Privacy Policy
Last updated: 17 August 2026
Hysa Tech ("we", "our", or "us") operates WhereShot: Photo Location AI (the "App"). This Privacy Policy explains what the App collects, what it deliberately keeps on your device, and who else is involved. WhereShot reads photographs and builds a map of where you have been, so being specific about this matters more than usual. By installing or using the App, you agree to the practices described here. If you do not agree, please do not use the App.
1. The Short Version
- A photo you ask us to identify is sent to Google to be read by its Gemini model, because the identification happens in the cloud rather than on your phone. That is the one thing the App cannot do without.
- Your camera-roll Atlas never leaves your device. The map built from the location tags already in your photo library is assembled on the phone, named against a dataset shipped inside the App, and stored only on that phone. We never receive it.
- Keeping the photo is optional. Turn off "Save result" in Settings and only the location is stored, never the picture.
- You can use the App without giving us your name or email. Signing in with Google or Apple is offered so your places follow you to a new phone; it is not required.
- We receive subscription, crash, analytics and advertising attribution data through Apple, Google, RevenueCat and Meta, described in section 6. None of it names a place you have been.
- You can delete your account and everything stored with it from inside the App, without contacting anyone.
2. Your Account
WhereShot creates an anonymous account for your device the first time you open it. That account is an identifier and nothing else: it carries no name, no email address and no password, and it exists so your saved places have somewhere to live.
You may optionally sign in with Google or with Apple. If you do, we receive the email address and display name that provider chooses to share, so that your places can be restored on another device. Apple's Hide My Email gives us a relay address instead of your real one, and the App works exactly the same either way. We never receive your password from either provider.
Accounts and sign-in are handled by Firebase Authentication. Deleting your account from Settings removes it, together with the data described in section 4.
3. Photos You Ask Us to Identify
When you choose a photo to identify, or send one to WhereShot through the share sheet, the App resizes and compresses it on your device and sends it to Google's Gemini model through Firebase AI Logic. Google acts as our processor: it reads the image, returns the place it believes the photo shows along with the visual clues behind that answer, and under the paid terms that apply to our project it does not use your image to train its models. Google retains request data for a limited period for abuse monitoring, as described in its own terms.
To turn a candidate into a real place with an address and opening hours, the App may make a second, grounded request that consults Google Maps data. That request carries the place under discussion, not your photo.
Some photos never need the model at all. If a photo already carries GPS coordinates of its own, WhereShot reads them on your device and names the place from a dataset bundled inside the App. When you open such a place, the App may ask the Google Geocoding API for the precise street address at those coordinates.
Whether the photo itself is kept is your choice. While "Save result" is on, a copy is stored in Firebase Storage under your account identifier so your Places can show it. Turn it off in Settings and no copy is stored: the location is saved and the picture stays on your phone.
4. Places and Results We Store
Under your account identifier, in Google Cloud Firestore, we store:
- Identified places: the place name, city and country, the coordinates, the address, the clues the model read, how confident it was, the date, and a link to the photo if you chose to save it.
- Saved places: anywhere you mark as "Been" or "Want to go", with the notes you write yourself.
- Your account record: the identifier, the sign-in details described in section 2, and any unspent identification credits bought in an earlier version of the App.
Taken together this is a record of places you have looked up, and we treat it that way. It is not sold, not shared with advertisers, and not used to build a profile of you. We access it only where we must to operate the service or to answer a support request you send us.
5. What Stays On Your Device
Some of what the App knows about you is deliberately never sent anywhere:
- The Atlas. When you let WhereShot scan your camera roll, it reads the coordinates already attached to your photos, names each one against a dataset of roughly 170,000 settlements shipped inside the App, and writes the result to a file on that device. It is the largest thing the App knows about where you have been, and it is the one thing we never receive. It is not backed up to our servers and does not follow you to a new phone; a new phone rebuilds it from its own library.
- The photos in your library. Scanning reads location metadata. Image pixels are only ever read for the specific photo you hand the App to identify.
- Your current location. Used to work out whether you are near somewhere on your list, compared against your places on the device, and never transmitted to us.
- Your reminders. Notifications are scheduled on the device from data already on it. There is no push server, so we do not learn when or whether you were nudged about a place.
6. Service Providers
WhereShot relies on the following third parties. Each has its own privacy policy, and we have linked them so you can read what they do with what they receive.
- Google (Firebase and Gemini): authentication, the Firestore database, photo storage, the AI identification described in section 3, crash reporting, analytics, app-integrity checks and remote configuration. Google Privacy Policy
- Google Maps Platform: the maps drawn in the App, the grounded place lookup, and reverse geocoding of coordinates.
- Apple and Google Play: payment for subscriptions. We never see your card details; the stores tell us only that a purchase is valid.
- RevenueCat: manages subscription entitlements, and receives a purchase identifier tied to your account identifier so the App knows what you are entitled to. RevenueCat Privacy Policy
- Meta: install attribution for our advertising, as described in section 8. Meta Privacy Policy
7. Permissions and Why They Are Needed
Every permission is optional, asked for at the moment it is used, and refusing one only disables the feature that needs it.
- Photos: to let you pick a photo to identify, and to read the location tags the Atlas is built from.
- Camera: only if you choose to take a new photo instead of picking an existing one.
- Location, while using the App: to tell you when somewhere on your want-to-go list is nearby. WhereShot never asks for background location and does not track your movements.
- Notifications: for the reminders described in section 5, all of them scheduled on your device.
- App Tracking Transparency (iOS): asked once, and covered in section 8. Declining changes nothing about how the App works.
8. Analytics and Advertising
We use Firebase Analytics and Firebase Crashlytics to understand whether the App works and whether people come back to it. The events we record are counts and outcomes: whether a permission was granted, whether a reminder was opened, whether a crash happened and where in the code. No analytics event carries a place name, a coordinate, or anything else about where you have been.
We advertise the App on Meta platforms, and the Meta SDK is included so that installs can be attributed to those campaigns. On iOS this uses the advertising identifier, which is why iOS asks you once for permission to track. If you decline, or if you are on Android with advertising ID collection disabled, attribution simply runs without it. There are no adverts inside WhereShot, and we do not sell or share your personal information for cross-context behavioural advertising as those terms are defined under United States state privacy laws.
9. Your Rights and Choices
Most of what you might want to do is available inside the App, with no request to us and no waiting:
- Delete a single place or result from Places at any time.
- Stop storing photos by turning off "Save result" in Settings.
- Delete your account and its data. Settings → Delete Account permanently removes your account, your identified places, your saved places and the Atlas on that device. If you are not signed in, the same option deletes the data held for your anonymous account. This cannot be undone, and a subscription must be cancelled separately through the App Store or Google Play. The full list of what goes and what does not is on our account and data deletion page.
- Revoke any permission from your device settings.
Depending on where you live, you may also have the right to access, correct, export or restrict the processing of your personal data, to object to it, and to complain to your local data protection authority. Where the GDPR applies, our legal bases are the performance of our contract with you (identifying photos, keeping your places, running your subscription), our legitimate interests (keeping the App working, preventing abuse, measuring whether our advertising works), and your consent where the device asks for it, such as tracking on iOS.
To exercise any of these rights, write to support@hysa-tech.com and we will respond within the time your law allows, and in any case within 30 days.
10. Data Retention
Your places, results and saved photos are kept until you delete them or delete your account, because their whole purpose is to still be there next year. Deleting a single result also deletes the photo saved with it; deleting your whole account leaves the stored image files permanently unreadable rather than erased, and we will erase them on request, as explained on our account and data deletion page. Crash and analytics records are retained for the default periods set by Firebase. Data held on your device, including the Atlas, disappears when you delete the App.
11. International Transfers
Our providers operate globally, so the data described above may be processed on servers outside your country, including in the United States. Where data leaves the European Economic Area or the United Kingdom, our providers rely on the European Commission's Standard Contractual Clauses and equivalent safeguards.
12. Children's Privacy
WhereShot is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Security
All connections between the App and our providers use HTTPS. Access to your stored places and photos is restricted to your own account by server-side security rules, and requests are checked with Firebase App Check so that data cannot be pulled from our backend by something that is not the App. No method of storage or transmission is perfectly secure, but the strongest protection here is structural: the largest record of your movements, the Atlas, is never uploaded, so there is no copy of it for anyone to breach.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date at the top and, where the change affects how your data is handled, note it in the App. Continued use of the App after a change constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions, concerns, or requests about this Privacy Policy or how WhereShot handles data, please contact us:
- Email: support@hysa-tech.com
- Company: Hysa Tech
- Website: hysa-tech.com
- App page: hysa-tech.com/whereshot
