This Privacy Policy explains how Gyde (the "App"), produced by the developer of Gyde (the "developer", "we", "us"), collects, uses, and protects information when you use the App. Gyde is a location-aware guide that surfaces stories and points of interest near you, using data from open sources such as Wikidata, OpenStreetMap, and Wikimedia Commons.
1. Information we collect
1.1 Information you provide
- Account information. If you sign in with Apple, Apple shares an opaque user identifier with us. If you choose to share your name and email with the App, we receive and store those values to identify your account and send service-related messages.
- Password account (if used). If you create an account with an email address and password, we store your email and a salted hash of your password. We never store your password in plain text.
- Account deletion requests. If you ask us to delete your account, we retain a non-identifying completion receipt containing a request ID, status, and timestamps so we can demonstrate that the deletion completed. The receipt does not retain your account ID, email, name, provider identifier, or a free-form reason.
- Social and planning content. We store crew names, member display names, messages, shared-place notes, saves, reactions, votes, and related timestamps so your group can plan together.
- Safety information. When you report content or block an account, we store the report reason, optional details, the involved account identifiers, a snapshot of the reported content, moderation decisions, and an audit record of moderator actions.
1.2 Information collected automatically
- Precise location (while in use). When you use features that require location, the App requests "While Using the App" location access. Your device's location is sent to our backend so it can return points of interest and events near you. Coordinates may also be stored with search or planning history so a conversation or plan works as expected. This history is deleted when you delete your account.
- Device session metadata. When you sign in or refresh your session, the App sends a short device label (for example, "iOS device") and platform name to associate with your session so you can see and revoke sessions in the future.
- Authentication tokens. Access and refresh tokens are stored on your device in the iOS Keychain (via Expo SecureStore) and sent in API requests so you stay signed in.
- Optional contact matching. If you choose to find friends from your contacts, the App normalizes email addresses and converts them to SHA-256 hashes on your device before sending them to our backend. We do not upload contact names or raw address-book email addresses. The backend compares the hashes with verified hashes for existing Gyde accounts. It stores import metadata, including the number of submitted and matched contacts, and stores hashes that match existing accounts so it can provide and manage friend suggestions. This information is associated with your signed-in Gyde account.
- Server logs. Like most internet services, our backend may log basic request information (timestamps, request paths, response codes, error messages, and IP address as seen by the server) for reliability and abuse prevention. We do not use these logs for advertising.
- First-party product analytics. In the App and on our website, we use a first-party visitor ID and session ID to measure page or screen views, searches, chat-message counts, link and point-of-interest clicks, active time, referrer, and campaign parameters. If you sign in, this data can be associated with your account so we can keep the product reliable and understand feature use. We do not use third-party advertising cookies or track you across apps or websites owned by others.
1.3 Information we do not collect
- We do not request microphone access or collect audio recordings from you.
- We do not use third-party advertising, marketing analytics, or cross-app tracking SDKs.
- We do not upload or store raw address-book names or email addresses, photos, calendar entries, health data, or HomeKit data. Optional contact matching does transmit hashed email addresses and stores matched hashes and import metadata as described in Section 1.2.
2. How we use information
- To provide the core App experience: showing nearby stories and points of interest, playing narration audio, and remembering your account.
- To match optional hashed contact email addresses with existing Gyde accounts and provide friend suggestions.
- To provide crew messages, shared saves, collaborative voting, reporting, blocking, and content moderation.
- To operate, secure, and improve the service (debugging, abuse prevention, capacity planning).
- To communicate with you about your account, including responding to support requests and confirming account deletion.
- To comply with legal obligations and respond to lawful requests.
3. Legal bases (EEA, UK, and similar regimes)
If the GDPR or UK GDPR applies to you, we process your personal data on the following legal bases:
- Performance of a contract - to provide the App's core features when you ask for them (for example, returning nearby points of interest after you grant location access).
- Legitimate interests - to keep the service secure, prevent abuse, debug errors, and maintain account integrity, balanced against your rights.
- Consent - for optional permissions you explicitly grant, such as precise location access. You can withdraw consent at any time in your device settings.
- Legal obligation - to comply with applicable laws.
4. Sharing and third parties
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only with the limited service providers we need to operate the App:
- Apple. If you sign in with Apple, Apple processes your authentication and may share your name and email with us according to the choices you make in the Sign in with Apple dialog.
- Hosting provider. Our backend runs on a third-party server hosting provider. Server operators may have technical access to data at rest as needed to operate the infrastructure.
- OpenAI moderation service. User-entered social text is sent to OpenAI's moderation endpoint before publication to detect potentially harmful content. We send the submitted text, not your email address, contacts, location, or surrounding group history. A report may trigger a second automated check for queue prioritization; automated results do not dismiss reports.
- Open data sources used to build content (not shared with). The points-of-interest, photos, and facts shown in the App are derived from public sources such as Wikidata, OpenStreetMap, Wikimedia Commons, and others. Google Places is used only for discovery and validation of public places, and Google data is not stored as canonical content (see our attributions). We do not send your personal information to these data sources.
- Law enforcement and legal process. We may disclose information if we believe in good faith that disclosure is required by law or is necessary to protect rights, safety, or property.
5. Data retention
- Account records and authentication identifiers are kept while your account is active.
- Refresh tokens expire and are rotated periodically.
- Contact-import metadata and matched contact hashes are retained with your account to provide friend suggestions and are covered by account and contact-import deletion requests.
- Blocks remain until you unblock the account or delete your account.
- Moderation reports, content snapshots, and action logs are retained for up to 12 months to investigate abuse, handle appeals, and prevent repeated harm, unless law requires longer retention.
- Operational logs are retained for a limited period for debugging and abuse prevention, then deleted or aggregated.
- Account-linked search history and first-party analytics are retained while needed to operate and improve the service and are permanently removed when you delete your account.
- In-App deletion permanently removes your account data immediately after the request succeeds. We retain only the non-identifying completion receipt described above and the limited safety or legal records described in this section.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict our processing of your personal data, and to object to certain processing. You may also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email drewb97@gmail.com. We may need to verify your identity before acting on a request. To delete your account specifically, see our Account Deletion page.
7. Children
Gyde is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal data to us, contact drewb97@gmail.com and we will take appropriate steps to remove it.
8. Security
We use industry-standard practices to protect your information, including HTTPS in transit, salted password hashing, signed access tokens, rotating refresh tokens, and encryption of stored third-party revocation credentials. No system is perfectly secure; we do not represent that the App is immune from every attack. We do not claim any specific security certification (such as SOC 2 or ISO 27001).
9. International data transfers
Gyde is operated from the United States. If you use the App from outside the United States, your information will be transferred to and processed in the United States or other jurisdictions where our service providers operate. These jurisdictions may have data protection laws different from those in your country.
10. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Effective date" above. Material changes will also be announced in the App or by email where reasonable.
11. Contact
Questions about privacy or this policy? Email drewb97@gmail.com.
Appendix A - Apple App Privacy disclosures
This appendix maps the practices above to Apple's App Privacy questionnaire categories.
Data linked to you
- Contact info: your email address and optional name, used for account management, app functionality, and support.
- Contacts: SHA-256 hashes derived from address-book email addresses when you choose contact matching. Matched hashes and import metadata are associated with your account for friend suggestions. Raw address-book names and email addresses are not uploaded.
- Precise location: coordinates used to return nearby places and events and to support location-aware search and planning.
- Identifiers: your Gyde account ID, opaque sign-in provider identifier, first-party visitor ID, and session IDs, used for authentication, app functionality, fraud prevention, and first-party analytics.
- Purchases: city-pass purchase and entitlement records, when you make a purchase, used to provide the purchased feature and prevent fraud.
- User content: crew names, member names, messages, shared-place notes, saves, reactions, votes, report details, and support communications, used for app functionality, safety, and support.
- Search history: searches, chat messages, and related planning context, used for app functionality and product improvement.
- Usage data: product interactions such as screen views, link and place clicks, feature activity, and session timing, used for app functionality and analytics.
- Diagnostics and safety: request and error logs, reports, blocks, moderation outcomes, and related identifiers, used for reliability, security, abuse prevention, and support.
Data not collected
- Audio recordings, health and fitness data, sensitive financial information, browsing history outside Gyde, advertising data, or third-party tracking identifiers.
Tracking
Gyde does not "track" you across apps and websites owned by other companies, as that term is defined by Apple's App Tracking Transparency framework. Gyde does not present the App Tracking Transparency prompt because it does not track.