Privacy Policy
Last updated: October 1, 2026
Overview
Middle-earth Explorer ("the app") is an unofficial fan app for iPhone made by one independent developer, Alp Ozcan ("I", "me"). This policy covers version 3.0 of the app. It explains what data the app handles, who receives it, why, how long it is kept and how you can say no.
The short version:
- The app has no accounts, no sign-in and no ads.
- It never asks for your name, email address, phone number or contacts.
- It does not track you across other companies' apps or websites, and it does not sell data.
- It sends usage analytics and crash reports tied to a random ID, so I can see what works and fix bugs. Both are on by default, and you can turn each one off in Profile > Privacy.
- Some features ask outside services for content, such as film details, book covers or live events. Those requests go straight from your device to that service.
Who Is Responsible
The app is made and run by Alp Ozcan, who is responsible for the data described here. You can reach me at hi@alp.me about anything in this policy.
Data That Stays on Your Device
Most of what you do in the app never leaves your iPhone:
- Bookmarks, recent searches, Spoiler Shield settings, quiz results, Daily Riddle progress and streaks, New Zealand filming trail check-ins and trip plans, your home city for Events, your app icon choice and your privacy choices are stored on your device.
- Search runs on your device. When analytics is on, the app records only how many results a search returned, never what you typed.
- Reminders (Season 3 episodes, the Daily Riddle, On this day, event reminders and city alerts) are local notifications. Your iPhone schedules and shows them; no server is involved. The app asks for notification permission only when you turn a reminder on.
- Widgets read the same on-device data through an app group on your iPhone.
- Places and characters can appear in iPhone Search (Spotlight). That index lives on your device.
- If you save your quiz result card, the app asks for permission to add it to your photo library. This is the only thing the app saves to Photos. It can add photos but cannot see or read your library.
- If you add an event to your calendar, the app asks for write-only calendar access. It can add the event but cannot read your calendar.
- If you use "Near me" or "Check in" on the New Zealand filming trail, your approximate location is used on your device to sort sites by distance and confirm a visit. It is not sent anywhere.
- A cached copy of your Fellowship+ status is stored in your device's Keychain.
iCloud Sync of Journey Progress (Fellowship+)
If you subscribe to Fellowship+, your Journey Order progress (which films, series and books you have marked) syncs between your devices through your own iCloud account, using Apple's iCloud key-value storage. I cannot see this data. Apple stores it under its own privacy policy. If Fellowship+ ends, nothing more is synced, and nothing is deleted from your devices. You can remove the synced copy by turning off iCloud for the app in iOS Settings.
Usage Analytics (TelemetryDeck and Statsig)
What: When "Share usage analytics" is on, the app sends TelemetryDeck short signals such as "a screen was viewed", "a map marker was tapped", "the paywall was shown" or "a purchase finished", with a few details like the screen or content type, the app version, iOS version, device model, language and region, and which App Store product page you installed from. Purchase signals include the plan (monthly or yearly), never payment details.
Identifier: Signals carry a random identifier created for this app on your device. TelemetryDeck hashes it again before storing it. It is not your Apple ID, your advertising identifier or anything that names you.
Why: To learn which features people use and where the app is confusing, so I can improve it. The legal basis is my legitimate interest in running and improving the app. You can object at any time with the switch.
Where: TelemetryDeck is based in Germany and stores data in the EU.
Statsig: The app also uses Statsig to run a short map performance test. Statsig receives a random, app-scoped identifier, which map renderer your device was assigned, and map speed and memory measurements. It never receives your location or anything that names you. While the test runs, the "Share usage analytics" switch does not stop it, and the Privacy page in the app says so. The test ends in October 2026. After that, Statsig will either follow the same switch or be removed from the app, and this policy will be updated. Statsig is based in the United States.
How to stop: Turn off Profile > Privacy > Share usage analytics. TelemetryDeck stops at once and is not started at the next launch.
Crash Reports (Sentry)
What: When "Send crash reports" is on and the app crashes or hits an unexpected error, it sends Sentry a technical report: the error and stack trace, the device model, iOS version, app version, memory and performance measurements, and a short trail of the screens and actions just before the problem (for example "opened the Events tab"). The trail never includes what you typed, your location or your name. Reports carry a random installation identifier.
When the switch is on, the app also sends Sentry performance measurements for a sample of visits: how long a screen takes to appear, how smoothly it draws (slow and frozen frames) and when the app stops responding. These carry the screen's name and timings only, never what you typed, your location or your name.
Why: To find and fix crashes. The legal basis is my legitimate interest in keeping the app working. You can object at any time with the switch.
Where: Sentry stores these reports in its EU region (Germany).
How to stop: Turn off Profile > Privacy > Send crash reports. Sentry stops at once and is not started at the next launch.
Live Events and Your Location (Ticketmaster)
The Events tab shows concerts and screenings near a city.
- If you pick a city, the app sends that city's coordinates to Ticketmaster's Discovery API to find events nearby.
- If you allow location access, the app asks iOS for your approximate location only (reduced accuracy, roughly city level) and sends those coordinates to Ticketmaster instead. The app asks for location only when you use this feature, and only while you are using the app.
Ticketmaster receives the request under its own privacy policy. The app does not store your location history and does not send your location to analytics or crash reports.
Content From Other Services
To show films, books, clips and lore, the app downloads content from these services. Each request goes from your device straight to the service, so the service sees your IP address and the item requested, as any website would. The app sends no identifier of its own with these requests.
- TMDB (themoviedb.org): film and TV details and images.
- YouTube (Google): video clips, their details and thumbnails. Clips play in YouTube's official embedded player, loaded from youtube-nocookie.com (YouTube's privacy-enhanced mode). YouTube runs that player under its own terms and privacy policy, and it may set cookies and collect data once a clip plays. The app keeps the player's storage in memory only, so it is cleared when the app quits. This app uses YouTube API Services: by watching clips you agree to the YouTube Terms of Service, and YouTube's handling of your data is described in the Google Privacy Policy.
- Open Library (Internet Archive): book covers.
- The One API (the-one-api.dev): character and quote data.
- The One Wiki to Rule Them All (lotr.fandom.com, run by Fandom): character text and images.
Each service handles these requests under its own privacy policy.
Purchases (Apple)
Fellowship+ is sold through the App Store using Apple's StoreKit. Apple handles the payment and your Apple ID. I never see your name, email or payment details. The app asks Apple whether you have an active subscription so it can unlock features. With analytics on, the app records that a purchase started, finished, failed or was restored, and which plan it was.
Ticket Links and Affiliate Commissions
The app never sells tickets. "See on" buttons open the seller's own page in a Safari view inside the app, and some of these links earn me a small commission when you buy tickets. Ticketmaster links carry three labels: the screen you tapped from, the event and the app version. Other ticket links may open through Skimlinks, which redirects to the ticket site and records the click so the seller can pay a commission. What happens on those pages is handled by Skimlinks and the seller under their own privacy policies; the app cannot see it and sends Skimlinks nothing about you.
News Alerts (Not Yet Switched On)
Version 3.0 contains optional news alerts, but they are switched off and the app does not send a push token anywhere. This section describes how they will work, so you know before they arrive. If this changes, the date at the top of this page will change too.
If you turn on news alerts, the app sends my news server the push notification token Apple issues for this app, your app language, your time zone, the news topics you chose, your Spoiler Shield level for news, your quiet hours and alert frequency, and the app version. Before it registers, the app uses Apple's App Attest to prove that the request comes from a genuine copy of the app; App Attest does not identify you. I use this data only to decide which news alerts to send you and when. I keep a record of which alerts were sent to your device for 90 days so I can limit how many you receive. The server does not collect your name, email address, location or advertising identifier, does not store IP addresses and does not use this data for advertising or tracking. Fly.io, the hosting provider, handles network traffic under its own privacy policy.
If you turn news alerts off, turn off notifications for the app, or do not open the app for 180 days, your device's registration is deleted. The server is hosted by Fly.io in the EU (Amsterdam), with encrypted backups stored with Cloudflare R2 in the EU. Backups are kept for 30 days, so a deleted registration can remain in an encrypted backup for up to 30 days before it is removed.
News headlines and summaries in the app are written with the help of an AI model (Claude, by Anthropic) from public headlines and feed descriptions, and every item links to its original source. No data about you is sent to the AI model.
What the App Does Not Do
- It does not use the advertising identifier (IDFA) and does not ask to track you.
- It does not show ads or share data with advertisers or data brokers.
- It does not sell or rent data.
- It does not collect precise location, contacts, photos, health data or anything you type.
Your Choices and Rights
- Profile > Privacy has the analytics and crash-report switches, the list of services the app uses and a link to iOS Settings.
- iOS Settings > Middle Earth lets you change location, notification, photo and calendar access at any time.
- Deleting the app removes everything stored on your device. Synced Journey progress stays in your iCloud until you remove it there.
If you are in the EU, the UK or a place with similar laws, you can ask to access, correct or delete data about you, object to its use or complain to your data protection authority. Because the app has no accounts, I usually cannot link data to you, but write to hi@alp.me and I will do what I can within 30 days.
Children's Privacy
The app is not directed to children under 13 and does not knowingly collect personal information from them.
Changes to This Policy
If this policy changes, the new version will be posted on this page with a new date. Significant changes will also be mentioned in the app's release notes.
Contact
Alp Ozcan, hi@alp.me. You can also visit the support page.