Privacy Policy — Pocket Guide
This policy applies to the iOS application "Pocket Guide" (問導遊), developed by Fermata ("we", "us"). Our principle is simple: we collect only what is necessary to provide the service, and we never sell your personal data.
The app offers several features: real-time spoken narration; reading and translating signs and menus from a photo, with digital menus you can share for ordering together; two-way live interpretation; finding a restroom and asking to use one; Location (sharing where you are so family or your guide can find you when you get separated); Meetup (group meeting-time reminders); your tour history; and bonus points you can earn and use when the day's free uses run out. Different features use different data and permissions, as described below.
1. Information We Collect
1.1 Anonymous identifier
There is no sign-up. The app uses Firebase Anonymous Authentication, which means we never ask for — and never receive — your name, email address, or any other contact information. Firebase simply assigns your installation a randomly generated anonymous identifier. We use it to manage the daily free uses, keep your bonus points, prevent abuse, and produce usage statistics. Wherever this policy says data is "tied to your anonymous identifier", it is linked to this identifier — not to your name or other real-world identity.
1.2 Images and voice (narration and reading signs)
The app's core feature is real-time spoken narration: images from your camera (photos you take, live camera frames while you hold to record, or a photo you pick from your photo library), the voice questions you ask, and any sign you photograph to have read aloud and translated, are sent directly from your device to our third-party AI service provider (currently Google's Gemini API) to generate live responses.
- For narration, these images and voice are never stored on our servers — our backend only issues short-lived access tokens and never sees your photos or audio. The exceptions are a feedback report you actively choose to submit (section 1.9) and menus (section 1.4).
- Images and voice are used only to generate the response in that moment, never for advertising or marketing.
- Our AI provider's handling of this data is governed by its own privacy policy and API terms (currently the Google Privacy Policy).
- If you allow location access, your GPS coordinates are attached to narration requests so explanations can reflect where you are.
1.3 Two-way live interpretation
The translation feature uses the microphone to capture what both you and the other person say, and interprets it in real time.
- In the current version, the conversation audio is sent directly from your device to OpenAI's API for real-time interpretation (some earlier versions use Google's Gemini API instead). The speech of both parties is processed. Before you start, we suggest letting the other person know you are using live interpretation.
- Our server only sets up the session (connection details and the languages you use) and records how long it lasted, to manage daily limits. Voice is never sent to or stored on our servers.
- To add helpful notes to a translation (for example, converting a price into your currency), the text of that line and its translation, the previous line or two, and your country and currency are sent through our server to OpenAI. We don't keep this text, and we ask OpenAI not to store it (OpenAI may still retain API data for a limited time for abuse monitoring, under its terms).
- OpenAI's handling of this data is governed by the OpenAI Privacy Policy and its API data commitments.
- Your translation history stays only on your phone.
1.4 Menus and ordering together
- When you photograph a menu (or pick menu photos from your library), the photos are uploaded to our server and processed by Google's Gemini API to create a translated digital menu. The photos and the digital menu are stored on our servers, tied to your anonymous identifier, so you can open the menu again.
- If you share a menu, anyone with its link, 6-digit code or QR code can view it and add orders — including people who don't have the app, through our web page. The display name and orders each person enters are stored with that menu. To let you know when someone orders, we store a notification token for your device.
- "Pick for me": the preferences you enter (such as allergies or foods you avoid) are sent through our server to Gemini to suggest dishes. They are not stored on our servers — they are kept on your phone.
- Menus are deleted automatically 30 days after they are created (a menu can be extended, up to 90 days from creation), or earlier when you delete your data. This refers to the copy on our servers that is used for sharing and ordering together; the menu saved on your phone stays on your phone until you delete it.
1.5 Find a restroom and ask to use a restroom
- Find a restroom: your current GPS coordinates, together with nearby places your phone finds through Apple Maps (name, category, brand and location), are sent to our server to return nearby restrooms and places that may let you use theirs (data from OpenStreetMap contributors, local government open data and other public sources). Your coordinates are used only for that query and are not tied to your identity. To improve the feature, we keep de-identified usage logs — a coarse area (about 1 km), which places were shown or tapped, and a code that changes every day — that are not tied to your anonymous identifier.
- Details from Google: a place card may show details from Google Maps. To do this, your device contacts Google directly with the place's name and the surrounding area, and Google may collect information such as a device identifier and location under the Google Privacy Policy.
- Restroom reports: when you report whether a place had a restroom you could use, the report is stored without your anonymous identifier: the place (location to within about 10 meters), the result and the time. A one-way code derived from your identifier is used only to stop duplicate reports on the same day. Reports are combined to help other people find a restroom. A report may earn you bonus points; they are added some hours later, so your points record does not show which report earned them.
- Ask to use a restroom: your device looks up nearby places locally via Apple Maps and sends that list to our server, which matches it against our "restroom etiquette" knowledge base to return guidance; this list is used at query time and not stored. The communication card uses the microphone to capture the staff's spoken reply and sends it to Gemini to help you understand it; the staff's voice is not stored. After a session, we keep only an anonymous statistic (the place, the outcome and the time, with coordinates coarsened to roughly identify the place only).
1.6 Looking up current information
During narration, if current or up-to-date information is needed, the AI may run a Google Search using a query it writes itself (not your raw conversation), and fold a brief factual summary back into the narration.
1.7 Usage records and statistics
- Daily free uses: to manage them and prevent abuse, we count how many times you use each feature each day (stored in Google Firestore, tied to your anonymous identifier). These counts contain no photo or conversation content.
- Usage statistics: to understand how features are used and what they cost, and to set fair limits, our server records events such as which feature was used, whether it was within the free uses or used points, points earned or used, how long an interpretation lasted, ratings, invite-code results and survey submissions. Each event is tied to your anonymous identifier and includes the app version, your phone's region setting and time zone, and the country you are in. The country is worked out on your phone from your location, and only the country code is sent — never your exact location. These events are stored in Google Cloud (BigQuery, in the United States) for up to 400 days.
- App analytics and crash reports: the app uses Google Analytics for Firebase and Firebase Crashlytics. Analytics records in-app events (such as which screens and buttons are used) with your anonymous identifier as the user ID; crash reports help us fix bugs. Neither includes your photos, voice or conversation content.
1.8 Bonus points, tasks and invite codes
- Your points balance and history (points earned and used, points reserved for a feature, and whether to use points automatically) are stored with your anonymous identifier. Points cannot be bought and have no cash value.
- Tasks: you can earn points by answering an optional survey, rating a narration, or reporting a restroom. Survey answers (including any short text you type) are stored with your anonymous identifier; please don't include personal information in text answers.
- Invite codes: each installation has an invite code. When someone enters your code, we record the link between the two anonymous accounts, to give you both points and to prevent abuse. The same field also accepts family codes, which turn on a PRO plan with more daily uses.
- Abuse prevention: when an invite code is entered, the app uses Apple's DeviceCheck so that Apple can remember, for this phone and our app only, whether it has already used an invite. We don't receive a device identifier, and Apple keeps this even if the app is deleted. Records of invite-code use are kept to prevent abuse, even after you delete your data.
1.9 Feedback and sharing
- When you actively rate a narration (thumbs up or thumbs down, optionally choosing a reason from a list), the photos and video frames, the conversation transcript and the location of that session are uploaded to us and used to improve the service. Your original voice recordings are never uploaded — only the text transcript of the conversation. Feedback reports are tied to your anonymous identifier. To withdraw a rating, tap it again: that report's photos, transcript and location are deleted, and the points it earned are taken back.
- When you tap "Share" to create a share card, the conversation transcript of that session is sent to our server to generate a quote in real time, then discarded and not stored.
1.10 Location (sharing where you are when separated)
The Location feature lets you share where you are with family or your tour guide when you get separated. We only store location data when you actively tap "Share my location" — we never track you in the background. When you report, your coordinates (and, only if you choose, a human-readable address, your battery level, one or more photos, videos or audio clips of your surroundings, and a selfie) are stored under a random, unguessable link so that anyone you share that link with can see where you are on a map. If you create a rescue link, the contact method you choose (FaceTime, LINE, or phone) is stored with the link so the person who is lost can reach you.
This data is temporary and is tied only to the random link, not to your identity:
- Lost-and-found link: deleted automatically after a few hours (at most 48 hours); cleared as soon as you close the link or leave.
- Group-tour tracking link: because a tour usually lasts several days, it is kept longer (about two weeks, at most 45 days); it is archived when the trip ends and deleted at expiry.
1.11 Meetup (group meeting reminders)
When you share a meeting point or group itinerary, the meeting place's name, coordinates, time and notes are stored under a random link (or a 6-digit code) so that the people traveling with you can subscribe via the link, code or QR code, view it on a map, and be notified when it changes. When someone subscribes, we store a device token used for notifications and the display name they set.
- This data is deleted automatically after the period you set (about one month by default, at most 90 days).
- Meeting points you create but do not share stay only on your phone and are not uploaded.
1.12 Kept only on your phone
- Tour history: the photos, short videos, conversation text and place (including coordinates) of your tours are kept on your phone so you can look back on them. They are not uploaded to us. The text records and small thumbnails may be included in your iCloud or device backup; full-size photos and videos are not.
- Save to Photos (optional): if you turn it on, the app adds a copy of your tour photos and videos to your photo library. It only asks for permission to add photos. When you choose a photo for a tour or a menu, the system photo picker shares only the photos you pick — the app never reads the rest of your library.
- Your settings, translation history, "Pick for me" preferences, and which announcements you have seen also stay on your phone.
2. Device Permissions
- Camera — to photograph what you want explained, a menu, or the text you want read aloud. No images are captured without your action.
- Microphone — to receive your spoken questions and real-time conversation; during interpretation or with the restroom communication card, it also captures the other person's or the shop staff's voice. Active only while the relevant feature is in use.
- Location — to make narration aware of where you are, to power finding a restroom, asking to use a restroom, Meetup and Location sharing, and to work out which country you are in for usage statistics (only the country code is sent). Granted as "While Using the App"; never tracked in the background.
- Speech Recognition — to convert your voice to text on your device (live captions and voice feedback). Only the resulting text is uploaded, and only where this policy says so.
- Photos (add only) — only if you turn on "Save to Photos", to add copies of your tour photos and videos to your library.
- Notifications — used by Location (someone joining a room, posting a message, or a rescue link about to expire), Meetup (meeting alarms and changes to a meeting point) and shared menus (someone placed an order). You can turn these off anytime in iOS Settings.
You can revoke these permissions anytime in iOS Settings; the related features will stop working.
3. How We Use Information
We use the information we collect only to:
- provide real-time image recognition, spoken narration, reading and translating signs and menus, ordering together, interpretation, finding/asking for a restroom, finding each other when separated, and meeting reminders;
- when you actively use those features, send the necessary data to our servers and service providers to complete the service;
- verify requests, manage the daily free uses and keep your bonus points;
- keep the service secure and prevent abuse, including abuse of points and invite codes;
- understand how features are used and what they cost, and improve the service, using usage statistics and the feedback you choose to send;
- show in-app announcements, such as changes to the daily free uses.
We do not sell or rent your personal data, we do not use it for advertising, and we do not track you across other companies' apps or websites.
4. Third-Party Services
- Google Firebase (authentication, notifications, app analytics, crash reporting and app integrity checks) — Privacy and Security in Firebase
- Google Cloud (our servers, databases and usage statistics) — Google Privacy Policy
- Google Gemini API (image analysis, voice narration, reading signs and menus, the restroom communication card, and translation in some versions) — Google Privacy Policy
- OpenAI API (live interpretation and translation notes) — OpenAI Privacy Policy
- Google Maps Platform (place details on restroom cards) — Google Privacy Policy
- Apple (Apple Maps, used on your phone to look up nearby places; DeviceCheck, used to prevent invite-code abuse).
- Public restroom data — OpenStreetMap contributors, local government open data and other public sources (attributions are shown in the app's "Data sources").
- Cloudflare (hosts our website, including the shared-menu and rescue-link pages).
Because these providers operate globally, your data may be processed on servers located outside your country or region (for example, in Taiwan and the United States). If we switch or add service providers, we will update this page before the change takes effect.
5. Data Retention & Deletion
- Daily-use counts, bonus points and their history, survey answers and feedback reports are tied to your anonymous identifier and kept while the service operates, until you delete your data. A feedback report is also deleted when you withdraw that rating.
- Menus on our servers are deleted 30 days after they are created (up to 90 days if extended), or when you delete your data. The menu saved on your phone stays until you delete it.
- Usage statistics are kept for up to 400 days and then deleted automatically. App analytics are kept according to our Google Analytics retention settings. Our servers' technical logs (such as IP address, time and the address requested — which for some map requests includes coordinates) are kept for about 30 days for security and troubleshooting.
- Location and Meetup data are tied only to a random link and are deleted automatically within the periods described above.
- Restroom reports and statistics are not tied to your anonymous identifier and are kept to keep restroom information accurate for everyone.
- Delete My Data: you can delete your data at any time directly in the app (Settings → Advanced → Delete My Data). This immediately deletes your feedback reports (including images, transcripts and locations), bonus points and their history, survey answers, your invite code, codes you have redeemed and any PRO plan, custom limits, menus you created, and Location rooms that only you are in (rooms other people are still using expire on their own). To prevent abuse, we keep today's usage counts until the end of the day, a minimal record for your account (such as when it was first seen, whether it has used an invite code, and task counts), and records of invite-code use; usage statistics and app analytics are kept until they expire, and anonymous restroom data is kept. Your anonymous identifier stays the same, so you can keep using the app.
- You may also email us to request access to or deletion of data tied to your anonymous identifier. Because the app is anonymous, we generally cannot otherwise identify which data belongs to you.
- Deleting the app removes the anonymous identifier from your device; it cannot be re-associated with you afterwards.
6. Children's Privacy
This app is not directed at children under 13. If we learn that we have collected personal information from a child without parental consent, we will delete it promptly.
7. Security
All network traffic is encrypted (HTTPS / WSS, and encrypted real-time audio for interpretation). Access to AI services uses short-lived tokens with usage and expiry limits, minimizing exposure. Only authorized staff can look up data tied to an anonymous identifier, through internal tools, for support and abuse prevention.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be announced in the app or on this page, and take effect when posted here.
9. Contact
Questions about this policy or your data: support@fermatalabs.co