Privacy Policy
This policy describes what the ilovay mobile app collects, why, who it is shared with, and how to get it deleted. It covers the app and the ilovay backend service.
What we collect, and why
| Data | Why | When |
|---|---|---|
| Account details — email, name, @handle, optional bio and avatar, how you travel, optional vehicle height | To create and run your account, show your profile to other travellers, and plan routes that fit your vehicle | You provide it at sign-up or in Edit profile |
| Password | To sign you in. Stored only as an argon2id hash — we cannot read it | At sign-up |
| Precise location, including in the background | To record a trip as a GPS track, to show you what is nearby, and to navigate | Only while you have started a trip recording, or while a navigation or map screen is open. While recording, a notification is shown for the entire session |
| Photos and videos you take in the app or pick from your gallery | To post Moments and Stories, and to attach media to spots and reviews | Only the files you choose. We do not scan your gallery |
| Content you create — trips, waypoints, spots, reviews, ratings, comments, messages, community membership, follows, bookmarks | To provide the app’s features | As you use them |
| Push notification token | To deliver notifications about follows, messages and activity | When you allow notifications |
| Subscription status — Google Play purchase token, order ID, status, renewal date | To confirm an ilovay Premium subscription is valid and unlock paid features | If you subscribe |
| Usage analytics — which screens you open and a fixed list of actions (signing up, saving a spot, starting a trip), with a pseudonymous app-instance id assigned by Firebase | To see which parts of the app are used and where people get stuck. Never linked to your account: we do not send your user id to Firebase | As you use the app. You can switch it off in Settings, and it stops |
| How you found the app — the Google Play install referrer and the campaign tags of the link you followed | To know which channel a new traveller came from, so we know where to spend effort | Once, on the first launch after you sign in |
| App and device basics — platform and app version, sent with each request; the time you were last active | Diagnosing faults on the build you actually have, and showing other users when you were last online | On every request to our servers |
| Technical logs — IP address, request identifier, timestamps | Security, abuse prevention, and diagnosing faults | On every request to our servers |
What we do not do. ilovay contains no advertising and no advertising ID — the app does not request one, and the permission is stripped from the build. We do not sell personal data, we do not profile you for advertising, and no third party receives your data for its own purposes. As a mobile app, ilovay does not use cookies.
Who your data is shared with
Other users
Your profile, and any content you publish — Moments, Stories, public trips, spots, reviews, comments — are visible to other ilovay users. A trip kept private, or shared only with a community, is not shown publicly. Direct messages are visible to their participants.
Service providers
- DigitalOcean — hosting of the ilovay backend and database, and storage of the photos and videos you upload (DigitalOcean Spaces).
- Google Firebase Cloud Messaging — delivering push notifications.
- Google Firebase Analytics — the usage analytics described above, under a pseudonymous app-instance id and with no user id attached.
- Google Play Billing and Google Play install referrer — processing subscriptions, and telling us which link produced an install. Google, not ilovay, handles your payment details; we never see your card.
- MapTiler — map imagery. Requests for map tiles go from your device to MapTiler.
- openrouteservice (HeiGIT) — route planning. Route coordinates are sent from our server, not from your device, and are not linked to your account when sent.
- OpenStreetMap Nominatim — converting a coordinate into a place name for a trip stop, from our server.
- Anthropic — optional AI-generated summaries of places. Only public information about a place is sent; never your personal data.
We do not share your data with anyone else, except where we are legally required to.
Where your data is stored
In the United States, on servers operated by DigitalOcean in their New York region. If you use the app from outside the United States — including from the EEA or the UK — your data is transferred there.
How long we keep it
Your account data and content are kept until you delete them or delete your account. Technical logs are kept for a short period for security and diagnostics. See below for deletion.
Deleting your data
In the app: Profile → gear icon → Settings → Delete account. You will be asked for your password. Deletion is immediate and cannot be undone.
By email: support@ilovay.com from the address on the account.
A full breakdown of exactly what is and is not removed is on the account deletion page.
Your rights
If you are in the EEA or the UK, the GDPR gives you the right to access, correct, delete, restrict or object to the processing of your personal data, and to receive a copy of it in a portable form. If you are in California, the CCPA gives you comparable rights, including the right not to be discriminated against for exercising them.
Most of these you can exercise directly in the app: Edit profile to correct your details, Settings → Delete account to erase everything. For anything else, write to support@ilovay.com.
We rely on your consent for location and camera access — you can withdraw it at any time in your device settings, and the app continues to work with those features unavailable. Analytics is consent-based in the same way and has its own switch in Settings. For everything else, we rely on the necessity of processing your data to provide the service you asked for.
Children
ilovay is not directed at children under 13 (or the equivalent minimum age where you live), and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
Blocking and reporting
You can report content or another user from the “…” menu on any post, place, route, comment or profile, and block another user from their profile. A block hides your content from them and theirs from you. Reports are reviewed by us and kept even if the reported content is later deleted.
Changes to this policy
If we change it materially we will update the date at the top and, where the change affects how we handle your data, tell you in the app.