Privacy Policy
DRAFT — operator details and legal review pending1. Who we are
Camino GO ("the App", "we", "us") is operated by:
- Operator: [LEGAL ENTITY NAME]
- Registered address: [ADDRESS]
- Contact (privacy): support@caminogo.app
- Contact (general support): support@caminogo.app
EU Representative (Art. 27 GDPR): [TO BE APPOINTED BEFORE LAUNCH]
We act as the data controller for the personal data described in this policy.
2. Scope
This policy covers the Camino GO mobile application, related backend services, and the caminogo.app website. It does not cover third-party websites or services we link to (e.g., an accommodation's own booking page).
3. What data we collect
3.1 Account data
- Email address, display name, profile photo (optional)
- Authentication identifiers from your sign-in provider (Apple, Google, or email) via Firebase Authentication
- Account settings (language, preferences)
3.2 Location and activity data
- Precise location (GPS) — when you enable location features: live map position, route tracking, daily route briefing, weather for your position, and location context for AI questions. Active walk tracking may continue in the background when you grant the necessary permission. You can stop tracking or revoke permission in your device settings.
- Walking records — daily distance, step counts, elevation gain, and recorded track points for trips you track. Step counts are read from your device's motion sensors (Core Motion on iOS, the step counter sensor on Android), with your operating-system permission. We do not access HealthKit or Google Fit.
- Track history is stored so you can review your journey; see §7 for retention and §8 for deletion.
3.3 AI questions, photos, search and voice
- Text, photos and relevant conversation context you submit to Camino AI, including translation and photo questions. Route assistance can include your location, nearby places and trip context when that feature uses them.
- When you explicitly request AI-assisted map search, the search text is sent for interpretation. Ordinary name matching and category filtering do not require an AI request. A place name or other personal information you type may be included in the text.
- Cloud speech recognition: recordings you submit are sent through our server to OpenAI for transcription. Audio is handled for the transcription request and is not stored as a permanent recording by our application server. The resulting text can be sent to an AI provider when you submit your question.
- Face-to-face translation: speech recognition is handled by your phone's operating-system speech service; Camino sends the recognized text for translation. System speech processing is subject to Apple or Google's settings and terms and is not necessarily entirely on-device.
- AI session data on our server, copies in your device's history and copies processed by AI providers have different retention rules; see §5 and §7.
3.4 User-generated content (UGC)
- Chat messages, announcements/forum posts, diary entries, photos you upload, accommodation/POI reports and community data edits.
- Diary entries are private in the current App — they are stored on our servers to sync across your devices and are not shown to other users through the current diary feature.
3.5 Purchases
Purchase entitlements (Trip Pass validity, AI-use balances and cloud speech allowances), platform transaction identifiers and purchase history. We use RevenueCat to validate and restore purchases and manage entitlements; its SDK associates purchase information with your Camino account identifier and receives relevant app/device information. Payment is processed entirely by Apple App Store / Google Play; we never receive your card details.
3.6 Technical data
- Device model, OS version, app version, language
- Push notification token (if you enable notifications)
- Server logs (IP address, request metadata, error logs) for security and reliability
- Optional diagnostic reports: local diagnostic logs are uploaded when you choose to send a report. Reports may include device/app details, error information and precise route or location details relevant to the problem. These reports are not an automatic upload of all your local logs.
3.7 Website visitors (caminogo.app)
- Launch notification list — if you submit your email address on our website, we store the address, signup time and verification status, solely to send you one launch announcement. You can withdraw at any time by emailing support@caminogo.app.
- Privacy-first analytics (no cookies) — the website uses Cloudflare Web Analytics, a cookieless tool that sets no cookies and does no cross-site tracking or fingerprinting. It records aggregate, non-identifying statistics (page views, referrers, country, device/browser type) via a lightweight beacon; no individual profile is created and we cannot identify you from it.
- Search performance — we use Google Search Console, a Google webmaster tool that reports how our pages appear in Google Search results. It does not run code, set cookies, or track visitors on our website; the data comes from Google's own search infrastructure.
- Standard CDN server logs (Cloudflare) for security and abuse prevention. Our signup endpoint also temporarily stores a hash derived from the IP address to limit repeated submissions, with a two-hour expiry. Where an anti-bot challenge is enabled, Cloudflare processes the challenge response and request information for verification.
4. Why we process it (purposes and legal bases)
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the App (account, maps, planner, tracking) | 3.1, 3.2, 3.6 | Art. 6(1)(b) contract |
| AI features you invoke (photo questions, translation, speech recognition, search interpretation and briefings) | 3.2, 3.3 | Art. 6(1)(b) contract |
| Weather for your route | Approximate location | Art. 6(1)(b) contract |
| Community features (chat, forum, community edits) | 3.4 | Art. 6(1)(b) contract |
| Public-content/profile moderation and AI safety screening | 3.1, 3.3, 3.4 | Art. 6(1)(f) legitimate interest (keeping the community safe) |
| Purchases and entitlements | 3.5 | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (accounting) |
| Security, abuse prevention, rate limiting | 3.6 | Art. 6(1)(f) legitimate interest |
| Investigate a diagnostic report you choose to send | 3.2, 3.6 | Art. 6(1)(f) legitimate interest in resolving reported faults |
| Service announcements | 3.1 | Art. 6(1)(b) contract |
| Launch notification list (website) | 3.7 | Art. 6(1)(a) consent |
| Aggregate, cookieless website analytics | 3.7 | Art. 6(1)(f) legitimate interest (understanding site usage without tracking individuals) |
| Website hosting, security & CDN server logs | 3.7 | Art. 6(1)(f) legitimate interest |
| Marketing communications (if any) | 3.1 | Art. 6(1)(a) consent — opt-in only |
We do not sell personal data or use it for third-party advertising. An operating-system permission controls access to a device feature; it is not blanket consent to every form of processing. Please avoid submitting sensitive personal information that is unnecessary for your request. An allergy or health note can reveal health data. Draft item: the applicable Article 9 condition and any necessary explicit-consent flow for such inputs must be confirmed before final publication.
5. AI processing — what you should know
- Google Gemini and OpenAI: the configured provider processes the text, images and relevant context needed for the AI feature you request. The current setup uses Gemini for general assistance and OpenAI for AI-assisted search interpretation and cloud transcription; OpenAI can also serve assistant features when configured.
- Safety screening: public content and profile information, including display names and avatars, may be screened using OpenAI's moderation API. AI requests are also subject to the AI provider's own safety checks and our assistant safety instructions. Content may be blocked or restricted. Contact support@caminogo.app to contest a decision and request human review.
- Model training: we do not use your submissions to train our own AI models. OpenAI's API does not use API content to train its models by default. Google's paid Gemini API terms do not use prompts or responses to improve its general models. Safety processing is separate: Google may use logged content for models specifically used to enforce its policies. See OpenAI API data controls and Gemini API terms.
- Provider retention: our short-lived server session does not determine how long a provider retains data. OpenAI generally retains abuse-monitoring logs for up to 30 days, subject to applicable exceptions; its published endpoint table lists no abuse-monitoring or application-state retention for the moderation and audio-transcription endpoints. Gemini's published abuse-monitoring policy describes 55-day retention of prompts, context and outputs and possible authorized human review. These are provider policies, not a claim that our account has Zero Data Retention.
- Global processing: the current AI connections use global services. We do not promise that AI input, output or service metadata remains within the EU/EEA. See §6.
- You can use ordinary map browsing and name/category search without submitting an AI question. Microphone permission can be revoked independently. AI output may be inaccurate; see the Terms of Service.
6. Service providers and international transfers
The following providers receive data for the services described. Provider contracts and service configurations determine the precise processing locations; a European application server does not make all downstream processing European.
| Provider | Purpose / data | Processing locations and documentation |
|---|---|---|
| Hetzner Online GmbH | Application hosting and database | EU hosting; the specific production and backup locations remain to be confirmed in this draft. |
| Cloudflare | Images, map delivery, website, launch-list storage and website analytics | Global services. An R2 bucket's EU jurisdiction setting, where enabled, applies to that bucket; it does not make Workers, Pages, KV or analytics EU-only. R2 location documentation. |
| Google — Firebase | Authentication identifiers, account sign-in and push notifications | International processing, including the US, depending on service. Firebase privacy information. |
| Google — Gemini API | AI prompts, photos, responses and relevant context | Global API; no EU-only processing commitment in the current setup. Service and data terms. |
| OpenAI — applicable contracting entity | AI search interpretation, transcription, configured assistant features and moderation | Global API; processing may take place in the US and other countries. Data Processing Addendum and subprocessors. |
| RevenueCat, Inc. | Account identifier, purchase transactions, entitlements and related SDK metadata | US and applicable subprocessors. Data Processing Addendum. |
| WeatherAPI.com | Forecasts for approximate route coordinates; no Camino account identifier is sent | See provider privacy policy; applicable transfer arrangements remain to be verified. |
| Apple / Google | Store payments and system speech services | International processing under the relevant platform terms; they act independently for their own services. |
Data may be processed outside the EEA, including in the United States and by the operator in Taiwan. Where GDPR transfer rules apply, transfers require an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, with any required transfer assessment and supplementary measures. The EU–US Data Privacy Framework applies only where the receiving entity and transfer are actually covered by a valid certification.
Draft item: providers including OpenAI, Google and RevenueCat offer standard data-processing terms. Camino GO's review of which terms apply to its accounts, the relevant recipient entities, processing countries and transfer safeguards remains incomplete. This is a pending verification of the arrangements, not a finding that a separate contract is missing. The applicable terms and transfer records must be confirmed before this becomes a final notice. You can contact support@caminogo.app for information about applicable safeguards and how to obtain a copy, subject to legitimate redactions.
7. Retention
These rules distinguish our application storage from provider processing. We may retain specific records where required by law or necessary for a documented dispute; retention is limited to the relevant purpose.
| Data | Retention / deletion |
|---|---|
| Account, synced walking records, tracks and private diaries | Until you delete the relevant data or your account, subject to the limited exceptions below. |
| AI photos and context in our server session | Default session lifetime of approximately 30 minutes. This does not delete device history or provider-held copies. |
| Cloud audio on our application server | Processed for the transcription request; no permanent recording is kept by the application server. |
| Camino AI history on your device | According to your history setting: the latest 10, 30 or 100 entries, or retained until you clear it. It can include text and compressed photos. Signing out preserves this account-separated history; account deletion or removal of app data clears it. |
| Unsynced walking recovery data on your device | May be retained for up to 30 days after sign-out so the same account can recover it. It is cleared before another account uses it, on account deletion, or when the app next checks expired recovery data. |
| Uploaded diagnostic reports | Eligible for automatic cleanup after 30 days; cleanup runs periodically. Account deletion also removes associated reports. |
| Public content and messages | Until deleted, with the account-deletion treatment described in §8. Moderation and abuse records are separate from public display. |
| Moderation, security logs and backups | Draft item: final retention limits and operational deletion schedules must be verified. The earlier draft's blanket 12-month moderation, 90-day log and 35-day backup limits are not confirmed here as implemented guarantees. |
| Purchase and accounting records | Retained as required for accounting, refunds, fraud prevention and legal obligations; the applicable statutory periods depend on the operator's jurisdiction and remain to be completed. |
| Website launch notification list | Until the launch announcement is sent, then deleted within 90 days, or earlier when you withdraw. This operational deletion schedule must be confirmed before launch. |
| AI provider records | Separate provider retention rules apply; see §5. Clearing Camino history does not itself delete a provider's security records. |
8. Your rights
Under the GDPR (and, where applicable, Taiwan's PDPA and other local laws) you have the right to: access, rectify, erase, port, restrict, and object to processing of your personal data, and to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal. These rights apply subject to their statutory conditions.
- Account deletion is available directly in the App (Settings → Delete account) and by emailing support@caminogo.app. Deletion permanently removes your profile, avatar, diaries, trips, GPS tracks, direct messages, and friendships through the account-deletion process. External authentication and image-storage cleanup may finish asynchronously and is retried if it fails. Limited accounting, security and legal records may remain as described in §7.
- Account deletion removes the content of your forum topics and discussion comments, including topic titles, bodies, attached images, location details, and poll options. Only deleted-content placeholders remain so replies written by other people stay readable. Other public contributions, such as bulletins, currently remain attributed to "Deleted pilgrim"; you can request removal at support@caminogo.app.
- We respond to rights requests within the applicable legal deadlines, normally one month under GDPR; if a permitted extension is necessary, we explain it within that period. You may lodge a complaint with your local supervisory authority. EU representative details will be published in §1 when appointed.
9. Security
Data in transit is encrypted (TLS). Access to production systems is restricted and logged. AI photo sessions are short-lived by design. No system is perfectly secure; we will notify affected users and authorities of personal data breaches as required by Art. 33/34 GDPR.
10. Children
Camino GO is not directed at children. You must be at least 16 years old (or the digital consent age in your country, if higher) to create an account.
11. Offline data
Route data, maps and settings may be cached on your device for offline use. AI history and unsynced walking recovery records follow the distinct rules in §7; signing out does not erase every local record. Local diagnostic and account-specific location caches are cleared on sign-out or account deletion. Device backups and their restore behavior are controlled by your operating system and backup settings.
12. Changes
We will notify you of material changes in-app before they take effect. Where a change requires consent, we will request it separately. Continuing to use the App is not a substitute for any consent required by law.
13. Contact
Privacy requests: support@caminogo.app
General support: support@caminogo.app
EU representative: [TO BE APPOINTED — see §1]