Guided
ExploreHow it worksFAQAttribution
Early accessGet early access

Privacy

Last updated 17 August 2026

Guided Tours needs to know where you are in order to work — that is the whole product. This page explains exactly what that means in practice, what leaves your phone, and how to stop it.

Who is responsible

Guided Tours is operated by [operator name and registered address]. For any question about this policy or your data, contact [contact email].

What is collected

Your account

Signing in uses Sign in with Apple. We store the stable identifier Apple gives us for you, which lets us recognise you across sessions and devices. We do not ask for a password, and we do not require your email address or real name.

Location

The app asks for background (“Always”) access to your precise location. This is what lets narration begin on its own as you arrive at a stop, with the app closed and your phone in your pocket.

Your position is evaluated on the device. Guided Tours does not stream a continuous location trail to its servers. What is recorded on the server is which stop you reached and when — not a track of everywhere you went.

If you decline background access, the app still works: you trigger each stop’s narration yourself instead of it starting automatically.

How you use a tour

The app records events about tour playback — stops reached, narration played, skipped, or abandoned, and how far through a tour you got. This exists for one reason: to find out where tours lose people, so they can be made better.

You can turn this off. There is an analytics opt-out in the app’s settings. With it enabled, these events are no longer collected.

Photo contributions

If you choose to, you can photograph a place that has no picture yet and submit it to the catalogue. This is the only camera or photo-library access the app has, and it only happens when you deliberately start a submission — the app never reads your photo library or camera roll on its own.

A submitted photo is reviewed before it is shown to anyone else. If it is accepted, it becomes part of the public catalogue for that place under the rights grant you agree to at the moment you submit — the same screen tells you what that grant covers. An accepted photo stays in the catalogue even after you delete your account (see “Your rights” below): it was contributed under that explicit grant specifically so the catalogue could keep relying on it, and removing it would silently take a picture away from every other person using the app. What changes is that the photo’s link to you, as its contributor, is removed.

Beta waitlist signups

The website at guidedtours.app has a form to join the TestFlight beta waitlist. If you use it:

  • What is stored: the email address you submit, lowercased, and the page path you submitted it from (for example, which city page led you here).
  • Why: to contact you when TestFlight beta access opens, and to understand which pages on the site lead people to sign up.
  • Where: in the project’s own Postgres database, on its own server. It is not sent to a third-party mailing-list provider.
  • No marketing email is sent today. Sending email is explicitly out of scope for the current build — signing up does not put you on a newsletter.
  • Removal: to have your submitted address removed, contact us at the address above.

Website pageviews

The website at guidedtours.app also keeps a simple, anonymous record of which pages people visit. Every page you view on this site, including a page reached without a full page reload:

  • What is stored: the page path you viewed, the name of the site that referred you here (if any), any campaign tags carried in the link you followed, an approximate screen width, the approximate country the visit appears to come from (a two-letter country code, worked out from your IP address), and a one-way code that stands in for “one visitor”, rebuilt from a new secret every day.
  • What is NOT stored: no cookie, no browser storage of any kind, no IP address, and no full referring URL — only the referring site’s name. The country is as specific as it gets: never a city, a region, or a location on a map.
  • Why: to see which pages on the site lead people to sign up for the beta waitlist, and roughly where in the world visitors are coming from.
  • The daily code: because that one-way code is rebuilt from a new secret each day, the same person cannot be followed from one day to the next.
  • How the country is worked out: your IP address is looked up against a locally-held country database at the moment the visit is recorded, and the address is discarded immediately afterwards — it is never saved.

The web server that hosts this site also keeps its own short-lived access logs, the way most web servers do, with the visitor’s address partially masked.

Place pages also embed a small map showing where the place is. Loading one of those pages fetches map tiles directly from the OpenStreetMap Foundation’s tile servers, so those servers receive the same request any image load produces — your IP address and the address of the page you’re viewing. How the OpenStreetMap Foundation handles that is described in its own privacy policy.

What is not collected

  • No advertising identifiers, and no third-party ad or tracking SDKs.
  • No contacts or microphone access, and no camera or photo-library access beyond the deliberate photo-contribution flow described above.
  • No continuous background location history.
  • Your data is never sold.

How narration is made

Tour narration is written and voiced in advance from public, openly licensed sources — see the attribution page. Generating it uses third-party AI services, but they receive only that public source material about places. Your personal data is not sent to them.

Where data is held

Data is stored on servers operated for Guided Tours in the European Union. Access is limited to the operator.

Legal basis and retention

  • Your account — necessary to provide the service you asked for. Kept until you delete your account.
  • Location — processed with your consent, which you give through the iOS permission prompt and can withdraw at any time in iOS Settings.
  • Usage events — our legitimate interest in improving tours, subject to the opt-out described above.
  • Beta waitlist email — your consent, given by submitting the form. We have not fixed a specific retention period beyond it: the honest answer today is that it is stored until beta access opens or you ask for removal.

Your rights

Under the GDPR you can request access to your data, correction, a portable copy, or object to processing. To exercise any of these, contact us at the address above.

Account deletion is available directly in the app, from the Account screen — it does not require contacting us. Deletion is immediate: the moment you confirm it, your account record, your saved items, your usage events, and your tour history are gone, and any photo submission you had pending review is withdrawn. If you had signed in with Apple, we also ask Apple to revoke the sign-in grant you gave us. Two things are not removed, deliberately: a photo you contributed that had already been accepted into the catalogue stays there, with only your link to it removed (see “Photo contributions” above); and your credit history keeps its record of what was earned, with only the link to you removed, so the ledger’s own totals stay accurate. Signing in again afterwards creates a new account, never your old one restored.

Children

Guided Tours is not directed at children under 13, and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects what is collected or why, the date at the top will change and the update will be noted in the app.

Map data © OpenStreetMap contributors. Full source credits on the attribution page.

Guided
CitiesStoriesDiscoverAttributionPrivacy
© 2026 Guided Tours