Walking to the Moon — Privacy Policy
• Effective date: 2026-08-01 • Last updated: 2026-08-01 • Operator: Joonwoo Park, individual developer • Contact: doldorijw@gmail.com • Available in: United States and South Korea • Minimum age of use: 14
이 방침의 한국어판: 개인정보처리방침 (한국어)
Walking to the Moon turns the steps you already take into progress toward the Moon. This policy explains exactly what the app reads, what stays on your iPhone, what is sent anywhere, and how to remove it.
The short version: your journey is stored on your iPhone and nothing about your walking leaves it unless you separately turn Social on.
Overview
Walking to the Moon turns steps into progress toward the Moon, Earth-equator equivalents, and a fictional World Trail. A person can start fresh or optionally bring an aggregate snapshot of the walking history Apple Health makes available through the journey’s activation boundary.
Total steps are the source of journey progress. The app converts steps into a standardized step-equivalent distance using steps × 0.75 m; personal height, stride, and recorded walking distance do not affect rank. Apple Health’s recorded Walking + Running Distance remains a private informational metric.
The solo journey is account-free. The local player profile, daily movement history, display-only Today cache, aggregate historical snapshot, recorded distance, and private recaps stay on the iPhone. Social features are optional. After consent, a person can create a Firebase guest profile without a provider login and may later link Apple or Google for recovery. Sharing imported aggregate steps requires an additional, separate consent that is off by default. Global visibility is a further opt-in.
Apple Health data
Walking to the Moon requests read-only access to:
• Steps
• Walking + Running Distance
The app never writes to Apple Health. It does not request workouts, heart rate, calories, Contacts, or real location.
The app captures an exact activation timestamp and uses two nonoverlapping intervals. Optional history is strictly before that boundary, and post-activation collection begins at the boundary. If a person chooses Bring available Apple Health history, the app previews the aggregate before saving it. Activity at or after the boundary is post-activation progress even if it occurs while the preview is open.
Walking to the Moon describes the result as available Apple Health history, not an entire-life history. Apple Health may expose only limited history, and Apple does not reliably reveal denied read access to apps. An empty result may mean no activity exists or that access is unavailable.
The history preview may show imported steps, recorded or resolved distance, estimation status, and the first and last observed activity dates. The dates identify observed activity only; they do not describe the beginning or end of an authorized window.
For private informational distance, recorded Walking + Running Distance is used when available for an interval. If steps exist without recorded distance, the app may resolve that interval as steps multiplied by 0.75 meters and marks it estimated. It does not add recorded and estimated distance for the same interval.
The Today screen separately queries the complete locally available Apple Health step total for the current calendar day. On the activation day, this can include steps taken before the activation boundary. A protected display cache stores only the local day, aggregate steps, and refresh time. That complete-day value never enters post-activation movement, all-time journey progress, Atlas crossings, recaps, Social Day, analytics, or uploads.
Data kept on the iPhone
The following information may be stored locally:
• journey activation time, home time zone, and selected route revision;
• post-activation daily step and recorded/resolved-distance aggregates;
• whether a daily distance includes an estimate;
• an optional `HistoricalImportSummary` containing aggregate imported steps, recorded/resolved distance, estimation status, first and last observed activity days, activation boundary, import date, and revision;
• a `TodayHealthSnapshot` containing only the current local day, aggregate steps, and refresh time;
• a local `PlayerProfile` containing a username, modular `AvatarDescriptorV1`, revision, and timestamps;
• private weekly and monthly recaps;
• local preferences, consent records, and pending aggregate sync operations.
Walking to the Moon does not store historical Health samples, workouts, device or source-app identities, real locations, or fabricated daily history for the imported baseline.
The local movement store is excluded from ordinary device backups and is not synchronized through CloudKit. Local journey data remains until the person removes imported history, resets the journey, or removes the app, subject to iOS storage behavior.
Refreshing imported history can preview a higher or lower corrected aggregate. A new nonempty snapshot is stored only after confirmation. An empty refresh does not erase an existing snapshot. Removing imported history does not move the activation boundary or delete post-activation movement.
Optional social data
Post-activation sharing
After social consent v2 and creation of a Firebase anonymous guest, Walking to the Moon may send a mission aggregate containing:
• total post-activation steps;
• current-day post-activation steps;
• current-week post-activation steps;
• current-month post-activation steps;
• fictional World Trail route ID and revision;
• a monotonic mission revision;
• freshness rounded to a calendar day;
• a server-claimed public username and validated modular character descriptor;
• invitation, friendship, block, pause, and Global-visibility state.
Imported-history sharing
History consent v1 is separate and off by default. If enabled, Walking to the Moon may send a separate baseline containing only:
• imported aggregate steps;
• a monotonic history revision.
The server stores mission and history baselines separately and derives combined totals for authorized leaderboard projections. Withdrawing history consent removes only the remote history baseline and the imported contribution to projections. It does not remove post-activation mission progress.
Walking to the Moon does not send the complete-day Today cache, recorded or resolved distance, estimation status, first or last observed dates, claimed authorization coverage, raw Apple Health samples, workouts, source devices or apps, actual routes, real location, granular activity timestamps, height, stride, private recaps, provider profile names, email addresses, profile photos, bios, chat messages, or Contacts.
Friends, Global, and leaderboard periods
Friends receive private aggregate leaderboard summaries after an invitation is accepted. The Global leaderboard is separately opt-in and exposes only an opaque public ID, claimed username, validated modular avatar, authorized aggregate progress, virtual checkpoint, rank, and day-rounded freshness. Firebase user IDs are not returned in leaderboard rows.
• Day, Week, and Month compare post-activation steps only.
• Total compares post-activation steps plus imported steps only when separate history sharing is active.
• Total profiles can show the imported and post-activation aggregate split.
• Equal step values share rank.
• A first Day, Week, or Month may be labeled partial because it begins at activation.
Walking to the Moon does not disclose whether a zero imported value means the person did not import history or chose not to share it.
Public usernames are 3–20 lowercase ASCII characters, begin with a letter, and permit digits or single underscores. The server claims usernames case-insensitively, filters reserved and profane terms, and limits public username changes to once every 30 days. Public avatars use only bundled allowlisted parts; uploaded photos are not supported. People can block another user immediately or submit a fixed-reason report. Reports are reviewed through Walking to the Moon’s moderation process, and suspended or removed profiles are removed from leaderboard projections. The final published policy and app must provide the operator’s support and moderation contact details.
Service providers and processing location
Optional social features use:
• Firebase Authentication for durable anonymous guest sessions and optional Apple or Google account linking;
• Cloud Firestore and Cloud Functions configured in `us-west2`;
• Firebase App Check with App Attest.
Firebase Authentication is a United States-hosted service. Google processes service data under its Firebase terms and privacy documentation. Walking to the Moon does not enable Firebase Analytics or Crashlytics for this revision.
Apple processes Apple Health and optional Sign in with Apple information under Apple’s terms. Google processes optional Google Sign-In authentication information under its terms. Walking to the Moon uses provider credentials only to authenticate or protect the Firebase account and does not copy provider name, email, or photo into its public social documents.
Linking Apple or Google preserves the guest Firebase account identifier and its social data. If a provider credential is already attached to another profile, Walking to the Moon does not automatically merge the profiles. The person can keep the guest profile or explicitly delete its remote social account before opening the provider-protected profile. This choice does not alter local Apple Health steps or the local journey on this iPhone.
Retention
• Pausing sharing deletes both canonical remote aggregate records and their friend and Global projections. Resuming requires republication from local storage after current consent is confirmed, and Global visibility must be explicitly enabled again.
• Withdrawing imported-history sharing deletes the history baseline and removes imported progress from projections while retaining authorized post-activation mission progress.
• Turning off Global visibility deletes the Global projection.
• An unlinked guest Social profile cannot be recovered after reinstalling or loss of its local Firebase credential. Firebase automatic anonymous-account cleanup is disabled because guest profiles are intended to remain durable until the person deletes them or Walking to the Moon takes a disclosed moderation action.
• Invitation records expire after 1 to 14 days and are eligible for Firestore time-to-live deletion after expiration.
• Deleting the social account revokes or disconnects linked provider access as applicable and deletes the Firebase Authentication account, username claim, social profile, mission and history aggregates, invitations, blocks, moderation relationships, friendships, and leaderboard projections.
• A failed deletion may temporarily retain a minimal retry marker. It contains no health value and is eligible for automatic deletion after seven days.
• Deleting the social account does not delete the account-free local journey unless the person separately resets it.
Cloud provider operational logs may retain request metadata under provider policies. Walking to the Moon does not intentionally place health values in application logs, analytics, crash reports, support tickets, or push-notification payloads.
Controls
The app provides controls to:
• keep using the app without an account;
• create and edit a local username and modular avatar without enabling Social;
• import, preview a refresh of, or remove the local aggregate Apple Health history;
• consent separately to post-activation sharing and imported-history sharing;
• withdraw imported-history sharing without removing post-activation sharing;
• opt into or out of the Global leaderboard;
• pause all social sharing and delete shared progress;
• remove or block a friend;
• report a public user for one of the available reasons;
• link Apple or Google to protect a guest Social profile;
• export server-held social, mission, and history data;
• delete the social account and revoke or disconnect linked provider access as applicable;
• reset the local journey separately.
Health access can be changed in iOS Settings or Apple Health. Apple does not reveal read-access denial directly to apps, so Walking to the Moon cannot always distinguish no data from unavailable access.
Security and integrity
The intended implementation uses transport encryption, provider encryption at rest, App Check, App Attest, server-only writes, strict Firestore rules, transactional username claims, strict modular-avatar allowlists, reserved-name and profanity filtering, hashed single-use invitations, fixed-reason reporting, suspension-aware projections, deletion fencing, and exact payload allowlists.
Implausible-jump filtering applies only to post-activation mission steps. Imported-history replacements may move up or down to reflect Health corrections, but require an active history consent, App Check, a higher revision, bounds checking, and a 24-hour server-side replacement cooldown. Health-derived totals can still be edited in Apple Health and are not represented as cheat-proof.
Children
Walking to the Moon is not intended for anyone under 14, and the operator does not knowingly collect personal information from anyone under 14.
Fourteen rather than thirteen: COPPA sets the United States threshold at 13, and PIPA requires a legal guardian’s consent below 14. The higher number satisfies both launch regions.
If you believe someone under 14 has created a social account, write to doldorijw@gmail.com and it will be deleted.
Overseas transfer of personal information
This section is provided for users in South Korea, where transferring personal information abroad must be disclosed.
The solo journey never leaves the iPhone, so nothing is transferred unless social sharing is turned on. If it is:
• Transferred to: Google LLC, through Firebase Authentication, Cloud Firestore, Cloud Functions, and Firebase App Check.
• Country and location: United States, in the `us-west2` region (Los Angeles).
• When and how: at the moment progress is published from the app, over an encrypted HTTPS connection.
• What is transferred: the aggregates listed under “Optional social data” above, plus the public username and character descriptor. Never raw Apple Health samples, recorded distance, real location, timestamps finer than a calendar day, or provider profile data.
• Purpose: operating the optional social features, and nothing else.
• Retention: as described under “Retention” above. Deleting the social account deletes the transferred data.
Refusing this transfer is possible and costs nothing: leave social sharing off, or turn it off later. The app remains fully usable, because the journey itself is local.
Privacy officer
PIPA requires a named person responsible for personal information. For Walking to the Moon that is the operator:
• Name: Joonwoo Park
• Role: operator and privacy officer
• Contact: doldorijw@gmail.com
Enquiries, access requests, correction requests, and deletion requests all go to that address. You can also delete everything yourself from inside the app, under Settings, without writing to anyone.
Your rights
In both launch regions you may ask what is held about you, ask for it to be corrected, and ask for it to be deleted.
Most of this does not require asking. The app exports server-held social data and deletes the social account from Settings, and the local journey can be reset there too. The email address above exists for anything the app cannot do for you.
Changes and contact
Material policy or upload-scope changes require an updated in-app consent version before affected publication resumes. Social consent v2 and history consent v1 are independent.
Questions about this policy: doldorijw@gmail.com
Reference material
• Apple Health authorization behavior
• Apple Health privacy
• Apple App Review Guidelines
• Firebase privacy and security
• Firebase Authentication with Apple
• Firebase anonymous authentication
• Firebase Authentication with Google