What do you know about me
You can ask for everything we hold about you and get it back as a file. No email to anyone, no waiting for somebody to answer, no form.
In the app: Settings → Your data → What do you know about me.
Why it is a file and not a screen
The honest answer to "what do you know about me" is large. A year of outings at one position every thirty seconds is around a million recorded points, and that is before your outings, messages, contacts, tags and devices.
A browsable screen would have to choose what to show you — and a selection we made is exactly what you should not have to trust when you are checking what is held about you. So the app hands you the whole thing instead, in a zip file you keep, open with ordinary tools, and can check for yourself.
How it works
- Ask. Request my data. Nothing is sent to anyone; the file is built on our servers.
- Wait. Usually seconds, sometimes a few minutes if you have a long history. You can leave the screen — the work carries on without you. We email you when it is ready.
- Download. Come back to the same screen and tap Download. You choose where the file is saved, like any other download.
The "your data export is ready" email contains no link that would open your archive and no attachment. Nothing in it is a key. An email is not a safe place for the most complete copy of your data, so the file only ever leaves our servers through the app, to a signed-in you.
Two limits, and why they exist
One copy every 30 days. Building the archive reads your entire history, and the right of access is not a right to a continuous feed. If you ask too soon the app tells you the date you can ask again.
The copy is deleted after 7 days. A file containing everything about you should not sit on a server indefinitely because you downloaded it once and moved on. After that it is gone and you ask for a new one — which is free and takes the same few minutes. If you want to keep it, save it somewhere you control.
Your copy is also destroyed immediately if you delete your account.
What is inside
A zip file, named for your account and the date. Unzip it anywhere.
Start with index.html. Double-click it and it opens in your browser,
offline — no internet, no map tiles, no scripts, nothing loaded from anywhere.
It is the readable version: your contacts, your outings with a drawing of each
track, and your routes.
Everything else is the complete, machine-readable version of the same data.
| In the archive | What it is |
|---|---|
index.html | The readable document. Open this first. |
metadata/art15.html | Why we hold each category, who it is shared with, how long we keep it, and your rights — the Art. 15 information, written out. |
data/profile.json | Your name, email, phone, when you registered, when you last signed in. |
data/devices.json | Every phone that has been registered, with its public key, and when it was activated or revoked. |
data/contacts.json | The contacts you created, in full. |
data/contacts-held-by-others.json | Contacts other people hold that point at you — see below. |
data/outings-owned.json | Your outings: plan, activity, place, expected return, participants, status. |
data/outings-shared-with-me.json | Outings other people shared with you. |
data/messages.json | Messages you sent, and messages you received in outings you can still see. |
data/sos.json | Any SOS you raised, with position. |
data/coverage-gaps.json | Where your phone had no network during an outing. |
data/notifications.json | What we notified you about, when, by which channel, and whether it arrived. |
data/push-registrations.json | Your push notification registrations. |
data/audit.json | The security trail: sign-ins, device activations and revocations, downloads of this archive. |
data/email-suppression.json | Whether your address was ever suppressed after a bounce, and why. |
geo/outing-<id>.geojson | The full track of each of your outings. |
geo/trace-<id>.geojson | Each of your GPX routes, as GeoJSON. |
gpx/trace-<id>.gpx | Each GPX file you imported, byte for byte as you gave it to us. |
positions/positions-<year-month>.geojson | Your complete position history, one file per month. |
README.txt | Plain-text orientation, and any shortening notice. |
manifest.json | Every file above with its size, its record count and its SHA-256 checksum. |
manifest.json is how you check we are not lying
It lists every file, how many records each holds, and a checksum. The counts in the readable document and the counts in the data files have to match it. You — or a regulator, or anybody you ask — can verify that nothing was quietly dropped between the database and the file in your hands.
If anything was shortened, you are told
There are upper limits on how much one archive can hold. If your history is
large enough to hit one, the export still succeeds and the shortening is
written in three places: on the screen before you download, in README.txt,
and in manifest.json — naming the section, the limit, and exactly how many
records were left out. It is never silent. Write to
privacy@alpik.fr for the remainder.
Contacts other people hold about you
This is the part that surprises people, and it is in the archive on purpose: when somebody adds you to their contacts, that is data about you, held by us, and you are entitled to know it exists.
So contacts-held-by-others.json tells you what was recorded — the name they
gave you, the phone number, when — and how many people hold such a row.
It does not usually tell you who they are. If the holder is somebody you
already know about through the app (you hold them as a contact, or they shared
an outing with you), they are named, because you can see that already. A
stranger is shown as an opaque reference like holder:a3f9… instead. Naming
them would hand you a piece of somebody else's address book, and their rights
do not stop where your curiosity begins. The reference is stable, so you can
tell support "the one labelled a3f9… — remove me" and be understood.
What is not in it
Some of this is about protecting other people, and some is about not handing you something dangerous.
Other people's data, beyond what the app already shows you. The rule the
whole archive is built on: it discloses about other people exactly what the
app already discloses to you, and nothing more. So you get your own track but
never the track of an outing you merely watched; messages from groups you are
still in but not from ones you were removed from; the holder count for contacts
about you but not strangers' names. Where a section leaves something out for
this reason, index.html says so, with the reason — an archive that quietly
drops a field is indistinguishable from one that is wrong.
Your password. We have never had it. You type it into Alpik's identity service, not into the app.
Your push notification token. Only a short fingerprint of it, enough for you to match it to a device. The full token is live routing material — anyone holding it could send notifications to your phone — and putting it in a file you may email to yourself would be handing out a working key.
Jikita sightings your phone submitted. A sighting is a record about somebody else's tag. It carries no reference to you, which is also why deleting your account does not delete it. Your own tags and their registrations are in the archive.
Free-text detail on security events. The audit trail is included, but some events carry technical detail that mentions other people's equipment. That detail is withheld unless it has been checked to contain nothing about anyone else.
Your GPX routes are already yours
Worth saying plainly: the GPX files you imported are on your phone, in a standard format, and you can copy them off at any time without asking us for anything. The archive includes them again, unchanged, so that one file contains everything — but you were never dependent on us for those.
If it does not work
"Your copy could not be prepared." Nothing is wrong with your account. Ask for another copy. If it keeps failing, write to contact@alpik.fr with the reference code the screen shows — it tells us which part failed.
"This copy has expired." It was more than 7 days ago. Ask for a new one.
The download stops partway. Nothing is lost and nothing is used up. The copy stays available until it expires; try again on a better connection.
Related
- Your rights over your data — the other rights, and how to use them.
- What data myJikita holds — the same material in ordinary language, before you download anything.
- Delete your account and your data — if what you actually want is for it to stop existing.