Paracord Privacy Policy

Last updated 1 July 2026


Who this policy is for

Paracord is built for adult Scout leaders to keep a personal log of their own activity sessions and permit evidence. Paracord is an independent app and is not affiliated with, endorsed by, or operated by The Scout Association.

This policy explains what personal data Paracord collects, why, and what rights you have over it.


Who is responsible for your data

Paracord is developed by Paracord App, an independent UK-based developer. For the purposes of UK GDPR, I am the data controller for the personal data Paracord processes.

Contact: app.paracord@gmail.com

If you have a complaint about how your data is handled that we can't resolve together, you can also contact the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.


What data Paracord collects, and why

Account information

When you create an account, we collect: - Your email address and a securely hashed password (if you sign up with email/password), or - Your name and email address from Google or Apple, if you choose to sign in that way. - A profile photo, if you choose to add one, or if one is provided automatically by Google sign-in.

This is used to create and secure your account, and to identify you across devices.

Activity, session, and permit data

The core purpose of Paracord is letting you log: - The activities you hold or are working toward permits in (e.g. Climbing, Archery). - Sessions — date, duration, your role, location, the number of participants (never their names), and any notes you choose to add. - Permit details you choose to record — level, assessor name, issue and expiry dates, and any restrictions.

A note on the notes field: the free-text notes and location fields are entirely under your control. Please don't enter identifying details about young people in these fields — see the safeguarding section below.

Location data

If you use the location button when logging a session, Paracord requests your device's GPS position only while the app is open and you've tapped that specific button — never in the background, and never without you asking.

Evidence and attachments (Pro feature)

If you attach photos or documents (risk assessments, route cards, certificates) as evidence for a session, these are stored securely and are visible only to you. Please do not upload photos that identify young people — the app reminds you of this when attaching a photo, and it's worth taking seriously: this app is not designed or intended to store images of children.

Subscription and payment information

If you subscribe to Paracord Pro, your payment itself is handled entirely by Apple or Google — Paracord and its developer never see or store your card details. We use a subscription-management service called RevenueCat to know whether your subscription is active, which receives your subscription status and a unique identifier for your account, but not your payment details.

Technical and diagnostic information

Paracord does not use third-party advertising trackers, and we do not sell your data to anyone, under any circumstances.


Who we share your data with

We use a small number of trusted service providers to run Paracord — these are processors acting on our instructions, not independent users of your data:

Service What it does What it sees
Firebase (Google Cloud) Hosts your account, activity data, and uploaded files Everything you store in the app — hosted in the EU
RevenueCat Manages subscription status Your subscription status and account identifier — not payment details
Apple / Google Process payments; provide Sign in with Apple/Google Payment details (Apple/Google only — never us); name/email if you use social sign-in
OpenStreetMap Provides map imagery shown on the session detail screen The geographic area being viewed, in order to fetch map tiles

We don't share your data with anyone else, and we don't use it for advertising.

Where your data is stored

Your activity, session, and permit data is hosted on Google Cloud infrastructure based in the EU, chosen specifically to keep UK/EU user data within that region. Some of our service providers (including RevenueCat, and Apple/Google for payments) are based outside the UK/EEA, in which case they're required to use legally recognised safeguards (such as Standard Contractual Clauses) to protect your data when it's transferred.


How long we keep your data

We keep your data for as long as your account exists. You can permanently delete your account and all associated data at any time, directly within the app (Settings → Delete my account). This is immediate and permanent — it removes your activities, sessions, permits, attachments, and account itself, and cannot be undone.

One important limit: deleting your Paracord account does not cancel an active App Store or Google Play subscription — that's something only you can do, via your Apple ID or Google account settings, since Paracord's backend has no ability to do this on your behalf. The app warns you about this before you delete your account.


Your rights

Under UK GDPR, you have the right to: - Access the personal data we hold about you. - Correct any inaccurate data (most of this you can already do yourself, directly in the app). - Delete your data (available directly in the app, as above). - Export your data in a portable format — Paracord lets you export your full log as a PDF, CSV, or JSON file at any time, from Settings → Export. - Object to or restrict certain processing.

To exercise any of these rights, contact app.paracord@gmail.com.


Children's privacy and safeguarding

Paracord is intended for use by adults — specifically, adult Scout leaders aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from children through the app.

Because Paracord is used in a youth-organisation context, we've made specific design choices to minimise any risk to young people, even though they are never users of the app themselves:

If you believe a photo or note has been added that identifies a child inappropriately, please contact us immediately at app.paracord@gmail.com so it can be removed.


Security

We use industry-standard security practices, including encrypted connections (HTTPS/TLS) for all data in transit, and access controls (Firebase security rules) that ensure your data can only be accessed by your own account, not by other users or by us directly during normal operation.

No system can be guaranteed 100% secure, but we take reasonable, proportionate steps to protect your data.


Changes to this policy

If we make material changes to this policy, we'll update the date at the top and, where appropriate, notify you within the app.


Contact us

Questions about this policy, or about your data: app.paracord@gmail.com


This document was last reviewed on 1 July 2026. Version 1.0