Walk with Isa Privacy Policy
Effective date: 27 July 2026 — Version 1.1
Walk with Isa is an AI-powered audio companion that tells you stories about the city around you as you walk. To do that, it needs to know where you are, what language you speak, and what kind of stories you enjoy. This policy explains — completely and honestly — what personal data we collect, why, who receives it, how long we keep it, and the rights you have.
This policy applies to the Walk with Isa mobile apps for iOS and Android, the Walk with Isa web player, our websites (including walkwithisa.com and its subdomains), and our support channels.
1. Who is responsible (Data Controller)
The controller within the meaning of Art. 4(7) of the EU General Data Protection Regulation ("GDPR") is:
Ulf Kuhn Hauptstr. 56 63619 Bad Orb Deutschland (Germany)
E-mail: cityspin11@gmail.com Phone: +372 5354 6281 WhatsApp: https://whatsapp.walkwithisa.com
We have not appointed a Data Protection Officer, as we are not legally required to do so at our current size. For all privacy matters, please contact the controller directly using the details above. If you contact us via WhatsApp, your messages are additionally processed by WhatsApp (Meta) under the WhatsApp Privacy Policy; use e-mail if you prefer to avoid this.
2. At a glance
| Question | Short answer |
|---|---|
| Do you sell my data? | No. We do not sell personal data. |
| Do you track my location all the time? | No. Location is used only while a listening session or walk is active. We do not build a continuous movement history of your life. |
| Who writes the narrations? | AI language models. They receive facts about the place, your language, and a few taste preferences — never your name, e-mail address, or account identity. |
| Is my voice recorded when I ask Isa a question? | No. Your device's own speech recognition converts your question to text. Only the text reaches our servers — never the audio. |
| Where is my data stored? | On AWS servers in Frankfurt, Germany (EU region eu-central-1). |
| Are there ads in the app? | No ads inside Walk with Isa. We measure the performance of our own ad campaigns (Google, Meta), only with your consent. |
| How do I delete everything? | In the app: Settings → Account → Delete Account & Data. Or e-mail cityspin11@gmail.com. |
3. Scope and definitions
"Personal data" means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR). "Processing" means any operation performed on personal data, such as collection, storage, use, or deletion. "You" means the person using Walk with Isa. Where we say "device", we mean the smartphone, tablet, or browser you use Walk with Isa on.
This policy does not cover third-party websites or services we merely link to (e.g. a Wikipedia article about a monument, or Google Maps when you open a place there). Their own privacy policies apply.
4. What personal data we collect
4.1 Data you actively provide
- Account data: your e-mail address. Walk with Isa uses passwordless sign-in ("magic link") via Firebase Authentication — you enter your e-mail, receive a sign-in link, and tap it. We never see or store a password. Firebase assigns you a technical user ID which we use internally.
- Onboarding and taste preferences: your language, interests, preferred narration style and tone (e.g. true crime, documentary, fun facts), and any free-text instructions you give your AI guide.
- Reflections: occasionally, after a story, Walk with Isa asks a light personal question ("What does home mean to you right now?"). Answering is always optional. If you answer, your text is stored in your narration profile and used solely to make future stories resonate with you.
- Mood: if you tell the app how you are feeling before a walk, that selection influences the music and tone of that session and your narration profile.
- User-generated content: routes you create, their names and descriptions, and content you choose to share (e.g. postcards or route links). Anything you deliberately publish or share may be visible to other people — do not include personal data in route names or descriptions that you don't want others to see.
- Support communications: the content of e-mails, WhatsApp messages, or calls you send us, plus your contact details.
- Ratings and feedback: in-app ratings and anything you submit through review prompts.
4.2 Data collected automatically when you use Walk with Isa
- Precise location (GPS): the core of the product. While a session is active, your device sends its coordinates so our servers can find points of interest ("POIs") near you and trigger the right story at the right moment. This continues while your screen is locked during an active walk (that's what makes hands-free listening work) and stops when you end the session or close the app. We also derive your city, district/suburb, and country from your coordinates (reverse geocoding) to give narrations local context.
- Playback and usage events: which POIs were narrated, whether you listened to the end, skipped, or replayed; session starts and completions; feature usage (e.g. news playback, trophy collection); streaming errors. See Section 12 (Analytics).
- Spoken questions ("Ask Isa"): see Section 7.
- Device and technical data: device model, operating system and version, app version, language and time zone settings, network type, screen properties, battery-level diagnostics, GPS accuracy readings, and your IP address (processed transiently for the connection and in short-lived server logs).
- Identifiers: your internal user ID, a Firebase app-installation ID, push-notification tokens, and — only if you consent (see Section 13) — your device advertising identifier (IDFA on iOS after the App Tracking Transparency prompt, GAID on Android).
- Crash and performance data: if the app crashes or misbehaves, technical diagnostics are sent to Sentry so we can fix it. These reports contain device and state information, not your narration content.
4.3 Data we receive from third parties
- App stores: Apple and Google Play tell us whether a purchase or subscription is active, refunded, or expired. We receive receipts and entitlement status — never your credit-card number.
- Advertising platforms: aggregated or pseudonymized install-attribution data from Google and Meta telling us that an ad campaign led to an install or purchase (Section 13).
4.4 Data we infer (your narration profile)
Walk with Isa builds a narration profile for you: a set of taste attributes (topics you enjoy, preferred tone, pacing, humor) derived from what you tell us and from your listening behavior (completions, skips, replays). This profile exists for exactly one purpose — making Isa's stories feel like they were written for you — and is covered in detail in Sections 10 and 11.
4.5 What we do NOT collect
We do not collect your contacts, photos, calendar, messages, or files. We do not record ambient audio. We do not track your location when no session is active. We do not collect government IDs, financial account numbers, health records, or biometric data. We do not buy data about you from data brokers, and we do not sell your data.
Anonymized and aggregated data: we may aggregate or irreversibly anonymize data so that it no longer relates to an identifiable person. Such data is no longer personal data, and we may use, retain, and share it without restriction — for example for statistics, benchmarks, research, and improving our product, content, and quality systems. Where we hold merely de-identified data, we maintain and use it only in de-identified form and do not attempt to re-identify it.
5. Why we process your data, and on what legal basis
Under the GDPR, every processing purpose needs a legal basis. Here is the complete mapping:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and operating your account; signing you in | E-mail address, user ID, sign-in events | Art. 6(1)(b) GDPR — contract |
| Finding nearby POIs, generating and streaming narrations to you | Precise location, derived city/district, language, POI selection, narration profile attributes | Art. 6(1)(b) GDPR — contract (this is the service) |
| Answering your spoken questions about a story | Question text, current story text, conversation turn history, POI name, city/country | Art. 6(1)(b) GDPR — contract |
| Personalizing narration style and topics | Stated preferences, reflections, mood, listening behavior | Art. 6(1)(b) GDPR; ongoing refinement from behavioral signals: Art. 6(1)(f) GDPR — legitimate interest in a genuinely useful product. You may object (Section 22). |
| Optional worldview-based story framing | A worldview/orientation preference you explicitly enable | Art. 9(2)(a) GDPR — your explicit consent (Section 11) |
| Product analytics and improvement | Usage events, device data | Art. 6(1)(a) GDPR — consent; § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act, formerly TTDSG) for device access |
| Crash reporting, debugging, service security, abuse and fraud prevention, rate limiting | Diagnostics, IP address, technical logs | Art. 6(1)(f) GDPR — legitimate interest in a stable, secure service |
| Quality logging of AI-generated narrations | Generated script, model and prompt metadata, profile-attribute snapshot | Art. 6(1)(f) GDPR — legitimate interest in narration quality, error diagnosis, and developing and improving our prompts, content selection, and quality-evaluation systems (using pseudonymized or de-identified data where feasible) |
| Measuring our advertising campaigns (attribution) | Advertising ID (only after consent), hashed event data | Art. 6(1)(a) GDPR — consent; § 25(1) TDDDG |
| Processing purchases and subscriptions | Store receipts, entitlement status | Art. 6(1)(b) GDPR; retention of billing records: Art. 6(1)(c) GDPR — German commercial and tax law |
| Push notifications | Push token, notification preferences | Art. 6(1)(a) GDPR — consent (OS-level permission), revocable any time |
| Responding to support requests | Contact data, message content | Art. 6(1)(b) or (f) GDPR |
| Establishing, exercising, or defending legal claims; complying with legal obligations | Data as required in the individual case | Art. 6(1)(c) and (f) GDPR |
Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR) — in the app settings, via the OS permission settings, or by e-mailing us. Withdrawal does not affect the lawfulness of processing before the withdrawal.
Where we further process personal data for a purpose other than the one it was collected for, we do so only where that purpose is compatible with the original purpose (Art. 6(4) GDPR) — such as record-keeping, statistics, security, fraud and abuse prevention, or the establishment, exercise, or defense of legal claims — or where a separate legal basis applies.
6. Location data in detail
Location is Walk with Isa's most sensitive data category, so here is exactly how it works:
- When you start a walk or session, your device begins sending GPS coordinates to our backend. Our servers use spatial indexing (H3 hexagonal cells) and geographic containment queries (PostGIS) to determine which POIs are near you and which city, district, and country you are in.
- Coordinates are used in the moment — to pick the right story, orient the narration ("on your left..."), and time playback. What we persist long-term is the record of which POIs were narrated to you, not a GPS breadcrumb trail of your movements.
- Raw coordinates may appear transiently in operational server logs used for debugging and security; these logs are automatically deleted after a short, fixed period (currently up to 30 days).
- You control the OS-level location permission at all times (iOS Settings / Android Settings). The app works in a limited mode without location, but the core experience — stories triggered by where you stand — obviously requires it. We request "While Using the App" access; active audio sessions keep the app running with the screen locked so narration continues during your walk.
- We do not share your precise location with advertisers, do not use it for advertising, and do not sell it.
- When you tap "open in Google Maps" for a POI, the POI's location (not your identity) is handed to Google Maps on your device, under Google's own policy.
7. Microphone and spoken questions ("Ask Isa")
After a story, you can tap the Ask button and ask Isa a question out loud. Here is precisely what happens:
- The app requests the microphone permission (RECORD_AUDIO on Android, Microphone on iOS) the first time you use the feature. You can decline; the feature simply won't be available.
- Your speech is converted to text by your device's own speech-recognition service (provided by your operating system vendor — Google on Android, Apple on iOS — under their respective privacy policies, and depending on your device settings possibly processed on their servers).
- Walk with Isa's servers receive only the resulting text of your question — never the audio recording. We do not record, store, or transmit your voice.
- Together with the question text, the app sends the story you just heard, the recent question-and-answer history of that session, your language, the POI name, and your current city/district/country, so the answer can be relevant. The answer is generated by an AI model (Section 9) and read aloud to you.
- The microphone is active only while the listening indicator is visible and stops immediately when you cancel or stop speaking.
8. Camera and AR trophies
If you use the augmented-reality trophy feature after visiting a POI, the app uses your camera to display the 3D trophy in your surroundings. The camera image is processed on your device only for AR rendering. It is not recorded, stored, or transmitted to our servers. The camera permission is requested only when you first use the feature and can be revoked at any time in your OS settings.
9. AI-generated content: which AI providers see what
Walk with Isa's narrations are not pre-recorded. When you approach a place, our servers assemble a briefing — encyclopedic facts about the place from Wikipedia, Wikidata, and OpenStreetMap, your language, and selected attributes from your narration profile — and send it to a large language model ("LLM"), which writes a short script. A text-to-speech ("TTS") engine then converts that script into Isa's voice and streams it to your device.
What is sent to AI providers: POI facts and names; coarse location context (the place and district being narrated — not your continuous GPS trail); selected narration-profile attributes (e.g. interest categories, tone preferences); your language; for the news feature, your city and general interests; and, when you use Ask Isa, the text of your question and the session's Q&A history. What is never sent: your name, e-mail address, account ID, contact details, or payment information. Requests are made under pseudonymous technical identifiers.
The providers we use:
| Provider | Role | Privacy policy |
|---|---|---|
| Anthropic | Primary narration model (Claude) | https://www.anthropic.com/legal/privacy |
| OpenRouter | LLM routing layer through which some model and TTS requests are dispatched | https://openrouter.ai/privacy |
| Cerebras | Fast inference for Ask Isa answers | https://www.cerebras.ai/privacy-policy |
| xAI | Current-events / local news generation (Grok) | https://x.ai/legal/privacy-policy |
| Deepgram | Text-to-speech (primary voice) | https://deepgram.com/privacy |
| Google Cloud | Text-to-speech (fallback) | https://policies.google.com/privacy |
| Cartesia | Text-to-speech (fallback) | https://www.cartesia.ai/legal/privacy |
We use these companies' business/API offerings under terms that restrict them to processing your data solely to return a response to us, with short or zero retention, and — to the extent the provider offers it — an exclusion of your inputs from AI training. Where a provider offers a zero-data-retention mode, we enable it.
Quality logging: to debug problems and improve narration quality, we log each generated script together with technical metadata: model used, prompt version, response latency, token counts, and a snapshot of the profile attributes that shaped the script. These logs are keyed to pseudonymous IDs and retained per Section 20. Small samples may be reviewed by us for quality assurance.
A note on accuracy: AI-generated narrations can occasionally contain errors. Stories are entertainment, not authoritative historical, legal, or safety advice.
10. Personalization, profiling, and automated decision-making
Walk with Isa personalizes content. In GDPR terms, this is "profiling" (Art. 4(4) GDPR), so we describe it fully:
- What the profile contains: taste attributes (favorite topics, tone, humor, pacing, depth), your language, your stated preferences and instructions, optional reflections and mood entries, and behavioral signals (which stories you finished, skipped, or replayed).
- How it is used: our backend code selects which profile attributes are relevant for a given place and passes them to the narration model so the story matches your taste. Selection logic runs in our own software; the profile is never handed to advertisers and never used for pricing, credit, or eligibility decisions of any kind.
- Art. 22 GDPR: Walk with Isa does not make automated decisions that produce legal effects concerning you or similarly significantly affect you. The only automated "decision" is which flavor of story you hear.
- Your controls: you can view and edit your preferences in the app, clear your reflections, reset your narration profile, or delete your account entirely (Section 23). You may object to profiling based on legitimate interest at any time (Section 22); Isa will then narrate in a generic style.
11. Special categories of data (Art. 9 GDPR)
We do not ask for, and do not want, data about your health, religion, ethnicity, sexual orientation, or trade-union membership. Two features deserve explicit treatment:
- Worldview-based story framing (optional, explicit consent): some historical and civic stories can be told from different perspectives. If — and only if — you explicitly enable this optional feature, you can indicate a broad worldview or political orientation preference, and Isa adapts the framing of certain narrations accordingly. Because information revealing political opinions is special-category data under Art. 9(1) GDPR, this feature is off by default, activates only after a separate, explicit consent (Art. 9(2)(a) GDPR), is used exclusively to adjust narration framing, is never shared with advertisers or any third party for their purposes, and can be withdrawn at any time in Settings — upon which the associated attributes are deleted from your profile.
- Free-text you volunteer: reflections and custom instructions are open text. If you choose to include sensitive information there, we process it only as part of your narration profile, on the basis of your deliberate act of providing it; you can edit or clear these entries at any time, and they are deleted with your account.
Mood selections ("How are you feeling?") are treated as ordinary preference data used for that session's tone and music; they are not medical or health data and we do not use them to draw health conclusions.
12. Analytics and product improvement
To understand whether Walk with Isa works and where it fails, we use:
- Firebase Analytics (Google): app events such as registration completed, audio completed, session completed, usage milestones, and streaming/preparation errors, together with device information. We have configured Google's data-sharing settings restrictively and use the data for product analytics and — with your separate consent — campaign measurement (Section 13). User-level analytics data is automatically deleted after 14 months.
- PostHog: behavioral product analytics (feature usage, funnels) under pseudonymous identifiers, used to understand which features help and which confuse.
- Sentry: crash and error reports (Section 4.2).
Analytics that require storing or reading identifiers on your device run only after your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR), which you can withdraw in the app's privacy settings at any time. Strictly necessary technical processing (e.g. delivering the audio stream you requested, security logging) does not require consent (§ 25(2) TDDDG).
13. Advertising and campaign measurement (attribution)
Walk with Isa shows no third-party ads inside the app. We do advertise Walk with Isa on other platforms, and we measure whether those campaigns work:
- Google Ads: we link our Firebase project with Google Ads so that aggregate conversion events (e.g. "an install happened", "a subscription started") can be attributed to campaigns. On iOS this respects Apple's App Tracking Transparency ("ATT") framework.
- Meta (Facebook/Instagram): we use a minimal Meta SDK integration for install attribution — on iOS primarily via Apple's privacy-preserving SKAdNetwork, which gives us aggregate campaign numbers, not individual identities — and a server-side Conversions API through which selected funnel events (e.g. registration completed, trial started) are transmitted with hashed identifiers. Duplicate events are matched via a technical event ID so nothing is double-counted.
- Your choices: on iOS, the ATT prompt lets you decline cross-app tracking; declining limits attribution to aggregate, non-identifying methods. On Android you can reset or delete your advertising ID in system settings. In-app, attribution events run only with your consent and can be switched off in privacy settings. You can additionally manage ad personalization at Google Ad Settings and Meta Ad Preferences.
We do not run "lookalike" audience targeting from your in-app behavior, do not share your narration profile, location, reflections, or listening content with ad platforms, and do not sell data.
14. Payments and subscriptions
All purchases are processed by the app stores: Apple (App Store) or Google (Google Play). They are independent controllers for the payment itself — we never receive your card or bank details. We receive and store purchase receipts and subscription entitlement status (product, start/expiry, refund status) to unlock your features and for our statutory bookkeeping. We may use RevenueCat as a processor to validate receipts and manage subscription status across platforms.
15. Push notifications and e-mail
- Push notifications are sent only if you grant the OS-level permission, via Apple Push Notification service and Firebase Cloud Messaging. You can disable them in your device settings at any time.
- E-mail: we send transactional e-mails (sign-in links, purchase confirmations, important service or legal notices) based on Art. 6(1)(b)/(c) GDPR. Marketing e-mails, if any, are sent only with your consent or within the narrow limits of § 7(3) UWG (German Act Against Unfair Competition) for existing customers, and every such e-mail contains a one-click unsubscribe.
16. User-generated content and sharing
If you create routes, postcards, or share links, remember: shared content is visible to its recipients, and public content is visible to anyone. Shared links contain route and city information, not your e-mail address or identity, unless you add such information yourself. You can delete your created routes in the app; already-shared copies or screenshots held by others are outside our control.
17. Cookies and similar technologies (websites and web player)
Our websites and web player use cookies and similar technologies (local storage, SDK identifiers). Under § 25 TDDDG and the GDPR:
- Strictly necessary technologies (session handling, sign-in state, load balancing, saving your consent choice) run without consent.
- Everything else — analytics and marketing technologies — runs only after you consent via the consent banner, and you can change or withdraw your choice at any time via the "Privacy settings" link in the footer.
Typical technologies in use:
| Name / type | Purpose | Category | Duration |
|---|---|---|---|
| Session cookie | Keeps you signed in during a visit | Strictly necessary | Session |
| Auth token | Keeps you signed in between visits | Strictly necessary | Up to 30 days |
| Consent storage | Remembers your cookie choices | Strictly necessary | 12 months |
| PostHog (ph_*) | Product analytics | Analytics (consent) | Up to 12 months |
| Firebase / Google Analytics (_ga and similar) | Web analytics, campaign measurement | Analytics (consent) | Up to 14 months |
| Meta Pixel (_fbp, _fbc) | Ad campaign measurement, deduplicated with our server events | Marketing (consent) | Up to 3 months |
The consent banner always shows the current, complete list. We honor the Global Privacy Control signal (GPC) where legally applicable, treating it as an opt-out of sharing for targeted advertising.
18. Who receives your data (recipients and processors)
We share personal data only with the following categories of recipients, only to the extent necessary, and under data-processing agreements (Art. 28 GDPR) where they act on our behalf:
| Recipient | Role / what they process | Location | Link |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting of our entire backend, database, and logs — region eu-central-1 (Frankfurt, Germany) | EU (support access may occur from third countries under safeguards) | https://aws.amazon.com/privacy/ |
| Google (Firebase) | Authentication (e-mail sign-in), app analytics, push messaging, campaign linking | EU/USA | https://firebase.google.com/support/privacy |
| Anthropic, OpenRouter, Cerebras, xAI | Narration, Q&A, and news text generation (Section 9) | USA | See Section 9 |
| Deepgram, Google Cloud, Cartesia | Text-to-speech synthesis of scripts (Section 9) | USA/EU | See Section 9 |
| Sentry | Crash and error diagnostics | USA/EU | https://sentry.io/privacy/ |
| PostHog | Product analytics | EU/USA | https://posthog.com/privacy |
| Meta Platforms | Ad attribution (Section 13); WhatsApp support channel if you use it | EU/USA | https://www.facebook.com/privacy/policy |
| Google Ads | Ad attribution (Section 13) | EU/USA | https://policies.google.com/privacy |
| Apple / Google Play | App distribution, payments, subscriptions (independent controllers) | EU/USA | https://www.apple.com/legal/privacy/ · https://policies.google.com/privacy |
| RevenueCat | Subscription receipt validation (if enabled) | USA | https://www.revenuecat.com/privacy |
| Mapbox | Map tiles when map views load (your IP reaches their servers to deliver tiles) | USA/EU | https://www.mapbox.com/legal/privacy |
| Contracted engineers and service staff | Development, operations, and support under confidentiality and access controls | EU and third countries | — |
| Professional advisors | Lawyers, tax advisors, accountants, auditors, and insurers, where needed and under professional secrecy or confidentiality | EU and third countries | — |
| Authorities, courts, law enforcement | Where legally required, or where necessary to establish, exercise, or defend legal claims, enforce our terms, prevent fraud and abuse, or protect the rights, property, or safety of Walk with Isa, our users, or the public | As applicable | — |
If our business is transferred or such a transaction is prepared (sale, merger, financing, restructuring, insolvency), your data may be disclosed and transferred as part of the transaction — including to prospective parties during due diligence, under confidentiality obligations. Any successor remains bound by this policy or one at least as protective; we would inform you of a change of controller.
19. International data transfers
Our servers are in Frankfurt, Germany. Some processors listed above process data in the USA or other third countries. Where personal data leaves the EEA, the UK, or Switzerland, we rely on:
- an adequacy decision of the European Commission (Art. 45 GDPR), in particular the EU-U.S. Data Privacy Framework for US providers certified under it — you can check certifications at https://www.dataprivacyframework.gov; and/or
- the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures where needed; and
- in rare individual cases, derogations under Art. 49 GDPR (e.g. your explicit consent or contractual necessity).
You can request a copy of the relevant safeguards via the contact details in Section 1.
20. How long we keep your data (retention)
We keep personal data only as long as needed for the purpose it was collected for, then delete or irreversibly anonymize it:
| Data | Retention |
|---|---|
| Account data and narration profile | For the life of your account; deleted within 30 days of account deletion |
| Reflections, mood entries, custom instructions | Until you clear them or delete your account |
| Playback / usage events tied to your account | Up to 24 months, then deleted or de-identified |
| AI narration quality logs (Section 9) | Up to 24 months, then deleted or de-identified |
| Firebase Analytics user-level data | 14 months (automatic) |
| Crash reports (Sentry) | Up to 90 days |
| Operational server logs (may contain IP, coordinates) | Up to 30 days |
| Ad-attribution event data | Up to 180 days, then aggregate only |
| Support correspondence | Up to 3 years after the case is closed (§ 195 BGB limitation period) |
| Purchase and billing records | 8–10 years, as required by German commercial and tax law (§ 257 HGB, § 147 AO) |
| Consent records (proof of consent) | 3 years after withdrawal |
| Backups | Encrypted backups roll off automatically within 90 days of deletion from live systems |
Where a statutory retention duty applies, data is blocked from other use during that period and deleted afterwards. Beyond the periods above, we may retain specific data for as long as required or permitted by law, and — where a dispute exists or is reasonably anticipated — until the matter and the applicable limitation periods have concluded, restricted to that purpose.
21. How we protect your data (security)
We apply technical and organizational measures appropriate to the risk (Art. 32 GDPR), including: TLS encryption for all data in transit; encryption at rest for databases and backups; hosting in an isolated private network in the EU (Frankfurt) with no direct public database access; short-lived, signed authentication tokens (Firebase JWT) validated on every request; API rate limiting and abuse protection; secrets kept in a dedicated secrets manager, never in code; role-based, least-privilege access for the small number of people who operate the service, under confidentiality obligations; continuous monitoring and alerting; and pseudonymization of analytics and AI-request data. No system is perfectly secure, but if a breach ever puts your rights at risk, we will notify the supervisory authority and, where required, you, in line with Art. 33/34 GDPR.
22. Your rights
Under the GDPR you have the right to:
- Access (Art. 15): confirmation whether we process your data, a copy of it, and the related information.
- Rectification (Art. 16): correction of inaccurate data.
- Erasure (Art. 17): deletion ("right to be forgotten") — see also Section 23.
- Restriction of processing (Art. 18).
- Data portability (Art. 20): your provided data in a structured, commonly used, machine-readable format.
- Objection (Art. 21): you may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 6(1)(f) GDPR) — including profiling based on it. We will then stop unless we can demonstrate compelling legitimate grounds. You may object to any direct marketing at any time, without conditions.
- Withdraw consent (Art. 7(3)): at any time, with effect for the future.
- Not to be subject to solely automated decisions with legal or similarly significant effect (Art. 22) — as stated in Section 10, we do not make such decisions.
- Lodge a complaint (Art. 77) with a supervisory authority — at your habitual residence, place of work, or the place of the alleged infringement.
The supervisory authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany — https://datenschutz.hessen.de. A list of all EU authorities is available from the European Data Protection Board.
To exercise any right, e-mail cityspin11@gmail.com from your account's e-mail address. We must verify your identity before acting on a request and may ask for additional confirmation where reasonable doubt exists — this protects your data from impostors. We answer within one month (Art. 12(3) GDPR); for complex or numerous requests, we may extend this by up to two further months and will tell you within the first month. Exercising your rights is free of charge; for manifestly unfounded or excessive requests — in particular repetitive ones — we may charge a reasonable administrative fee or refuse to act (Art. 12(5) GDPR). All rights apply within their statutory limits (including Art. 23 GDPR and, in Germany, §§ 34, 35 BDSG).
23. Deleting your account and data
Two ways, both complete:
- In the app: Settings → Account → Delete Account & Data. This permanently deletes your account, your narration profile, reflections, preferences, and cached audio.
- By e-mail: write to cityspin11@gmail.com from your account's e-mail address.
Deletion from live systems is completed within 30 days; encrypted backups roll off within a further 90 days. Data under statutory retention duties (e.g. invoices) is blocked and deleted when those periods expire. Aggregate statistics that no longer identify you may be retained. We may also retain the minimum data necessary to comply with legal obligations, resolve disputes, enforce our agreements, and prevent fraud and abuse — including a hashed identifier used solely to prevent previously blocked accounts from re-registering.
24. Children
Walk with Isa is not directed at children. You must be at least 16 years old (or the age of digital consent in your country, where lower — never below 13) to create an account. We do not knowingly collect personal data from children below that age; if you believe a child has provided us data, contact us and we will delete it.
25. Regional information
25.1 Argentina
For users in Argentina, we process personal data consistent with the Personal Data Protection Act No. 25.326 ("Ley de Protección de los Datos Personales") and its regulations. You have the rights of access (free of charge at intervals of six months or longer, unless a legitimate interest is shown), rectification, updating, and deletion (supresión) of your data, exercisable via cityspin11@gmail.com. The supervisory authority is the Agencia de Acceso a la Información Pública (AAIP) — https://www.argentina.gob.ar/aaip — which accepts complaints regarding non-compliance with data protection rules (the holder of the data may file a complaint before the AAIP). Data is processed on servers in Germany, a jurisdiction providing an adequate level of protection under Argentine law. We honor all GDPR-level rights described in Section 22 for Argentine users as well.
25.2 United States / California (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended ("CCPA") gives you specific rights. In the preceding 12 months we have collected these categories of personal information: identifiers (e-mail, device and user IDs); commercial information (purchases, subscriptions); internet or other electronic network activity (app usage events); geolocation data, including precise geolocation (used only to deliver the service you request); audio-derived information (text of spoken questions — not recordings); and inferences (your narration profile). Sources, purposes, and recipients are as described throughout this policy.
- We do not "sell" personal information. Ad-attribution transfers to Google and Meta may qualify as "sharing" for cross-context behavioral advertising under the CCPA; you can opt out of sharing at any time in the app's privacy settings, via the "Do Not Sell or Share My Personal Information" control on our website, by enabling Global Privacy Control in your browser, or by e-mailing cityspin11@gmail.com.
- Sensitive personal information: precise geolocation is used solely to provide the service you request; we do not use or disclose sensitive personal information for purposes requiring a "Limit the Use of My Sensitive Personal Information" right.
- You have the rights to know/access, delete, correct, opt out of sale/sharing, and non-discrimination for exercising your rights. You may use an authorized agent. We do not offer financial incentives in exchange for personal information. We have no actual knowledge of selling or sharing personal information of consumers under 16. We disclose each category listed above to service providers for business purposes as described in this policy. We may decline a deletion or other request where the CCPA permits — for example to complete a requested transaction, detect and protect against security incidents or fraud, debug, exercise or defend legal claims, comply with a legal obligation, or for internal uses reasonably aligned with your expectations — and will tell you if we rely on such an exception.
25.3 United Kingdom
For UK users, references to the GDPR include the UK GDPR and the Data Protection Act 2018. You may complain to the Information Commissioner's Office (ICO) — https://ico.org.uk. Transfers from the UK rely on the UK's adequacy and transfer mechanisms, including the UK Addendum to the EU Standard Contractual Clauses and the UK-US Data Bridge where applicable.
25.4 Brazil
For users in Brazil, we process personal data consistent with the Lei Geral de Proteção de Dados ("LGPD", Law No. 13.709/2018). You have the rights set out in Art. 18 LGPD (confirmation, access, correction, anonymization, deletion, portability, information about sharing, and revocation of consent), exercisable via cityspin11@gmail.com. The supervisory authority is the ANPD — https://www.gov.br/anpd/pt-br.
25.5 India
For users in India, we process personal data consistent with the Digital Personal Data Protection Act, 2023, on the basis of your consent or for the legitimate uses recognized by that Act. You may access, correct, and erase your personal data and nominate another person to exercise your rights, and you may raise grievances via cityspin11@gmail.com; we respond within the statutory period.
25.6 Everywhere else
Wherever you are, the commitments in this policy apply. Where your local law grants you data-protection rights, we honor them as that law requires; where it does not, we aim to honor requests of the kind described in Section 22 as a courtesy and at our reasonable discretion, without this creating obligations beyond applicable law.
26. Third-party links, content, and your responsibilities
Narrations and app screens may link to external content — Wikipedia articles, official websites of attractions, Google Maps, our social channels. Once you leave Walk with Isa, the privacy policy of the destination applies. Map tiles displayed in the app are loaded from the map provider's servers, which technically receive your IP address to deliver the tiles.
A few things remain in your hands. Keep the e-mail inbox linked to your account secure — sign-in links grant access to your account, and we are not responsible for access resulting from a compromised inbox or an unattended, unlocked device. Provide accurate information and use Walk with Isa lawfully. Stay aware of your surroundings at all times: narrations, AR, and headphones must never take your attention off traffic, terrain, or other hazards — you are responsible for your own safety while walking. Narrations are AI-generated entertainment (Section 9), not professional, historical, legal, or safety advice. For third-party services we link to or that your operating system provides (e.g. speech recognition, maps, app stores), the third party's terms and privacy policies apply, and we are not responsible for their practices.
27. Changes to this policy
We will update this policy when our product, providers, or the law change. The current version is always available in the app and at our website, with its effective date at the top. For material changes — especially any new purpose of processing — we will notify you in the app or by e-mail before the change takes effect and, where the law requires it, ask for your consent. Where permitted by applicable law, your continued use of Walk with Isa after the effective date of an updated policy constitutes acknowledgment of the update; where the law requires consent for a change, we will obtain it. Earlier versions are available from us on request.
28. Contact
For anything in this policy, your rights, or privacy questions of any kind:
Ulf Kuhn Hauptstr. 56, 63619 Bad Orb, Deutschland E-mail: cityspin11@gmail.com Phone: +372 5354 6281 WhatsApp: https://whatsapp.walkwithisa.com
We're glad you're walking with Isa — and we intend to keep earning that trust.