A travel app that uses precise location and personal photos should not hide behind vague reassurance. Those inputs are sensitive. The right response is to collect them for narrow reasons, keep them behind clear boundaries, and make deletion real.

This article explains the product in plain language. For the complete policy, read the Unlocked Privacy Policy.

Location is used at two specific moments

Unlocked can use your location to show nearby Landmarks and to verify a visit when you choose Unlock. It does not need continuous background tracking.

For a Landmark unlock, the server checks the location sample’s timestamp, reported accuracy, and distance from the Landmark. A successful unlock stores the verified coordinates, accuracy, method, time, and risk flags with the permanent visit record. That evidence prevents the app from treating a client-side button tap as proof that you were there.

Reference photos are private inputs

To create a Memory featuring you, Unlocked needs at least one reference photo you approve. Upload requires explicit consent. The image is checked, reoriented, stripped of embedded metadata through re-encoding, and stored in a private bucket.

The app does not:

  • perform facial recognition;
  • compare your identity with another person;
  • create biometric embeddings or profiles;
  • publish your reference photos in a gallery; or
  • sell or share them for advertising.

When you ask to create a Memory, approved reference images are sent through the selected image-generation service for that request. The service receives only what is needed to produce the requested result.

Memories stay behind signed access

Generated Memories are stored privately. The API does not hand the app a permanent public object address. It creates a short-lived signed URL so an authenticated request can display the image without making the underlying storage public.

This is a meaningful boundary. A private bucket with expiring access is different from an unlisted but permanent public link.

Content Default access Your control
Reference photos Private Remove one or all in Profile
Generated Memories Private Removed with account deletion
Landmark unlocks Account-only Removed with account deletion
Purchase records Account-only Processed through app stores and RevenueCat

Purchases do not expose store credentials

Memory credits are purchased through Apple or Google and coordinated by RevenueCat. Unlocked records the store transaction identifiers and ledger entries needed to grant or reverse credits. It does not store your payment-card number, store password, receipt secret, or purchase token in credit-ledger metadata.

Deletion is a product action

You can remove an individual reference photo, remove all references, or delete the entire account from Profile. Account deletion removes private reference-photo and generated-Memory storage, deletes the application account, and deletes the connected sign-in identity when configured.

If you cannot access the app, the public account deletion page explains how to request help.

The principle behind the controls

Privacy is easiest to understand when the product can say why each sensitive input exists.

  • Location proves a chosen Landmark visit.
  • Reference photos help create a Memory you requested.
  • Purchase records grant the credits you bought exactly once.
  • Email handles account and service communication according to your choices.

If an input does not serve the journey from physical presence to private Memory, it should not quietly become part of it.