WanderWalk privacy policy
Effective 6 September 2026
WanderWalk is a walking audio guide for London. You walk, your phone notices where you are, and when you come within about 40 metres of a place with a story, a short narrated story plays in your ear. We built it for people who cannot help but look, and that same curiosity is why we want to be straight with you about what the app knows, what it keeps, and what it never does. This policy explains, in plain English, what personal data WanderWalk handles, why, and the rights you have over it. It covers the WanderWalk iOS app and the marketing website at https://wanderwalk.app. The short version: your precise location is used mostly on your own device to decide which story to play next. We do not sell your data. Sentry receives crash and technical fault reports by default so we can keep the app working. Optional product analytics goes to PostHog only when you enable Share analytics, which we ask you to choose when you first set up the app and which you can change at any time in Settings. The longer version, with the specifics, follows below.
Who we are and what this covers
WanderWalk is an iOS walking audio-tour app for London, and a marketing website at https://wanderwalk.app. The app is available on the App Store.
WanderWalk is operated by MT-DEVA LIMITED, a company registered in England and Wales (company number 15768175), with its registered office at 71-75 Shelton Street, London, England, WC2H 9JQ. In this policy "we", "us" and "our" mean that company. We are the data controller for the personal data described here, which means we decide what is collected and why, and we are responsible for looking after it.
This policy applies to:
- the WanderWalk iOS app, and
- the wanderwalk.app marketing website.
If you only visit the website and never install the app, only the section on the marketing website and analytics applies to you.
Questions, or want to exercise a right? Email privacy@wanderwalk.app for anything privacy-related, or hello@wanderwalk.app for general queries.
Information we collect
We try to collect as little as possible, and to keep as much as we can on your own device. Here is the full picture.
Precise location (When-In-Use only). WanderWalk uses your device's precise location to work out where you are as you walk, so it can trigger the right story at the right spot, roughly within 40 metres of a place with a story to tell. A few things matter here:
- We request location access When-In-Use only. We never ask for "Always" location.
- During an active walk, location can continue while the app is in the background or your screen is locked, so stories can still play with your phone in your pocket. iOS shows its location indicator while this is happening. Background location stops when you end the walk or after one hour of inactivity.
- This location work happens on your device. Your phone holds the map of stories and decides locally which one to play next. We do not send a stream of your movements to our servers or store a movement history.
- We do not sell your location or share precise location for advertising.
Account information. You can create an account using Sign in with Apple or Google Sign-In. When you do, we receive a basic identifier and, depending on what the provider and you choose to share, an email address and optional display name. We use these details to recognise your account across devices. With Sign in with Apple you may use Apple's private email relay, in which case we never see your real email address.
Subscription and purchase data. WanderWalk+ is sold through Apple's In-App Purchase as a 3-Day Pass, a 7-Day Pass or an annual subscription. Existing monthly subscriptions can continue until the subscriber cancels. RevenueCat manages access for us. We receive purchase status, including whether access is active and when it renews or expires. We never see or store your card details because Apple handles payment.
Free access. Bow Street Police Museum plays in full from anywhere. Other stories have a 20-second preview. Your one-time 15-minute Wander trial starts when GPS triggers your first London story. We store the seconds used against your account so the same trial follows you across devices and survives a reinstall. We do not store a history of where you used it.
Suggested places. If you suggest a place, we receive its exact latitude and longitude, the place name you provide, any optional note and the version of the app you used. We also record our review status for the suggestion. It is linked to your user account while that account exists. If you delete your account, we remove that link but retain the anonymised suggestion as an editorial lead. Please do not put private personal data in the place name or note.
Technical and security data. When the app talks to our backend, for example to confirm your subscription, sync your account, or stream audio, our servers briefly process your device's IP address and basic request information so we can enforce fair-use rate limits, prevent fraud and abuse of our audio, and keep the service secure. The app also uses Apple's App Attest to confirm a request comes from a genuine, unmodified copy of WanderWalk. These produce security signals, not advertising identifiers, and we do not use them to build a profile of you.
Crash and technical-fault reports. Sentry receives crash and technical fault reports by default so we can detect and fix problems that stop the app working properly. A report can include technical details about the app and device, a stack trace, the part of the app where the fault happened, recent diagnostic breadcrumbs naming app actions and, if you are signed in, your account identifier and current subscription tier. These reports do not include advertising identifiers. We do not send Sentry product-usage Logs.
Product analytics (optional). PostHog receives pseudonymous product-usage events, for example that a walk was started or a paywall was viewed, only when you enable Share analytics. We ask you to make that choice during onboarding, when you first set up the app, and you can change it at any time in WanderWalk Settings. We configure PostHog to host this data in the EU. You can turn Share analytics off again at any time. PostHog does not receive advertising identifiers, and we do not sell or use this data to profile you for adverts.
On-device data. Your chosen interest categories, your listening history (which stories you've heard), playback preferences such as speed, and cached audio for offline play are stored on your device. If you have an account, your interests and listening history may also be saved to your account so the experience follows you to a new device. Cached audio simply lets a story keep playing once it's downloaded, even when your signal is patchy.
We do not collect contacts, photos, microphone audio or health data.
How we use your information
We use the data above only for the purposes described here. Specifically:
- Play the right story in the right place: your precise location, used on-device, decides which nearby story to trigger as you walk and ranks free-roam stories to the interests you've picked.
- Recognise your account, so your interests, listening history and WanderWalk+ access can follow you across devices.
- Unlock WanderWalk+: subscription and pass status from Apple and RevenueCat tells the app to unlock every story, all curated walks and full free roam.
- Remember your preferences, including the categories you lean into, playback speed and which stories you've already heard.
- Review suggested places as editorial leads for possible new stories.
- Keep the service secure and prevent abuse, using IP-based rate limits and App Attest checks so our audio is not scraped or abused.
- Detect and fix technical faults: Sentry's default crash and technical-fault reports help us find problems that stop the app working properly.
- Improve the app with optional product analytics: PostHog product-usage events help us understand which features people use and decide what to build, but only when you enable Share analytics.
We do not sell personal data or make decisions about you using solely automated processing that produces legal or similarly significant effects.
Legal bases for processing (UK and EU GDPR)
Under UK GDPR and EU GDPR we must have a lawful basis for each use of your personal data. Ours are:
- Performance of a contract, providing the core app: triggering stories from your location, running your account, applying the free trial and unlocking WanderWalk+ when you subscribe or buy a pass. Without this processing, the app simply cannot do what you installed it to do.
- Consent, for sending optional product-analytics data to PostHog. PostHog stays off unless you enable Share analytics, which we offer during onboarding and in Settings, and you can withdraw consent without losing access to WanderWalk.
- Legitimate interests, detecting and fixing crashes and technical faults through Sentry, keeping the app and our audio secure and preventing fraud and abuse, reviewing suggested places to improve our catalogue, understanding cookieless aggregate usage of our marketing website so we can improve it, and measuring OpenAI ads on /how-it-works/, /pricing/ and /walks/ so we can attribute installs, trials and purchases. We balance these interests against your rights, do not send Sentry product-usage Logs and keep the processing minimal.
Where we rely on consent, you can withdraw it at any time. Where we rely on legitimate interests, you have the right to object, see Your rights below.
Third parties and processors we use
We keep the list of companies that touch your data short, and we only use reputable providers for the purposes described here. Here is everyone, and why:
- Apple, Sign in with Apple and In-App Purchase for WanderWalk+. Apple handles payment; we never see your card details.
- Google (Google Sign-In), an optional way to sign in. We receive a basic identifier and, if shared, your email and display name; this is standalone Google Sign-In for authentication, not advertising.
- RevenueCat, manages subscription and pass state on our behalf so the app knows what to unlock. It processes purchase status, not payment card data.
- Sentry, receives crash and technical-fault reports by default so we can detect and fix problems under our legitimate interests. It does not receive advertising identifiers or product-usage Logs.
- PostHog, receives pseudonymous product-usage events only when you enable Share analytics in the app. On /download it receives an anonymous, cookieless pageview. On /how-it-works/, /pricing/ and /walks/ it stores first-touch OpenAI click identifiers on a person profile and landing pageview so later app install, trial and purchase events can be attributed. We host this data in the EU. PostHog does not receive advertising identifiers, and we do not sell this data.
- Cloudflare, our backend runs on Cloudflare Workers. Cloudflare D1 stores your account record, chosen interests, listening history, trial state, suggested places and WanderWalk+ entitlement; Cloudflare KV serves the story catalogue; and Cloudflare R2 serves the audio your app downloads. Cloudflare also provides cookieless website analytics.
- Ahrefs, provides cookieless Web Analytics and technical site auditing so we can understand aggregate website traffic, including referring sources, and find SEO problems.
- OpenAI, provides the Measurement Pixel on /how-it-works/, /pricing/ and /walks/ so we can measure OpenAI ads and attribute later app installs, trials and purchases. On those pages we store first-touch click identifiers in first-party cookies named __oppref and __obref. The pixel may also set those cookies.
We do not sell your personal data or share it for third-party advertising.
The marketing website and analytics
Our website at https://wanderwalk.app tells you about the app and where to download it.
On /how-it-works/, /pricing/ and /walks/, including each walk page, we run the OpenAI Measurement Pixel. We use it to measure visits from OpenAI ads and to attribute later app installs, trials and purchases. Those pages store first-touch OpenAI click identifiers in first-party cookies named __oppref and __obref, and in local storage, so later browser and server conversion events can reuse them. The pixel may also set those cookies.
On those same pages, PostHog stores the first-touch oppref and __obref values on the visitor's person record and on the landing pageview. We keep the first values we see. Later visits do not overwrite them. Later app events can then be attributed to the original OpenAI ad click. Those events include Application Installed, trial_started and rc_initial_purchase_event. PostHog on these pages uses person profiles. It does not use autocapture, session recording or feature flags. We host this PostHog data in the EU.
Cloudflare Web Analytics and Ahrefs Web Analytics stay cookieless across the site. They give a basic count of visits, pages and referring sources. The /download page also sends a cookieless PostHog pageview so we can compare download-page visits with app activation. PostHog autocapture, feature flags and session recording stay off on the website.
The rest of the site does not run the OpenAI pixel. We keep this use of website measurement under review and will update this policy if it changes.
How long we keep your data
We keep data only as long as we need it:
- Location for triggering stories is used in the moment on your device and is not retained by us as a history of your movements.
- Account data, including your identifier, email or display name if shared, interests, listening history, is kept while your account exists. Delete your account and we delete this data, except anything we're legally required to keep for a limited period.
- Suggested places are linked to your account while it exists. When you delete the account, we remove that link and retain the suggestion anonymously as an editorial lead.
- Subscription and pass records are retained as needed to manage your access and meet Apple's and our legal and accounting obligations.
- Security and rate-limit data, including short-lived IP-based counters, is kept only as long as needed to enforce limits and protect the service, then aged out.
- Sentry crash and technical-fault reports are kept only for as long as they are useful for detecting, investigating and fixing faults, then aged out in line with our Sentry retention settings.
- Optional PostHog product-analytics data is kept only for as long as it is useful for understanding and improving the app, then aged out in line with our PostHog retention settings.
- On-device data, including preferences, cached audio and local history, stays on your device until you clear it, delete the app or it's evicted from the cache. Deleting the app removes this local data from your device.
International transfers
Some of our providers, including Apple, Google, RevenueCat, Sentry, PostHog, Cloudflare, Ahrefs and OpenAI, operate globally, so your data may be processed outside the UK or the European Economic Area.
Where that happens, we rely on appropriate safeguards recognised under UK and EU GDPR, such as the UK International Data Transfer Agreement or Addendum, the European Commission's Standard Contractual Clauses, or transfers to countries with an adequacy decision, so your data gets a comparable level of protection wherever it's handled. You can ask for a copy of the transfer safeguards that apply to your data by emailing privacy@wanderwalk.app.
Your rights
Under UK and EU GDPR you have rights over your personal data, including the right to:
- access a copy of the personal data we hold about you;
- rectify data that's inaccurate or incomplete;
- erase your data ("the right to be forgotten");
- restrict or object to certain processing, including processing based on legitimate interests;
- receive your data in a portable format (data portability);
- withdraw consent at any time where we rely on it.
You can withdraw product-analytics consent at any time by turning off Settings > Share analytics. This stops new PostHog product-usage events and does not affect the rest of WanderWalk. Sentry's default crash and technical-fault reports rely on our legitimate interests rather than consent. You have the right to object to that processing by emailing privacy@wanderwalk.app; we will consider your circumstances and respond as the law requires.
Deleting your account is built in. You can do it at any time in the app: open Settings, choose Delete Account and confirm. This permanently removes your account record, chosen interests, listening history from our servers. If you submitted a suggested place, we remove its link to your account and retain the suggestion anonymously as an editorial lead. You can also email privacy@wanderwalk.app and we'll handle the request for you.
To exercise any other right, email privacy@wanderwalk.app. We'll respond within the timeframes the law requires, normally one month. Using these rights is free, and we will not penalise you for it. If you're in the United States, see the section on US and California privacy rights below.
If you think we've mishandled your data, you can complain to a supervisory authority. In the UK that's the Information Commissioner's Office (ico.org.uk); in the EU it's your local data protection authority. We'd appreciate the chance to put things right first, so do get in touch.
Your US and California privacy rights (CCPA/CPRA)
If you live in the United States, and in particular in California, you have specific privacy rights. This section explains them and how they apply to WanderWalk.
The personal information we handle about you falls into these categories: identifiers, such as an account identifier, email and display name if shared; commercial information, such as your WanderWalk+ purchase status; internet or app activity, such as default crash and technical-fault reports, optional product-usage events; user-provided content in suggested places; and geolocation. Precise location is normally processed only on your device to trigger stories and is not collected into a movement history. If you suggest a place, we receive the single precise coordinate you choose to submit.
We do not sell or share your personal information for cross-context behavioural advertising. We do not use or disclose your precise geolocation or any other sensitive personal information for advertising.
Your rights include the right to know and access the personal information we hold, the right to delete it, the right to correct it, the right to opt out of sale or sharing, and the right not to be discriminated against for exercising any of these rights.
To exercise these rights, delete your account in the app (Settings, then Delete Account) or email privacy@wanderwalk.app. We will verify your request through your account and will not charge you or treat you differently for asking. You may use an authorised agent where the law allows.
Children
WanderWalk is not directed at children under 13, and we do not knowingly collect personal data from them.
If you believe a child under 13 has provided us with personal data, please contact privacy@wanderwalk.app and we'll delete it.
Security
We take sensible steps to protect your data. Payments and subscriptions run through Apple's secure In-App Purchase system, so we never handle your card details. Connections between the app, our backend and our providers are encrypted in transit. We keep as much as we can on your device, and we limit access to account data to what's needed to run the service.
No system is perfectly secure, but we design WanderWalk to collect little, share less, and guard what it does hold. If a breach affecting your personal data ever occurs, we will act promptly and notify you and the relevant authorities where the law requires it.
Changes to this policy
As the app grows, more stories, more cities, new features, we may update this policy. When we make a material change, we'll update the effective date below and, where appropriate, let you know in the app or on the website. We will not reduce your rights under this policy without your consent where the law requires it.
Effective date: 6 September 2026. We'd encourage you to check back from time to time.
Contact us
For privacy questions or to exercise any of your rights:
- Privacy and data requests: privacy@wanderwalk.app
- General enquiries: hello@wanderwalk.app
- Postal: MT-DEVA LIMITED, 71-75 Shelton Street, London, England, WC2H 9JQ
We read these, and we'd rather hear from you than have you wondering.