Privacy Policy

Version: 0.10 (draft) · Last updated: 11 September 2026 · Effective date: [DATE]

DRAFT — operator details and legal review pending
This is the English draft. Operator details, transfer arrangements and the retention items marked below must be completed before final publication. Mandatory rights under local law are not limited by this document.

1. Who we are

Camino GO ("the App", "we", "us") is operated by:

EU Representative (Art. 27 GDPR): [TO BE APPOINTED BEFORE LAUNCH]

We act as the data controller for the personal data described in this policy.

2. Scope

This policy covers the Camino GO mobile application, related backend services, and the caminogo.app website. It does not cover third-party websites or services we link to (e.g., an accommodation's own booking page).

3. What data we collect

3.1 Account data

3.2 Location and activity data

3.3 AI questions, photos, search and voice

3.4 User-generated content (UGC)

3.5 Purchases

Purchase entitlements (Trip Pass validity, AI-use balances and cloud speech allowances), platform transaction identifiers and purchase history. We use RevenueCat to validate and restore purchases and manage entitlements; its SDK associates purchase information with your Camino account identifier and receives relevant app/device information. Payment is processed entirely by Apple App Store / Google Play; we never receive your card details.

3.6 Technical data

3.7 Website visitors (caminogo.app)

4. Why we process it (purposes and legal bases)

PurposeDataLegal basis (GDPR)
Provide the App (account, maps, planner, tracking)3.1, 3.2, 3.6Art. 6(1)(b) contract
AI features you invoke (photo questions, translation, speech recognition, search interpretation and briefings)3.2, 3.3Art. 6(1)(b) contract
Weather for your routeApproximate locationArt. 6(1)(b) contract
Community features (chat, forum, community edits)3.4Art. 6(1)(b) contract
Public-content/profile moderation and AI safety screening3.1, 3.3, 3.4Art. 6(1)(f) legitimate interest (keeping the community safe)
Purchases and entitlements3.5Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (accounting)
Security, abuse prevention, rate limiting3.6Art. 6(1)(f) legitimate interest
Investigate a diagnostic report you choose to send3.2, 3.6Art. 6(1)(f) legitimate interest in resolving reported faults
Service announcements3.1Art. 6(1)(b) contract
Launch notification list (website)3.7Art. 6(1)(a) consent
Aggregate, cookieless website analytics3.7Art. 6(1)(f) legitimate interest (understanding site usage without tracking individuals)
Website hosting, security & CDN server logs3.7Art. 6(1)(f) legitimate interest
Marketing communications (if any)3.1Art. 6(1)(a) consent — opt-in only

We do not sell personal data or use it for third-party advertising. An operating-system permission controls access to a device feature; it is not blanket consent to every form of processing. Please avoid submitting sensitive personal information that is unnecessary for your request. An allergy or health note can reveal health data. Draft item: the applicable Article 9 condition and any necessary explicit-consent flow for such inputs must be confirmed before final publication.

5. AI processing — what you should know

6. Service providers and international transfers

The following providers receive data for the services described. Provider contracts and service configurations determine the precise processing locations; a European application server does not make all downstream processing European.

ProviderPurpose / dataProcessing locations and documentation
Hetzner Online GmbHApplication hosting and databaseEU hosting; the specific production and backup locations remain to be confirmed in this draft.
CloudflareImages, map delivery, website, launch-list storage and website analyticsGlobal services. An R2 bucket's EU jurisdiction setting, where enabled, applies to that bucket; it does not make Workers, Pages, KV or analytics EU-only. R2 location documentation.
Google — FirebaseAuthentication identifiers, account sign-in and push notificationsInternational processing, including the US, depending on service. Firebase privacy information.
Google — Gemini APIAI prompts, photos, responses and relevant contextGlobal API; no EU-only processing commitment in the current setup. Service and data terms.
OpenAI — applicable contracting entityAI search interpretation, transcription, configured assistant features and moderationGlobal API; processing may take place in the US and other countries. Data Processing Addendum and subprocessors.
RevenueCat, Inc.Account identifier, purchase transactions, entitlements and related SDK metadataUS and applicable subprocessors. Data Processing Addendum.
WeatherAPI.comForecasts for approximate route coordinates; no Camino account identifier is sentSee provider privacy policy; applicable transfer arrangements remain to be verified.
Apple / GoogleStore payments and system speech servicesInternational processing under the relevant platform terms; they act independently for their own services.

Data may be processed outside the EEA, including in the United States and by the operator in Taiwan. Where GDPR transfer rules apply, transfers require an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, with any required transfer assessment and supplementary measures. The EU–US Data Privacy Framework applies only where the receiving entity and transfer are actually covered by a valid certification.

Draft item: providers including OpenAI, Google and RevenueCat offer standard data-processing terms. Camino GO's review of which terms apply to its accounts, the relevant recipient entities, processing countries and transfer safeguards remains incomplete. This is a pending verification of the arrangements, not a finding that a separate contract is missing. The applicable terms and transfer records must be confirmed before this becomes a final notice. You can contact support@caminogo.app for information about applicable safeguards and how to obtain a copy, subject to legitimate redactions.

7. Retention

These rules distinguish our application storage from provider processing. We may retain specific records where required by law or necessary for a documented dispute; retention is limited to the relevant purpose.

DataRetention / deletion
Account, synced walking records, tracks and private diariesUntil you delete the relevant data or your account, subject to the limited exceptions below.
AI photos and context in our server sessionDefault session lifetime of approximately 30 minutes. This does not delete device history or provider-held copies.
Cloud audio on our application serverProcessed for the transcription request; no permanent recording is kept by the application server.
Camino AI history on your deviceAccording to your history setting: the latest 10, 30 or 100 entries, or retained until you clear it. It can include text and compressed photos. Signing out preserves this account-separated history; account deletion or removal of app data clears it.
Unsynced walking recovery data on your deviceMay be retained for up to 30 days after sign-out so the same account can recover it. It is cleared before another account uses it, on account deletion, or when the app next checks expired recovery data.
Uploaded diagnostic reportsEligible for automatic cleanup after 30 days; cleanup runs periodically. Account deletion also removes associated reports.
Public content and messagesUntil deleted, with the account-deletion treatment described in §8. Moderation and abuse records are separate from public display.
Moderation, security logs and backupsDraft item: final retention limits and operational deletion schedules must be verified. The earlier draft's blanket 12-month moderation, 90-day log and 35-day backup limits are not confirmed here as implemented guarantees.
Purchase and accounting recordsRetained as required for accounting, refunds, fraud prevention and legal obligations; the applicable statutory periods depend on the operator's jurisdiction and remain to be completed.
Website launch notification listUntil the launch announcement is sent, then deleted within 90 days, or earlier when you withdraw. This operational deletion schedule must be confirmed before launch.
AI provider recordsSeparate provider retention rules apply; see §5. Clearing Camino history does not itself delete a provider's security records.

8. Your rights

Under the GDPR (and, where applicable, Taiwan's PDPA and other local laws) you have the right to: access, rectify, erase, port, restrict, and object to processing of your personal data, and to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal. These rights apply subject to their statutory conditions.

9. Security

Data in transit is encrypted (TLS). Access to production systems is restricted and logged. AI photo sessions are short-lived by design. No system is perfectly secure; we will notify affected users and authorities of personal data breaches as required by Art. 33/34 GDPR.

10. Children

Camino GO is not directed at children. You must be at least 16 years old (or the digital consent age in your country, if higher) to create an account.

11. Offline data

Route data, maps and settings may be cached on your device for offline use. AI history and unsynced walking recovery records follow the distinct rules in §7; signing out does not erase every local record. Local diagnostic and account-specific location caches are cleared on sign-out or account deletion. Device backups and their restore behavior are controlled by your operating system and backup settings.

12. Changes

We will notify you of material changes in-app before they take effect. Where a change requires consent, we will request it separately. Continuing to use the App is not a substitute for any consent required by law.

13. Contact

Privacy requests: support@caminogo.app
General support: support@caminogo.app
EU representative: [TO BE APPOINTED — see §1]