapshot remain until you delete the account. The API is hosted by Contabo in the EU. Infrastructure backups and snapshots are not currently enabled. Provider arrangements are being verified before public registration opens.
Maps and connected services
The app uses the following services. They can receive technical request information, including an IP address, in addition to the feature-specific data described here.
- Google Maps: map display and the location indicator. Google’s SDK handles map and device information under its own privacy terms. Google privacy policy.
- OpenStreetMap Nominatim: text you type into address search is sent to the geocoding service. Reverse address lookup also sends the coordinates being looked up to Nominatim at nominatim.openstreetmap.org. OpenStreetMap Foundation privacy policy.
- Google Places, when enabled: coordinates of places where you stopped are sent to suggest nearby names and categories.
- Valhalla routing, when enabled: the start and end coordinates of a trip are sent for route snapping. The route samples between those endpoints are not sent by this feature. The configured routing endpoint is valhalla1.openstreetmap.de by default and may vary by build.
These requests are distinct from uploading a complete location-history backup. See the app’s settings before enabling a connected feature.
Website and support
This website does not include advertising pixels, analytics scripts, a mailing-list form, or a location prompt. The fonts and illustration are served with the site. Interactive sample data is fictional and is not a record of your location.
The public website is hosted on our Contabo server. Your IP address, requested URL, and connection information are processed to deliver and protect the website. We do not enable visitor access logs, analytics, advertising cookies, or website accounts. Technical error logs may be retained for up to seven days. The separate private preview uses its hosting platform’s access controls and essential session cookies.
Opening a mailto contact link uses your email application. The account deletion form sends the email address you enter to api.placeloader.com. The account-action page sends the confirmation token and, for a password reset, your new password to the same service when you confirm. These forms do not store your credentials in browser cookies or local storage. If you send a support email, its contents and your email address are available to the recipient and email providers. Never send passwords, recovery phrases, or raw location history for a routine support request.
Retention and deletion
Raw location samples and arrival/exit events are scheduled for removal after your selected retention period (180 days by default). Android schedules cleanup, so it may run later. Daily totals are recalculated from remaining records. This is not a promise that every type of saved data is erased after 180 days: saved visits, places, notes, settings, and other stored records follow their own deletion controls.
Use Settings → Delete all data to erase the app’s records on your device. Exported files and remote backups are separate copies. Deleting local data, uninstalling the app, and signing out are not the same as deleting an account or its cloud backups.
See Delete data & account for local steps and a web request form that works without the app. Account deletion removes the account, linked device credentials, sessions, pending action tokens, and active encrypted snapshot in the service database. Email action links expire after 30 minutes; refresh sessions expire after 30 days. Expired records are cleaned up when the service next handles requests. To limit abuse, the account API processes your IP address and stores a hashed IP counter for a one-hour rate-limit window. Expired counters are removed on the next request. Linked device credential records remain with your account until revoked or the account is deleted. Infrastructure backups and snapshots are not currently enabled. Before introducing them, we will document their retention and how account deletion is applied to restored data.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal data; restrict or object to processing; and withdraw consent without affecting earlier lawful processing. You may also have the right to complain to your local data protection authority.
Local history can be exported and removed directly in the app. Send requests about information held by Axenta to office@axenta.at. We may need proportionate identity verification. We normally respond within one month. If a complex request requires a permitted extension of up to two further months, we will explain the reason within the first month. In Austria, you can lodge a complaint with the Austrian Data Protection Authority.
Why we process information
We process necessary website connection information to provide a secure, functioning website (our legitimate interests under Article 6(1)(f) GDPR; we also use this basis to protect accounts and prevent API abuse). We handle support requests to respond to your enquiry or provide requested service (Article 6(1)(b), or Article 6(1)(f) for other correspondence). We keep correspondence while needed to resolve the enquiry and for any applicable legal obligations.
Location tracking and optional location-sharing features rely on your consent (Article 6(1)(a) GDPR), where Axenta processes personal data for these purposes. You can withdraw it by disabling the feature or revoking location permission, without affecting prior lawful processing. Android permission is a device control; the in-app disclosure must also explain the processing you agree to. Requested account and backup operations, when available, use Article 6(1)(b) for service delivery. Processing required by a specific legal obligation uses Article 6(1)(c). Public cloud accounts are not open. Their hosting, email processing, retention, and any international-transfer arrangements will be described before registration opens.
Summaries and sensitive information
Placeloader automatically estimates visits, routes, and time-at-place summaries. These are personal journal features; we do not use them to make decisions that produce legal or similarly significant effects on you.
Location history and notes can reveal sensitive aspects of your life. Avoid including other people’s private information in notes or support messages. We cannot retrieve history held only on your device to answer a support request.
Changes and questions
This page will be updated when data practices or connected services change. Significant new uses of location data require a corresponding disclosure and, where needed, permission in the app.
For practical help, visit Support. For the publication status of contact details and operator information, see the legal notice.