1. Who is responsible for your data
ChapterWalks is operated by Leandro Ligetta, ditta individuale, Via dei Mocenigo 7, 20137 Milano, Italy, Partita IVA 14484440962 (the Controller).
Privacy and data-rights requests: privacy@chapterwalks.com. General support: support@chapterwalks.com.
2. Scope and the short version
This policy covers the ChapterWalks iOS app and chapterwalks.com. The app can be explored without a named account. A random anonymous user ID is created when the app needs the server, including for downloads or problem reports. If you sign in, we receive the email address associated with Apple, Google, or the email code you use.
- Your location is used on the device for tour playback and proximity hints.
- Precise location leaves the device only when you choose to send a problem report and location permission has already been granted.
- We do not sell personal data, show ads, or track you across other companies' apps or websites.
- Apple handles payment details. We do not receive your card number.
- Listening progress is synced so a signed-in or anonymous account can resume across devices.
- Optional app analytics are off unless you turn them on in the app, and every tour works fully either way.
- Google sign-in can provide your display name and profile-picture URL to Supabase Auth.
- Optional website Product analytics is off unless you turn it on. With your consent, PostHog counts five specific tour-choice actions and Cloudflare measures aggregate page views and website performance. The whole site works either way.
- The website uses no advertising or analytics cookies, visitor profiles, cross-site tracking, or session replay.
Website security cookie
chapterwalks.com uses the technical cookie __cf_bm, provided by Cloudflare, for strictly necessary security and bot protection. It helps Cloudflare distinguish automated traffic and protect the site. It expires after 30 minutes of continuous inactivity.
Cloudflare generates this cookie independently for each site. It is not tied to a ChapterWalks user ID or another identifier in the ChapterWalks application, and ChapterWalks does not read its contents, use it to profile visitors, or use it for cross-site tracking.
3. Personal data we process
| Data | Purpose and legal basis | Where it comes from |
|---|---|---|
| Anonymous user ID | Provide downloads and reports with minimal identification; legitimate interests in operating the service. | Created automatically by Supabase Auth when the app needs the server. |
| Name and Google profile-picture URL | Authenticate and operate an account; performance of the service contract. | Google sign-in profile data retained by Supabase Auth. ChapterWalks does not display the profile picture. |
| Email address and sign-in identity | Account access, purchase restoration, and account management; performance of the service contract. | Apple, Google, or the email address used for a one-time sign-in code. |
| User ID and purchase history | Validate purchases, prevent fraud, restore entitlements, and operate purchase history and service analytics; performance of the service contract and legitimate interests in operating the service. | Supabase, Apple purchase receipts, and RevenueCat entitlement processing. |
| Listening progress | Resume a tour across devices; performance of the service contract. | Tour, last stop, completion, and played-stop IDs synced from the app to Supabase. |
| Optional product-analytics events | Learn which tours people browse, preview, and buy; your consent (Art. 6(1)(a) GDPR), given and withdrawable in the app. | Only if you turn on “Product analytics”: allowlisted in-app events with a random per-install identifier, sent to PostHog. See section 4. |
| Optional walk-quality diagnostic events | Find stops where audio triggers at the wrong spot; your consent (Art. 6(1)(a) GDPR), given and withdrawable in the app. | Only if you turn on “Walk quality diagnostics”: bucketed trigger and playback facts sent to our Supabase database. See section 4. |
| Optional website tour-choice events | Learn which tour pages and actions help people choose a tour; your consent under Art. 6(1)(a) GDPR. | Only after you turn on Product analytics, ChapterWalks sends PostHog the five allowlisted website events described in section 4. They use a temporary random browser-memory identifier and are not connected to a ChapterWalks account. |
| Optional website performance measurements | Understand aggregate page views and diagnose how quickly the website loads and responds; your consent under Art. 6(1)(a) GDPR. | Only after you turn on Product analytics, Cloudflare's browser beacon measures the current page using browser performance APIs. See section 4. |
| Problem-report content | Investigate factual, audio, route, and trigger problems; legitimate interests in support and quality assurance. | Your category and message, tour and stop, app version, device model, and nearest stop when available. |
| Precise location in a problem report | Reproduce a problem at the place it occurred; legitimate interests in support and quality assurance. | The device's last known location, only when you submit a report and permission was already granted. |
| Support and privacy correspondence | Answer requests and keep a record of their resolution; contract, legal obligations, and legitimate interests. | Email you send to our published contact addresses. |
| Technical request data | Deliver and secure the service, prevent abuse, and diagnose faults; legitimate interests in security and operations. | IP address, IP-derived country, user agent, route, status, duration, timestamps, and short-lived infrastructure logs. |
4. Optional analytics you choose
The app asks once whether you want to help improve ChapterWalks. Both options are off unless you turn them on, every tour works fully either way, and you can change your choices anytime in Settings → Privacy choices. Turning an option off stops sharing immediately; each recorded choice stores the version of the notice you saw.
- Product analytics (processed by PostHog, EU Cloud) — counts of what gets browsed, previewed, and bought: a closed list of in-app events such as “tour detail viewed” or “download succeeded”, each carrying only fixed category values (for example the tour and a coarse network or failure category). Events carry a random identifier created in the app that is not connected to your account; no profile of you is created, your IP address is discarded at ingestion, and no location is derived from it.
- Walk quality diagnostics (stored in our Supabase database) — flags stops where audio triggers at the wrong spot, using rough distance ranges — never your route or exact position. The database accepts only bucketed ranges (for example “21–40 m”) and has no columns for coordinates, so exact positions cannot be stored.
Neither option ever collects your route, exact position, addresses, free-text input, or advertising identifiers, and neither is used to track you across other companies' apps or websites. Consent is never inferred from creating an account, buying a tour, granting location permission, or continued use. Withdrawal stops future collection but does not retroactively erase data already received; you can request deletion of shared data from the same screen or at privacy@chapterwalks.com. Retention for both streams is in section 7.
On chapterwalks.com, Product analytics is one optional choice and starts off. If you turn it on, it allows two separate streams:
- PostHog tour-choice events. ChapterWalks sends exactly five types of event: a tour page viewed; sample audio started; sample audio reached halfway or completed; route guide opened; or App Store link opened. Each event uses only the approved tour, stop, source, milestone, referrer category, and bounded campaign fields. PostHog receives no raw page address, referring-page address, query string, fragment, account ID, or location.
- Cloudflare website performance measurements. Cloudflare measures aggregate page views and how quickly pages load and respond. Measurements can include navigation, resource, paint, layout-shift and interaction timings; the page address and referring-page address with query strings and fragments excluded; browser, device and operating-system categories; navigation type; coarse country; the affected static page element; a query- and fragment-free resource address and byte size; numeric layout rectangles; and provider-defined interaction, initiator and fetch-priority categories. Cloudflare generates a random reference for that page load; it is not a ChapterWalks account or visitor profile. It does not use advertising, session replay, location services, cookies or other browser storage for this stream.
Cloudflare receives the source IP address as part of normal request handling, discards it at the nearest Cloudflare data centre, and does not store it in its core databases or logs for Web Analytics. It may derive only the coarse country category. The first time you grant this notice, the page reloads before Cloudflare loads, so it cannot use performance information from the page on which you made the choice.
Withdrawal limitation. When you turn off website Product analytics, ChapterWalks records your withdrawal and immediately reloads the website without analytics. PostHog stops immediately. Cloudflare does not provide a supported way to stop a beacon already running in the current page; as that page closes for the reload, it may send one final measurement about that page. Cloudflare cannot load again or start a later capture window unless you turn Product analytics back on. Withdrawal does not erase measurements already received.
A choice recorded under the earlier notice web-2026-08-22.v0-1 covered PostHog only and is not reused for Cloudflare. You must make a new choice under web-2026-08-23.v0-2 before either stream can run under the revised notice.
5. Data that stays on your device
Even with the optional choices in section 4 turned on, ChapterWalks does not receive:
- your continuous location or route during a walk;
- fine-grained playback events such as seeking and exact listening timestamps;
- your preference settings — consented analytics events note only which trigger mode was active when the event fired (section 4);
- downloaded tour audio, text, and images stored locally; or
- Health data. If you choose “Save to Health,” the app writes a walking workout to Apple Health and requests no permission to read Health data.
6. Service providers and international transfers
We use the following providers only as needed to operate ChapterWalks:
- Supabase Pte. Ltd. — authentication, database, storage, and server functions, including short-lived service logs. The ChapterWalks project region is Frankfurt, Germany. Supabase's DPA incorporates the EU Standard Contractual Clauses where required.
- RevenueCat, Inc. — purchase validation and entitlement synchronization. RevenueCat processes the account ID and purchase history for entitlements, fraud prevention, customer history, and purchase analytics, not payment-card details. Its DPA incorporates the EU Standard Contractual Clauses where required.
- PostHog, Inc. — optional product analytics, only with your consent (section 4). ChapterWalks uses PostHog's EU Cloud, hosted in Frankfurt, Germany; IP capture and IP-based location enrichment are disabled, and no person profiles are created. PostHog's DPA incorporates the EU Standard Contractual Clauses where required.
- Google Workspace — support and privacy email. Google's data-processing terms and transfer safeguards apply to those messages.
- Cloudflare, Inc. — DNS, website delivery, security and related request logs. Only with your website Product analytics consent, Cloudflare Web Analytics also processes the aggregate page-view and real-user performance measurements described in section 4. For that optional stream, Cloudflare transiently receives and discards the source IP at the nearest data centre, may derive coarse country, and does not create a ChapterWalks account link or visitor profile. Cloudflare's DPA and transfer safeguards apply to that processing.
Apple acts as an independent controller for App Store accounts, payments, refunds, and its own device or store services. Its privacy policy governs that processing.
ElevenLabs is used before publication to synthesize tour narration. No ChapterWalks user data is sent to ElevenLabs.
7. How long we keep data
- Problem reports: 24 months from submission.
- Anonymous accounts that never sign in: 18 months after the last activity.
- Listening progress: until account deletion or the inactive-anonymous-account purge above.
- Signed-in accounts and entitlement records: until the account is deleted, subject to records the law requires us to retain.
- Support and privacy correspondence: normally 24 months after the request is closed, longer only when needed for a legal obligation or claim.
- Optional walk-quality diagnostic events (Supabase): 12 months, deleted by a scheduled purge. Your consent record is kept until account deletion as proof of the choice you made.
- Optional product-analytics events (PostHog): retained by the analytics provider for up to 7 years under its platform policy; the events are not connected to your account.
- Optional website performance measurements (Cloudflare): provider-managed aggregate retention. Cloudflare currently documents that it keeps unsampled beacon data for 7 days, then aggregates it to around 10% for long-term storage, with the previous six months accessible in Web Analytics. Those are the provider's current processing and access periods, not a ChapterWalks promise that every measurement is deleted after 7 days or six months.
- Supabase API, Auth, and service logs: 7 days on the current Pro plan.
- Website delivery logs and backups: according to the provider's security, backup, and deletion schedule.
8. Account and data deletion
Website Product analytics is not connected to a ChapterWalks account. A verified privacy request can delete the first-party website consent record associated with the consent-only browser token. PostHog and Cloudflare data already received follow the provider boundaries and retention in sections 4 and 7. Cloudflare Web Analytics has no ChapterWalks user ID, visitor profile, analytics cookie or browser-storage identifier that ChapterWalks can use to select a person's aggregate measurement. Disabling or deleting a Cloudflare Web Analytics site stops later collection but is not represented as retroactive erasure unless Cloudflare expressly guarantees it.
In the app, go to Settings → Account → Delete account. Deletion removes the RevenueCat customer, Supabase account, sign-in identity, server-side entitlement records, synced listening progress, consented walk-quality diagnostic events and consent records, and local account state. If Sign in with Apple was used, its ChapterWalks authorization is revoked before deletion; an older Apple account may need to sign in with Apple again first so revocation can complete safely. The account link is removed from problem reports, while the report text and technical context remain for the retention period above. That retained content may still contain personal data that the user typed into the report. You may also request deletion at privacy@chapterwalks.com.
Deleting the ChapterWalks account does not cancel or erase the purchase record held by Apple. If you later sign in again, Apple's Restore Purchases process may restore eligible purchases.
9. Your data-protection rights
Depending on the law that applies, you may request access, correction, deletion, restriction, objection, or portability of your personal data. You may also complain to a supervisory authority. Our lead authority is the Italian Garante per la protezione dei dati personali; you may also contact the authority where you live or work.
Send requests to privacy@chapterwalks.com. We may ask for information needed to verify that the request concerns your account.
10. Children
ChapterWalks is not directed to children under 16, and we do not knowingly seek their personal data. If you believe a child has provided data, contact us and we will investigate and delete it where appropriate.
11. Security
We use access controls, encrypted connections, provider security controls, and data minimization. No online system is completely secure, but we limit collection and access to what is needed to operate and support ChapterWalks.
12. Changes and contact
We will update the date above when this policy changes. If a change materially affects how the app uses personal data, we will provide an appropriate notice before the change takes effect. The current version is always available at chapterwalks.com/privacy.
The website Product analytics change does not take effect from an old consent. The revised notice is shown before collection, starts off, and requires a new affirmative choice. The current policy remains available at chapterwalks.com/privacy.
Leandro Ligetta, ditta individuale
Via dei Mocenigo 7, 20137 Milano, Italy
Partita IVA 14484440962
privacy@chapterwalks.com