Back to Home

Privacy Policy

Last Updated: March 7, 2026 · Effective Date: January 5, 2026

1. Introduction

OxGuide ("we," "our," or "us") operates the OxGuide mobile application and website (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and ensuring transparency about our data practices. Please read this Privacy Policy carefully. By using the Service, you consent to the practices described herein.

Contact Email: hello@oxguide.com

2. Information We Collect

2.1 Information You Provide

Account Information:

  • Email address
  • Display name
  • Password (encrypted, never stored in plain text)
  • Authentication method (email/password, Google Sign-In, or Apple Sign-In)

Purchase Information:

  • Transaction history for in-app purchases
  • Subscription status and expiration dates
  • Payment processing is handled entirely by Apple App Store or Google Play Store; we do not collect or store payment card details

AI Guide Conversations:

  • Messages you send to our AI Guide
  • Conversation history for context continuity
  • Landmark-specific chat threads

2.2 Information Collected Automatically

Location Data:

  • Precise location (GPS coordinates) when you grant permission
  • Used for: navigation, nearby landmark detection, map positioning
  • Location data is processed in real-time and not permanently stored on our servers

Camera Data:

  • Camera access for landmark detection feature
  • Images are processed on-device using machine learning
  • We do not store, transmit, or retain any images or video from your camera

Device Information:

  • Device type and model
  • Operating system version
  • Unique device identifiers (for analytics and crash reporting)
  • App version

Usage Data:

  • Features accessed and frequency of use
  • Navigation routes and landmarks visited
  • App performance metrics
  • Crash reports and error logs

Partner Attribution Data:

  • On Android, we may read the Play Store install referrer to determine if you installed the app via a partner link
  • On iOS and as a fallback on Android, we may read your device clipboard once at first launch to check for a partner attribution code
  • Attribution data (partner ID, timestamp) is stored to credit the referring partner. No other clipboard content is collected or stored

2.3 Information from Third Parties

We may receive information from third-party services you use to sign in. Google Sign-In: Email address, display name, profile picture URL. Apple Sign-In: Email address, display name.

3. How We Use Your Information

PurposeLegal Basis (GDPR)
Provide navigation and tour guide servicesContract performance
Process in-app purchases and subscriptionsContract performance
Deliver AI-powered landmark informationContract performance
Send service-related communicationsLegitimate interest
Improve app functionality and user experienceLegitimate interest
Analyze usage patterns and fix bugsLegitimate interest
Prevent fraud and ensure securityLegitimate interest
Comply with legal obligationsLegal obligation

4. Data Sharing and Disclosure

4.1 Third-Party Service Providers

We share data with the following service providers who process data on our behalf:

ServicePurposeData Shared
Firebase (Google)Authentication, database, analyticsAccount data, usage analytics
MapboxMaps and navigationLocation data (anonymized)
Google Places APIPlace information and photosLocation queries
RevenueCatSubscription managementPurchase data, user ID
GroqAI model inferenceChat messages, landmark context
LangChain / LangGraphAI conversation orchestrationChat messages, landmark context
LangSmithAI conversation tracingChat messages, metadata
TavilyWeb search for landmark infoSearch queries
Amazon Polly (AWS)Text-to-speech narrationAI-generated descriptions
Fly.ioCloud hosting for AI backendChat messages in transit
Google Sign-InAuthentication via Google accountEmail, display name, profile picture URL
Apple Sign-InAuthentication via Apple accountEmail, display name
Android Play Install ReferrerPartner attribution trackingInstall referrer URL (partner ID if via partner link)

4.2 We Do NOT:

  • Sell your personal information to third parties
  • Share your data for third-party advertising purposes
  • Use your AI conversations to train external AI models
  • Share your precise location with advertisers

4.3 Legal Disclosures

We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety.

5. Data Retention

Data TypeRetention Period
Account informationUntil account deletion + 30 days
AI conversation history12 months, or until you delete it
Purchase/transaction records7 years (legal/tax requirements)
Usage analytics26 months (anonymized after 14 months)
Location dataNot stored; processed in real-time only
Camera/image dataNot stored; processed on-device only

6. Data Security

  • Encryption in transit: All data transmitted using TLS 1.2+
  • Encryption at rest: Sensitive data encrypted in databases
  • Authentication: Secure token-based authentication via Firebase
  • Access controls: Limited employee access on need-to-know basis
  • Regular audits: Periodic security reviews and updates

While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

7. Your Rights and Choices

7.1 All Users

You have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete your account and associated data
  • Withdraw consent for optional data collection
  • Disable location or camera permissions via device settings

7.2 European Economic Area (EEA) Users -GDPR Rights

If you are in the EEA, you have additional rights under the GDPR:

  • Right to erasure ("right to be forgotten")
  • Right to data portability
  • Right to restrict processing
  • Right to object to processing based on legitimate interests
  • Right to lodge a complaint with your local data protection authority

Data Controller: OxGuide
Contact for GDPR requests: hello@oxguide.com

7.3 California Residents -CCPA Rights

If you are a California resident, the CCPA provides you with:

  • Right to know what personal information we collect and how it's used
  • Right to delete your personal information
  • Right to opt-out of the sale of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your privacy rights

To exercise CCPA rights: Email hello@oxguide.com with subject "CCPA Request"

8. International Data Transfers

Your data may be transferred to and processed in countries outside your residence, including the United States, where our service providers operate.

For EEA users, we ensure appropriate safeguards through Standard Contractual Clauses (SCCs) with service providers, adequacy decisions where applicable, and your explicit consent for certain transfers.

9. Children's Privacy

OxGuide is not intended for children under 13 years of age (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at hello@oxguide.com.

10. How to Delete Your Data

Delete Specific Data Types

You can request deletion of specific data without deleting your entire account. Email hello@oxguide.com with any of the following subject lines:

Data TypeEmail SubjectWhat Gets Deleted
AI Conversations"Delete Chat History Request"All AI guide conversation history and chat threads
Saved Lists"Delete Saved Lists Request"All saved places lists and itineraries
Navigation Data"Delete Navigation Data Request"Navigation history, route data, and location history
App Preferences"Delete Preferences Request"All app settings, analytics consent, and cached data

Delete Your Account

Option 1: In-App Deletion

Open the OxGuide app → Profile tab → Delete Account → Confirm

Option 2: Email Request

Email hello@oxguide.com with subject "Account Deletion Request". Include your account email. Processed within 30 days.

Upon account deletion, the following is permanently deleted:

  • Account information (email, display name, profile)
  • AI conversation history and chat threads
  • Saved places lists and itineraries
  • Navigation history and route data
  • App preferences and settings
  • Partner attribution data
  • Landmark detection history

Retained: Purchase/transaction records (7 years, required by law) and anonymized analytics data.

11. Push Notifications

With your permission, we may send push notifications for navigation alerts, landmark arrival notifications, and important service updates. You can disable notifications in your device settings at any time.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy, updating the "Last Updated" date, and sending an email notification for significant changes. Your continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data:

Email: hello@oxguide.com
For Data Protection Requests: Use subject line "Privacy Request", "GDPR Request", or "CCPA Request"

We aim to respond to all requests within 30 days.

14. Additional Disclosures

Analytics

We use Firebase Analytics to understand how users interact with the Service. This includes anonymous usage statistics, feature engagement metrics, and crash/error reporting. You can opt out of analytics collection in the App settings or by contacting us.

Machine Learning

Our landmark detection feature uses on-device machine learning (TensorFlow Lite). The ML model runs entirely on your device, does not send images to external servers, and does not learn from or store your images.

This Privacy Policy was last updated on March 7, 2026.