AppyPilgrim Privacy Policy

Effective: 27 April 2026 · Last updated: 27 April 2026

This policy explains what data the AppyPilgrim mobile application (“AppyPilgrim”, “the app”, “we”), operated by AppyPilgrim S.r.l. (Via Marino Ghetaldi 84, 00143 Roma, Italy — VAT 17660741004), collects, why we collect it, who we share it with, and the rights you have over it. We wrote it in plain English because we want you to actually read it. If anything is unclear, write to support@appypilgrim.com.

The short version. AppyPilgrim is a free walking-route companion. We collect the minimum data needed to keep you signed in, save your routes, show you walks near you, and let you talk to our on-device assistant. We do not sell your data. We do not run advertising trackers. You can delete your account from inside the app at any time and we will erase your data within 30 days.

1. Who is the data controller

The data controller is:

AppyPilgrim S.r.l.
Via Marino Ghetaldi 84
00143 Roma · Italy
VAT / P.IVA: 17660741004
Email: support@appypilgrim.com

For all privacy matters — including questions, complaints, and data-subject rights requests — write to support@appypilgrim.com.

2. Data we collect

The table below maps to the declarations in our App Store Connect privacy nutrition label and the PrivacyInfo.xcprivacy manifest bundled with the app.

CategoryWhat it isWhy we collect itLegal basis (GDPR)
Account identifiers Email address, anonymous user ID issued by our authentication provider, and your display name if you set one. To sign you in, sync your saved routes across devices, and contact you if you write to support. Contract performance (Art. 6(1)(b)).
Sign in with Apple The opaque user identifier returned by Apple. If you choose to share your name, we receive that too. To authenticate you without storing a password. We never receive your real Apple ID. Contract performance (Art. 6(1)(b)).
Precise location GPS coordinates while the app is open or while a walking stage is active. To show your position on the route, detect which stage you are on, surface nearby trail highlights, and power the in-app SOS feature. Consent (Art. 6(1)(a)) — granted via the iOS location permission prompt.
Photos A single image you choose, only if you set a profile picture. To display your avatar in the app. Consent (Art. 6(1)(a)).
Chat messages with Appy AI (cloud tier only) The text you send to Appy in cloud mode (the default 5-messages-per-day tier). To generate the assistant’s reply. The on-device tier (“Appy AI Local”) processes everything on your phone — those messages never leave your device. Contract performance (Art. 6(1)(b)).
Product interaction Anonymous, aggregated counts of which routes are opened, which stages are completed, and which features are used. To understand which content is useful and to fix bugs. We do not link these events to your identity for advertising. Legitimate interest (Art. 6(1)(f)) — operational analytics.

What we do not collect

3. Required Reason API declarations

Apple requires apps to declare specific common APIs and the reason they are used. AppyPilgrim accesses the following, and only for these purposes:

4. How we use your data

We do not use your data for targeted advertising, profiling for advertising, or training machine-learning models for third parties.

5. Where your data is processed

AppyPilgrim is operated from the European Union and uses the following data processors:

Where data leaves the EU/EEA, we rely on Standard Contractual Clauses or equivalent transfer mechanisms approved by the European Commission.

6. How long we keep it

DataRetention
Account record (email, user ID, display name)Until you delete your account, then erased within 30 days.
Saved routes and preferencesSame as above.
Cloud-tier chat messagesUp to 30 days, for abuse prevention and quality monitoring; then deleted.
Anonymous product analyticsUp to 24 months in aggregated form.
Support emailUp to 24 months.

7. Your rights

If you are in the EU/EEA, the UK, Switzerland, or California, you have the right to:

To exercise any of these rights, email support@appypilgrim.com from the address linked to your account, or use the in-app deletion flow described below.

8. Account deletion

You can delete your account directly from the app:

  1. Open the Profile tab.
  2. Tap Preferences.
  3. Scroll to the bottom and tap Delete Everything.
  4. Confirm.

Deletion is processed immediately. If you signed in with Apple, the app revokes the Apple authorization token on your behalf (per Apple Technote TN3194) so the connection between your Apple ID and AppyPilgrim is severed. All personal data tied to your account is erased from our active systems within 30 days. Backups are rotated out within 90 days. Anonymous, aggregated analytics that cannot be re-associated with you may persist.

9. Children

AppyPilgrim is rated 4+ but is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us and we will delete it.

10. Security

Data is encrypted in transit (TLS 1.2 or higher) and at rest. Access to production systems is restricted to authorized personnel using two-factor authentication. We follow the principle of least privilege and review access quarterly. No system is perfectly secure; if we discover a breach affecting your data we will notify you and the relevant authority within 72 hours, as required by law.

11. Changes to this policy

We may update this policy as the app evolves. The “Last updated” date at the top will change. Material changes will also be communicated through an in-app notice or email before they take effect.

12. Contact

Questions, complaints, or rights requests: support@appypilgrim.com.