Legal
Privacy Policy
What WayFinder processes
Camera image
When you press the analysis button, ask a visual question, or open navigation after enabling "start navigating on launch," the app takes one photo and sends it over encrypted HTTPS to the WayFinder backend. The backend sends that photo to Google's Gemini API to produce a scene description. WayFinder does not continuously record video.
WayFinder does not write the raw photo to its server database or durable application storage. The camera plugin creates a temporary device file for upload and the app deletes it after the request, although an operating-system cache may survive a crash. Google's processing is governed by the Gemini API Additional Terms and Google Privacy Policy. The production service uses a billing-enabled Gemini API project so Paid Services data terms apply.
Voice questions
Your device's operating-system speech recognizer converts speech to text. WayFinder sends the resulting text to the backend. WayFinder does not send or store raw microphone audio.
Account and history
Firebase Authentication provides a stable account identifier and may provide your email address, display name, and sign-in provider. WayFinder stores your question, derived response, confidence and grounding metadata, timestamps, request identifiers, and model-usage accounting. It does not collect device location or request location permission, but question text or a visible sign can contain a place name or address.
Why the data is used
- To describe the requested scene and answer a question about it.
- To keep each user's history isolated.
- To enforce rate limits and the lifetime analysis quota.
- To diagnose reliability and safety failures without logging photos, tokens, or question text.
WayFinder does not sell personal data, show advertising, or use user data to train its own models.
Retention and deletion
Interaction history and duplicated response text used for idempotent retries are scheduled for deletion after 30 days. Non-content lifetime usage accounting remains until account deletion. You can erase history and duplicated ledger response text at any time inside the app. Deleting your account erases messages, sessions, model-usage records, rate-limit state, and the scene memory in the handling process, then requests deletion of the Firebase identity. Other running processes can retain isolated scene facts for at most 30 seconds. We retain only an irreversible hash of the former account identifier to serialize deletion against already in-flight writes. If Firebase proves that identity deletion failed, the app reports the partial failure and allows a retry. If Firebase's status cannot be determined safely, the write barrier remains and support is required. Encrypted Cloud SQL backups may retain deleted rows until their configured expiration, but are not available through the product and are removed through backup expiry.
Security
Traffic is encrypted in transit. Protected API routes require a Firebase ID token, and inference routes enforce Firebase App Check. Stored records are scoped by Firebase UID. Production secrets are held in Google Secret Manager, and the database is encrypted at rest by Google Cloud.
Children
WayFinder is not directed to children under 13. If you believe a child provided personal data, contact us so it can be deleted.
Contact
Email support@way-finder.tech.