GPS JoyStick Fake GPS Location
Privacy Policy
Introduction
GPS JoyStick Fake GPS Location ("GPS JoyStick," "this Application," or "the App") is a mock-location utility for Android that lets users simulate GPS coordinates on their device. This privacy policy explains what Personal Data the App collects, why it is collected, how it is processed, and what rights you have regarding your data.
The Data Controller is The App Ninjas Inc. (referred to as "the Owner," "we," or "us"), based in the United States. The Owner can be contacted at [email protected].
Types of Data collected
GPS JoyStick collects the following categories of Personal Data, either directly or through the third-party services described below:
- Device location: approximate and precise geographic position, accessed through Android location permissions. Your real device location is used locally on-device for mock-location functionality and is not transmitted to our servers. (Note: when you view or search the map, the map viewport area and search queries are sent to Google Maps; see the Map and location services section below.)
- Device identifiers: Google Advertising ID (GAID), used by the AdMob advertising SDK to serve and measure ads.
- Usage Data: information collected automatically, including IP addresses, device type, operating system version, app version, session duration, crash logs, and interaction patterns.
- Subscription and purchase data: Google Play purchase tokens, subscription tier, and validation timestamps, processed through Google Play Billing and our backend validation service.
- Push notification tokens: Firebase Cloud Messaging registration tokens used to deliver push notifications.
Location data provided to the App (coordinates you enter or select on the map) is stored locally on your device. We do not upload your mock-location coordinates to any server.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. Data is encrypted at rest on-device using the Tink cryptographic library backed by the Android Keystore. All network communication uses TLS encryption. Server-side purchase validation uses nonce-based replay-attack prevention and cryptographic signature verification.
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes. Under some applicable laws the Owner may be allowed to process Personal Data until the User objects ("opt-out"), without having to rely on consent or any other legal basis. This does not apply whenever the processing of Personal Data is subject to European data protection law;
- provision of Data is necessary for the performance of a contract with the User and/or for any pre-contractual obligations thereof (e.g., processing subscription purchases);
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party (e.g., app stability monitoring via crash reporting).
The Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Place
The Data is processed at the Owner's operating offices and on servers located in the United States. Third-party service providers (Google LLC, elevation API providers) may process data in other locations.
For transfers of Personal Data from the European Economic Area (EEA) to the United States, the Owner relies on the EU-US Data Privacy Framework (adequacy decision adopted by the European Commission on July 10, 2023) specifically for transfers to Google LLC, which is a certified participant. For transfers to the Owner's own servers (api.gpsjoystick.theappninjas.com), the Owner relies on Standard Contractual Clauses (SCCs) or the User's explicit consent. Users can contact the Owner for further details about the specific safeguards applied to their data transfers.
Retention time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
- Crash reports and performance data are retained by Google according to Firebase's data retention policies (typically 90 days for raw crash data).
- Subscription validation records are retained for the duration of the subscription plus any legally required retention period.
- Advertising data is retained by Google according to Google's advertising data policies.
- Data stored locally on your device (saved locations, routes, favorites, preferences) persists until you clear the App's data or uninstall it.
The Owner may retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn, or whenever required by law or by order of an authority. Once the retention period expires, Personal Data shall be deleted. The right to access, erasure, rectification, and data portability cannot be enforced after expiration of the retention period.
The purposes of processing
The Data concerning the User is collected to allow the Owner to provide its Services, as well as for the following purposes:
- Advertising: serving banner, interstitial, native, app-open, and rewarded ads through AdMob
- Infrastructure monitoring: crash reporting and performance monitoring through Firebase Crashlytics
- Analytics: understanding how the App is used, identifying popular features, measuring upgrade funnels, and improving the user experience through Firebase Analytics
- Push notifications: delivering messages and deep links through Firebase Cloud Messaging
- Subscription management: processing and validating in-app purchases through Google Play Billing and our backend service
- App configuration: fetching remote configuration (ad settings, feature flags, app state) from our backend
- Map and location services: rendering maps and searching for places through Google Maps and Google Places
- Elevation data: looking up terrain elevation through third-party elevation APIs
Device permissions for Personal Data access
GPS JoyStick requests the following Android permissions:
Location permissions
Approximate location (ACCESS_COARSE_LOCATION) and precise location (ACCESS_FINE_LOCATION) are required for the App's core mock-location functionality. Location data is processed on-device; your real coordinates are not transmitted to our servers.
Background location (ACCESS_BACKGROUND_LOCATION) is requested on Android 10 and above to allow the mock-location service to continue operating while the App is in the background.
Other permissions
- Internet and network state: required for ads, push notifications, subscription validation, map loading, and fetching app configuration.
- Advertising ID (AD_ID): allows the AdMob SDK to serve personalized ads and measure ad performance.
- Display over other apps (SYSTEM_ALERT_WINDOW): enables the floating joystick overlay used to control mock location.
- Foreground service: keeps the mock-location service running while the App is in the background.
- Notifications (POST_NOTIFICATIONS): allows the App to display notifications for the foreground service and push messages.
Permissions must be granted by the User before the respective data can be accessed. Permissions can be revoked at any time through Android Settings. Revoking location permissions will prevent the App from functioning correctly.
Detailed information on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Advertising
This Application displays ads to support its free tier. Ads may be personalized based on User interests and behavior. Users can opt out of ad personalization through their device's Google advertising settings.
AdMob (Google LLC)
AdMob is an advertising service provided by Google LLC. GPS JoyStick uses AdMob to display banner ads, interstitial ads, native ads, app-open ads, and rewarded ads. Rewarded ads allow Users to earn temporary ad-free access or temporary Pro feature access. In order to understand Google's use of Data, consult Google's partner policy.
Personal Data collected: Google Advertising ID, Usage Data, device identifiers and similar tracking technologies, IP address.
Place of processing: United States. Privacy Policy. Opt Out.
Google LLC is a certified participant in the EU-US Data Privacy Framework.
Infrastructure monitoring
These services allow the Owner to monitor the App's performance and stability so that issues can be identified and resolved quickly.
Firebase Crashlytics (Google LLC)
Firebase Crashlytics is a crash reporting service provided by Google LLC. It collects crash reports, stack traces, and device state information when the App encounters an error. Crash reporting is disabled in debug builds and enabled only in production.
Personal Data collected: device type, OS version, app version, crash logs, stack traces, unique installation identifiers.
Place of processing: United States. Privacy Policy. Google LLC is a certified participant in the EU-US Data Privacy Framework.
Analytics
This Application logs analytics events to understand how the App is used, identify popular features, measure upgrade funnels, and improve the user experience.
Firebase Analytics / Google Analytics for Firebase (Google LLC)
Firebase Analytics is an analytics service provided by Google LLC. GPS JoyStick logs custom app events to understand feature usage and improve the experience. These events include: feature interactions (e.g., which screens are viewed, which features are used), upgrade and purchase funnel steps (e.g., which subscription tier was selected, whether a purchase completed or failed), spoofing session metrics (e.g., session duration, spoofing mode - no GPS coordinates are included), content actions (e.g., when a favorite is saved or a route is created), app setting changes (e.g., language selection, theme preference - only the setting name and selected option are logged, no personal data), error diagnostics (e.g., location provider error types, permission denial reasons), ad telemetry (e.g., ad impressions and ad lifecycle events), setup wizard step completion, and feature lifecycle events such as Privacy Mode start, complete, and cancel.
GPS JoyStick also sets custom user properties that are attached to analytics events: subscription tier (free, ad-free, or pro) and approximate install age (days since first install). These properties help the Owner understand usage patterns across different user segments. No personally identifiable information is included in user properties.
Personal Data collected: app events and event parameters (as described above), user properties (subscription tier, install age), session data, device type, OS version, app version, unique installation identifiers.
Analytics event data is retained by Google according to Firebase Analytics data retention settings.
Place of processing: United States. Privacy Policy. Google LLC is a certified participant in the EU-US Data Privacy Framework.
Push notifications
This Application may send push notifications to the User to deliver updates, promotional content, or deep links to external content.
Firebase Cloud Messaging (Google LLC)
Firebase Cloud Messaging (FCM) is a messaging service provided by Google LLC. It allows the Owner to send notifications to Users across platforms. Notifications may contain deep links that open URLs or other applications.
Personal Data collected: FCM registration token, device type, various types of Data as specified in the privacy policy of the service.
Place of processing: United States. Privacy Policy. Google LLC is a certified participant in the EU-US Data Privacy Framework.
Subscription and purchase validation
Google Play Billing (Google LLC)
GPS JoyStick offers in-app subscriptions (Ad-Free and Pro tiers) through Google Play Billing. Google processes subscription payments and provides purchase tokens to the App.
Personal Data collected: purchase tokens, subscription status, purchase history.
Place of processing: United States. Privacy Policy.
Backend validation service (The App Ninjas Inc.)
Purchase tokens are sent to our backend server at api.gpsjoystick.theappninjas.com for server-side validation. The server verifies the purchase with Google and returns the validated subscription tier. A randomly generated nonce is included with each request to prevent replay attacks.
Personal Data collected: purchase token, package name, app version, subscription tier.
Place of processing: United States, governed by this privacy policy.
App configuration
Backend configuration service (The App Ninjas Inc.)
On launch, the App fetches configuration data (ad unit IDs, feature settings, app state) from our backend server. This request includes the app version and package name but does not include any personal identifiers.
Data collected: app version, package name.
Map and location services
Google Maps and Google Places (Google LLC)
GPS JoyStick uses Google Maps for map rendering and Google Places for location search. When you search for a place, your search query is sent to Google.
Personal Data collected: search queries, map viewport coordinates, IP address.
Place of processing: United States. Privacy Policy.
Elevation APIs
GPS JoyStick may send geographic coordinates to third-party elevation services to look up terrain altitude. Only latitude and longitude are transmitted; no personal identifiers are included. The providers used are:
- Open Elevation API (open-elevation.com), open-source, no account required.
- Google Elevation API (Google LLC). Privacy Policy.
Data collected: geographic coordinates (latitude, longitude).
Local data storage
GPS JoyStick stores saved locations, routes, favorites, custom markers, and user preferences in an encrypted local database (Realm) and encrypted SharedPreferences on your device. This data is not transmitted to any server. It is deleted when you clear the App's data or uninstall the App.
The rights of Users
Users may exercise certain rights regarding their Data processed by the Owner.
Rights under the GDPR and UK GDPR (EEA and UK Users)
If you are located in the European Economic Area, you have the right to:
- Withdraw consent at any time where processing is based on your consent.
- Access your Data and obtain a copy of the Personal Data undergoing processing.
- Rectify your Data: verify the accuracy of your Data and request correction.
- Erase your Data: obtain the deletion of your Personal Data under certain circumstances.
- Restrict processing: under certain circumstances, restrict the processing of your Data so that it is only stored.
- Data portability: receive your Data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Object to processing: object to the processing of your Data where processing is based on legitimate interests.
- Lodge a complaint with your local data protection authority.
Details about the right to object to processing
Where Personal Data is processed for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Where Personal Data is processed for direct marketing purposes, Users can object to that processing at any time without providing any justification.
Rights under CCPA/CPRA (California Users)
If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Right to know: request disclosure of the categories and specific pieces of Personal Data we have collected about you.
- Right to delete: request deletion of your Personal Data, subject to certain exceptions.
- Right to correct: request correction of inaccurate Personal Data.
- Right to opt out of sale or sharing: GPS JoyStick does not sell your Personal Data in the traditional sense. However, the use of third-party advertising services (AdMob) may constitute "sharing" of Personal Data for cross-context behavioral advertising under the CPRA. You may opt out of personalized advertising through your device's advertising settings (Settings > Google > Ads > Opt out of Ads Personalization) or by emailing [email protected] to request that the Owner limit the sharing of your Personal Data for cross-context behavioral advertising.
- Right to non-discrimination: we will not discriminate against you for exercising any of these rights.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner at [email protected]. Requests will be addressed free of charge and within one month (extendable by two further months for complex requests, with prior notice to the User) or 45 calendar days for CCPA requests (extendable by an additional 45 calendar days upon notice). We may request verification of your identity before processing your request.
Children's privacy
GPS JoyStick is rated for users aged 13 and above. Ad serving is configured to not target children. We do not knowingly collect Personal Data from children under 13. If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us at [email protected] and we will take steps to delete such information.
Additional information about Data collection and processing
Legal action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
System logs and maintenance
For operation and maintenance purposes, this Application and any third-party services may collect system logs that record interaction with this Application and use other Personal Data (such as IP addresses) for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the end of this document.
How "Do Not Track" requests are handled
This Application does not respond to "Do Not Track" browser signals. This Application is a native Android app and does not receive Global Privacy Control (GPC) browser signals. Users who wish to limit data sharing for advertising purposes may adjust their device advertising settings or contact the Owner. For additional information about opting out of personalized advertising, see the CCPA/CPRA rights section above.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by posting the updated version on this page. Users are advised to check this page periodically, referring to the date of the last modification listed at the bottom. If changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User where required.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information, including a personal identification number, allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: IP addresses, device type, operating system, the features of the browser and the operating system utilized by the User, session duration, interaction patterns, and other parameters about the device and the User's environment.
User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
This Application
The GPS JoyStick Fake GPS Location Android application, which is the means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Application as described in the relative terms (if available) and on this site/application.
Cookies
Small sets of data stored in the User's device by websites or web-based services (such as advertising SDKs operating within an app) to remember information about the User.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Legal information
This privacy statement has been prepared based on provisions of multiple laws, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation), the UK General Data Protection Regulation (UK GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act.
This privacy policy relates solely to this Application, if not stated otherwise within this document.
Contact Information
Latest update: April 12, 2026