Privacy Policy — Pocket Guide
This policy applies to the iOS application "Pocket Guide" (問導遊), developed by Fermata ("we", "us"). Our principle is simple: we collect only what is necessary to provide the service, and we never sell your personal data.
The app offers several features: real-time spoken narration; reading and translating menus and signs from a photo; two-way live translation; finding a restroom; asking to use a restroom; Location (sharing where you are so family or your guide can find you when you get separated); and Meetup (group meeting-time reminders). Different features use different data and permissions, as described below.
1. Information We Collect
1.1 Anonymous identifier
There is no sign-up. The app uses Firebase Anonymous Authentication, which means we never ask for — and never receive — your name, email address, or any other contact information. Firebase simply assigns your installation a randomly generated anonymous identifier, which we use solely to manage service quotas and prevent abuse.
1.2 Images and voice (narration and reading signs)
The app's core feature is real-time spoken narration: images from your camera (photos you take, and live camera frames while you hold to record), the voice questions you ask, and any menu or sign you photograph to have read aloud and translated, are sent directly from your device to our third-party AI service provider (currently Google's Gemini API) to generate live responses.
- Your images and voice are never stored on our servers — our backend only issues short-lived access tokens and never sees or handles your photos or audio. The only exception is a feedback report you actively choose to submit (see section 1.7).
- Images and voice are used only to generate the response in that moment, never for advertising or marketing.
- Our AI provider's handling of this data is governed by its own privacy policy and API terms (currently the Google Privacy Policy).
- If you allow location access, your approximate GPS coordinates are attached to narration requests so explanations can reflect where you are.
1.3 Two-way live translation
The translation feature uses the microphone to capture what both you and the other person say, and sends it directly to Google's Gemini translation model for real-time interpretation.
- The speech of both parties is processed. Before you start translating, we suggest letting the other person know you are using live translation.
- Voice and translation content are never stored on our servers (we only issue short-lived tokens).
1.4 Find a restroom and ask to use a restroom
- Find a restroom: your current GPS coordinates are sent to our server to return nearby public restrooms (data from OpenStreetMap contributors and local government open data). The coordinates are used only for that query and are not stored or tied to your identity.
- Ask to use a restroom: your device looks up nearby venues locally via Apple Maps (name, category, brand) and sends that batch to our server to match against our "restroom etiquette" knowledge base and return guidance; this venue data is used at query time and not stored.
- The communication card uses the microphone to capture the shop staff's spoken reply and sends it to Gemini to help you understand it; the staff's voice is not stored. After a session, we keep only an anonymous, identity-free statistic (the venue, the outcome, and the time, with coordinates coarsened to roughly identify the venue only) to improve how well this feature works.
1.5 Looking up current information
During narration, if current or up-to-date information is needed, the app sends a search query generated by the AI (not your raw conversation) to our server, which uses Google Search to return a brief factual summary that is folded back into the narration.
1.6 Usage records
To manage service quotas and prevent abuse, we record how many sessions of each feature you start and when (stored in Google Firestore). These records contain counts and timestamps only — no photo or conversation content.
1.7 Feedback and sharing
- When you actively rate a narration (thumbs up or thumbs down), the image frames and the conversation transcript of that session are uploaded to us and used to improve the service. Your original voice recordings are never uploaded — only the text transcript of the conversation. Feedback reports are tied to your anonymous identifier and are covered by the deletion process in section 5.
- When you tap "Share" to create a share card, the conversation transcript of that session is sent to our server to generate a quote in real time, then discarded and not stored.
1.8 Location (sharing where you are when separated)
The Location feature lets you share where you are with family or your tour guide when you get separated. We only store location data when you actively tap "Share my location" — we never track you in the background. When you report, your coordinates (and, only if you choose, a human-readable address, your battery level, one or more photos, videos or audio clips of your surroundings, and a selfie) are stored under a random, unguessable link so that anyone you share that link with can see where you are on a map. If you create a rescue link, the contact method you choose (FaceTime, LINE, or phone) is stored with the link so the person who is lost can reach you.
This data is temporary and is tied only to the random link, not to your identity:
- Lost-and-found link: deleted automatically after a few hours (at most 48 hours); cleared as soon as you close the link or leave.
- Group-tour tracking link: because a tour usually lasts several days, it is kept longer (about two weeks, at most 45 days); it is archived when the trip ends and deleted at expiry.
1.9 Meetup (group meeting reminders)
When you share a meeting point or group itinerary, the meeting place's name, coordinates, time and notes are stored under a random link (or a 6-digit code) so that the people traveling with you can subscribe via the link, code or QR code, view it on a map, and be notified when it changes. When someone subscribes, we store a device token used for notifications and the display name they set.
- This data is deleted automatically after the period you set (about one month by default, at most 90 days).
- Meeting points you create but do not share stay only on your phone and are not uploaded.
2. Device Permissions
- Camera — to photograph what you want explained or the text you want read aloud. No images are captured without your action.
- Microphone — to receive your spoken questions and real-time conversation; when using two-way translation or the restroom communication card, it also captures the other person's or the shop staff's voice. Active only while the relevant feature is in use.
- Location — to make narration aware of where you are, and to power finding a restroom, asking to use a restroom, Meetup, and Location sharing. Granted as "While Using the App"; never tracked in the background.
- Speech Recognition — to convert your voice to text on your device (live captions and voice feedback). Only the resulting text is uploaded, and only where this policy says so.
- Notifications — used by Location (someone joining a room, posting a message, or a rescue link about to expire) and Meetup (meeting alarms and changes to a meeting point). You can turn these off anytime in iOS Settings.
You can revoke these permissions anytime in iOS Settings; the related features will stop working.
3. How We Use Information
We use the information we collect only to:
- provide real-time image recognition, spoken narration, translation, finding/asking for a restroom, finding each other when separated, and meeting reminders;
- when you actively use those features, send the necessary location or query to our servers to complete the service;
- verify requests and manage service quotas;
- keep the service secure and prevent abuse;
- improve service quality, using de-identified statistics only.
We do not sell or rent your personal data, and we do not use it for third-party advertising.
4. Third-Party Services
- Google Firebase (authentication, database, anonymous usage analytics & crash reporting) — Privacy and Security in Firebase
- AI model provider (image analysis, voice narration and translation) — currently the Google Gemini API (Google Privacy Policy)
- Public restroom data — OpenStreetMap contributors and local government open data (attributions are shown in the app's "Data sources").
- Apple Maps (used locally to look up nearby venues for "ask to use a restroom"; queried in real time, not stored).
Because these providers (such as Google) operate globally, your data may be processed on servers located outside your country or region. If we switch or add service providers, we will update this page before the change takes effect.
5. Data Retention & Deletion
- Usage records are tied only to your anonymous identifier and are retained while the service operates.
- Location and Meetup data are tied only to a random link and are deleted automatically within the periods described above.
- The restroom statistic is anonymous and contains no identity information.
- You can delete your data at any time directly in the app (Settings → Advanced → Delete My Data). This immediately deletes your feedback, submitted reports (including images and transcripts), and custom quota settings. To prevent abuse, today's usage count is kept until the end of the day. You may also email us to request access to or deletion of data tied to your anonymous identifier. Because the app is anonymous, we generally cannot otherwise identify which data belongs to you.
- Deleting the app removes the anonymous identifier from your device; it cannot be re-associated with you afterwards.
6. Children's Privacy
This app is not directed at children under 13. If we learn that we have collected personal information from a child without parental consent, we will delete it promptly.
7. Security
All network traffic is encrypted (HTTPS / WSS). Access to the AI service uses short-lived tokens with usage and expiry limits, minimizing exposure.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be announced in the app or on this page, and take effect when posted here.
9. Contact
Questions about this policy or your data: support@fermatalabs.co