Your data, in plain language
Privacy Policy
Unlocked uses sensitive information for narrow product reasons: to verify a place you chose to unlock and to create a private Memory you requested. This policy explains those boundaries.
Effective September 17, 2026
1. Scope
This Privacy Policy applies to the Unlocked mobile applications, the website at unlockhere.app, and related services (together, the “Service”). In this policy, “Unlocked,” “we,” “us,” and “our” refer to the operator of the Service.
Unlocked is a location-locked travel app. A successful visit opens curated photographic Experiences for a Landmark. Travelers may then use approved reference photos to create personal Memories and keep them in My World.
Our baseline: Unlocked does not perform facial recognition, compare identities, create biometric embeddings, publish a public photo gallery, or sell reference photos.
2. Information we handle
Account and profile information
When you create an account, our authentication provider processes identifiers and sign-in information such as your email address, authentication tokens, and account status. Unlocked stores an application user identifier linked to the verified sign-in account. We do not receive your sign-in password.
Location and Landmark unlock information
If you allow location access, the app may use a current location sample to show nearby Landmarks. When you choose to unlock a Landmark, we receive precise latitude and longitude, the reported horizontal accuracy, and the time the sample was captured.
For a successful unlock, we retain the verified coordinates, reported accuracy, verification method, verification time, and limited risk flags with your permanent Landmark visit. We do this to prove the unlock and protect the integrity of the location-locked experience. Unlocked does not continuously track your route in the background.
Optional nearby Landmark reminders
If you enable Nearby discoveries, your device can notify you when you approach a supported Landmark, even when the app is closed or not in use. The initial feature covers Paris. It requires precise location and notification permissions; Android also requires background location access. Your device checks proximity using the operating system’s location services. These reminder checks do not send your current coordinates or route to Unlocked’s servers.
The app stores your reminder preference, prepared Landmark identifiers and coordinates, and reminder history on your device, associated with your account. Landmark coordinates describe the public places, not a history of your movements. Reminders do not verify a visit or unlock a badge. The separate arrival verification described above still applies when you choose to unlock a Landmark. Turn reminders off from Explore or You; signing out also disables them and removes prepared reminders. Memory-ready notifications are managed separately.
Reference photos and generated Memories
You may upload up to three approved reference photos for the primary subject on your account. Upload requires an explicit consent action. We validate the file, apply orientation, remove embedded metadata by re-encoding the image, constrain its dimensions, and store it in private object storage.
When you request a Memory, we send your saved reference images, any photo added for that Memory, the selected Landmark and Experience, the visit date and time of day, and any personal aesthetic instructions to OpenAI, our AI image-generation service. Photos may include your face and likeness. We do not send your account email or the GPS sample used to verify your visit in the image-generation request. Generated Memories are stored privately. The app receives short-lived signed links rather than permanent public object addresses.
A photo added only for a particular Memory is stored temporarily while that job is processed and is removed from Unlocked’s storage when it completes or permanently fails. Reusable reference photos remain until you remove them. OpenAI has its own processing and safety retention rules; deletion from Unlocked does not mean immediate deletion from every service provider or backup. See OpenAI’s API data controls for its handling of API inputs and outputs.
You may also optionally import up to nine photos to create a personal aesthetic profile. We store those samples privately and measure visual characteristics such as colour, exposure, contrast, texture, composition, and palette. The resulting profile is linked to your account and used only to personalize future Memories. You can remove individual samples or delete all of them from Profile.
Purchases and credits
Apple App Store or Google Play processes your payment. RevenueCat helps coordinate in-app purchases and report eligible store transactions to Unlocked. We receive information such as store transaction identifiers, product identifiers, purchase status, refund or reversal events, and an app-specific customer identifier. We do not receive or store your full payment-card number, store password, or store payment credentials.
Communications and support
If you contact support, we process your email address, message, and any information you choose to include. If you join the launch waitlist, we store your email address, requested city, phone platform preference, standard UTM campaign parameters, the time and version of your consent, and whether the address was synchronized to our email provider. Transactional messages are sent when needed to operate the Service. As part of using the Service, account holders receive occasional Service emails such as new-city announcements, and every such email includes an unsubscribe mechanism; unsubscribing stops these emails without affecting your account.
Android guide attribution
If you install Android from a city or landmark guide, Google Play may pass the guide's city, campaign, and page identifier to the app. We associate those labels with your account after sign-in to understand which guides lead people to Unlocked. We do not collect an advertising identifier, browsing history, or precise location for this purpose. The local labels are removed after delivery, and the account record is removed when you delete your account.
Optional invitations
If you accept a referral, we keep your accepted terms, account relationship, eligibility, qualification deadline and credit history to fulfill the offer and prevent duplicate rewards. Your friend sees aggregate progress only; this can imply that you created a Memory, but does not reveal your photos or location. You explicitly accept this before joining the referral. Invitation pages do not send referral codes to Swetrix. First-party landing, store-intent and rejected-attempt diagnostics are deleted after 90 days. Account-linked entitlement and exposure records support rewards and outcome measurement until account deletion. Deleting your account removes its code and detaches referral links; another person's already earned credit remains. You can use Unlocked without accepting or sharing an invitation.
Passport feature usage
To understand and improve Passport sharing, we record account-linked observations when you open a card or recap composer, prepare a preview, encounter a preparation or sharing error, or open your phone’s share sheet. These contain the feature, platform, selected design and format, badge and page counts, whether a Memory is included, a random composer identifier, and receipt time. They do not contain your caption, trip title, photos, selected places, coordinates, recipients, or the app you share to. A share-sheet observation does not tell us whether you posted or saved an image. These records are removed when you delete your account.
We also count successful public Passport requests, including repeat requests and link previews, without storing visitor identifiers, IP addresses, user agents, or referrers in those counts. Counts are associated with the Passport owner and are removed with that account.
Product usage analytics
The apps record bounded, first-party analytics events so we can understand which features people use, how they move through the app, and where progress stops. These events cover the screens you open and the screen you came from, session starts with foreground and background durations, taps on important buttons together with whether the enabled button was shown to you, flow starts, cancellations and safe failure codes, and permission request outcomes.
Before you sign in, events are associated with a random identifier generated on your device. If you sign in, that identifier is linked to your account only through your authenticated session, and signing out resets the identifier so separate identities stay distinct. Events never include photos, captions, coordinates or precise location, credentials, or arbitrary text from your screen; every event name and attached property comes from a fixed allowlist of short, non-identifying values such as a landmark identifier or a product identifier. Server-confirmed outcomes such as unlocks, created Memories, and verified purchases are recorded under the sections above rather than inferred from these events. We do not use a third-party analytics SDK for in-app events. Analytics events are kept for a bounded period of roughly thirteen months, and events linked to your account are removed when you delete your account.
Technical and security information
We may process request identifiers, timestamps, app version, device and operating-system information, IP address, error details, and security events to operate, protect, and improve the Service. Authentication headers, image bytes, and signed private URLs are not intentionally written to application logs.
Our website uses Swetrix for privacy-focused page-view and conversion measurement. Waitlist events contain the form location, request result, and non-empty standard UTM campaign parameters retained for the browser session. They do not contain the email address, requested city, phone platform, or consent choice you submitted. We do not use this analytics data for cross-site advertising.
3. How we use information
We use information to:
- authenticate you and maintain your account;
- show nearby Landmarks and verify a visit you choose to unlock;
- keep permanent unlocks and assemble your private My World passport;
- store approved references and create the Memories you request;
- grant, spend, refund, and reconcile Memory credits;
- manage the launch waitlist, send requested updates, and respond to support requests;
- understand feature adoption, journeys, and friction through bounded first-party product analytics;
- prevent abuse, investigate errors, and secure the Service; and
- comply with law and enforce our Terms.
Depending on where you live, our legal grounds may include performing our agreement with you, your consent, our legitimate interests in operating and securing the Service, and compliance with legal obligations. You may withdraw consent for optional processing, but withdrawal does not affect processing already completed.
4. When information is shared
We share information only as needed with service providers that help deliver the Service, including:
- Clerk for account authentication and identity management;
- Apple, Google, and RevenueCat for in-app purchases and transaction reconciliation;
- OpenAI to create a Memory you request using the photos and instructions described above;
- cloud database, storage, network, and hosting providers to run the Service and keep private content;
- Resend for transactional email and communications you choose to receive;
- Swetrix for website traffic and conversion measurement; and
- professional advisers or authorities when reasonably necessary to comply with law, protect rights, or address fraud and security.
Providers are permitted to process information only for the services they supply to us, subject to their agreements and applicable law. We may also transfer information as part of a merger, financing, acquisition, or sale of assets, with appropriate notice and protections.
Unlocked does not sell personal information or share it for cross-context behavioural advertising.
5. Retention and security
We retain account information, successful unlock evidence, reference photos, generated Memories, and credit-ledger records while your account is active and as needed to provide the Service. Support and security records may be retained for a reasonable period to resolve requests, prevent abuse, and meet legal obligations. Some purchase or transaction records may need to be retained where required for financial, tax, fraud-prevention, or dispute purposes.
Waitlist records are retained while you remain subscribed and for a reasonable period needed to honor suppression, deletion, security, and compliance obligations. You can unsubscribe from launch emails at any time.
First-party product analytics events and unlinked device identifiers are deleted after a bounded period of roughly thirteen months; account-linked analytics events are removed when you delete your account.
You can remove one reference photo, remove all references, delete an individual Memory, or delete your account. Individual Memory deletion removes it from your gallery and schedules permanent image removal, with retries if storage is temporarily unavailable. We remove associated feedback and retain a creation record for credits, referral rewards, and service history. Other devices update when they reconnect; copies you saved or shared remain. Account deletion removes private reference-photo and generated-Memory object prefixes, deletes the application account and its owned records, and deletes the connected authentication identity when enabled. Deletion from encrypted backups may follow the backup rotation schedule, and limited records may be preserved where law requires.
We use safeguards designed for the sensitivity of the information, including TLS in transit, restricted service accounts, private object storage, short-lived signed URLs, parameterized database access, security headers, production configuration checks, and access controls. No system can guarantee absolute security.
6. Your choices and rights
- Location: deny or change location permission in device settings. You may browse supported Landmark information without granting continuous location access, but presence verification needs a current sample.
- Reference photos: remove an individual reference or all references from Profile.
- Memories: open a Memory, choose Delete Memory from its menu, and confirm. Your Landmark stays unlocked and credits are not refunded.
- Account deletion: choose “Delete account and all data” in Profile or follow the instructions on our account deletion page.
- Marketing email: use the unsubscribe link in a marketing message, or contact us to delete a waitlist record. Service messages may still be sent when necessary.
- Access, correction, portability, restriction, or objection: contact us. Rights vary by jurisdiction, and we may need to verify your request.
You may also have the right to complain to your local privacy or data-protection authority.
Children
The Service is not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from children below the applicable minimum age. Contact us if you believe a child has provided information in violation of this section.
7. International use and transfers
Unlocked and its service providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use contractual or other lawful safeguards for international transfers.
Changes to this policy
We may update this policy as the Service changes. We will post the revised version here, update the effective date, and provide additional notice in the app or by email when a change is material and applicable law requires it.
8. Contact
Questions, privacy requests, and deletion requests can be sent to [email protected]. General product support is available at [email protected].