We collect what the app needs, keep precise evidence restricted, respect your visibility choices, never sell your data and give you export and deletion controls.
1. Information we handle
Account information includes your email address, public handle, authentication provider references, profile choices, consent history and secure session/device records. Social information includes relationships, clubs, comments, reactions, reports and the visibility you choose.
A visit can include point ID, capture time, location samples, reported accuracy, a fresh proof photo, your note and server verification evidence. We strip unnecessary photo metadata before ordinary display. We do not publish your exact live position by default.
We also process subscription entitlement events from Apple or Google, push tokens and preferences, support conversations, safety reports and limited security/diagnostic events.
2. Why we use it
We use data to provide the map and offline catalogue; authenticate accounts; verify and synchronise visits; calculate collections, achievements and eligible rankings; run social and club features; reconcile Premium access; deliver requested notifications; prevent abuse; moderate content; answer support; and keep the service secure and reliable.
Marketing notifications require the relevant choice. Product operation, safety, fraud prevention and legal obligations are kept distinct from marketing consent.
3. Visibility and location controls
Profiles and individual visits can be public, friends-only or private. Clubs can be public, private or invite-only. Leaderboard participation has a separate opt-out and minimum privacy thresholds.
Verification evidence may be more precise than content you choose to share. Precise samples are restricted to the verification, integrity, appeal and authorised support purposes that require them. Blocking and muting affect search, feeds, comments, mentions and notifications according to the product rules.
5. Retention
We keep account and product data while your account is active and then delete or anonymise it according to the account-deletion workflow. Proof media and precise evidence use documented operational and appeal periods rather than indefinite retention.
Limited transaction, consent, security, moderation and audit records may remain for fraud prevention, dispute handling or legal duties. Backup copies expire on a controlled cycle and are not restored to ordinary product use after deletion.
6. Your choices and rights
The app lets you change privacy and notification preferences, revoke device sessions, export your data and request account deletion. Depending on where you live, you may also have rights to access, correct, restrict, object, port or erase personal data and to complain to a data-protection authority.
Use support for a privacy question or the verified deletion process if you cannot access the app. We verify identity before releasing or deleting account data.
7. Security and international processing
We use access controls, secure transport, protected device storage, restricted evidence access, audit trails and service-boundary safeguards. No system can promise absolute security; suspected incidents are investigated and notified where required.
If a provider processes data outside the United Kingdom, we use an appropriate transfer mechanism and assess the relevant protection.
8. Changes and contact
Material changes are explained in the app or by email where appropriate, with a new effective date. Contact the privacy team through Peak Quest support. The responsible operator and postal contact are identified in the live app-store listing and account settings.