Skip to content

Privacy policy

Effective date: Not yet in effect.

This is a draft. It has not been reviewed by a lawyer and is not yet in effect.

Who is responsible for your data

WalkGuide is a self-guided audio walking tour app for iOS and Android, with this website beside it.

The data controller's legal name and address have not yet been published.

What we collect, and why

You do not need an account to use the app. On first launch it creates a random identifier on your device — not derived from your name, email, phone number or device — and keeps it in the device’s secure storage. That identifier is how our server and our purchase provider recognise the same app across sessions.

Our server creates a record for that identifier only when it first has something to store for you. Until then it holds nothing about you.

  • A purchase: which pass you bought and when, so our server can let you download what you paid for.
  • Your consent choices: what you chose, which version of the wording you chose it under, and the country and region our network inferred from your connection when you chose — never your street address or position.
  • A data request: that you asked to export or delete your data, and when it completed.
  • A report about a tour stop: the kind of issue, any comment you typed, your device’s operating system and the app version. It carries no position.
  • With analytics turned on: which screens and features you used, keyed to the random identifier and never to your name, email or position.

Your location

The app uses your device’s location while you walk, so it can start the narration for a stop when you reach it. That decision is made on your device.

When the app asks our server what is near you, your position travels with that one request and is used to answer it. Before it is used as part of any cache key it is rounded to a grid of about 50 metres.

Your position is never written to our database, our storage or our logs, and the progress the app saves about a walk you are on holds no position.

We apply the strictest consent rules everywhere, whatever country you are in, and relax them only where the law where you are allows it.

The app asks for two choices on first launch — analytics, and personalisation. Both are off until you turn them on, and you can change either one from the app’s profile tab at any time.

If your browser sends a Global Privacy Control signal, we treat it as a refusal of analytics and do not ask.

This website uses two analytics services. Cloudflare Web Analytics counts page views without cookies and without identifying you, and runs on every page. Google Analytics runs only if you accept it in the site’s cookie banner, and stops if you withdraw. Both record page views only.

Who we share data with

We do not sell your personal data. The services below process data on our behalf, and only for the purpose given.

  • Cloudflare hosts our server, our database, our file storage and this website.
  • RevenueCat records your purchases and what they entitle you to, using the random identifier. The purchase itself is made through the App Store or Google Play.
  • Sentry receives crash reports from the app, only if you have turned analytics on. Reports are stripped of request details, user details and breadcrumbs before they are sent. Our server reports its own unexpected errors to Sentry, redacted first.
  • PostHog receives the usage events described above, only if you have turned analytics on.
  • Google receives page-view data from this website, only if you accept Google Analytics in the cookie banner.

How long we keep it, and what deletion removes

When you ask us to delete your account, the request is processed within 24 hours. Your sign-in on every device is cancelled first, so the request cannot be undone by an old session.

Deletion removes your account record and, with it, your registered devices, our copy of your entitlements, any Party Pass share code you bought and every redemption of it, anything you redeemed with someone else’s code, photos you submitted, any score you gave a tour, and your consent records.

Some records outlive the account with your identity removed from them, because they are needed for other reasons: purchase and refund records, for tax, accounting and legal claims; reports about a tour stop, which are safety information about a place and whose comment text is wiped; and the record that your deletion request was made and completed.

Your rights

You can ask for a copy of your data, or for it to be deleted, from the app’s profile tab under “Your data”. This website has no sign-in and cannot identify you, so the request is made from the app.

Your export is one file holding everything this app keeps about you: your account and every record on our server that names it, and what this device holds — favourites, your consent choice, preferences, walk progress and downloaded tours.

Before you delete your account, note:

  • If you bought a Party Pass, deleting your account revokes every redemption of its share code, so the people you shared it with lose access too.
  • A subscription bought through the App Store or Google Play is not cancelled by this. Cancel it in the store.
  • The text of any issue report you sent is wiped.

Maps and third-party content

Our maps are built from OpenStreetMap data, available under the Open Database Licence, and every map shows “© OpenStreetMap contributors”.

Photographs from Wikimedia Commons are used only under the CC BY-SA 4.0 licence, and each one is credited where it appears.

Children

The service is not directed at children, and nothing in it is designed for them. The same strict privacy defaults apply to everyone who uses it.

Changes to this policy

No version of this policy takes effect until an effective date is shown at the top of this page. A later change will show its own effective date there.

Contact

A privacy officer has not yet been named.