Privacy Policy
Last updated: 2 August 2026
This policy covers both the Parlawalk app and this website ("we", "us"). Parlawalk is a self-guided audio walking-tour app. We keep data collection to the minimum the product needs to work. We do not require an account, and we never ask for your name, email, or any other personal identifier to use the app.
Who we are
The data controller responsible for your information is Kirill Grabar, an individual based in Spain. You can reach us about privacy at [email protected].
Location (app)
The app uses your device's location to play audio automatically as you approach points of interest, and to generate walking routes. Most location processing happens on your device. When you ask the app to build a route, your current coordinates are sent to our server to find nearby places and shape the route. We use these coordinates only to answer that request — they are not stored and not linked to your identity.
We calculate route geometry using a mapping provider (Mapbox). We send Mapbox only the coordinates of the points of interest on the route — never your own location. Your position stays between your device and our server.
Map tiles are served by OpenFreeMap. Like any map, displaying the map involves requesting the area you are viewing; this does not transmit your device's GPS location and requires no account. Location is never used for advertising.
Where EU/EEA or UK law applies, our legal basis for processing location is your consent, given through your device's location permission, which you can withdraw at any time in your device settings (see "Your choices and rights" below).
Usage analytics (app)
To understand how the app is used and improve it, we count events such as opening the app, starting, finishing or abandoning a tour, and which points of interest get played. The app stores no identifier on your device and sends none with these events, so they can only ever be added up — never grouped into one person's activity, and never linked to you or to each other.
A point of interest can be played either by walking up to it or by tapping it on the map, and we deliberately do not record which of the two happened — so no entry ever says that anyone was actually in a particular place. These events are dated only to the day.
When something fails — for example when a walking route cannot be generated — the app sends a short failure report so we can find and fix the problem. It contains the error message and the HTTP status code, and nothing else: no location, no identifier, and nothing about you or your device.
Since nothing in these events identifies a person or a device, they are anonymous statistics rather than personal data. We keep them on our server and automatically delete them 90 days after they are recorded.
This website
On this site we measure aggregate engagement — page views, how far people scroll, and which buttons or questions they interact with — to learn what resonates. We do not use tracking cookies, and we do not store any analytics or advertising identifier on your device: each event is tagged only with a random id that exists in memory for that single page load and disappears when you leave, so it cannot follow you across visits or across sites. Tapping a store button records only that a download link was followed and which store it was — it does not collect your email or any contact details, and what you do on Google Play or the App Store afterwards is governed by their own privacy policies. These website events are stored on our server and automatically deleted 90 days after they are recorded, the same as the app analytics.
Who processes your data
We do not sell your data, and we do not share it with anyone for their own purposes. A small number of providers process data on our behalf, strictly to deliver the product:
- Cloudflare, our content-delivery and security network, which routes traffic to our site and server and processes technical request data (including IP addresses) at its edge to deliver content and protect against abuse.
- DigitalOcean, which hosts our backend server (Amsterdam, EU).
- Supabase, our database and storage provider (EU, Ireland), which stores the usage analytics described above.
- Mapbox, which receives only point-of-interest coordinates to calculate route geometry.
- OpenFreeMap, which serves map tiles.
Our backend hosting (DigitalOcean, Amsterdam) and our database (Supabase, Ireland) are located within the EU/EEA, so the usage analytics described above stay within the EEA. Mapbox is based in the United States, and Cloudflare is a US-based provider operating a global network; where processing involves a transfer of personal data outside the EEA/UK — point-of-interest coordinates in Mapbox's case, or technical request data such as IP addresses in Cloudflare's case — that transfer is covered by an appropriate safeguard under GDPR Chapter V, such as the European Commission's Standard Contractual Clauses, together with the provider's own data-processing terms. We enter into a data-processing agreement with each provider that processes personal data on our behalf.
What we do not collect
No accounts, names, email addresses, or phone numbers. No contacts, photos, messages, or calendar data. No advertising identifiers, and no third-party advertising or tracking SDKs.
Security, IP addresses and server logs
All communication between the app, this website, and our servers is encrypted using HTTPS.
As with any internet service, our content-delivery network (Cloudflare), our servers, and our hosting providers necessarily receive your device's IP address in order to deliver and secure responses, and may record it briefly in standard technical logs to operate the service, prevent abuse, and ensure security. These logs are kept only for a short period. We do not enable request logging on Cloudflare and receive no request logs from them; Cloudflare's own retention of the technical data it processes at its edge is governed by its privacy policy. We do not use your IP address to determine your location for any feature of the app, to build a profile of you, or to link your activity across services, and we do not combine it with the usage events described above.
Your choices and rights
You can revoke location permission at any time in your device settings; proximity playback and route generation will stop working, but the rest of the app remains usable. Usage statistics are deleted automatically within 90 days.
If you are in the EU/EEA or UK, you have rights to access, correct, or delete personal data we hold about you, to object to or restrict its processing, to data portability, and (where processing is based on consent) to withdraw that consent at any time without affecting prior processing. In practice we hold almost nothing to act on: the app stores no identifier and sends none, so our usage statistics cannot be traced back to you or to your device, and there is no record for us to look up, export, or erase. For any request or question, contact us at the address below.
You also have the right to lodge a complaint with your local data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk); in the EU/EEA it is the supervisory authority in your country of residence.
Children
If you are under 18, you should use Parlawalk only with the involvement of a parent or guardian. The app stores no identifier and sends none, so we hold no personal data about children. If you believe we hold personal data about a child, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above, and the updated policy takes effect when posted. If we make a material change to how we use personal data, we will take reasonable steps to highlight it.
Contact
Questions about this policy? Email [email protected].