Privacy Policy

This policy explains which personal data we process in the GeoWunder app and on geowunder.com — pursuant to Articles 13 and 14 of the EU General Data Protection Regulation (GDPR). California residents will find a CCPA / CPRA addendum at the end.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

GeoWunder GmbH
Represented by the managing directors: Damir Orec, Martin Albers, Ulrich Koj
Kirschgartenstr. 6/4, 69126 Heidelberg, Germany
Email: info@geowunder.com

Data-protection inquiries about the GeoWunder app and geowunder.com should be sent to info@geowunder.com.

We are not legally required to appoint a data protection officer.

2. At a glance

The table below summarises which data we process for which purpose. Details follow below.

Data Purpose Legal basis Retention
User ID, optional email, sign-in provider Account, login Art. 6(1)(b) GDPR until account deletion
Location data (GPS) during an active rallye Navigation, waypoint detection, party mode Art. 6(1)(b) GDPR Solo: until rallye is deleted; party: until pin expires (max. ~24h)
Uploaded photos and videos Solving tasks, proof media Art. 6(1)(b) GDPR until rallye or account is deleted
Photo data for AI verification Automated task verification Art. 6(1)(b) GDPR not stored at the AI provider (passed through only)
Topic scan when creating a rallye (on-device text recognition) Deriving the topic from your own material Art. 6(1)(b) GDPR photo: none — never leaves your device; recognised text: until creation completes
Feed posts in group sessions (photos, texts, reactions) Shared session feed, photo/story relays, award ceremony Art. 6(1)(b) GDPR until pin expires (max. ~24h)
Nickname, score, chat messages in party mode Multiplayer gameplay Art. 6(1)(b) GDPR until pin expires (max. ~24h)
Device info, crash reports, usage statistics Stability, product improvement Art. 6(1)(a) GDPR (consent) max. 14 months
Email address for sign-in links Magic-link login Art. 6(1)(b) GDPR transactional, not archived

3. Account and sign-in

You can use GeoWunder anonymously first — a technical device identifier is generated locally. If you sign in, depending on the chosen provider we process:

Processor: Firebase Authentication (Google Ireland Limited / Google LLC).
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Retention: until you delete your account.

4. Location data (GPS)

The core function of GeoWunder is to use your location to guide you between stations of a rallye and automatically detect that you have reached a waypoint. We process your GPS coordinates only during an active session.

4.1 Foreground and background location (iOS)

To reliably capture progress and to enable Live Activities on the lock screen, the app requests the iOS "Always" location permission. We only use background location while a rallye is running. You can revoke this permission anytime in iOS Settings.

4.2 Sharing location in party mode

When you join a group rallye ("party mode"), your current game progress — including your position on the route — is shared with the other participants of the same session. This data lives in a temporary session (pin) and is automatically deleted at the latest about 24 hours after the session ends.

Legal basis: Art. 6(1)(b) GDPR (contract performance); for party mode additionally Art. 6(1)(a) GDPR (consent by joining the session).

5. Uploaded photos and videos

Two distinct types of media can appear when you build and play rallyes — we treat them differently:

5.1 Media uploaded by tour creators

When you build your own rallye, you can upload intro videos, reference images for image tasks, and video task material. These files are stored in our encrypted cloud-storage (Firebase Storage). They are visible only to you and — in group sessions — to fellow players in the same session.

Storage location: Google Cloud Storage, region europe-west6 (Zurich, Switzerland).
Processor: Google Ireland Limited / Google LLC.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete the rallye or your account (server-side account deletion automatically removes these files as well).

5.2 Photo proofs captured while playing (photo missions)

For pure verification photo tasks while playing, you take a picture with the camera or pick one from your library. This image is not stored in our cloud. It is passed through to the AI service for verification only (details in Section 6) and discarded after the analysis. We only store the verification result (solved / not solved) next to your progress, never the image itself.

Legal basis: Art. 6(1)(b) GDPR.
Retention: none — the image leaves our backend as soon as the AI returns the answer.

5.3 Posts in the shared group feed (photos and texts)

Certain group game modes — for example team competitions across multiple routes — include a shared session feed as well as photo and story relays where one team's post becomes another team's task. Photos and short texts you post there are — unlike the verification photos in Section 5.2 — stored in our cloud storage and shown to the other participants of the same session.

Before publication, every post is automatically reviewed by an AI (content safety and, where applicable, task relevance — details in Sections 6 and 24). Without approval the post is not shown; if the review fails for technical reasons, the post is likewise not published as a precaution. At the end of a session, nicknames, post texts, game statistics and individual photos may be sent to the AI service again for a playful "award ceremony" (Section 6).

Storage location: Google Cloud Storage, region europe-west6 (Zurich, Switzerland); fellow players access photos via time-limited access links.
Processor: Google Ireland Limited / Google LLC.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until the session ends, at the latest about 24 hours — posts and photos are deleted automatically together with the session.

5.4 Topic scan when creating a rallye (on-device text recognition)

When creating a rallye, you can optionally photograph your own material (e.g. a worksheet or book page) with the camera, or pick an image from your library, to derive the topic from it. Text recognition (OCR) runs entirely locally on your device (Google ML Kit, on-device processing): the photo is neither stored nor transmitted to us or third parties and is discarded immediately after recognition.

Only the recognised text — which you can fully review, edit and delete before use — is sent to our backend as part of your generation request, just like a topic you typed yourself, and is passed on to the AI service for rallye creation there (Section 6). It is stored briefly in your user area together with the generation job and deleted automatically.

Legal basis: Art. 6(1)(b) GDPR.
Retention of the photo: none — it never leaves your device.

6. AI image and content review

To automatically verify photo tasks, to review group-feed posts before publication (Section 5.3), and for the award ceremony at the end of a group session, we send the respective content (photo or post text; for awards additionally nicknames and game statistics) to an AI service (Google Gemini via Vertex AI). The content is used only for immediate analysis and discarded afterwards; use for training the AI models is contractually excluded.

Recipient: Google Ireland Limited (via Vertex AI).
Processing region: EU — europe-west4 (Netherlands). No third-country transfer of this image data takes place.
Legal basis: Art. 6(1)(b) GDPR.

7. AI tour generation

When you request an AI-generated tour, we send your input (location, theme, target group, difficulty, language) to Google Gemini via Vertex AI. The AI proposes stations, descriptions and tasks. You must not enter personal data of third parties.

The AI's response is stored in your personal rallye library and is visible only to you until you actively share it (e.g. by starting a group session).

Recipient: Google Ireland Limited (via Vertex AI).
Processing region: EU — europe-west4 (Netherlands). No third-country transfer.
Legal basis: Art. 6(1)(b) GDPR.

8. Maps and place data (Google Maps Platform)

To display maps, compute routes and enrich place information we use the Google Maps Platform (Maps SDK, Places API, Routes API). When you use maps, technical data — including your IP address and a coarse location — is transmitted to Google.

We do not persistently store Google Maps Content. Concretely: each tour function call fetches the Maps fields it needs (place name, type classification, photo references, address) fresh from the Places API and discards them afterwards. Our database retains only the identifiers Google explicitly permits to keep indefinitely — place IDs and coordinates — and our own AI-generated enrichments (description texts, mission hints). These AI enrichments are not Maps Content and may be retained for up to 12 months from creation.

Some route and place queries (currently for tours in Germany) are answered by our own servers running OpenStreetMap data (hosted on Google Cloud infrastructure in the Zurich region, Switzerland — the EU Commission has issued an adequacy decision for Switzerland). These requests contain only coordinates and no account data.

Details on Google's processing: policies.google.com/privacy.

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in functional navigation).

9. Multiplayer chat in party mode

In party mode you can send messages to fellow players. These messages are stored within the temporary session and visible only to the participants of the same session.

Chat messages are not moderated in real time. Posts in the shared group feed (Section 5.3), however, are automatically reviewed by an AI before publication; without approval they are not shown to fellow players. If you encounter content that violates our terms or applicable law, use the "Report" function. Reported content is sent to us and reviewed.

Retention: until the session ends, at the latest about 24 hours after.
Legal basis: Art. 6(1)(b) GDPR.

10. Push notifications and Live Activities

During an active game session, GeoWunder can send you push notifications (e.g. when it is your team's turn again). For this we use Firebase Cloud Messaging (FCM) by Google — on Android devices, and for regular notifications on iOS as well. If you allow the app to send push notifications, a device push token is generated and stored together with your session data for the duration of the game session; it is deleted along with that data.

On iOS devices, GeoWunder can additionally show "Live Activities" on the lock screen and in the Dynamic Island so you can see live game information (position, scores) without opening the app. Our backend pushes score updates via the Apple Push Notification service (APNs).

Recipients: Google Ireland Limited / Google LLC (Firebase Cloud Messaging) and Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (APNs).
Third-country transfer: US, EU Standard Contractual Clauses.
Legal basis: Art. 6(1)(b) GDPR; push messages are sent only if you allowed them in system settings.

11. Usage statistics (Firebase Analytics) and crash reports (Crashlytics)

To improve the app, we collect only with your consent anonymous usage events (e.g. "rallye started", "task solved") plus device and version info. Analytics events are linked to your Firebase user ID, never to your real name. We do not profile for advertising and never sell, rent or share your data for marketing.

If the app crashes, Firebase Crashlytics sends a crash report with stack trace, device and version data, and your Firebase user ID to Google. We use this strictly for debugging.

You can revoke your consent at any time under Settings → Privacy → Anonymous usage statistics. No further analytics or crash data will be sent thereafter.

Recipient: Google LLC. For Firebase Analytics there is a joint controllership (Art. 26 GDPR) between us and Google; see firebase.google.com/terms/data-processing-terms.
Retention: 14 months (Firebase Analytics default, configurable), up to 90 days for Crashlytics crash data.
Legal basis: Art. 6(1)(a) GDPR (consent).

12. App verification (Firebase App Check)

To deter abuse of our backend, we use Firebase App Check (Apple App Attest / Google Play Integrity). Device- and installation-specific attestation tokens are generated; no content or personal data is evaluated.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse protection).

13. Email delivery (Resend)

We use Resend to deliver sign-in links and, where applicable, system notifications. We send your email address and the relevant token to Resend.

Recipient: Resend, Inc., 2261 Market Street #4667, San Francisco, CA 94114, USA.
Third-country transfer: US, EU Standard Contractual Clauses.
Legal basis: Art. 6(1)(b) GDPR.

14. In-app purchases

Once GeoWunder leaves the closed beta, certain features ("AI coins") can be acquired via in-app purchase. Payment is handled exclusively by Apple (App Store) and Google (Play Store). We only receive a confirmation of your purchase — never payment data such as card numbers.

During the closed beta, in-app purchases are not active.

Recipients: Apple Inc. (iOS), Google LLC (Android).
Legal basis: Art. 6(1)(b) GDPR.

15. Visiting geowunder.com

When you visit the website, technically necessary data (IP address, date/time, user agent) is recorded in server logs by our hosting provider Google Firebase Hosting, solely to deliver the site and defend against attacks. Fonts (Nunito, Inter) are self-hosted — no transfer to third parties. Legal basis: Art. 6(1)(f) GDPR.

Cookieless reach measurement

We count page views with our own cookieless counter: only aggregated daily counts per page are stored — no IP addresses, no device identifiers, no profiles, no cookies. The data cannot be linked to a person. Legal basis: Art. 6(1)(f) GDPR.

Google Analytics 4 (only with your consent)

If you consent via our cookie banner, we use Google Analytics 4, a web analytics service by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Without consent, no analytics cookies are set. Purpose: reach measurement and improving our offering (pages visited, dwell time, clicks on download and purchase buttons). IP anonymisation is active; advertising features are disabled. Analytics cookies (e.g. _ga) are stored for up to 2 years. Data may be transferred to the USA; Google is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(a) GDPR, § 25(1) German TTDSG. Withdrawal: at any time via “Cookie settings” in the footer — as easy as giving consent.

Sales and contact forms

If you use our sales or feedback form, we process the data you provide (name, email, organisation if given, message) to answer your request. Data is deleted automatically after 90 days unless a business relationship is established. Legal basis: Art. 6(1)(b) GDPR.

Organisation dashboard and license accounts

For organisation licenses (schools, companies) we process the work email address, the role within the organisation and aggregated usage figures (number of AI generations per month). Sign-in to the web dashboard uses a one-time email code; an account may be created in the process. Organisation admins only see whether a member's seat was used in the current month — no individual counters. Legal basis: Art. 6(1)(b) GDPR.

Payment processing via Paddle

Licenses are sold via Paddle.com Market Limited (Judd House, 18–29 Mora Street, London EC1V 8BT, UK) as merchant of record. Paddle processes billing and payment data under its own responsibility; see Paddle’s privacy policy. We do not receive full payment data from Paddle, only contract master data (e.g. subscription status, seats, contact email).

16. Processors and third-country transfer

We rely on the following processors:

Processor Purpose Processing region
Google Ireland Limited (Vertex AI) AI image verification, AI tour generation, pre-publication review of feed posts, award ceremony, place enrichment, embeddings EU — europe-west4 (Netherlands)
Google Ireland Limited / Google LLC (Firebase) Authentication, Firestore, Storage, Cloud Functions, Hosting, App Check, Google Maps Platform Firestore + Storage + Functions: europe-west6; Authentication / Maps / App Check: global Google infrastructure (may include the US)
Google LLC (Crashlytics, Analytics, Cloud Messaging) Crash reports, anonymous usage statistics (opt-in only), push notifications USA
Apple Inc. Push Notification service (APNs), Sign in with Apple, App Store purchases USA
Resend, Inc. Transactional email delivery (sign-in links) USA

Data residency for AI processing: All content we send to Gemini (photos, tour themes, location inputs, free text) is processed exclusively within Vertex AI europe-west4 (Netherlands). This data does not leave the EU.

Data residency for backend: Firestore, Cloud Storage and Cloud Functions are pinned to europe-west6. The authentication and platform components (Firebase Auth, App Check, Maps APIs) are operated by Google as global services and may route requests through US infrastructure.

Remaining third-country transfers (opt-in Crashlytics/Analytics, Apple services, Resend, Google platform components) are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and — where applicable — the EU-US Data Privacy Framework (adequacy decision of 10 July 2023).

17. Retention and deletion

We store personal data only as long as needed for the stated purposes:

When you delete your account in the app (Settings → Delete account), all data tied to your identifier — including uploaded photos and videos and your rallyes — is removed. Orphaned session data under pins is cleaned up by the 24-hour process above.

18. Your rights

Under the GDPR you have the following rights:

Send access and deletion requests informally by email to info@geowunder.com. You can perform account deletion yourself under Settings → Delete account.

19. Competent supervisory authority

For you the competent supervisory authority is generally the one of your German federal state. Ours, as the controller's place of establishment, is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
(State Commissioner for Data Protection and Freedom of Information Baden-Württemberg)
Lautenschlagerstraße 20
70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de

20. Obligation to provide data

Providing data is neither required by law nor by contract. You are not obliged to create an account or use the app. However, without providing the relevant data you can only use the app to a limited extent or not at all.

21. Security (Art. 32 GDPR)

We use technical and organisational measures to protect your data against unauthorised access, loss, or tampering:

22. Children and young people

GeoWunder is intended for users aged 13 and older. We do not knowingly process personal data of children under 13 — this age limit also aligns with the US Children's Online Privacy Protection Act (COPPA). If you become aware that a child under 13 is using our app, please notify info@geowunder.com; we will delete the data without undue delay.

For users between 13 and 15 (Art. 8 GDPR), processing of personal data — in particular optional analytics consent and transfers to third-country processors — is permitted only with the consent of the parents or legal guardians. By accepting this policy, minors confirm that such consent has been obtained.

In a school or educational context, teachers can let their classes use the app anonymously (no personal account) — in that case no real names or email addresses are collected.

23. Cookies and similar technologies

The geowunder.com website does not use cookies and has no tracking, analytics or marketing pixels — with two technically required exceptions: (1) If you start a purchase on the pricing page, we load the checkout library of our payment provider Paddle (Section 14) only at that moment; Paddle may then set strictly necessary cookies (§ 25(2) TTDSG, Art. 6(1)(b) GDPR). (2) The password-protected web dashboard loads technically required Firebase libraries from Google servers. The app stores settings and session data only locally on your device (app sandbox); these are not cookies under § 25 TTDSG (German TDDDG).

24. Automated decisions

Automated AI evaluation of photos serves only the gameplay (task solved / not solved). The automated review of feed posts before publication (Section 5.3) likewise serves only the protection of fellow players and the gameplay; a post that is not approved is simply not shown — you receive an in-app notice with a reason and can contest the decision via the complaint procedure in our Terms of Use (Section 10). There is no automated decision in the sense of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.

25. Law-enforcement requests

We only disclose your data to law-enforcement or other authorities when legally compelled to do so (e.g. by court order). Each request is reviewed for legality and proportionality.

26. Changes to this policy

We may amend this policy when the legal situation or the functions of our app change. Material changes will be announced at least four weeks in advance inside the app. The current version is always available at geowunder.com/en/privacy.


CCPA / CPRA Addendum — California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you additional rights. This addendum supplements the GDPR sections above; in case of conflict, this addendum prevails for California residents.

A. Categories of personal information we collect

In the 12 months preceding the date below we have collected the following CCPA categories of personal information:

We do not collect: government IDs, financial-account info, biometric data, health data, precise religious or political opinions, sexual-orientation data, or genetic data.

B. Sources of personal information

C. Business and commercial purposes

We use the categories above for:

D. Recipients

We share personal information with the following categories of recipients, only to the extent needed for the purposes above:

E. "Sale" or "sharing" of personal information

We do not sell your personal information for monetary or other valuable consideration. We do not share your personal information for cross-context behavioural advertising. We have no signals to honour for the Global Privacy Control (GPC) because we operate no advertising mechanisms.

F. Your California rights

G. How to submit a request

Send a verifiable consumer request by email to info@geowunder.com with the subject "CCPA request". Include enough information so that we can reasonably verify your identity (e.g. the Firebase user ID associated with the request, the email address on file).

You may use an authorized agent to submit a request on your behalf — please attach a signed permission. We will respond within 45 days; if we need more time, we will notify you and extend by up to another 45 days.

H. Shine the Light

California Civil Code §1798.83 lets California residents request information about disclosures we have made of personal information to third parties for their direct marketing purposes. We do not share data for third-party direct marketing, so we have nothing to disclose here.

I. Retention

We retain personal information only as long as needed to provide the service or to comply with legal obligations. See Section 17 above for category-level retention periods.

Last updated: 14 July 2026 · Version 1.3