Privacy Policy
Effective 10 July 2026
This Privacy Policy explains what personal data we collect when you use the GuideMe mobile app and website (the “Service”), why we collect it, and the rights you have over it. We designed the Service to collect as little data as possible — this policy reflects that.
1. Data Controller
The data controller responsible for your personal data is:
- Ivan Bošnjaković, operating under the trade name “GuideMe”
- Kalnička 15, 10000 Zagreb, Croatia
- Email: hello@guidemeapp.xyz
2. What We Collect
We collect the following categories of personal data:
- Account data (from Clerk): when you sign in with Google or Apple, we receive your name, email address, profile picture, and a unique identifier from that provider. We store only the unique identifier (“Clerk user ID”) and a record that a user exists; everything else remains with our authentication provider, Clerk.
- Favorites: the cities, tours, places, and sub-stops you save in the app. We store these as references (type + slug), linked to your Clerk user ID.
- Location data: with your permission, the app uses your device location for map centring and walking directions. Location is processed on your device. Walking-direction requests may be sent to Google Maps (see “Third-Party Services” below) but are not stored by us.
- Technical data: IP address and standard request metadata received by our servers when your app or browser makes a request. We use this for security, rate-limiting, and error diagnostics; we do not link it to your account for profiling.
- Product analytics: the mobile app sends usage events to our analytics processor, PostHog. These events record actions like sign-in, starting or completing a walking tour, tapping a favorite, playing audio (duration in milliseconds), and switching language. Each event carries a pseudonymous device identifier and, once you sign in, your Clerk user ID so we can count unique users. The events also include coarse device and app metadata attached automatically by the analytics library — operating system name and version, app version, device type, locale, and timezone. We use this data only in aggregate to understand how the app is used and to publish community numbers on our marketing site. We do not sell it, share it with advertisers, or use it for profiling.
We do not collect: advertising identifiers, contact lists, photos, microphone data, health data, financial data, or any special-category data (as defined by Article 9 GDPR).
3. Why We Use Your Data
- To provide the Service — authenticate you, sync favorites across devices, show walking directions. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To keep the Service secure and working — detect abuse, prevent fraud, diagnose errors. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
- To understand how the app is used in aggregate — measure feature adoption, spot broken flows, and publish community-level statistics on our marketing site. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR). You can object at any time by deleting your account, which stops future analytics events tied to your identifier.
- To comply with legal obligations where they apply. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
4. Third-Party Services
We rely on a small number of processors to run the Service. Each is bound by a data-processing agreement:
- Clerk — authentication provider. Handles sign-in with Google/Apple and stores your profile attributes. Clerk Privacy Policy.
- Google Maps Platform — provides map tiles and walking-direction routing. Location coordinates for directions are sent to Google. Google Privacy Policy.
- MongoDB Atlas — hosts our application database (your Clerk user ID and favorites). Data is stored on AWS in Frankfurt, Germany (
eu-central-1). - Render — hosts our API servers, deployed in the Frankfurt region.
- Vercel — hosts our website and admin dashboard.
- Google Cloud Storage — stores audio and image content that we publish (not user-generated content); bucket is located in
europe-west8(Milan, Italy). - PostHog — receives the product-analytics events described in section 2 and stores them for aggregation. We use the EU cloud instance (
eu.i.posthog.com), which hosts data on infrastructure inside the European Union. PostHog Privacy Policy.
5. International Transfers
Your personal data (account record, favorites, and product- analytics events) is stored on infrastructure located within the European Union — MongoDB Atlas in Frankfurt, Render in Frankfurt, and PostHog EU. Published media content is stored on Google Cloud in Milan.
Some of the processors we rely on are headquartered outside the European Economic Area (EEA) — in particular Clerk and Google. Where personal data is transferred outside the EEA in connection with those services, we rely on the safeguards provided by those processors, including Standard Contractual Clauses approved by the European Commission and, where applicable, EU-U.S. Data Privacy Framework certifications.
6. How Long We Keep Your Data
- Account and favorites: kept for as long as your account exists. Delete your account and both are erased immediately.
- Technical/server logs: retained for up to 30 days, then discarded, except where a longer period is required to investigate a security incident.
- Product-analytics events: retained by PostHog for aggregation according to PostHog's default retention (12 months for events at time of writing). Events are never re- identified back to your account by us after collection; they are only used in aggregate.
7. Your Rights
Under GDPR and Croatian law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure of your data — you can delete your account and associated data yourself from within the app (Profile → Delete account);
- restrict or object to certain processing;
- data portability — request a copy of the data you provided in a structured, machine-readable format;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a supervisory authority, in Croatia the Agencija za zaštitu osobnih podataka (AZOP, azop.hr), or your local authority in another EU member state.
To exercise any right, email us at hello@guidemeapp.xyz. We respond within one month.
8. Deleting Your Account
You can delete your account directly from the mobile app: open Profile, scroll to “Account”, and choose “Delete account”. This permanently deletes your profile record, favorites, and sign-in identity. This action cannot be undone.
9. Children
The Service is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Cookies and Similar Technologies
The GuideMe website (this site) does not set analytics or advertising cookies. The mobile app does not use browser cookies. Our authentication provider, Clerk, may set cookies necessary for sign-in if you sign in via the web. The mobile analytics library (PostHog) stores its pseudonymous device identifier in on-device storage (not a browser cookie); this identifier is cleared when you sign out or reinstall the app.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by updating the effective date above. Continued use of the Service after changes take effect constitutes acceptance.
12. Contact
For any privacy question or to exercise your rights, email us at hello@guidemeapp.xyz.