Privacy Policy
Last updated: 12 August 2026
This Privacy Policy explains what personal data the Viti app ("Viti", "the app", "we", "us") collects, why we collect it, and how you can control it. Viti is a travel companion app for exploring points of interest in Iceland, developed by an individual developer based in the European Union.
If anything here is unclear, contact us at hey@viti.guide.
Viti is operated by an individual developer, not a registered company. The developer is the data controller for the purposes of the EU General Data Protection Regulation (GDPR). Contact: hey@viti.guide.
1. What data we collect
We only collect data you give us directly through the app, or that is generated by using its features. We do not buy data about you from third parties, and we do not use advertising trackers.
| Category | What it includes | Why we collect it |
|---|---|---|
| Account & authentication | Email address and password (stored securely by our authentication provider, Supabase Auth — we never see or store your raw password) | To create and secure your account, and to log you in |
| Profile data | Display name, avatar photo, bio, preferred language, preferred currency, and whether your profile is public or private | To personalize the app and, if you choose to make your profile public, to show it to other users (public profile, friends, leaderboard) |
| Tick-off photos & visit records | Photos you take to "tick off" a point of interest, the date/time of the visit (including the photo's EXIF timestamp), which point of interest it relates to, and any friends you tag as travel companions on that visit | To record your travel history, show it back to you, calculate badges/achievements, and (if the visit or your profile is public) show it to other users |
| Location tied to visits | The location of the point of interest you tick off (a fixed, pre-catalogued Iceland location — not continuous GPS tracking of your movements) | To associate your visit with the correct place and show it on the map |
| Friends & social connections | Friend requests and friendships between accounts, shared/collaborative travel lists | To power the friends list, shared lists, and leaderboard features |
| User-generated content | Travel tips you write, custom travel lists and their contents, points of interest you suggest for addition to the app (with optional photos) | To power lists, tips shown to other travelers, and to grow the app's point-of-interest catalog |
| Content reports | Reports you submit about another user's profile, visit, or tip; reports submitted about your own content; and the moderation outcome of a report | To review and act on reports of inappropriate content or behavior |
| Notifications | In-app notifications (e.g. friend requests, list invites) and their read status | To let you know about activity relevant to you |
| App usage & diagnostics | Basic in-app events (e.g. app opened, a point of interest ticked off) tied to your account | To understand how the app is used and to improve it |
2. How we store and process your data
Viti's backend is built on Supabase, a third-party Backend-as-a-Service provider, which hosts our database, file storage, and authentication. Your account credentials, profile, visit records, and photos are stored on Supabase's infrastructure. Supabase acts as our data processor and applies row-level security so that, in almost all cases, only you can read or write your own private data.
We also use the following processors for specific features:
- Microsoft Azure Translator — used to automatically translate travel tips into the app's supported languages.
Some of these providers may process data on servers located outside the European Economic Area (EEA). Where that happens, the provider is contractually bound (for example via the EU Standard Contractual Clauses) to protect your data to a standard equivalent to the GDPR.
3. Photos
Tick-off photos, profile avatars, and photos attached to point-of-interest suggestions are uploaded to Supabase Storage. Tick-off and suggestion photos may be visible to other users if the related content is public (e.g. a public profile's visit history, or the point-of-interest submission itself). Avatar photos are shown wherever your profile is shown. We read the photo's EXIF date/time (when present) to timestamp your visit, but we do not extract or store embedded GPS coordinates from photo EXIF data.
4. Public profiles and visibility
Making your profile public is optional and is your choice, controlled in Settings. If your profile is public, other users may see your display name, avatar, visit history, badges, and position on the leaderboard. If your profile is private, this information is only visible to you (and, for a specific visit, to any friend you've tagged as a companion on that visit).
5. Legal basis for processing (GDPR)
- Performance of a contract — processing needed to create your account and provide the app's core features (visits, lists, friends).
- Consent — for optional features you actively choose, such as making your profile public or tagging a friend on a visit.
- Legitimate interests — for basic diagnostics/usage events, keeping the app secure, and reviewing content reports.
6. Data retention
We keep your account data for as long as your account is active. If you delete your account (see our Account Deletion page), your profile, visit records, photos, lists, friendships, and notifications are deleted. One exception: if content you created is the subject of an open content report, we may retain that specific content for up to 90 days after account deletion so the report can be reviewed, after which it is deleted.
7. Your rights
If you are in the EEA, UK, or a jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (most profile fields are editable directly in the app)
- Request deletion of your account and data (see Account Deletion)
- Object to or restrict certain processing
- Request a copy of your data in a portable format
- Lodge a complaint with your local data protection supervisory authority
To exercise any of these rights, email hey@viti.guide.
8. Children's privacy
Viti is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
9. Security
We rely on Supabase's infrastructure security, encrypted connections (HTTPS/TLS) between the app and our backend, and database-level access rules (row-level security) that restrict each user to their own data. No method of transmission or storage is 100% secure, but we take reasonable steps to protect your information.
10. Changes to this policy
We may update this Privacy Policy from time to time, for example as the app gains new features. We'll update the "Last updated" date above when we do. Material changes will be noted in the app.
11. Contact
Questions about this policy or your data: hey@viti.guide