Privacy Policy
Last updated: 6 October 2026
Detour is an app for small groups of friends ("parties"). It gives your party one small real-world quest at a time. You go and do it, post a photo as proof, and see your friends' photos. This policy explains what personal data Detour handles, why, who can see it, and what you can do about it.
We have tried to keep it short and plain. Detour has no ads, no analytics or tracking SDKs, and we never sell your data.
1. Who we are
Detour is operated by support@detourapp.eu, an individual developer based in Romania ("we", "us"). We are the controller of your personal data under the EU General Data Protection Regulation (GDPR).
- Email: support@detourapp.eu
- Post: Bd. Timisoara 53, Bloc C2, Scara 2, Apartament 29
Write to us about anything in this policy, including requests to use your rights (section 9).
2. What we collect
You give us
| Data | Details |
|---|---|
| Account | Email address, password (stored only as a salted bcrypt hash; we never see it), display name, @username. |
| Date of birth | Asked at sign-up only to check you meet the minimum age (16). It is never stored. We keep only the time the check passed and the minimum age it was checked against. |
| Terms acceptance | When you agreed to the Terms of Use, and which version. |
| Profile (optional) | Profile photo, city, timezone. |
| Parties | Parties you create or join, party name and cover photo, your role, title and points in each party. |
| Quest activity | Whether you accepted or passed on a quest, proof photos and captions, votes on friends' proofs, votes to skip a quest, XP, levels and streaks. |
| Proof location (optional) | Only if you switch on "pin to map" for a particular proof. See section 4. |
| Reports and blocks | Reports you make about photos or people (reason, optional note), and who you have blocked. |
| Support requests | Messages you send to the Detour team in "help & support", and our replies. |
Collected automatically
| Data | Details |
|---|---|
| Push notification token | If you allow notifications: a device token from Expo, plus whether the device is iOS or Android, and which kinds of notifications you have switched off. |
| Technical data | When your phone talks to our server, the server necessarily sees your IP address. It is used for security and rate limiting (blocking floods of requests) and may appear in short-lived server logs. Our logs record which endpoint was called and how long it took, not what you did in it. |
| Sign-in sessions | Session tokens that keep you signed in on a device. They expire after 30 days of non-use or when you log out. |
Photo metadata. Every photo you upload is re-encoded on our server, and its EXIF metadata (including any GPS position the camera saved) is removed before it is stored. A photo never reveals where it was taken unless you separately choose to pin it to the map.
What we do not collect
We don't collect contacts, browsing history, advertising identifiers, background location, microphone audio, health data or payment information. Detour doesn't ask for any of these.
3. Why we use it, and our legal basis
| Purpose | Data used | Legal basis (GDPR art. 6) |
|---|---|---|
| Create and run your account, sign you in, keep you signed in | Account data, sessions | Performing our contract with you (the Terms of Use) |
| Run parties and quests: drop quests, show proofs to your party, count votes, XP, streaks | Party and quest activity, photos, captions | Contract |
| Show a proof on your party's memory map | Proof location you chose to share | Your consent, given per photo. Turn it off any time. |
| Send push notifications | Push token, notification settings | Your consent (the system permission) and your settings |
| Send emails: verification codes, account notices, replies to support requests | Email address | Contract |
| Confirm you meet the minimum age | Date of birth (checked, then discarded) | Legal obligation and legitimate interest in keeping under-16s off a social app |
| Keep Detour safe: handle reports, moderate content, suspend accounts, prevent abuse | Reports, flagged content, account and activity data | Legitimate interests (a safe service for everyone) and legal obligations |
| Security, rate limiting, fixing bugs | Technical data | Legitimate interests |
| Answer support requests | Support messages | Contract and legitimate interests |
| Comply with the law and defend legal claims | Any relevant data | Legal obligation, legitimate interests |
We do not use your data for advertising or profiling, and we make no automated decisions with legal or similarly significant effects. Proof approvals are decided by your friends' votes, not by an algorithm. Photos are hidden automatically for review only after several separate reports, and a person then decides.
4. Location
Detour never tracks your location in the background.
- Location is used only when you switch on "pin to map" while posting a proof. The app then reads your position once.
- Before storing it, we round the coordinates to about 11 metres, so they're precise enough to find the café but not a particular flat.
- Your phone's own geocoding service (Apple's on iOS, Google's on Android) turns the coordinates into a place name such as a neighbourhood or street. That lookup happens on the operating system's service, under Apple's or Google's privacy terms.
- A pinned location is shown only to your party, and only once they could see the photo itself.
- The memory map's background map is loaded from Esri's map tile servers (see section 6). Esri receives your IP address and which map area is being displayed, not your account or your proofs.
5. Who can see what
- Your party sees your display name, @username, profile photo and city, your quest status, and your proof photos, captions and pinned locations. They see proofs only after the reveal rules allow it: once they've posted their own proof or the quest has closed. Members of a party see each other's points and streaks within that party.
- Anyone with your @username (for example, someone checking if a username is free) learns only that it is taken.
- Your email address is never shown to other users.
- Reports are confidential. The person you report is not told who reported them, and neither is your party.
- Blocks are private. The person you block is not told.
- The Detour team (currently only the operator) can access account and content data where needed to run the service, handle reports and support requests, and enforce the Terms. Every moderation action is recorded in an internal audit log.
6. Service providers
We use a small number of providers to run Detour. They process data on our behalf, under contracts that require them to protect it, or for the narrow purpose described.
| Provider | What for | Data involved | Where |
|---|---|---|---|
| Netcup | Servers that run Detour's database, API and photo storage | All service data | European Union |
| Neo Mail | Delivering verification codes, account notices and support replies by email | Email address, message content | Cayman Islands |
| Expo (650 Industries, Inc.) | Relaying push notifications to Apple and Google | Push token, notification text (which can include a friend's first name and a quest title) | United States |
| Apple Push Notification service / Google Firebase Cloud Messaging | Delivering push notifications to your device | Push token, notification text | United States / worldwide |
| Esri | Map tiles for the memory map | IP address, map area being viewed | United States / worldwide |
| Apple / Google device geocoding | Turning a pinned position into a place name | Rounded coordinates | Under Apple's / Google's terms |
We do not share personal data with anyone else except:
- when the law requires it, for example a valid order from a court or authority;
- to protect someone's safety, for example reporting child sexual abuse material to the authorities (see our Child Safety Standards);
- to establish, exercise or defend legal claims.
7. International transfers
Some providers above are based in, or may process data in, the United States. Where personal data leaves the European Economic Area, we rely on an adequacy decision by the European Commission, such as the EU–US Data Privacy Framework for certified companies, or on the Commission's Standard Contractual Clauses. Write to us for more detail.
8. How long we keep it
| Data | Kept until |
|---|---|
| Account, profile, parties, proofs, votes, reports you made, support requests, blocks | You delete your account, or we delete it under the Terms |
| Date of birth | Never stored |
| Email verification codes | They expire, after minutes, and are then purged |
| Sign-in sessions | 30 days after last use, or when you log out |
| Push tokens | You log out, switch off notifications, or the device stops accepting them |
| Server logs | A short rolling period, normally no more than 14 days |
| Backups | Overwritten in our normal backup cycle, within 30 days |
| Moderation audit log | Kept to show how the rules were enforced. When the account is deleted, the log entry is no longer linked to it. |
When you delete your account, your data is deleted straight away from the live system. That includes your photos, which are removed from storage. Copies in backups disappear as the backups roll over (within 30 days). A party you own is handed to the member who has been in it longest; a party with no other members is deleted with your account.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- rectify it. Most of your profile can be edited in the app;
- erase it. Delete your account in the app (profile → delete account) or see how to delete your account;
- restrict or object to processing based on legitimate interests;
- data portability: receive the data you gave us in a machine-readable format;
- withdraw consent at any time, for location pins and notifications. This doesn't affect processing that happened before.
To use a right, email support@detourapp.eu from the address on your account. We may ask you to confirm it's you. We answer within one month, or tell you within that month if we need longer (up to two further months for complex requests).
You can also complain to a data protection authority. In Romania that is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro. If you live elsewhere in the EU or EEA, you can complain to the authority where you live or work. We'd appreciate the chance to sort it out with you first.
10. Your choices in the app
- Notifications: profile → notifications switches individual kinds on or off. Your phone's settings can switch them all off.
- Location: leave "pin to map" off and no location is ever read. You can also deny the permission in your phone's settings.
- Camera and photos: used only when you take or pick a proof or profile photo.
- Block: someone in your party → block. Their photos, captions and pins are hidden from you.
- Leave a party at any time from the party's settings.
- Delete your account: profile → delete account.
11. Age limit
Detour is only for people aged 16 and over. We check age at sign-up and don't knowingly collect data from anyone younger. If you believe someone under 16 is using Detour, tell us at support@detourapp.eu and we'll delete the account.
12. Security
We protect your data with industry-standard measures: encrypted connections (HTTPS), hashed passwords, short-lived access tokens, photos served only through short-lived signed links, and a database not reachable from the internet. Locked proofs are never sent to your device until you are allowed to see them; only a blurred placeholder is. No system is perfectly secure. If a breach puts your rights at risk, we will tell you and the authorities as the law requires.
13. Changes to this policy
If we change this policy, we'll update the date at the top. For significant changes we'll also tell you in the app or by email before they take effect.
14. Contact
Questions or requests: support@detour.app.