Privacy Policy
Last updated: July 2026 (added website analytics disclosure — Cloudflare Web Analytics, cookieless; previously: clarified that NPS survey answers go to Mixpanel, not Google Forms; added Firebase Remote Config disclosure)
WhereIGo is designed with your privacy in mind. All trip data stays on your device. No account is required to use the app.
Data stored on your device
Trips, days, activities, preferences, and your Google Places API key are stored locally using MMKV encrypted storage. This data never leaves your device unless you explicitly share a trip via the Export function.
Anonymous analytics
WhereIGo collects anonymous usage data to understand how the app is used and to fix crashes. A random identifier is generated on first launch and stored on your device — it is never linked to your name, email, or any personal information. The analytics SDKs (Mixpanel and Firebase) may also access your device's resettable Advertising ID for analytics de-duplication. This identifier is never used for advertising or profiling. You can reset or opt out of it at any time in your device's Google settings.
Mixpanel — records which features you use (e.g. creating a trip, opening the map), performance timing (e.g. how long network requests take), your answer to the in-app 0–10 recommendation (NPS) question if you respond to it, and — if you reset app data — the categorical reasons you optionally select. No trip content, location coordinates, free text, or personal details are included in any event. Subject to Mixpanel's Privacy Policy.
Firebase Crashlytics — records crash reports and the app screen you were on when a crash occurred. No personal data is attached to crash reports. Subject to Google's Privacy Policy.
Firebase Remote Config — used to deliver feature-flag defaults remotely. No personal data is sent — only anonymous flag keys and boolean values. Subject to Google's Privacy Policy.
Third-party services
WhereIGo optionally connects to the following services when configured:
Google Places API — used for location search and nearby recommendations. Requests are sent directly from your device to Google's servers. Subject to Google's Privacy Policy.
Open-Meteo — used for weather forecasts. No personal data is sent. Open-Meteo is a free, open-source weather API.
Wikipedia — used for destination hero images. Image requests do not include personal data.
Google Forms — when you submit feedback via the post-trip prompt or the in-app "Share feedback" link, your star rating, the free text you type, your platform (iOS / Android), and the app version are sent to a Google Form. No identifier links the submission to you. Subject to Google's Privacy Policy.
This website
whereigo.app uses Cloudflare Web Analytics, a privacy-first measurement tool. It sets no cookies, stores nothing on your device, and does not fingerprint or track you across sites — we only see aggregate counts of page views and where visitors came from. Subject to Cloudflare's Privacy Policy.
Permissions
Location access is requested only when you tap "My Location" on the Map tab. Notification access is requested when you set a reminder on an activity, or when you turn on any trip-level notification (countdown, empty-day nudge, morning digest) in Profile → Notifications. All notifications are scheduled locally on your device — none are sent from a server. None of these features are required to use the app.
No required accounts, no ads
WhereIGo does not require an account — the app works fully offline. There are no ads. Analytics are fully anonymous — we cannot identify you from the data collected.
Account & data deletion
WhereIGo has no accounts — all your data lives on your device. Open Profile → Reset app data inside the app to clear your trips, days, activities, and settings. Uninstalling the app has the same effect. To also purge your historical anonymous analytics events, see the Account & Data Deletion page.
Contact
Questions about this policy? Email privacy@whereigo.app