Privacy Policy
Last updated 24 July 2026
This policy explains what NOTCH collects, why, and who else sees it. It is written to be read, not to be survived. If anything here is unclear, email us and we will explain it properly.
Who we are
NOTCH ("we", "us") is the data controller for the information described here.
Raayan Hemrajani
PLACEHOLDER_ADDRESS
notchappusa@gmail.com
For any privacy question, request or complaint, email the address above. We aim to respond within 7 days, and within 30 days at the outside for formal data requests.
What we collect
Information you give us
- Account details — your email address, and a username. If you sign in with Apple or Google, we receive the email address associated with that account.
- Profile content — display name, bio, and profile photo, if you add them.
- Your ratings and places — the places you log, how you rank them, notes, tags and photos you attach.
- Quests and itineraries — the preferences you enter when generating a quest (activity type, budget, group, timing, free-text notes), and the resulting itineraries.
- Social content — quest posts, captions, comments and likes.
- Support messages — anything you send us directly.
Information collected automatically
- Approximate location — only while the app is open, and only if you grant permission. We use it to find places near you. We do not track your location in the background, and we do not build a location history.
- Push notification token — if you enable notifications, so we can send them.
- Basic technical data — device type and app version, as part of ordinary service operation and error logs.
Camera, photos and location
NOTCH asks for three device permissions, each only when you first use the feature that needs it, and each is optional:
- Location — to find places near you when generating a quest. Without it you can still search for a location manually.
- Photo library — to attach photos to places and quests you have logged.
- Camera — to take those photos directly.
You can revoke any of these at any time in your device settings. The app continues to work with reduced functionality.
How we use your information
- To create and run your account.
- To generate quest itineraries matched to your stated preferences and your ranked places.
- To show your content to other users where you have chosen to make it public.
- To calculate aggregate place ratings from many users' ratings.
- To send push notifications you have opted into.
- To handle subscriptions, and to enforce free-tier usage limits.
- To investigate reports, prevent abuse, and keep the service secure.
Artificial intelligence
Quest generation uses third-party AI services. When you generate a quest, we send the preferences you entered and a list of nearby candidate places, together with the names of places you have ranked highly, to one of the providers below. This is how the itinerary is written.
- Groq — generates most itineraries.
- Anthropic — used for some itinerary generation.
We do not send your email address, your name, your precise coordinates, your photos, or your contact details to these providers. We ask for your consent before the first time this happens, and you can decline; the AI features will then be unavailable, and the rest of the app continues to work.
Who else processes your data
We use a small number of service providers. They process data on our instructions, for the purposes below, and nothing else.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All account and content data |
| Groq | AI itinerary generation | Quest preferences, candidate places, names of your top-ranked places |
| Anthropic | AI itinerary generation | As above |
| Google Maps Platform | Place search, maps, place details | Search terms and approximate coordinates |
| RevenueCat | Subscription management | Your account identifier and purchase status |
| Apple / Google | App distribution, sign-in, payment processing | Handled under their own privacy policies |
| Expo | Push notification delivery | Your notification token and message content |
Payment card details never reach us. Purchases are handled entirely by Apple or Google.
What other users can see
Some content is public within the app by design:
- Your username, profile photo and bio.
- Quest posts you choose to publish, with their captions and comments.
- Your ranked places, if "Rankings public" is enabled in Settings.
- Your completed routes on the map, if "Show my routes" is enabled.
Each of these can be turned off in Settings. Your email address is never visible to other users.
How long we keep things
We keep your data while your account is open. When you delete your account, we delete your profile, ratings, quests, posts, comments, photos and account record. Deletion is immediate and permanent — we cannot restore a deleted account.
Two limited exceptions: content reports are retained in anonymised form so that abuse patterns remain visible after an account is gone, and we may retain records required for tax or legal compliance.
Your rights
Wherever you live, you can:
- Access and export your data — Settings → Export my data produces a complete JSON file.
- Delete your account and data — Settings → Delete account. No email required, no waiting.
- Correct your information — edit your profile at any time.
- Control what is public — the privacy toggles in Settings.
- Withdraw consent — revoke device permissions, disable notifications, or decline AI processing.
If you are in the UK, EU or EEA, you additionally have the right to object to or restrict processing, the right to data portability, and the right to complain to your local data protection authority. Our lawful bases are: performance of a contract (running your account), legitimate interests (security, abuse prevention, improving the service), and consent (location, notifications, AI processing).
If you are in California, you have the right to know what we collect, to delete it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
Security
Data is encrypted in transit and at rest. Access is restricted by database-level row security, so accounts cannot read each other's private data. API credentials are held server-side and never shipped in the app. No system is perfectly secure, but we treat this seriously and fix problems quickly when we find them.
Children
NOTCH is not intended for anyone under 13, is not directed at children, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we delete it. If you believe a child has created an account, contact us and we will remove it promptly.
Automated decision-making and profiling
NOTCH builds a taste profile from the places you rank, and uses it to order recommendations and to suggest other users with similar taste. This is profiling in the sense meant by the GDPR, but it has no legal or similarly significant effect on you: it only changes which places appear first. You can opt out of appearing in other users' taste matching in Settings, and you can stop the profile growing at any time by not ranking places.
Analytics and tracking
NOTCH contains no third-party advertising or analytics SDKs. We do not use cookies in the app, and we do not track you across other apps or websites. We therefore do not respond to browser Do Not Track signals, because there is nothing to disable.
International transfers
Our providers operate in the United States and elsewhere. If you use NOTCH from outside those countries, your data will be transferred and processed there, under appropriate safeguards.
Changes
If we change this policy materially, we will update the date above and notify you in the app before the change takes effect.
Contact
Questions, requests or complaints: notchappusa@gmail.com.