Statement from Polarsteps

4 September 2026

We care deeply about user privacy, and privacy is a key part of our app's design. All user trips and profiles are set to “private/followers only” by default, never public. We communicate to our users when they switch their privacy settings to 'Anyone' that this means publicly accessible, even by people not using Polarsteps.

Follow the Money recently published an investigation into Polarsteps. Despite their claim that this is a data leak, we would like to emphasize that is incorrect. FTM only had access to public trip data and to the best of our knowledge, there has been no data breach.

For clarity: all trip data that was never made public by the user has remained private, and no authentication was bypassed (i.e. no passwords were breached and no one got access to any Polarsteps account or private trips).

Public trip data 

The journalists have taken public trip data - where users have actively chosen to share their trips and contents publicly - and information that is public in Polarsteps to allow users to find each other (name, profile picture, mutual followers). You can see here on our support page what this information is.

Following other users

FTM also followed a lot of profiles who had set their privacy settings to “Anyone can follow me” rather than “Only people I approve”. This allowed them to see the trips for followers, because they had become followers of these accounts. 

Polarsteps allows people to choose to approve their followers, or not, and our default setting is that people must approve their followers. Some people - e.g. travel writers who want to share their trips to inspire others - will decide to override the default privacy setting and accept any follower. 

FTM made use of the auto-follow setting to follow some user accounts set to auto-accept followers. They did not breach any privacy controls. They then saw trips that were set to followers-only on accounts that auto accept followers (a tiny fraction of Polarsteps users). No private data was breached or shared because of this. 

You can see here the privacy options available to our users and the default settings, which are always private or follower-only, not public. 

Security researcher

The FTM piece also says that a security researcher raised issues with Polarsteps six months ago. To be clear: we read the report by the researcher, and were already acting on the things that were raised in it. It is not the case that we knew about security issues and did not act on them.

Security improvements

This investigation did, however, raise a couple of points around security where we could have done better, and we've taken them seriously, as we truly value our users’ security. We’ve already acted on these - we've implemented even stricter API controls to prevent large-scale access to our public user data, and strengthened protections around our secret link feature (which allows people to share trips with non-followers).

And, as ever, we’re working to improve how users understand what's public versus what’s private for their Polarsteps trips. We’ve also been working over the years, long before FTM’s investigation, to add extra privacy features in our app (e.g. this year adding hide start/end location and hide current location options).

We’re a team that cares deeply about security, and as soon as we become aware of issues, we act on them immediately, as we've done in this case.

If any of our users have concerns, feel free to contact us here: support.polarsteps.com/contact

FAQ

Frequently Asked Questions

Frequently Asked Questions

Has there been a data breach under the GDPR at Polarsteps?

Follow the Money has referred to this as a data breach, but what actually occurred is that FTM was able to access a large volume of publicly available data through our public API. To the best of our knowledge, no data breach has taken place. We are in contact with the Dutch Data Protection Authority (AP) regarding FTM's findings.

FTM says "FTM was able to download the data of more than 23 million international users, including their names, photos, and information about their friends and family.”. What does this mean?

The data they’re referring to for our 23 million users is public profile data. In order for people to be able to find each other in the app, they need to be able to search for other users, and see things like name, profile picture, mutual followers, etc. This is how it also works for other community apps (like Alltrails, or LinkedIn). FTM has downloaded the already-public information. 

You can see here on our support page what this information is: 

https://support.polarsteps.com/hc/en-us/articles/38224904688786-Which-parts-of-my-profile-can-other-people-see-publicly

Did Polarsteps ignore a report from a security researcher six months ago?

This is not true. We acted on many things the researcher had raised in their report, between the report in December 2025 and before FTM’s investigation in July (these things were hygiene improvements in the API, which we were already working to improve before the report came in in December). 

What happened with follower-only trips?

FTM followed a lot of profiles who had set their privacy settings to “Anyone can follow me” rather than “Only people I approve”. This allowed them to see the trips  for followers, because they had become followers of these accounts. 

Polarsteps allows people to choose to approve their followers, or not, and our default setting is that people must approve their followers. Some people - e.g. travel writers who want to share their trips to inspire others - will decide to override the default privacy setting and accept any follower. FTM made use of this setting to follow these accounts and did not breach any privacy controls. They simply saw the trips that were set to followers-only on accounts that auto accept followers (a tiny fraction of Polarsteps users). No private data was breached or shared because of this.

Are my planned trips or steps shared publicly?

You choose the privacy setting of your planned trips, just like your tracked trips.You can choose “Only me”, “Followers only”, or “Everyone”. Please remember that everyone means your trip is public, even to those who don’t have the Polarsteps app.

What were the things Follow the Money found that Polarsteps should have done better?

  1. They found a hypothetical vulnerability in how our links for sharing trips work (only in the case where someone had actively chosen to make their trip public, and then later switched the ‘Who can see this trip’ setting to ‘Followers only’, which is not common behaviour by our users as far as we know).

    This does not apply to any trip that has never been set to ‘Everyone’ (public). Our default settings for any trip when being created is ‘Followers only’. If you have not actively set your trip to ‘Everyone’, your trips are not covered by FTM’s investigation.

    We've fixed this and expired all historical links immediately as an extra precautionary measure. We have seen nothing to suggest this has ever been exploited or was ever known other than by FTM. 

  2. We have something called a public API (it needs to be public so users can find and follow each other and public trips can be seen by friends and family without a Polarsteps account). Although this only includes public information, FTM's investigation showed our rate limiting (to limit how much of this public information someone can get at once, in order to avoid “scraping”) wasn't as good as it should have been. We fixed this, too. To be clear: no private data was exposed to our knowledge.

  3. We’ve also made other improvements as a result of this report, e.g. further limiting the public data that’s available as part of the API, and resetting every profile in Polarsteps to the default privacy setting so that each user needs to give approval for anyone to be able to follow them as an extra cautionary measure.

Has my data been exposed?

To the best of our knowledge to this date, no private trip data has been exposed. If your trips are set to “Only me” and/or “Followers only”, only you and your followers can see your data.

To be clear: the profile picture, name and home city you share in Polarsteps to allow people to find and follow you is already publicly available information. The journalists found a way to download this already-public information. This does not mean they downloaded any of your private trip data. They downloaded information that has always been public (which is there so people can find their friends and family on Polarsteps).

The journalists also found that they could follow trips of people who had set their profile privacy settings for “Who can follow me” to “Anyone” (which means they auto-accepted new followers). This setting allows anyone to follow you and we advise you to be very careful when turning it on. It is not the default setting. The default setting means you have to approve every follower.

If you’re worried about someone you don’t know or trust following your account, you can always remove anyone from your list of followers, and you can always set your trips to “Only me” so even your followers can’t see them.

For more questions and answers around this, see here. If you have worries or concerns, please reach out to our support team here who are happy to help: support.polarsteps.com/contact

I’m worried about my trips, photos, and locations. Have they been accessed or downloaded?

If your trip has always been set to “Only me” or “Followers only” and you have never shared a secret link, no one except you and your followers can see or has ever been able to see that trip.

If you have a current or past trip that you’ve set to “Everyone”, this does mean anyone can see the trip, including people without a Polarsteps account that are simply browsing on the internet. You can always and instantly change this trip to “Only me” to make this private, or to “Followers only” in your trip privacy settings. If you need help, reach out to our support team here.

If you’ve got a public trip right now or you’ve had a public trip in the past and you’re worried about its privacy, please contact our team here.

Is there any way someone has my secret link even if I’ve never shared it?

If your trip has always been set to “Only me” or “Followers only”, and you have never shared a secret link, no one else (outside of your followers) can see your trip or any of its private data.

For public trips:
We recently discovered a vulnerability that could, hypothetically and in a very rare set of circumstances (which to our knowledge have not actually occurred), allow a user’s previously-public trip link to be discovered even if it’s been set to “Followers only’ later.

If your trip was set to “Everyone” in the past, and you’ve then set it to “Followers only”, a technical expert may have for a brief period been able to reverse-engineer the secret link from your trip while it was public and later use it to view the trip (but never if it was only ever set to “Only me” or “Followers only”). To our knowledge, this has not happened to any user.

If your trip has never been a public trip, this does not apply to you. The vast majority of our trips are never public.

Nevertheless, to be safe, on August 20, 2026 we expired all secret links as a precaution, and created a new way of generating secret links that is secure. So: right now, no one has the secret link to your trip, unless you have sent it to them since August 20. All new secret links generated from August 20 on have fixed the vulnerability and are secure.

⇒ important note: this only affects secret links, normal link sharing hasn't been touched (i.e. if you share a link to your trip that is set to “Followers only”, only your followers will be able to see your trip).

Is it still safe to use Polarsteps? How do I check or change my privacy settings?

Privacy Settings

Yes, it’s still safe to use Polarsteps. You can easily check your privacy settings. These two are most important:

  1. Polarsteps app > Settings > Who can follow me. (We recommend setting this to “Only people I accept”)

  2. Polarsteps app > Me tab. On every trip in your profile, you see an icon in the bottom right corner which indicates the privacy level for that trip. Here’s what the icons mean:

    🌍 Globe = Everyone can view this trip

    👥 People = Followers can view this trip (and people who have your secret trip link if you’ve chosen to share this). This is the default.

    🔒 Lock = Only you can view this trip. If you have added Travel Buddies to your trip, they can see it too. Trip links you may have shared previously do not give access.

I have more questions. How do I contact you?

Polarsteps user?
You can reach us via support.polarsteps.com/contact

Journalist?
Please reach out to press@polarsteps.com

You can also read more in our FAQ here about privacy settings, secret links, and followers.