Privacy Policy
Last updated: 25 July 2026
This policy covers both the Parlawalk app and this website ("we", "us"). Parlawalk is a self-guided audio walking-tour app. We keep data collection to the minimum the product needs to work. We do not require an account, and we never ask for your name, email, or any other personal identifier to use the app.
Who we are
The data controller responsible for your information is Kirill Grabar, an individual based in Spain. You can reach us about privacy at [email protected].
Location (app)
The app uses your device's location to play audio automatically as you approach points of interest, and to generate walking routes. Most location processing happens on your device. When you ask the app to build a route, your current coordinates are sent to our server to find nearby places and shape the route. We use these coordinates only to answer that request — they are not stored and not linked to your identity.
We calculate route geometry using a mapping provider (Mapbox). We send Mapbox only the coordinates of the points of interest on the route — never your own location. Your position stays between your device and our server.
Map tiles are served by OpenFreeMap. Like any map, displaying the map involves requesting the area you are viewing; this does not transmit your device's GPS location and requires no account. Location is never used for advertising.
Where EU/EEA or UK law applies, our legal basis for processing location is your consent, given through your device's location permission, which you can withdraw at any time in your device settings (see "Your choices and rights" below).
Usage analytics (app)
To understand how the app is used and improve it, we record events such as opening the app, or starting and completing a tour. These are tied only to a random identifier generated on your device, which resets if you reinstall the app. We do not collect your name, email, contact details, or precise location with these events. Because the random identifier lets us group several events from the same device, this data is pseudonymous rather than fully anonymous, and we treat it as personal data where data-protection law applies.
Where EU/EEA or UK law applies, our legal basis for this processing is our legitimate interest (GDPR Article 6(1)(f)) in measuring and improving how the app works, balanced against the limited, non-identifying nature of the data.
We keep these events on our server and automatically delete them 90 days after they are recorded.
This website
On this site we measure aggregate engagement — page views, how far people scroll, and which buttons or questions they interact with — to learn what resonates. We do not use tracking cookies, and we do not store any analytics or advertising identifier on your device: each event is tagged only with a random id that exists in memory for that single page load and disappears when you leave, so it cannot follow you across visits or across sites. Tapping a store button records only that a download link was followed and which store it was — it does not collect your email or any contact details, and what you do on Google Play or the App Store afterwards is governed by their own privacy policies. These website events are stored on our server and automatically deleted 90 days after they are recorded, the same as the app analytics.
Who processes your data
We do not sell your data, and we do not share it with anyone for their own purposes. A small number of providers process data on our behalf, strictly to deliver the product:
- Cloudflare, our content-delivery and security network, which routes traffic to our site and server and processes technical request data (including IP addresses) at its edge to deliver content and protect against abuse.
- DigitalOcean, which hosts our backend server (Amsterdam, EU).
- Supabase, our database and storage provider (EU, Ireland), which stores the usage analytics described above.
- Mapbox, which receives only point-of-interest coordinates to calculate route geometry.
- OpenFreeMap, which serves map tiles.
Our backend hosting (DigitalOcean, Amsterdam) and our database (Supabase, Ireland) are located within the EU/EEA, so the usage analytics described above stay within the EEA. Mapbox is based in the United States, and Cloudflare is a US-based provider operating a global network; where processing involves a transfer of personal data outside the EEA/UK — point-of-interest coordinates in Mapbox's case, or technical request data such as IP addresses in Cloudflare's case — that transfer is covered by an appropriate safeguard under GDPR Chapter V, such as the European Commission's Standard Contractual Clauses, together with the provider's own data-processing terms. We enter into a data-processing agreement with each provider that processes personal data on our behalf.
What we do not collect
No accounts, names, email addresses, or phone numbers. No contacts, photos, messages, or calendar data. No advertising identifiers, and no third-party advertising or tracking SDKs.
Security, IP addresses and server logs
All communication between the app, this website, and our servers is encrypted using HTTPS.
As with any internet service, our content-delivery network (Cloudflare), our servers, and our hosting providers necessarily receive your device's IP address in order to deliver and secure responses, and may record it briefly in standard technical logs to operate the service, prevent abuse, and ensure security. These logs are kept only for a short period; in Cloudflare's case, this request data is retained for around 24 hours. We do not use your IP address to determine your location for any feature of the app, to build a profile of you, or to link your activity across services, and we do not combine it with the usage events described above.
Your choices and rights
You can revoke location permission at any time in your device settings; proximity playback and route generation will stop working, but the rest of the app remains usable. Anonymous analytics reset when you reinstall the app and are deleted automatically within 90 days.
If you are in the EU/EEA or UK, you have rights to access, correct, or delete personal data we hold about you, to object to or restrict its processing, to data portability, and (where processing is based on consent) to withdraw that consent at any time without affecting prior processing. Because our usage events are pseudonymous and not linked to your name or contact details, we may be unable to single out your specific records without additional information from you (GDPR Article 11), in which case we will tell you so. For any request or question, contact us at the address below.
You also have the right to lodge a complaint with your local data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk); in the EU/EEA it is the supervisory authority in your country of residence.
Children
Parlawalk is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above, and the updated policy takes effect when posted. If we make a material change to how we use personal data, we will take reasonable steps to highlight it.
Contact
Questions about this policy? Email [email protected].