Privacy Policy
Last updated: 20 August 2026
NodeHop (nodehop.com) plans cycling and walking routes along the numbered node networks — the knooppunten — of Belgium, the Netherlands, Germany, France and Denmark. There is a website and a phone app. The same service also runs on knoophop.be, knoophop.nl, knotenhop.de, nodehop.be, nodehop.nl, nodehop.de and nodehop.lu. This page says what the software actually does with your data, including the parts that are less comfortable to read. Questions: admin@nodehop.com.
Who runs NodeHop
NodeHop is run by one person, not a company: Dimitri Blondeel, in Belgium. He decides what happens to everything described here, and he is who you write to — admin@nodehop.com, or by post at [POSTAL ADDRESS — TO BE COMPLETED]. NodeHop is meant for people of 16 and over. Belgian law applies to this policy.
What we collect on the website
- Signing in — you sign in with Google, with Apple, or with an email address and a password. We receive your email address, and from Google or Apple the name and picture you have there. Signing up also creates a public profile: your username is built from the part of your email address before the @ plus four random characters, together with that name and picture. Profiles, likes and follows can be read by anyone, signed in or not.
- Routes you keep — the start, the node numbers, the line on the map and the name. Tap Share and you get a seven-character code and a link: anyone who has them sees that route, it does not expire, and there is no button in the app that takes it back. If you are signed in, your routes are also stored under your account.
- Where your rides start — when you keep a route, we store its starting point separately, to about a metre, next to a random number your browser made up for itself. That is what stops the planner handing you the same loop again next week. The planner only looks at the last 120 days of it, but nothing deletes the older rows.
- What you type to the planner— your messages go to Anthropic, whose model reads them and works out what you want. We also store the sentence you typed for 90 days on its own, with no name, no account and no address beside it, and once a night a model reads that day’s sentences and writes us a short summary of what riders asked for. If you give a route a thumbs-down, your comment, the route and a picture of the map go to Anthropic too, so the complaint reaches us with a diagnosis.
- Location— if you tap “Use my location”, your browser gives us a position to plan from. On our advertising landing page that position is then carried in the web address of the next page (
?o=…), so it also lands in your browser history. - What you do here — we log the meaningful steps: a page opened, a route built, a route kept. Beside each one we store your account number if you are signed in, the random device number above if your device has one, an id for this visit, your country, whether you are on a phone, tablet or computer, your operating system, your language and the site you came from. Nothing deletes these rows.
- Feedback — what you write, the email address you leave if you leave one, the photo you attach, and the make and version of your browser. The photo goes first to a model at Anthropic that decides whether it looks like report evidence and is safe for work; if the answer is no, the photo is thrown away and only your words are kept. There is no way to appeal that in the app — mail us. Feedback stays until we delete it by hand.
- Counting visitors — to count visitors rather than visits, we derive a one-way code from your IP address and browser, combined with a secret and today’s date. Nothing is stored on your device for this, we never store your IP address, and because the date is part of the code it changes every day — so the same visitor cannot be recognised tomorrow, and we cannot work backwards from a code to a person. We also record your country (never your town), whether you are on a phone, tablet or computer, your language, and which site referred you.
The phone app
- Where you are, during a ride — while a ride is running the app follows your position continuously, about once a second and at the best accuracy your phone can give. That is what lets it call out your next knooppunt in time. It stops when the ride ends, and the app does not follow you when no ride is running. On Android a notification stays on the lock screen for the whole ride.
- Your track stays on the phone — the app draws the path you actually rode. It is kept on your phone and is never sent to us. It is deleted when you close off the ride at the finish; if you break off a ride and never come back to it, that path stays on the phone.
- What leaves the phone while you ride — your current position goes to our servers to fetch the weather, to look up stops near you and to name the place you are in. Your planned route goes to us so we can find things along it. If you have saved a home address on the phone, its coordinates travel with every command you speak, so the app can turn you toward home.
- Speaking to the app — the microphone is on only while you hold the button. Your words are turned into text by Google on Android and by Apple on iPhone, which means the recording leaves your phone. The text is then sent to us, and on to Anthropic, which works out what you asked for. Your position is not sent to Anthropic.
- Camera — only to scan a route QR code. Nothing from the camera is stored or sent.
- Paying in the app — Apple or Google take the payment. RevenueCat checks for us whether you bought the unlock, and receives your NodeHop account number.
- Updates— every time you start the app it asks Expo’s servers whether there is a newer version. They see your IP address and which version you have.
- Planning inside the app — the Plan and Routes screens are our website in a window, so everything above about the website is true there too.
What is kept on your device
In your browser: your sign-in session; your language, theme, text size, units and pace; the routes you keep on this device (up to 50); the personal addresses you save (up to 100); a random number that tells us it is this device keeping a route; a copy of a route you send to the print page; and the conversation you are having with the planner, which disappears when you close the tab. In the app, on your phone: your sign-in tokens, your saved addresses including home, the path of a ride that is still open, and your voice, volume, language, theme and unit settings. None of it sits in an encrypted store. Clearing site data, or clearing the app’s data or uninstalling it, removes it — but there is no “delete my data” button inside the app itself.
What we use it for
To run the service: sign you in, build and keep your routes, share them, send a route to your Garmin, Wahoo or other bike computer, and guide you along it. To see whether the product works: which steps riders finish, what they ask for, what goes wrong. And to measure our own advertising, which is the next section. We do not sell your data.
Advertising
We advertise on Google and on Meta (Facebook, Instagram). We load noadvertising tag or pixel here — nothing in your browser talks to Google or Meta. What happens instead: if you arrive from one of our ads, the web address carries the ad network’s click number (gclid, gbraid, wbraid, or Meta’s fbclid). In the EU/EEA, the UK and Switzerland we keep it only if you say yes to the cookie question; elsewhere we keep it without asking. It goes into a cookie your browser’s own scripts cannot read, and it lasts 90 days. If you then do something we count as a result — sign up, build a route, keep one, send feedback — our server sends that click number back to the ad network: to Meta’s Conversions API, along with the value we put on it and the page you were on, and to Google Ads as an offline conversion. No email address, no name and no IP address goes with it. That is how the ad network learns its ad worked. Say no to the cookie question and none of this happens.
Cookies
We set a sign-in session, your saved preferences (language, theme), a short-lived note of whether you are in a region where the cookie question is required, and a record of your answer to it. The advertising click cookie described above is the only other one. We use no third-party or cross-site tracking cookies. Traffic is measured with Vercel Web Analytics, which sets no cookie and runs for every visitor, and by our own counting on the server. In the EU/EEA, the UK and Switzerland you are asked before the advertising cookie is set, and you can change your mind whenever you like: .
Who else sees something
Running NodeHop means other companies handle part of it. These are the ones that see something of yours:
- Vercel — hosts the site; every request passes through them. Also runs the cookieless traffic count and the bot check on the planner.
- Supabase — the database and the sign-in. Your browser talks to them directly, so they see your IP address.
- Anthropic — the model that reads what you type and what you say out loud, that checks the photos you attach, and that writes the nightly summary of what riders asked for.
- OpenFreeMap, waymarkedtrails and Amazon Web Services — the map itself. Your browser and the app fetch map tiles straight from them for as long as a map is open, so they see your IP address and which piece of the map you are looking at.
- Komoot (Photon) — turning a place name into a point on the map and back. We ask from our server, so they see ours and not yours.
- Open-Meteo — the weather where your route starts, asked from our server.
- BRouter and OpenStreetMap — the road data and the line between two knooppunten, asked from our server.
- Google Places — ratings and opening hours for cafés and other stops. We ask about places, never about riders.
- Resend — sending our email.
- Paddle — payment on the website. They are the seller and receive your billing and payment details, and their checkout runs in your browser.
- Apple, Google and RevenueCat — payment in the app and checking what you bought. RevenueCat receives your NodeHop account number.
- Expo— the app’s update check.
- Google (Android) and Apple (iPhone) — turning your spoken commands into text.
- Google Ads and Meta — see Advertising above.
- Wahoo — when you send a route to a Wahoo we send them the route and its starting point. Garmin works differently: your browser downloads the file and you upload it there yourself.
How long we keep it
- Your account and your saved routes: until you delete them, or delete your account.
- The sentence you typed to the planner: 90 days.
- The temporary share behind the “send to phone” QR code: 48 hours. A share code you made on purpose: it stays, and there is no revoke button.
- The advertising click cookie: 90 days.
- Everything else has no end date in the code today: the usage log, the starting points of the routes you kept, feedback and its photos, and the advertising conversions. We would rather tell you that than promise a schedule we do not actually run.
Your rights, and what you can do today
Under the GDPR you can ask to see, correct, export or erase your personal data. Two of those are buttons rather than emails: on your Account page you can download your data and delete your account. The download holds your profile, your saved routes, comments, likes and follows, your connected devices and your purchases. It does not hold your saved addresses, the starting points of the routes you kept, your feedback, or the usage log. Deleting your account removes your profile, saved routes, comments, likes, follows, connected devices and purchase records. It does notreach routes you shared with a code, the starting points kept against your device’s random number, your feedback and its photos, the usage log, or the advertising conversions — some of that is not linked to your name at all, and the rest we have to remove by hand. Mail admin@nodehop.com and ask, and it will be done.
Changes
We update this page when what the software does changes, with a new “last updated” date.