Privacy Policy
How I handle your data — in plain English, and in full legal detail.
✋ The short version (what actually matters)
- I collect only what I need: your name, email address, city, and the profile info you choose to share.
- I never use your real location. Your position on the map is based solely on the city you set in your profile settings — it is approximate (within a couple of kilometres of the city centre) and never derived from GPS or device location.
- I don't sell your data. Not to anyone. Ever.
- Photos stay mine to delete: if you delete your account, your photos are deleted too.
- Deleting a trip schedules chat deletion: messages are automatically deleted 3 days after a trip is deleted or completed. You can also delete them immediately when deleting a trip.
- Completed trips stay on record for both the traveller and guide so you can leave reviews. You can delete them manually at any time.
- Leaderboard entries are anonymous: only your first name and trip count are shown. When you delete a trip you can opt out of having it counted. Your leaderboard entry is removed automatically when you delete your account.
- Deleting your account deletes your profile, trips, messages, and reviews. There is no going back.
- Push notifications are optional. You can turn them off any time in Settings.
- Tip links are external. If a guide adds a PayPal.me link to their profile, tapping "Tip your guide on PayPal" takes you directly to PayPal. I do not process, store, or take any cut of payments — the transaction is entirely between you and the guide on PayPal.
- Profile photos are only visible to logged-in users. Visitors who are not signed in cannot see any profile pictures.
- I cannot be held responsible for technical failures: bugs, outages, data loss caused by third-party infrastructure, or security incidents that are outside my reasonable control.
- Google login only gives me your name, email, and profile picture. I don't get access to anything else in your Google account.
- Apple login only gives me your name and email address. No profile picture is shared. Apple may provide a private relay email address instead of your real one — this is fine and works exactly the same.
- Want a copy of your data? Email info@you-in-town.com and I'll send you everything I hold about you.
- Questions? Email me at info@you-in-town.com and I'll answer in plain language.
Last updated: 10 June 2026
1. Controller
The controller within the meaning of the GDPR is:
Fernando Schwarz, Austria.
Contact: info@you-in-town.com
A postal address will be added shortly pending confirmation of a registered P.O. box.
2. Data I collect and why
2.1 Account data
When you register, I collect your name and email address. If you register with Google, I also receive your Google profile picture. If you register with Apple, I receive your name and email address only (no profile picture); Apple may provide a private relay email address in place of your real one. Legal basis: Article 6(1)(b) GDPR (performance of a contract).
2.2 Profile data
You may optionally provide a bio, city, languages spoken, and a profile photo. This data is visible to other logged-in users only. Profile photos are not shown to visitors who are not signed in. Legal basis: Article 6(1)(a) GDPR (consent).
Your approximate position on the map is derived solely from the city you enter in your profile settings. I do not access, request, or store your device's GPS or precise location at any point.
2.2b Feedback submissions
If you use the "Feedback & suggestions" feature, your message and your account email address are stored and shared with the developer to review and act on your feedback. This data is not shared with any third party. Legal basis: Article 6(1)(a) GDPR (consent).
2.2c Tip links
Guides may optionally add a PayPal.me link to their profile. This URL is stored in your profile and displayed to travellers on completed trips. I do not process any payments and have no access to your PayPal account. All transactions take place on PayPal. Legal basis: Article 6(1)(a) GDPR (consent). You can remove your PayPal.me link at any time via your profile settings.
2.3 Trip and message data
Trips you post (destination, dates, notes) and messages you exchange with other users are stored to provide the core service. Legal basis: Article 6(1)(b) GDPR.
2.4 Push notification subscriptions
If you enable push notifications, your browser's push subscription endpoint is stored. This data is used solely to deliver notifications to your device. Legal basis: Article 6(1)(a) GDPR (consent). You can withdraw consent at any time via Settings.
2.5 Technical data
Server logs may record IP addresses and request metadata for security and debugging purposes. These are retained for a maximum of 30 days. Legal basis: Article 6(1)(f) GDPR (legitimate interest).
3. Data sharing
I do not sell, rent, or share your personal data with third parties for marketing purposes.
Your profile (name, city, bio, photo) is visible to other logged-in users of the platform. In public listings — such as the home page, guide cards, and community stats — only your first name is shown. Your full name is only visible when another logged-in user opens your profile page directly.
The platform is hosted on Fly.io (infrastructure provider). Fly.io processes data on my behalf under a data processing agreement. Their privacy information is available at fly.io/legal/privacy-policy.
If you use Google login, Google processes authentication data under their own privacy policy. If you use Apple login, Apple processes authentication data under Apple's privacy policy.
4. Data retention
I retain your data for as long as your account is active. You may delete your account at any time via Settings, which permanently removes your profile, trips, messages, reviews, and leaderboard entries.
When a trip is deleted or marked complete, the associated chat messages are automatically deleted after 3 days. You may also choose to delete the chat immediately when deleting a trip.
Completed trip records remain visible to both the traveller and guide for the purpose of leaving reviews. They can be deleted manually at any time from the My Trips or Guide pages.
The leaderboard displays only your first name and trip count. When deleting a trip you may choose whether it continues to count on the leaderboard. Opting out removes that trip's contribution. Deleting your account removes all leaderboard entries associated with your email.
5. Your rights
Under the GDPR, you have the right to:
- Access the personal data I hold about you
- Rectify inaccurate data (via your profile settings)
- Erasure ("right to be forgotten") — request deletion of your account and all associated data
- Restriction of processing in certain circumstances
- Data portability — request a copy of your data
- Object to processing based on legitimate interest
- Withdraw consent at any time (e.g., push notifications)
To exercise any of these rights, contact me at info@you-in-town.com. I will respond within 30 days.
You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde) at dsb.gv.at.
6. Cookies and local storage
I use a session cookie for authentication and browser localStorage to remember your notification preferences. I do not use advertising or tracking cookies.
7. Limitation of liability
The operator makes reasonable efforts to keep the platform secure and available, but cannot guarantee uninterrupted or error-free operation. To the fullest extent permitted by applicable law, the operator accepts no liability for:
- Temporary unavailability, bugs, or technical errors on the platform;
- Loss of data caused by failures of third-party infrastructure providers (e.g. hosting, database services);
- Security incidents — including unauthorised access, data breaches, or cyberattacks — that are beyond the operator's reasonable control, provided that reasonable security measures were in place.
This limitation does not affect any rights you may have under mandatory applicable law.
8. Changes to this policy
If I make material changes to this policy, I will notify users via a notice on the platform. The "last updated" date above will always reflect the current version.