WayFinder

Legal

Privacy Policy

Last updated: 30 July 2026

Important: WayFinder is assistive support only. It does not guarantee safety or replace primary mobility tools.

What WayFinder processes

Camera image

When you press the analysis button, ask a visual question, or open navigation after enabling "start navigating on launch," the app takes one photo and sends it over encrypted HTTPS to the WayFinder backend. The backend sends that photo to Google's Gemini API to produce a scene description. WayFinder does not continuously record video.

WayFinder does not write the raw photo to its server database or durable application storage. The camera plugin creates a temporary device file for upload and the app deletes it after the request, although an operating-system cache may survive a crash. Google's processing is governed by the Gemini API Additional Terms and Google Privacy Policy. The production service uses a billing-enabled Gemini API project so Paid Services data terms apply.

Voice questions

Your device's operating-system speech recognizer converts speech to text. WayFinder sends the resulting text to the backend. WayFinder does not send or store raw microphone audio.

Account and history

Firebase Authentication provides a stable account identifier and may provide your email address, display name, and sign-in provider. WayFinder stores your question, derived response, confidence and grounding metadata, timestamps, request identifiers, and model-usage accounting. It does not collect device location or request location permission, but question text or a visible sign can contain a place name or address.

Why the data is used

WayFinder does not sell personal data, show advertising, or use user data to train its own models.

Retention and deletion

Interaction history and duplicated response text used for idempotent retries are scheduled for deletion after 30 days. Non-content lifetime usage accounting remains until account deletion. You can erase history and duplicated ledger response text at any time inside the app. Deleting your account erases messages, sessions, model-usage records, rate-limit state, and the scene memory in the handling process, then requests deletion of the Firebase identity. Other running processes can retain isolated scene facts for at most 30 seconds. We retain only an irreversible hash of the former account identifier to serialize deletion against already in-flight writes. If Firebase proves that identity deletion failed, the app reports the partial failure and allows a retry. If Firebase's status cannot be determined safely, the write barrier remains and support is required. Encrypted Cloud SQL backups may retain deleted rows until their configured expiration, but are not available through the product and are removed through backup expiry.

Security

Traffic is encrypted in transit. Protected API routes require a Firebase ID token, and inference routes enforce Firebase App Check. Stored records are scoped by Firebase UID. Production secrets are held in Google Secret Manager, and the database is encrypted at rest by Google Cloud.

Children

WayFinder is not directed to children under 13. If you believe a child provided personal data, contact us so it can be deleted.

Contact

Email support@way-finder.tech.