AppyPilgrim Privacy Policy
This policy explains what data the AppyPilgrim mobile application (“AppyPilgrim”, “the app”, “we”), operated by AppyPilgrim S.r.l. (Via Marino Ghetaldi 84, 00143 Roma, Italy — VAT 17660741004), collects, why we collect it, who we share it with, and the rights you have over it. We wrote it in plain English because we want you to actually read it. If anything is unclear, write to support@appypilgrim.com.
1. Who is the data controller
The data controller is:
AppyPilgrim S.r.l.
Via Marino Ghetaldi 84
00143 Roma · Italy
VAT / P.IVA: 17660741004
Email: support@appypilgrim.com
For all privacy matters — including questions, complaints, and data-subject rights requests — write to support@appypilgrim.com.
2. Data we collect
The table below maps to the declarations in our App Store Connect privacy nutrition label and the PrivacyInfo.xcprivacy manifest bundled with the app.
| Category | What it is | Why we collect it | Legal basis (GDPR) |
|---|---|---|---|
| Account identifiers | Email address, anonymous user ID issued by our authentication provider, and your display name if you set one. | To sign you in, sync your saved routes across devices, and contact you if you write to support. | Contract performance (Art. 6(1)(b)). |
| Sign in with Apple | The opaque user identifier returned by Apple. If you choose to share your name, we receive that too. | To authenticate you without storing a password. We never receive your real Apple ID. | Contract performance (Art. 6(1)(b)). |
| Precise location | GPS coordinates while the app is open or while a walking stage is active. | To show your position on the route, detect which stage you are on, surface nearby trail highlights, and power the in-app SOS feature. | Consent (Art. 6(1)(a)) — granted via the iOS location permission prompt. |
| Photos | A single image you choose, only if you set a profile picture. | To display your avatar in the app. | Consent (Art. 6(1)(a)). |
| Chat messages with Appy AI (cloud tier only) | The text you send to Appy in cloud mode (the default 5-messages-per-day tier). | To generate the assistant’s reply. The on-device tier (“Appy AI Local”) processes everything on your phone — those messages never leave your device. | Contract performance (Art. 6(1)(b)). |
| Product interaction | Anonymous, aggregated counts of which routes are opened, which stages are completed, and which features are used. | To understand which content is useful and to fix bugs. We do not link these events to your identity for advertising. | Legitimate interest (Art. 6(1)(f)) — operational analytics. |
What we do not collect
- We do not run advertising or tracking SDKs.
NSPrivacyTrackingis set tofalsein the app manifest. - We do not collect contacts, calendars, browsing history, SMS, or call logs.
- The on-device AI tier does not transmit conversation content to any server.
- We do not currently process biometric or health data. The app declares HealthKit and Camera/NFC permission strings for forward compatibility with future opt-in features that are disabled in this version. If we activate them, we will update this policy and request your consent first.
3. Required Reason API declarations
Apple requires apps to declare specific common APIs and the reason they are used. AppyPilgrim accesses the following, and only for these purposes:
- UserDefaults (CA92.1) — saving your app preferences, onboarding progress, and saved routes locally on your device.
- File timestamp APIs (3B52.1) — used by the bundled inference engine (llama.cpp) to validate the on-device AI model file.
- Disk space APIs (7D9E.1) — checking that you have room before downloading the optional 2.7 GB AI model.
- System boot time APIs (35F9.1) — used by the inference engine for performance timing.
4. How we use your data
- To run the app — sign-in, route storage, search, navigation, chat replies.
- To improve the app — anonymous usage counts and crash diagnostics.
- To support you — answering email you send to
support@or bug reports filed via the in-app “Report this response” action. - To meet legal obligations — responding to lawful requests from authorities or to defend our rights.
We do not use your data for targeted advertising, profiling for advertising, or training machine-learning models for third parties.
5. Where your data is processed
AppyPilgrim is operated from the European Union and uses the following data processors:
- Supabase — backend database and authentication. EU region. Stores your account, preferences, and saved routes.
- Resend — sending the magic-link sign-in email. Stores only the email address and the link metadata for delivery.
- Apple — Sign in with Apple, App Store, push notifications, and HealthKit (when enabled in a future version).
- Google Cloud Vertex AI — only when you use the cloud AI tier; receives the message text to generate a reply, and is contractually prohibited from using it to train models.
Where data leaves the EU/EEA, we rely on Standard Contractual Clauses or equivalent transfer mechanisms approved by the European Commission.
6. How long we keep it
| Data | Retention |
|---|---|
| Account record (email, user ID, display name) | Until you delete your account, then erased within 30 days. |
| Saved routes and preferences | Same as above. |
| Cloud-tier chat messages | Up to 30 days, for abuse prevention and quality monitoring; then deleted. |
| Anonymous product analytics | Up to 24 months in aggregated form. |
| Support email | Up to 24 months. |
7. Your rights
If you are in the EU/EEA, the UK, Switzerland, or California, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data (“right to be forgotten”).
- Restrict or object to processing based on legitimate interest.
- Receive your data in a portable format.
- Withdraw consent at any time, where we relied on it.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@appypilgrim.com from the address linked to your account, or use the in-app deletion flow described below.
8. Account deletion
You can delete your account directly from the app:
- Open the Profile tab.
- Tap Preferences.
- Scroll to the bottom and tap Delete Everything.
- Confirm.
Deletion is processed immediately. If you signed in with Apple, the app revokes the Apple authorization token on your behalf (per Apple Technote TN3194) so the connection between your Apple ID and AppyPilgrim is severed. All personal data tied to your account is erased from our active systems within 30 days. Backups are rotated out within 90 days. Anonymous, aggregated analytics that cannot be re-associated with you may persist.
9. Children
AppyPilgrim is rated 4+ but is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us and we will delete it.
10. Security
Data is encrypted in transit (TLS 1.2 or higher) and at rest. Access to production systems is restricted to authorized personnel using two-factor authentication. We follow the principle of least privilege and review access quarterly. No system is perfectly secure; if we discover a breach affecting your data we will notify you and the relevant authority within 72 hours, as required by law.
11. Changes to this policy
We may update this policy as the app evolves. The “Last updated” date at the top will change. Material changes will also be communicated through an in-app notice or email before they take effect.
12. Contact
Questions, complaints, or rights requests: support@appypilgrim.com.