Privacy Policy
Last updated 9 September 2026
WhereToGo is an app for sharing places you like with people you choose. This policy explains exactly what the app collects, why, where it is kept, and how to get rid of it. It describes what the app actually does — not what a template says.
The short version. We collect your account details, your profile, what you post, and your location while the app is open. We show your location only to the people your own privacy settings allow. We measure how the app is used and record crashes so we can fix them. There are no adverts, no advertising identifier, and nothing about you is ever sold or shared with data brokers. You can delete everything, permanently, whenever you want.
Who this applies to
This policy covers the WhereToGo mobile app and the services behind it at
getwheretogo.com. WhereToGo is operated from Morocco. Wherever this policy
says “we”, it means the operator of WhereToGo.
What we collect, and why
| What | Why |
|---|---|
| Account Your email address. If you sign in with Google, also the name and profile picture on your Google account. |
To create your account and let you sign back in. Sign-in is handled by Firebase Authentication — if you use a password, we never see it. |
| Profile Your @handle, display name, profile photo, age, short bio, whether your account is private, and your per-field privacy settings. |
So other people can find you and recognise you, and so the app knows which parts of your profile you are willing to show. |
| Location Your device's position and its accuracy, the place you are at, whether you are currently out, and when that was last updated. |
To show you places near you, and — only if you allow it — to let people see that you are out somewhere. See the section below. |
| What you post Photos, captions, comments, messages in a place's chat, likes, saves, and who you follow. |
This is the content of the app. It is shown to whoever your privacy settings and follower list allow. |
| Push token A notification identifier issued by Google for your device, and whether it is Android or iOS. |
To send you a notification when someone follows you or replies to you. Deleted as soon as it stops working or you sign out of that device. |
| Connection data Your IP address, briefly, as part of every internet request. |
Handled by Cloudflare to deliver the request and to block abuse. We do not build profiles from it or keep it alongside your account. |
| Usage and crashes Which screens are opened and which features are used, your device model, operating system version, language, and the country your connection appears to come from. If the app crashes: the technical report describing where it failed and what the device was doing. |
To understand which parts of the app people actually use, and to find and fix crashes. Collected through Google Analytics for Firebase and Firebase Crashlytics, against a random identifier for your app installation. See below. |
Location, specifically
Location is the part of this app people care most about, so here is precisely how it works:
- Location is read only while the app is open. WhereToGo does not request background-location permission and cannot follow you when the app is closed.
- We keep only your most recent position — not a history. Each new reading overwrites the previous one. There is no trail of where you have been, because the app never stores one.
- Who can see that you are out is governed by your own privacy settings. Set presence or location to private and other people are shown a count they are part of, never you.
- Crowd information shown on the map is aggregated. A place is only ever described as busy once enough people are there for no individual to be identifiable from it.
- You can refuse the location permission entirely. The map then shows places without centring on you, and the rest of the app works normally.
Photos
Photos you post are stored on Cloudflare R2 in the European Union and served from
photos.getwheretogo.com. Before uploading, the app shrinks each photo and
strips the metadata your camera attached to it, so the GPS coordinates, camera model and
timestamp embedded in the original file are not uploaded.
Photos of places that nobody has posted at yet come from Google and are fetched fresh each time they are displayed. We do not copy or store them, and they are credited to their photographer on the image.
Who else is involved
We use a small number of service providers to run the app. They process data on our instructions and for no purpose of their own.
| Provider | What they do | Where |
|---|---|---|
| Google (Firebase Authentication, Firebase Cloud Messaging) | Signing you in; delivering push notifications | EU / United States |
| Google (Analytics for Firebase, Crashlytics) | Measuring how the app is used; crash reports | EU / United States |
| Cloudflare | Serving the API; storing photos and map tiles | European Union |
| PlanetScale | The database holding your account and content | Ireland (eu-west-1) |
| Google Maps Platform | Photos of places, fetched live and not stored | United States |
Place information itself — names, addresses, categories — comes from Foursquare's open places data and map tiles are built from OpenStreetMap. Neither receives anything about you.
We may also disclose information if the law genuinely requires it, or where it is necessary to protect someone's safety. We will tell you when we are permitted to.
Measurement and crash reports
The app includes Google Analytics for Firebase and Firebase Crashlytics. Analytics tells us things like how many people opened the map this week or how far people get through signing up; Crashlytics tells us when the app has broken and where.
- Both are tied to a random identifier generated for your installation of the app, not to your name or email. Deleting and reinstalling the app produces a new one.
- The advertising identifier is switched off. The app does not collect it, so nothing here can be used to target adverts at you anywhere.
- We do not send the content of your posts, messages, photos or your precise position to either service. Location in Analytics is only the country your connection appears to come from.
- Crash reports contain technical state — the sequence of code that failed, device model, memory — and can occasionally include a place identifier where that is what caused the crash.
What we do not do
- We do not sell your personal data, and we do not share it for advertising.
- There are no adverts in the app.
- The app does not collect an advertising identifier.
- We do not track you across other apps or websites.
Your choices inside the app
- Private account. Only approved followers see your posts.
- Per-field privacy. Your photo, age, bio, location, presence and posts each have their own visibility setting.
- Permissions. Location and notifications are both optional and can be withdrawn at any time in your phone's system settings.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to a particular use. Where we rely on your consent — precise location and push notifications — you can withdraw it at any time without affecting what came before.
If you are in the European Economic Area or the United Kingdom, our legal bases are: performing our contract with you (your account and the content you post), your consent (location and notifications), and our legitimate interest in keeping the service safe, working and improving (crash reports and usage measurement). You have the right to complain to your national data protection authority. In Morocco, that authority is the CNDP.
To exercise any of these, write to privacy@getwheretogo.com. We will answer within 30 days.
Deleting your account
You can delete your account and everything in it permanently. This erases your profile, your posts and photos, your comments and messages, your likes and saves, who you follow, your stored location and your notification tokens. It cannot be undone.
How long we keep things
- Your account and content: until you delete them.
- Your location: only the latest reading, replaced each time and removed with your account.
- Push tokens: removed when they stop working or you sign out.
- Usage and crash data: kept by Google for up to 14 months, and crash reports for 90 days, then deleted automatically.
- Backups: deleted data can persist in encrypted database backups for up to 30 days before those backups expire.
Children
WhereToGo is not for children. You must be at least 13 to use it, and older where your country sets a higher age for consenting to online services on your own. If we learn that an account belongs to a child below that age we will delete it.
Security
Traffic is encrypted in transit. The app has no direct access to the database: every read and write goes through a function that enforces your privacy settings on the server, so there is no request the app could make that would return something you were not permitted to see. No system is perfect, and we will tell you and the relevant authority promptly if a breach ever affects you.
Changes
If we change this policy we will update the date at the top, and we will tell you in the app before anything that materially affects you takes effect.
Contact
Questions, requests, or anything that looks wrong: privacy@getwheretogo.com.