Privacy Policy

Last updated: October 1, 2026

Overview

Middle-earth Explorer ("the app") is an unofficial fan app for iPhone made by one independent developer, Alp Ozcan ("I", "me"). This policy covers version 3.0 of the app. It explains what data the app handles, who receives it, why, how long it is kept and how you can say no.

The short version:

Who Is Responsible

The app is made and run by Alp Ozcan, who is responsible for the data described here. You can reach me at hi@alp.me about anything in this policy.

Data That Stays on Your Device

Most of what you do in the app never leaves your iPhone:

iCloud Sync of Journey Progress (Fellowship+)

If you subscribe to Fellowship+, your Journey Order progress (which films, series and books you have marked) syncs between your devices through your own iCloud account, using Apple's iCloud key-value storage. I cannot see this data. Apple stores it under its own privacy policy. If Fellowship+ ends, nothing more is synced, and nothing is deleted from your devices. You can remove the synced copy by turning off iCloud for the app in iOS Settings.

Usage Analytics (TelemetryDeck and Statsig)

What: When "Share usage analytics" is on, the app sends TelemetryDeck short signals such as "a screen was viewed", "a map marker was tapped", "the paywall was shown" or "a purchase finished", with a few details like the screen or content type, the app version, iOS version, device model, language and region, and which App Store product page you installed from. Purchase signals include the plan (monthly or yearly), never payment details.

Identifier: Signals carry a random identifier created for this app on your device. TelemetryDeck hashes it again before storing it. It is not your Apple ID, your advertising identifier or anything that names you.

Why: To learn which features people use and where the app is confusing, so I can improve it. The legal basis is my legitimate interest in running and improving the app. You can object at any time with the switch.

Where: TelemetryDeck is based in Germany and stores data in the EU.

Statsig: The app also uses Statsig to run a short map performance test. Statsig receives a random, app-scoped identifier, which map renderer your device was assigned, and map speed and memory measurements. It never receives your location or anything that names you. While the test runs, the "Share usage analytics" switch does not stop it, and the Privacy page in the app says so. The test ends in October 2026. After that, Statsig will either follow the same switch or be removed from the app, and this policy will be updated. Statsig is based in the United States.

How to stop: Turn off Profile > Privacy > Share usage analytics. TelemetryDeck stops at once and is not started at the next launch.

Crash Reports (Sentry)

What: When "Send crash reports" is on and the app crashes or hits an unexpected error, it sends Sentry a technical report: the error and stack trace, the device model, iOS version, app version, memory and performance measurements, and a short trail of the screens and actions just before the problem (for example "opened the Events tab"). The trail never includes what you typed, your location or your name. Reports carry a random installation identifier.

When the switch is on, the app also sends Sentry performance measurements for a sample of visits: how long a screen takes to appear, how smoothly it draws (slow and frozen frames) and when the app stops responding. These carry the screen's name and timings only, never what you typed, your location or your name.

Why: To find and fix crashes. The legal basis is my legitimate interest in keeping the app working. You can object at any time with the switch.

Where: Sentry stores these reports in its EU region (Germany).

How to stop: Turn off Profile > Privacy > Send crash reports. Sentry stops at once and is not started at the next launch.

Live Events and Your Location (Ticketmaster)

The Events tab shows concerts and screenings near a city.

Ticketmaster receives the request under its own privacy policy. The app does not store your location history and does not send your location to analytics or crash reports.

Content From Other Services

To show films, books, clips and lore, the app downloads content from these services. Each request goes from your device straight to the service, so the service sees your IP address and the item requested, as any website would. The app sends no identifier of its own with these requests.

Each service handles these requests under its own privacy policy.

Purchases (Apple)

Fellowship+ is sold through the App Store using Apple's StoreKit. Apple handles the payment and your Apple ID. I never see your name, email or payment details. The app asks Apple whether you have an active subscription so it can unlock features. With analytics on, the app records that a purchase started, finished, failed or was restored, and which plan it was.

Ticket Links and Affiliate Commissions

The app never sells tickets. "See on" buttons open the seller's own page in a Safari view inside the app, and some of these links earn me a small commission when you buy tickets. Ticketmaster links carry three labels: the screen you tapped from, the event and the app version. Other ticket links may open through Skimlinks, which redirects to the ticket site and records the click so the seller can pay a commission. What happens on those pages is handled by Skimlinks and the seller under their own privacy policies; the app cannot see it and sends Skimlinks nothing about you.

News Alerts (Not Yet Switched On)

Version 3.0 contains optional news alerts, but they are switched off and the app does not send a push token anywhere. This section describes how they will work, so you know before they arrive. If this changes, the date at the top of this page will change too.

If you turn on news alerts, the app sends my news server the push notification token Apple issues for this app, your app language, your time zone, the news topics you chose, your Spoiler Shield level for news, your quiet hours and alert frequency, and the app version. Before it registers, the app uses Apple's App Attest to prove that the request comes from a genuine copy of the app; App Attest does not identify you. I use this data only to decide which news alerts to send you and when. I keep a record of which alerts were sent to your device for 90 days so I can limit how many you receive. The server does not collect your name, email address, location or advertising identifier, does not store IP addresses and does not use this data for advertising or tracking. Fly.io, the hosting provider, handles network traffic under its own privacy policy.

If you turn news alerts off, turn off notifications for the app, or do not open the app for 180 days, your device's registration is deleted. The server is hosted by Fly.io in the EU (Amsterdam), with encrypted backups stored with Cloudflare R2 in the EU. Backups are kept for 30 days, so a deleted registration can remain in an encrypted backup for up to 30 days before it is removed.

News headlines and summaries in the app are written with the help of an AI model (Claude, by Anthropic) from public headlines and feed descriptions, and every item links to its original source. No data about you is sent to the AI model.

What the App Does Not Do

Your Choices and Rights

If you are in the EU, the UK or a place with similar laws, you can ask to access, correct or delete data about you, object to its use or complain to your data protection authority. Because the app has no accounts, I usually cannot link data to you, but write to hi@alp.me and I will do what I can within 30 days.

Children's Privacy

The app is not directed to children under 13 and does not knowingly collect personal information from them.

Changes to This Policy

If this policy changes, the new version will be posted on this page with a new date. Significant changes will also be mentioned in the app's release notes.

Contact

Alp Ozcan, hi@alp.me. You can also visit the support page.