Privacy Policy
Quick Navigation
1. Overview
Discoveroo is a Venice audio tour guide mobile application available on iOS and Android. This privacy policy explains how we collect, use, process, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
We are committed to privacy by design. Discoveroo is anonymous and local-first: there are no user accounts, no sign-up and no email address required to use the app. We do not display advertisements. We do not sell your personal data, and we do not share it for third-party or cross-app advertising or with data brokers. Your location and voice are used only to deliver the tour experience and are never permanently stored on our servers. Apart from a pseudonymised per-device identifier used solely to prevent free-trial abuse (a one-way hash, see section 3.10), the personal data we store is kept locally on your device.
We use two optional services, both off by default and running only if you explicitly opt in: PostHog for anonymous usage statistics (see section 3.7) and AppsFlyer for measuring the effectiveness of our own advertising campaigns (see section 3.11). You can turn either of them off again at any time from the Profile settings.
Key Principle: The app’s core features (finding nearby landmarks, voice questions, AI narration) require your location and voice to function, so these are processed as a necessary part of providing the service. Anything that is not strictly necessary — analytics and ad measurement — is opt-in and can be disabled at any time in the app settings.
2. Data Controller & Operator Information
The data controller responsible for your personal data is:
Discoveroo
Data Controller: Simone Biasotto (individual)
Contact Email: simone@solarrise.it
Purpose: Operation and maintenance of the Discoveroo mobile application
Simone Biasotto is the sole data controller responsible for all data processing activities described in this policy. All decisions regarding data collection, usage, and retention are made by the data controller. For any privacy request, please write to simone@solarrise.it.
3. Data Collection & Processing Activities
3.1 GPS Location Data
What We Collect
When you grant the location permission, we read your precise GPS coordinates from the device. Location is accessed only in the foreground while you are actively using the app, and is used to find the landmarks near you.
How We Process It
- Continuous Foreground Read: While the app is open and in the foreground, your precise location is read continuously (a live position watch) so the nearby landmarks stay up to date as you move. This stream stays in the device’s memory, is never saved, and is never read while the app is in the background
- Local Processing: Your coordinates are held only in the device’s memory (our Zustand state) while the app is open
- POI Discovery: Coordinates are used on-device to compute which landmarks from our curated catalogue are nearby. Your coordinates are sent off-device only to Google Maps to render the map view. Nearby-landmark matching happens locally and is not sent to a discovery server.
- No Server Storage: Location is never stored on Discoveroo servers — we do not operate a backend that keeps your data
- Foreground Only: We do not track your location in the background; access stops when the app is closed or moved to the background
Technical Implementation
We use the expo-location library configured for foreground-only access. This prevents background tracking and ensures the location is read only while you are using the map and discovery features.
3.2 Voice Recordings & Transcription
What We Collect
A voice recording is created only when you start it yourself by tapping the microphone button to ask a question. It captures a short audio clip of your spoken question.
How We Process It
- Device Recording: Audio is captured on your device using Expo’s audio library
- Transcription: The audio clip is sent to OpenAI (speech-to-text) via our Vercel proxy, so it can be turned into text and answered
- Device Deletion: The local audio clip is removed from your device after it has been processed
- Proxy in Front: Audio goes through our proxy, not directly from your device to OpenAI; the OpenAI API key lives only on the proxy and is never shipped in the app
What Happens at OpenAI
Once your audio reaches OpenAI it is handled under OpenAI’s API terms and data usage policy. API inputs are not used to train OpenAI’s models by default. Retention of API data follows OpenAI’s own policy [exact retention to be confirmed]. We do not retain audio samples for analytics or training.
3.3 Text Queries & Search
What We Collect
When you enter search queries or ask questions about locations within Discoveroo, the text is sent to our AI processing system.
How We Process It
- Query Processing: Text questions are sent via our Vercel proxy to OpenAI for analysis and response generation
- No Account, No PII: Queries are sent without any account, name, email or user identifier — the app has no accounts
- Stateless Processing: Each query is handled on its own; we do not keep a conversation history on a server (chat history, if any, stays on your device)
- Analytics (only if you opted in): if you have enabled analytics, the question text (truncated to 200 characters) may also be recorded in PostHog to help us prioritise features — see section 3.7
3.4 Text-to-Speech Audio Generation
What We Collect
Text content from tour descriptions and AI responses is converted to audio for narration purposes.
How We Process It
- TTS Processing: Text is sent to OpenAI Text-to-Speech API via our proxy service for audio generation
- Audio Caching: Generated audio is cached temporarily on your device for playback and re-use during the same tour
- Automatic Cleanup: The cached audio is cleaned up automatically and is not kept beyond what is needed for playback
- No Permanent Storage: Audio is never stored permanently on device or server
3.5 Local Storage & Preferences
What We Store
The only data stored persistently is kept locally on your device (in AsyncStorage). It never leaves the device unless you export it yourself. It consists of:
| Data Type | Purpose | Retention |
|---|---|---|
| Stories-used counter | Track usage against the free tier | Until you delete your data or uninstall |
| Heard stories | Remember which landmarks you have already listened to | Until you delete your data or uninstall |
| Premium status | Remember whether you have unlocked the one-time lifetime purchase | Until you delete your data or uninstall |
| Preferences | Voice, language, interests, theme, units, narration style | Until changed, deleted or uninstall |
| Consent / settings flags | Whether you accepted the privacy notice and whether analytics and ad measurement are on | Until changed, deleted or uninstall |
Important: No name, email, phone number or account ID is stored — Discoveroo has no accounts. There is no server-side profile of you.
3.6 Notifications
Discoveroo uses local notifications only — for example, to let you know when you are near a landmark worth exploring. These are scheduled and generated on your device. No remote push tokens are collected, stored or transmitted, and we do not send notifications from a server. The notification permission is requested by the operating system, and you can disable notifications at any time from your device settings.
3.7 Analytics (Opt-In)
Discoveroo uses PostHog for anonymous product analytics. This is the only analytics service in the app, and it is opt-in: it is switched off by default and only starts collecting once you explicitly enable it.
- What it collects: anonymous usage events (for example: a story was started, the paywall was shown, a setting was changed), to help us understand which features are used
- Crash & error diagnostics: when the app hits an unexpected error, we send a crash report (the error message and a technical stack trace — no personal content) to PostHog so we can fix bugs
- Question text: the text of the questions you ask (truncated to 200 characters) may also be recorded in analytics, so we can understand what users want and prioritise features. This is separate from sending your question to OpenAI to generate the answer (see section 3.3)
- EU hosting: our PostHog instance is hosted in the EU (
eu.i.posthog.com), so this analytics data is not transferred to the United States - No account, no name: events are not tied to your real-world identity, because the app has no accounts
- You stay in control: you can turn analytics on or off at any time from the Analytics toggle in your Profile settings. Turning it off stops further collection.
3.8 Advertisements
Discoveroo does not display advertisements. There is no ad-serving SDK in the app and no ad network shows you ads inside Discoveroo. Advertising support was removed from the app, so this is genuinely the case.
This is separate from ad attribution (section 3.11): we run our own advertising campaigns elsewhere (for example on social networks) to let people know Discoveroo exists, and — only if you opt in — we measure which of those campaigns brought you to the app. Attribution does not show you any ads and, unless you enable it, no advertising identifier (such as the IDFA) is collected or used.
3.9 Wikipedia Data Integration
What We Do
To show photos and descriptions of a place, we query the Wikipedia API at runtime using the landmark’s name.
Data Sent
- Landmark/attraction names only
- No location coordinates
- No user identifiers or account information (there are no accounts)
3.10 Device Identifier (Free-Trial Abuse Prevention)
What We Use
A per-device identifier provided by your operating system — Identifier for Vendor (IDFV) on iOS, Android ID (SSAID) on Android. This is not an advertising identifier (it is not the IDFA/AAID), it is not used for advertising or cross-app tracking, and reading it requires no permission and no App Tracking Transparency prompt. It resets if you uninstall the app (iOS) or factory-reset the device (Android).
Why We Use It
Solely to enforce the limits of the free trial fairly and prevent abuse (for example, resetting the free quota by reinstalling the app), and to recognise customers who purchased the lifetime unlock so they are exempt from those limits.
Where It Goes
- Our Vercel proxy: the identifier is sent to our proxy, which stores only a one-way SHA-256 digest of it (never the raw value) together with simple usage counters, on Upstash Redis (see 4.8)
- RevenueCat: it is provided to RevenueCat as the app-user identifier so we can confirm your purchase status (see 4.3)
We do not build a behavioural profile and do not link it to your name, email or any account (there are none).
Retention
The usage digest and counters auto-expire after approximately 400 days of inactivity. This digest is kept server-side for the abuse-prevention purpose and therefore survives the on-device “Delete all my data” action (see sections 5.3 and 7.4).
3.11 Ad Attribution & Campaign Measurement (Opt-In)
Discoveroo uses AppsFlyer to understand which of our own advertising campaigns bring users to the app and to measure their effectiveness. Like analytics, this is opt-in: it is switched off by default and only starts once you explicitly enable the Ad measurement toggle in the privacy step of the onboarding. You can withdraw at any time from the Ad measurement toggle in the Profile settings — the SDK stops immediately and stays stopped.
What It Collects (Only With Your Consent)
- Advertising identifier: the IDFA on iOS (only if you additionally allow tracking via the separate App Tracking Transparency prompt) or the GAID on Android. On iOS, if you decline the App Tracking Transparency prompt, attribution is limited to Apple’s privacy-preserving SKAdNetwork framework (aggregated conversion data, no device identifier).
- Customer identifier: an anonymous per-device installation identifier (the raw identifier from which the abuse-prevention hash described in section 3.10 is derived) — no name, email or account, because the app has none
- In-app events: that a guide or narration was started or completed, that a question was asked (only the fact that it happened — the question text is never sent to AppsFlyer), and that the paywall was viewed
- Purchase events: forwarded server-side by RevenueCat (see 4.3), so campaign performance can be tied to purchases
- Technical data: IP address, device model and OS version
What It Is Used For
Solely to attribute app installs to the advertising campaigns we run and to measure which campaigns work. Attribution data is shared with the advertising networks we use for those campaigns (Meta, Google, TikTok) exclusively for measurement and attribution — it is never sold. Where required (EU Digital Markets Act), the consent signals for ad user data and ad personalisation are passed to those partners only if you have opted in.
How to Opt Out
- Turn off the Ad measurement toggle in the Profile settings — effective immediately
- iOS: Settings > Privacy & Security > Tracking, to deny tracking for Discoveroo (or all apps)
- Android: reset or delete your advertising ID in the device’s Google settings
- Use AppsFlyer’s own opt-out: www.appsflyer.com/optout
4. Third-Party Data Processors
Discoveroo uses the third-party services below. They act on our behalf under their respective Data Processing Agreements and/or publicly available privacy terms. The validity of the transfer mechanisms named here (SCCs, EU-U.S. Data Privacy Framework) is subject to confirmation by legal counsel.
4.1 OpenAI (Speech-to-Text, AI Answers & Text-to-Speech)
| Service | Data Sent | Retention Policy |
|---|---|---|
| Speech-to-Text | Short audio clip of your spoken question | Per OpenAI API data policy [to be confirmed] |
| AI Answers (text model) | Your text question / landmark context, no account or PII | Per OpenAI API data policy [to be confirmed] |
| Text-to-Speech | Text to be narrated | Per OpenAI API data policy [to be confirmed] |
How it is sent: All OpenAI calls go through our Vercel proxy. The OpenAI API key lives only on the proxy and is never embedded in the app.
International transfer: OpenAI processes data in the United States. The transfer relies on OpenAI’s safeguards (EU-U.S. Data Privacy Framework certification and/or EU Standard Contractual Clauses). The exact mechanism in force is [to be confirmed with counsel].
Legal basis: Necessary to provide the service (GDPR Art. 6(1)(b)) — the voice, AI and narration features cannot work without sending this data to OpenAI.
4.2 PostHog (Analytics — Opt-In)
| Service | Data Sent | Retention Policy |
|---|---|---|
| PostHog (EU host) | Anonymous usage events, crash/error diagnostics (message + stack trace), and truncated question text — only if you opted in | Per our PostHog project configuration [to be confirmed] |
International transfer: Our PostHog instance is EU-hosted (eu.i.posthog.com), so analytics data stays in the EU and is not transferred to the United States.
Legal basis: Consent (GDPR Art. 6(1)(a)). Analytics is off by default and can be toggled off in the Profile settings at any time.
4.3 RevenueCat (In-App Purchase)
| Service | Data Sent | Retention Policy |
|---|---|---|
| RevenueCat | Purchase receipt for the one-time lifetime unlock and a per-device app-user identifier (derived from your device’s IDFV / Android ID), used to validate and restore the purchase and to confirm premium status server-side | Per RevenueCat’s policy [to be confirmed] |
International transfer: RevenueCat is a U.S. provider; transfers rely on its safeguards (EU-U.S. Data Privacy Framework and/or SCCs) [mechanism to be confirmed with counsel].
Note: Payment itself is handled by Apple App Store / Google Play. We do not receive or store your card or payment details.
4.4 Google Maps (Map Rendering)
| Service | Data Sent | Retention Policy |
|---|---|---|
| Google Maps | Your coordinates / map region, to render the map and tiles | Per Google’s policy [to be confirmed] |
International transfer: Google is a U.S. provider; transfers rely on Google’s safeguards (EU-U.S. Data Privacy Framework and/or SCCs) [mechanism to be confirmed with counsel].
4.5 Supabase (Landmark Catalogue Hosting)
| Service | Data Sent | Retention Policy |
|---|---|---|
| Supabase | A fixed city identifier only; the app reads public catalogue data | No personal data sent or retained |
Data Usage: Supabase hosts our public catalogue of Venice landmarks (names, monument coordinates, descriptions, photos). The app sends only a fixed city identifier and reads public data; no personal data is sent. Hosting region [to be confirmed].
Legal Basis: Necessary to provide the service (GDPR Art. 6(1)(b)) — the landmark catalogue is the guide content.
4.6 Vercel (API Proxy Hosting)
Discoveroo’s API proxy is hosted on Vercel. This proxy sits between the app and OpenAI to:
- Keep the OpenAI API key server-side so it is never shipped in the app
- Forward voice/text requests to OpenAI without storing your voice or PII
Data Retention: The proxy is designed not to log your voice or personal content. Operational/security logs (if any) are not used for profiling or analytics. [Exact log retention to be confirmed.]
4.7 Wikipedia API
| Service | Data Sent | Retention Policy |
|---|---|---|
| Wikipedia API | Landmark/attraction names | Query-time only, not retained |
Data Usage: Wikipedia API returns public encyclopedic content. Requests are anonymous and not linked to any user identity.
4.8 Upstash Redis (Free-Trial Quota Storage)
| Service | Data Sent | Retention Policy |
|---|---|---|
| Upstash Redis | A SHA-256 digest of the device identifier (never the raw value) plus integer usage counters | ~400 days, then automatic expiry |
Purpose: server-side free-trial quota and abuse prevention (see section 3.10).
International transfer: both our proxy and the Upstash Redis database are hosted in the EU (Frankfurt), so this data stays in the EU and is not transferred to the United States.
Legal basis: Legitimate Interest (GDPR Art. 6(1)(f)) — fraud and abuse prevention.
4.9 AppsFlyer (Ad Attribution — Opt-In)
| Service | Data Sent | Retention Policy |
|---|---|---|
| AppsFlyer (AppsFlyer Ltd.) | Advertising identifier (IDFA on iOS with ATT authorisation, GAID on Android), an anonymous per-device installation identifier (the raw identifier from which the abuse-prevention hash described in section 3.10 is derived) — no name, email or account —, in-app events (guide/narration started or completed, question asked — the fact only, never the text —, paywall viewed), purchase events forwarded server-side by RevenueCat, and technical data (IP, device model, OS version) — only if you opted in | AppsFlyer retains user-level end-user data for no longer than 24 months (aggregated reports up to 25 months) |
Purpose: attribute app installs to our own advertising campaigns and measure their effectiveness (see section 3.11). Attribution data is shared with the ad networks we advertise on (Meta, Google, TikTok) exclusively for measurement and attribution, and is never sold.
International transfer: Transfers rely on the EU adequacy decision for Israel (AppsFlyer Ltd.), the EU-U.S. Data Privacy Framework certification (AppsFlyer Inc.) and Standard Contractual Clauses under AppsFlyer’s Data Processing Agreement. See AppsFlyer’s services privacy policy.
Legal basis: Consent (GDPR Art. 6(1)(a)). Ad measurement is off by default and can be toggled off in the Profile settings at any time; the SDK stops immediately on withdrawal.
4.10 International Data Transfers
Some processors are located in the United States. The transfer mechanisms are:
- OpenAI (US): EU-U.S. Data Privacy Framework and/or SCCs [mechanism to be confirmed].
- RevenueCat (US): EU-U.S. Data Privacy Framework and/or SCCs [mechanism to be confirmed].
- Google Maps (US): EU-U.S. Data Privacy Framework and/or SCCs [mechanism to be confirmed].
- AppsFlyer: Transfers rely on the EU adequacy decision for Israel (AppsFlyer Ltd.), the EU-U.S. Data Privacy Framework certification (AppsFlyer Inc.) and Standard Contractual Clauses under AppsFlyer’s Data Processing Agreement — only if you opted in to ad measurement.
- PostHog: EU-hosted — no transfer to the United States.
Note: Transfers to OpenAI, Google Maps and RevenueCat happen because those services are necessary to run the app (location, AI features, in-app purchase). The validity and adequacy of the safeguards above should be confirmed with legal counsel.
5. Your Rights Under GDPR
As a data subject, you have the following rights under GDPR (Arts. 13-22). To exercise any of these rights, contact simone@solarrise.it with your request.
5.1 Right to Access (GDPR Art. 15)
You have the right to access all personal data we hold about you.
Discoveroo does not maintain user accounts or a server-side profile, so there is no central database holding your data. The personal data involved in using the app is:
- Data stored locally on your device (preferences, heard stories, counters) — you can see and export it yourself
- Your location, voice and text questions, which are sent to processors (OpenAI, Google Maps) only while you use the related features
- Anonymous analytics events, only if you opted in to analytics
- Ad attribution data (see section 3.11), only if you opted in to ad measurement
You can obtain the locally stored data directly via the “Export my data” option in the Profile settings. For any further request, contact simone@solarrise.it and we will respond within 30 days.
5.2 Right to Rectification (GDPR Art. 16)
You have the right to correct inaccurate personal data.
Since Discoveroo processes only transient data (location, voice, queries) that is not stored in user profiles, rectification is limited. However, if you believe any stored preferences are incorrect, you can modify them directly in the app settings or contact us.
5.3 Right to Erasure (GDPR Art. 17 – “Right to Be Forgotten”)
You have the right to request deletion of your personal data.
Discoveroo provides a “Delete all my data” function in the Profile settings that:
- Clears all locally stored preferences, counters, heard stories and settings from your device
- Resets the privacy and analytics flags
- Resets the analytics state on the device
Important: This deletes the data on your device. Data already sent to a processor (for example a past request to OpenAI) is subject to that processor’s own retention policy and is not something we can delete from your phone. The only data we hold server-side is the pseudonymised free-trial abuse-prevention digest described in section 3.10; because it exists specifically to prevent free-trial abuse, it is retained for its retention period (≈400 days) and is intentionally not cleared by this on-device deletion (GDPR Art. 17 is not absolute where the data remains necessary for the legitimate anti-abuse purpose for which it was collected).
To erase attribution data already collected by AppsFlyer, contact us at simone@solarrise.it and we will forward the deletion request to AppsFlyer (which supports the OpenDSR framework).
For any request concerning a specific processor, contact simone@solarrise.it and we will help you direct it appropriately.
5.4 Right to Restrict Processing (GDPR Art. 18)
You have the right to restrict how we process your data.
You can restrict processing as follows:
- Location: deny or revoke the location permission in your device settings — this stops location collection and POI discovery (the related features become unavailable)
- Microphone / voice: deny or revoke the microphone permission — this stops voice recording and transcription
- Analytics: turn off the Analytics toggle in the Profile settings — this stops analytics collection immediately
- Ad measurement: turn off the Ad measurement toggle in the Profile settings — the AppsFlyer SDK stops immediately. You can also deny tracking in iOS (Settings > Privacy & Security > Tracking), reset or delete your advertising ID in Android’s Google settings, or use AppsFlyer’s opt-out at www.appsflyer.com/optout
Because the location, voice and AI features are necessary to provide the service, switching them off means those specific features will not work; the analytics and ad measurement toggles have no effect on the rest of the app.
5.5 Right to Data Portability (GDPR Art. 20)
You have the right to receive and reuse your personal data.
Discoveroo provides an “Export my data” function in the Profile settings that:
- Exports the data stored locally on your device (preferences, counters, heard stories) in a machine-readable JSON format
- Uses the system share sheet, so you can save it or send it wherever you want
- Can be used for backup or to keep a copy of your data
You can run the export yourself at any time, directly from the app, with no request needed.
5.6 Right to Object (GDPR Art. 21)
You have the right to object to processing.
You can object to any processing activity by:
- Disabling that feature in the app (automatic objection)
- Contacting us at simone@solarrise.it to request processing suspension
We will immediately honor your objection without delay.
5.7 Right to Withdraw Consent (GDPR Art. 7)
You have the right to withdraw consent at any time.
The processing that relies on consent is analytics and ad measurement (both are opt-in). You can withdraw either consent at any time by turning off the Analytics or Ad measurement toggle in the Profile settings; this is effective immediately (the AppsFlyer SDK stops and stays stopped) and does not affect the lawfulness of processing before withdrawal.
The location, voice and AI features are not based on consent but on the necessity to provide the service; you control them by granting or denying the relevant device permissions (location, microphone) or by not using those features.
5.8 Rights Related to Automated Decision-Making (GDPR Art. 22)
Discoveroo does not use automated decision-making or profiling. All data processing is transparent and does not result in legal effects or significantly affect your interests.
How to Exercise Your Rights
To exercise any of the above rights:
- Send a written request to simone@solarrise.it
- You do not need to provide identifying information; describe your request and device type (iOS or Android)
- Specify which right you are exercising
- We will respond within 30 days (extendable to 90 days for complex requests)
6. Data Security & Encryption
6.1 In-Transit Encryption
Data transmitted between your device and external services (OpenAI, Wikipedia, Google Maps, Supabase, Vercel) uses encrypted HTTPS/TLS connections. Calls to OpenAI pass through our Vercel proxy so that the OpenAI API key is never exposed in the app.
6.2 Key Protection
The OpenAI API key is stored server-side on the Vercel proxy and is never bundled into the mobile app. The app talks to the proxy, and the proxy talks to OpenAI. This is the core security measure of the architecture.
6.3 Local Data Protection
Preference data stored on your device is held in the app’s private storage, protected by the operating system’s app sandbox and the standard storage protections of your device. We do not claim additional Keychain/Keystore encryption for this data. Because there are no accounts and no server-side database, there is no central store of personal data to breach.
6.4 Third-Party Security
We rely on the security programs of our processors (OpenAI, Vercel, PostHog, RevenueCat, AppsFlyer, Google). Each publishes its own security and compliance information; we do not independently audit them.
6.5 Security Practices
- No hardcoded API keys or secrets in the app (the OpenAI key lives only on the proxy)
- Data minimization and a local-first design to reduce the attack surface
- Analytics and ad measurement off by default (opt-in)
6.6 Breach Notification
Where a breach involving personal data occurs and the law requires it, we will notify the competent supervisory authority and, where applicable, affected users in line with GDPR Arts. 33-34 (generally within 72 hours of becoming aware). [Concrete breach-response process to be confirmed with counsel.]
7. Data Retention & Deletion
7.1 Retention Schedule
| Data Type | Storage Location | Retention Period | Deletion Method |
|---|---|---|---|
| GPS Location | Device memory only | During active use only | Cleared when the app is closed or backgrounded |
| Voice clip (local) | Device storage (temporary) | Until the clip has been sent for transcription | Removed from the device after processing |
| Voice / text sent to OpenAI | OpenAI | Per OpenAI’s API data policy [to be confirmed] | Governed by OpenAI |
| Analytics events (if opted in) | PostHog (EU) | Per our PostHog project configuration [to be confirmed] | Governed by PostHog config |
| Ad attribution data (if opted in) | AppsFlyer | AppsFlyer retains user-level end-user data for no longer than 24 months (aggregated reports up to 25 months) | Governed by AppsFlyer; collection stops when you toggle Ad measurement off |
| One-time purchase data | RevenueCat / Apple / Google | Per their policies [to be confirmed] | Governed by those providers |
| Local data (preferences, counters, heard stories) | Device storage | Until you delete it or uninstall | “Delete all my data” in Profile, or app uninstall |
| Device-id digest + free-trial counters | Upstash Redis (abuse prevention) | ~400 days, then automatic expiry | Auto-expiry; retained for the anti-abuse purpose (see 3.10 / 5.3) |
7.2 Automatic Behaviour on the Device
- Location: kept in memory only and cleared when the app closes or is backgrounded
- Voice clip: removed from the device after it has been processed for transcription
7.3 Manual Deletion Options
- “Delete all my data”: in the Profile settings, clears all local data and resets the analytics state on the device
- “Export my data”: exports a copy of your local data (it does not delete; use it for backup)
- App uninstall: removes all locally stored data from your device
7.4 No Server-Side Profile or Archives
Important: Discoveroo does not maintain:
- User accounts or a server-side profile of you
- A backend database of your behaviour or preferences
- Our own backups of your location, voice or queries
The single exception is the pseudonymised free-trial abuse-prevention digest (a one-way hash of your device identifier plus usage counters) described in section 3.10, held on Upstash Redis solely to enforce the free-trial limits and expiring automatically after ~400 days. It contains no name, email, account, location, voice or query content.
Data held by processors (OpenAI, PostHog, RevenueCat, AppsFlyer, Google) is retained according to their own policies, which we link to or summarise above.
8. Children’s Privacy
Discoveroo’s content is suitable for ages 13 and older (App Store rating: 13+). Separately, for data protection under GDPR Art. 8, where a user’s country sets the digital age of consent at 16 we treat 16 as the threshold for parental consent (see below). We comply with GDPR Art. 8 requirements for children’s data.
8.1 Age Requirement
Users under 16 require parental consent to use Discoveroo. If you are under 16, please have your parent or legal guardian review this policy and provide consent before using the app.
8.2 Parental Controls
Parents and guardians can:
- Use device-level parental controls (iOS Screen Time, Android Family Link) to monitor app usage
- Deny or revoke the location and microphone permissions in the device settings, which disables the related features
- Use the “Delete all my data” option in the app to clear the child’s on-device data
8.3 Data Protection for Minors
Because Discoveroo is anonymous and has no accounts, we cannot identify a user’s age and we do not knowingly collect data from anyone we know to be under 16. If a parent or guardian believes a child has used the app, they can contact simone@solarrise.it, and the on-device data can be cleared via the “Delete all my data” option. The approach to age assurance is being reviewed with legal counsel.
9. Policy Changes & Updates
9.1 Right to Modify This Policy
We may update this privacy policy to reflect changes in our services, technology, legal requirements, or other factors. Material changes will be:
- Announced within the app (notification on policy update)
- Published on this policy page, with an updated timestamp; you can also reach us at simone@solarrise.it
- Effective 30 days after announcement to allow you to review
9.2 Your Rights Upon Changes
If material changes are made to privacy practices:
- You will be informed of the changes within the app on the next launch
- You can review the full updated policy before continuing to use the app
- If you do not agree with the updated policy, you can stop using the app and clear your on-device data with the “Delete all my data” option
9.3 Notification Method
Policy updates will be communicated via:
- In-app notice on the next app launch
- This policy page, with an updated timestamp
We do not have your email address (there are no accounts), so we cannot notify you by email.
10. Contact & Support
If you have questions, concerns, or want to exercise your data rights under GDPR, please contact:
Discoveroo Privacy
General contact & reports: simone@solarrise.it — for general enquiries, support and in-app content reports
Privacy requests: all privacy enquiries and requests to exercise your GDPR rights should be sent to simone@solarrise.it — this is the channel for exercising your rights
Data Controller: Simone Biasotto
Response Time: Within 30 days
10.1 Your Request Options
You can contact us to:
- Request access to your personal data (Art. 15)
- Request correction of inaccurate data (Art. 16)
- Request deletion of your data (Art. 17)
- Request restriction of processing (Art. 18)
- Request data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent for any feature (Art. 7)
- Report a privacy concern or data breach
10.2 What to Include in Your Request
You do not need to provide identifying information. To help us respond, please include:
- A description of your request and what data it concerns
- Device type (iOS or Android) and approximate dates of use
- Preferred response method (email, etc.)
10.3 Data Protection Authority Contact
If you believe your data rights have been violated or you have concerns about our privacy practices, you have the right to lodge a complaint with the relevant data protection authority:
Italy: Garante per la protezione dei dati personali
Website: www.garanteprivacy.it
You may lodge a complaint with the Garante (or your local EU supervisory authority) at any time.
10.4 Response Commitment
We are committed to responding to all privacy requests within 30 days. If your request is complex, we may take up to 90 days with notice. If we cannot fulfil your request, we will explain why.
GDPR Compliance Summary
This privacy policy aligns with all GDPR requirements through explicit legal bases, granular consent management, and data minimization:
| GDPR Article | Requirement | Discoveroo Compliance |
|---|---|---|
| Art. 5 | Data Principles | Lawful basis: service necessity for core features, consent for analytics and ad measurement; fair, transparent, minimized, accurate, retained minimally |
| Art. 6 | Lawfulness of Processing | Service features (location, voice, AI) on the basis of necessity to provide the service; analytics and ad measurement on the basis of consent (opt-in) |
| Art. 7 | Consent Management | Analytics and ad measurement are opt-in, off by default, withdrawable via the Profile toggles |
| Art. 13 | Information at Collection | This policy plus the in-app privacy notice describe what data is used and why |
| Art. 15 | Access Right | “Export my data” in Profile; or contact simone@solarrise.it |
| Art. 17 | Erasure (“Right to Be Forgotten”) | “Delete all my data” clears on-device data; processor data follows their own retention |
| Art. 20 | Data Portability | “Export my data” exports on-device data in JSON |
| Art. 25 | Privacy by Design | Local-first, no accounts, no server-side profile, analytics and ad measurement off by default, no ads displayed |
| Art. 28 | Processors | Processors operate under their own DPAs / data processing terms [coverage to be confirmed with counsel] |
| Art. 33-34 | Breach Notification | Notification to the Garante and affected users where required by law |