Privacy Policy

Version: 0.21 (draft) · Last updated: 25 September 2026 · Effective date: [DATE]

DRAFT — legal review pending
This is the English draft. Mandatory rights under local law are not limited by this document.

1. Who we are

Camino GO ("the App", "we", "us") is operated by:

EU Representative (Art. 27 GDPR): Data Protection Representative Limited (trading as DataRep), 77 Camden Street Lower, Dublin, D02 XE80, Ireland. You can contact DataRep about our processing of your personal data by email at [email protected] (please quote “CaminoGO” in the subject line), through the form at www.datarep.com/data-request, or by post to the DataRep location most convenient for you. Letters must be addressed to “DataRep”, not to CaminoGO, or they may not reach them.

UK Representative (Art. 27 UK GDPR): Data Protection Representative Limited (trading as DataRep), 107-111 Fleet Street, London, EC4A 2AB, United Kingdom, reachable in the same ways.

DataRep postal addresses in the EU/EEA and the UK

For questions about the App or your account, please contact us directly at [email protected].

We act as the data controller for the personal data described in this policy.

2. Scope

This policy covers the Camino GO mobile application, related backend services, and the caminogo.app website. It does not cover third-party websites or services we link to (e.g., an accommodation's own booking page).

Users in the United Kingdom. The UK GDPR and the Data Protection Act 2018 apply to personal data of users in the UK. For those users, references in this policy to the GDPR, the EU/EEA, supervisory authorities, adequacy decisions and transfer safeguards also mean their UK equivalents, such as UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework and the UK International Data Transfer Addendum to the Standard Contractual Clauses.

3. What data we collect

3.1 Account data

3.2 Location and activity data

3.3 AI questions, photos, search and voice

3.4 User-generated content (UGC)

3.5 Purchases

Purchase entitlements (Trip Pass validity, AI-use balances and cloud speech allowances), platform transaction identifiers and purchase history. We use RevenueCat to validate and restore purchases and manage entitlements; its SDK associates purchase information with your Camino account identifier and receives relevant app/device information. Payment is processed entirely by Apple App Store / Google Play; we never receive your card details.

3.6 Technical data

3.7 Website visitors (caminogo.app)

4. Why we process it (purposes and legal bases)

PurposeDataLegal basis (GDPR)
Provide the App (account, maps, planner, tracking)3.1, 3.2, 3.6Art. 6(1)(b) contract
AI features you invoke (photo questions, translation, speech recognition, read aloud, search interpretation and briefings)3.2, 3.3Art. 6(1)(b) contract
Weather for your routeApproximate locationArt. 6(1)(b) contract
Community and sharing features (chat, forum, community edits, family groups, trip sharing and companions)3.2, 3.4Art. 6(1)(b) contract
Public-content/profile moderation and AI safety screening3.1, 3.3, 3.4Art. 6(1)(f) legitimate interest (keeping the community safe)
Purchases and entitlements3.5Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (accounting)
Security, abuse prevention, rate limiting3.6Art. 6(1)(f) legitimate interest
Detect and fix crashes and errors (automatic error reports)3.6Art. 6(1)(f) legitimate interest in keeping the App stable and secure
Investigate a diagnostic report you choose to send3.2, 3.6Art. 6(1)(f) legitimate interest in resolving reported faults
Service announcements3.1Art. 6(1)(b) contract
Launch notification list (website)3.7Art. 6(1)(a) consent
Aggregate, cookieless website analytics3.7Art. 6(1)(f) legitimate interest (understanding site usage without tracking individuals)
Website hosting, security & CDN server logs3.7Art. 6(1)(f) legitimate interest
Marketing communications (if any)3.1Art. 6(1)(a) consent — opt-in only

We do not sell personal data or use it for third-party advertising. An operating-system permission controls access to a device feature; it is not blanket consent to every form of processing. This release does not offer personalized allergy or intolerance analysis and does not ask you to enter those details in a dedicated field. Menu assistance uses general food preferences and cannot assess whether food is safe for a medical condition. Please do not submit unnecessary health or other sensitive information in free-text questions, photos or voice recordings. If you include such information yourself, it may be present in the content sent to AI providers and in their responses, subject to the AI history, temporary-context and provider rules below. You can disable AI in Settings and clear local AI history. Contact [email protected] for data-rights requests.

5. AI processing — what you should know

6. Service providers and international transfers

The following providers receive data for the services described. Provider contracts and service configurations determine the precise processing locations; a European application server does not make all downstream processing European.

ProviderPurpose / dataProcessing locations and documentation
Hetzner Online GmbHApplication hosting and databaseNuremberg, Germany (application, database and routing servers). Database backups are stored in Cloudflare R2 buckets set to EU jurisdiction. Hetzner acts under a GDPR Article 28 data processing agreement that limits processing to the EU/EEA.
CloudflareSecure connection routing for all App and website traffic to our servers (IP addresses and request contents pass through Cloudflare's network), protection against attacks, sign-in for our remote administration, images, map delivery, encrypted database backups, website, launch-list storage and website analyticsGlobal network; requests are usually handled at a Cloudflare data centre near the user. R2 buckets holding database backups are set to EU jurisdiction; this applies to those buckets only and does not make the network, Workers, Pages, KV or analytics EU-only. Cloudflare acts under its Data Processing Addendum, which includes the Standard Contractual Clauses, and is certified under the EU–US Data Privacy Framework. Cloudflare DPA · R2 location documentation.
Google — FirebaseAuthentication identifiers, account sign-in and push notificationsInternational processing, including the US, depending on service. The Firebase Data Processing and Security Terms apply; Google relies on the EU–US Data Privacy Framework and Standard Contractual Clauses. Firebase privacy information.
Google — Gemini APIAI prompts, photos, responses and relevant contextGlobal API; no EU-only processing commitment in the current setup. As a paid-tier customer, prompts and responses are processed under Google's Data Processing Addendum for Products Where Google is a Data Processor. Service and data terms.
Google — Cloud Text-to-SpeechText of answers or translations you ask to hear read aloud, and its languageGoogle Cloud global service, covered by the Cloud Data Processing Addendum, which we have accepted with the Standard Contractual Clauses that apply to customers subject to the GDPR.
OpenAI OpCo, LLCAI search interpretation, transcription, configured assistant features and moderationGlobal API; processing may take place in the US and other countries. OpenAI's Data Processing Addendum applies; under it, data subject to EU/EEA or Swiss law is processed by OpenAI Ireland Ltd., with Standard Contractual Clauses for onward transfers. Our organisation settings do not share API inputs or outputs with OpenAI for model training. Subprocessors.
RevenueCat, Inc.Account identifier, purchase transactions, entitlements and related SDK metadataUS (Amazon Web Services, Snowflake) and applicable subprocessors. RevenueCat's Data Processing Addendum applies, with EU Standard Contractual Clauses.
WeatherAPI.comForecasts for the centre of an approximately 5 km grid cell around the map centre or your location. The request is sent from our server without any account or device identifier.We do not consider these requests to contain personal data. See the provider privacy policy.
Infomaniak Network SAEmail hosting for [email protected] and our team's mailboxes: messages you send us, their attachments and our repliesSwitzerland (Infomaniak's own data centres). The European Commission recognises Switzerland as providing adequate protection. Infomaniak acts under a data processing agreement based on Article 28 GDPR and the Swiss Federal Act on Data Protection. Infomaniak GDPR information.
Functional Software, Inc. (Sentry)Automatic crash and error reports (see §3.6)EU data storage region selected for our organisation; storage of IP addresses is disabled. Sentry is certified under the EU–US Data Privacy Framework. Sentry's Data Processing Addendum and subprocessors.
Apple / GoogleStore payments and system speech servicesInternational processing under the relevant platform terms; they act independently for their own services.

Data may be processed outside the EEA, including in the United States and by the operator in Taiwan. Where GDPR transfer rules apply, transfers require an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, with any required transfer assessment and supplementary measures. The EU–US Data Privacy Framework applies only where the receiving entity and transfer are actually covered by a valid certification.

We have reviewed or concluded the data-processing terms of the providers listed above, including Hetzner, Firebase, the Gemini API, Google Cloud, OpenAI, RevenueCat, Sentry and Infomaniak.

Access from Taiwan. Our application servers and database are hosted in Germany. Our team in Taiwan administers the service remotely, for example for maintenance, support and troubleshooting, and may view personal data where a task requires it. Taiwan is not covered by an EU adequacy decision. We are directly subject to the GDPR for this processing (Article 3(2)) and apply its obligations to this access. Our safeguards include:

You can contact [email protected] for more information about these safeguards and how to obtain a copy of the relevant terms, subject to legitimate redactions.

7. Retention

These rules distinguish our application storage from provider processing. We may retain specific records where required by law or necessary for a documented dispute; retention is limited to the relevant purpose.

DataRetention / deletion
Account, synced walking records, tracks and private diariesUntil you delete the relevant data or your account, subject to the limited exceptions below.
AI photos and context in our server sessionDefault session lifetime of approximately 30 minutes. This does not delete device history or provider-held copies.
Cloud audio on our application serverProcessed for the transcription request; no permanent recording is kept by the application server.
Read-aloud audioKept in our server's memory for up to about 30 minutes to avoid repeat synthesis. Your device keeps a limited cache of recent audio (up to 200 items), which is replaced as new audio is added or cleared when app data is removed.
Camino AI history on your deviceAccording to your history setting: the latest 10, 30 or 100 entries, or retained until you clear it. It can include text and compressed photos. Signing out preserves this account-separated history; account deletion or removal of app data clears it.
Unsynced walking recovery data on your deviceMay be retained for up to 30 days after sign-out so the same account can recover it. It is cleared before another account uses it, on account deletion, or when the app next checks expired recovery data.
Uploaded diagnostic reportsEligible for automatic cleanup after 30 days; cleanup runs periodically. Account deletion also removes associated reports.
Automatic crash and error reports (Sentry)Retained by Sentry for 30 days under our current plan (never more than 90 days), then deleted.
Public content and messagesUntil deleted, with the account-deletion treatment described in §8. Moderation and abuse records are separate from public display.
Reports about content or usersKept while the accounts involved exist, so we can handle appeals and repeated abuse. Deleted automatically 90 days after the reporting or reported account is deleted.
Server logsOur servers record technical details of each request, such as IP address, time, requested address and result, for security, abuse prevention and troubleshooting. These logs are deleted automatically within 35 days.
Records of administrative actionsKept so moderation and administrative decisions can be accounted for. The IP address and browser details recorded with our staff's sign-ins and actions are removed after 90 days.
Database backupsEncrypted daily backups are stored in the EU (Cloudflare R2, EU jurisdiction). Each backup is locked against deletion for 30 days and deleted automatically after 45 days, so data you delete, including a deleted account, can remain in backups for up to 45 days. Backups are used only to restore the service after a failure.
Purchase and point-transaction recordsKept while your account exists. After account deletion they are linked only to an internal ID and kept for accounting, tax, refunds and fraud prevention for the periods required by Taiwan's Business Entity Accounting Act: supporting records at least 5 years and accounting books at least 10 years after the annual accounts are closed. Apple, Google and RevenueCat keep their own purchase records under their own terms.
Website launch notification listKept until we send the launch announcement, then deleted within 90 days. You can ask us to remove your address earlier at any time.
Support and privacy-request emailsKept for up to 2 years after the matter is closed, so we can handle follow-up questions and show how a request was handled, then deleted.
Previously recorded allergy-analysis consent receipts, if anyThis release does not create new receipts for the retired feature. Existing receipts contain only account ID, disclosure version, language and server timestamp, not allergy text. They remain subject to daily cleanup after 365 days, or immediate removal as part of account deletion.
Moderation notification queueDrafts, the final delivered text and delivery references support manual notification. Completed or unreachable notices are removed by the daily cleanup after 180 days; pending notices remain until handled. Queue entries for a deleted account are erased during account deletion. Separate underlying report or email records follow their applicable retention rules.
AI provider recordsSeparate provider retention rules apply; see §5. Clearing Camino history does not itself delete a provider's security records.

8. Your rights

Under the GDPR and the UK GDPR (and, where applicable, Taiwan's PDPA and other local laws) you have the right to: access, rectify, erase, port, restrict, and object to processing of your personal data, and to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal. These rights apply subject to their statutory conditions.

9. Security

Data in transit is encrypted (TLS). Access to production systems is restricted and logged. AI photo sessions are short-lived by design. No system is perfectly secure; we will notify affected users and authorities of personal data breaches as required by Art. 33/34 GDPR.

10. Children

Camino GO is not directed at children. You must be at least 16 years old (or the digital consent age in your country, if higher) to create an account.

11. Offline data

Route data, maps and settings may be cached on your device for offline use. AI history and unsynced walking recovery records follow the distinct rules in §7; signing out does not erase every local record. Local diagnostic and account-specific location caches are cleared on sign-out or account deletion. Device backups and their restore behavior are controlled by your operating system and backup settings.

12. Changes

We will notify you of material changes in-app before they take effect. Where a change requires consent, we will request it separately. Continuing to use the App is not a substitute for any consent required by law.

13. Contact

Privacy requests: [email protected]
General support: [email protected]
EU and UK representative: DataRep, [email protected] — see §1

Report content & appeal / 內容通報與申訴