detour

Privacy Policy

Last updated: 6 October 2026

Detour is an app for small groups of friends ("parties"). It gives your party one small real-world quest at a time. You go and do it, post a photo as proof, and see your friends' photos. This policy explains what personal data Detour handles, why, who can see it, and what you can do about it.

We have tried to keep it short and plain. Detour has no ads, no analytics or tracking SDKs, and we never sell your data.

1. Who we are

Detour is operated by support@detourapp.eu, an individual developer based in Romania ("we", "us"). We are the controller of your personal data under the EU General Data Protection Regulation (GDPR).

Write to us about anything in this policy, including requests to use your rights (section 9).

2. What we collect

You give us

Data Details
Account Email address, password (stored only as a salted bcrypt hash; we never see it), display name, @username.
Date of birth Asked at sign-up only to check you meet the minimum age (16). It is never stored. We keep only the time the check passed and the minimum age it was checked against.
Terms acceptance When you agreed to the Terms of Use, and which version.
Profile (optional) Profile photo, city, timezone.
Parties Parties you create or join, party name and cover photo, your role, title and points in each party.
Quest activity Whether you accepted or passed on a quest, proof photos and captions, votes on friends' proofs, votes to skip a quest, XP, levels and streaks.
Proof location (optional) Only if you switch on "pin to map" for a particular proof. See section 4.
Reports and blocks Reports you make about photos or people (reason, optional note), and who you have blocked.
Support requests Messages you send to the Detour team in "help & support", and our replies.

Collected automatically

Data Details
Push notification token If you allow notifications: a device token from Expo, plus whether the device is iOS or Android, and which kinds of notifications you have switched off.
Technical data When your phone talks to our server, the server necessarily sees your IP address. It is used for security and rate limiting (blocking floods of requests) and may appear in short-lived server logs. Our logs record which endpoint was called and how long it took, not what you did in it.
Sign-in sessions Session tokens that keep you signed in on a device. They expire after 30 days of non-use or when you log out.

Photo metadata. Every photo you upload is re-encoded on our server, and its EXIF metadata (including any GPS position the camera saved) is removed before it is stored. A photo never reveals where it was taken unless you separately choose to pin it to the map.

What we do not collect

We don't collect contacts, browsing history, advertising identifiers, background location, microphone audio, health data or payment information. Detour doesn't ask for any of these.

3. Why we use it, and our legal basis

Purpose Data used Legal basis (GDPR art. 6)
Create and run your account, sign you in, keep you signed in Account data, sessions Performing our contract with you (the Terms of Use)
Run parties and quests: drop quests, show proofs to your party, count votes, XP, streaks Party and quest activity, photos, captions Contract
Show a proof on your party's memory map Proof location you chose to share Your consent, given per photo. Turn it off any time.
Send push notifications Push token, notification settings Your consent (the system permission) and your settings
Send emails: verification codes, account notices, replies to support requests Email address Contract
Confirm you meet the minimum age Date of birth (checked, then discarded) Legal obligation and legitimate interest in keeping under-16s off a social app
Keep Detour safe: handle reports, moderate content, suspend accounts, prevent abuse Reports, flagged content, account and activity data Legitimate interests (a safe service for everyone) and legal obligations
Security, rate limiting, fixing bugs Technical data Legitimate interests
Answer support requests Support messages Contract and legitimate interests
Comply with the law and defend legal claims Any relevant data Legal obligation, legitimate interests

We do not use your data for advertising or profiling, and we make no automated decisions with legal or similarly significant effects. Proof approvals are decided by your friends' votes, not by an algorithm. Photos are hidden automatically for review only after several separate reports, and a person then decides.

4. Location

Detour never tracks your location in the background.

5. Who can see what

6. Service providers

We use a small number of providers to run Detour. They process data on our behalf, under contracts that require them to protect it, or for the narrow purpose described.

Provider What for Data involved Where
Netcup Servers that run Detour's database, API and photo storage All service data European Union
Neo Mail Delivering verification codes, account notices and support replies by email Email address, message content Cayman Islands
Expo (650 Industries, Inc.) Relaying push notifications to Apple and Google Push token, notification text (which can include a friend's first name and a quest title) United States
Apple Push Notification service / Google Firebase Cloud Messaging Delivering push notifications to your device Push token, notification text United States / worldwide
Esri Map tiles for the memory map IP address, map area being viewed United States / worldwide
Apple / Google device geocoding Turning a pinned position into a place name Rounded coordinates Under Apple's / Google's terms

We do not share personal data with anyone else except:

7. International transfers

Some providers above are based in, or may process data in, the United States. Where personal data leaves the European Economic Area, we rely on an adequacy decision by the European Commission, such as the EU–US Data Privacy Framework for certified companies, or on the Commission's Standard Contractual Clauses. Write to us for more detail.

8. How long we keep it

Data Kept until
Account, profile, parties, proofs, votes, reports you made, support requests, blocks You delete your account, or we delete it under the Terms
Date of birth Never stored
Email verification codes They expire, after minutes, and are then purged
Sign-in sessions 30 days after last use, or when you log out
Push tokens You log out, switch off notifications, or the device stops accepting them
Server logs A short rolling period, normally no more than 14 days
Backups Overwritten in our normal backup cycle, within 30 days
Moderation audit log Kept to show how the rules were enforced. When the account is deleted, the log entry is no longer linked to it.

When you delete your account, your data is deleted straight away from the live system. That includes your photos, which are removed from storage. Copies in backups disappear as the backups roll over (within 30 days). A party you own is handed to the member who has been in it longest; a party with no other members is deleted with your account.

9. Your rights

Under the GDPR you have the right to:

To use a right, email support@detourapp.eu from the address on your account. We may ask you to confirm it's you. We answer within one month, or tell you within that month if we need longer (up to two further months for complex requests).

You can also complain to a data protection authority. In Romania that is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro. If you live elsewhere in the EU or EEA, you can complain to the authority where you live or work. We'd appreciate the chance to sort it out with you first.

10. Your choices in the app

11. Age limit

Detour is only for people aged 16 and over. We check age at sign-up and don't knowingly collect data from anyone younger. If you believe someone under 16 is using Detour, tell us at support@detourapp.eu and we'll delete the account.

12. Security

We protect your data with industry-standard measures: encrypted connections (HTTPS), hashed passwords, short-lived access tokens, photos served only through short-lived signed links, and a database not reachable from the internet. Locked proofs are never sent to your device until you are allowed to see them; only a blurred placeholder is. No system is perfectly secure. If a breach puts your rights at risk, we will tell you and the authorities as the law requires.

13. Changes to this policy

If we change this policy, we'll update the date at the top. For significant changes we'll also tell you in the app or by email before they take effect.

14. Contact

Questions or requests: support@detour.app.