Roamlore Legal Center

Explore like a local. · Questions: roamlore.app@gmail.com

Privacy Policy · Roamlore

Last updated: 19 August 2026 Effective date: Upon the app's first public release on the Apple App Store and Google Play Store.


1. Who we are

Roamlore ("we", "us", "our") is an AI-assisted, community-driven app for discovering, recording, and sharing travel and activity routes (walking, hiking, cycling, running, driving). This Privacy Policy explains what personal information we collect, why, how we use and share it, and the choices and rights you have.

  • Operator (data controller): Zaviyaa Ellis, operating as Roamlore (sole proprietor).
  • App: Roamlore (iOS + Android), bundle identifier app.roamlore.mobile.
  • Privacy contact: roamlore.app@gmail.com
  • General contact: roamlore.app@gmail.com

By using the app you agree to this Policy and to our Terms of Use, EULA, and Community Guidelines.


2. Information we collect

2.1 Information you provide

  • Account credentials. Email address and password, or Sign in with Apple (which shares your name and an email — possibly an Apple private-relay address). At signup you also choose an account type (individual or business).
  • Profile. Display name (defaults to the part of your email before the "@" — you can change it), optional avatar photo, optional bio (up to 160 characters), a "creator" flag, and optional social links (YouTube, TikTok, Instagram, X, website). ⚠️ Your profile (name, avatar, bio, social links) is publicly visible to anyone using the app.
  • Routes you record. A route includes its GPS coordinate trace (a series of latitude/longitude points with timestamps and accuracy — often thousands of points), plus name, description, distance, duration, difficulty, and type. You choose each route's visibility: public, friends-only, or private (the default for new routes is friends-only).
  • Photos. Optional photos you attach to a route, and an optional profile avatar image.
  • Community content. Route ratings (1–5 stars) and optional condition notes, favorites you save, reports you file about a route (a reason plus optional notes), and friend connections and invitations.
  • Friends by email. To add a friend, you can look them up by email address; we use it only to find the matching account and create the connection.
  • Business accounts (if you register one). Business name, category, description, address, phone, email, website, logo, location coordinate, and team members. Business phone and email are visible only to that business's own members, not the public. (We do not currently collect identity documents or formal "KYC" verification materials.)
  • Referrals. A referral code is generated for your account; if you refer or are referred, we record the referrer/referred accounts and the referral status.

2.2 Location data — sensitive

  • Precise GPS location is collected to record your routes, show nearby community routes, and ground route "postcards" in a real place.
  • Background location is collected only while you are actively recording a route (so a recording keeps working when the screen is locked or the app is backgrounded). While this happens, a persistent "Roamlore is recording" notification and the system location indicator are shown. If you deny background permission, recording still works while the app is open.
  • Recorded traces are stored in your account and are subject to the visibility you choose. If you publish a route publicly, its path and place are visible to others and attributed to your display name and avatar.

2.3 Information collected automatically

  • Activity mode (walk / run / bike / drive) is inferred from your GPS speed only — we do not access your device's motion/accelerometer sensors.
  • Local device storage. The app stores some data on your device using standard app storage: your login session, any in-progress recording (including buffered GPS points so a recording can be recovered), an offline "outbox" of routes waiting to upload, and small interface flags (e.g. whether you've seen onboarding). See our Cookie & Local-Storage Policy.
  • Basic technical data needed to operate the service (e.g. app version, language) may be processed by our backend provider.

2.4 What we do not do

  • We do not use any advertising network, advertising identifier (IDFA/AAID), or third-party tracking/analytics SDK. We do not track you across other apps or websites.
  • We do not use cookies (this is a native app).
  • We use Sentry for crash and performance diagnostics (technical data such as crash logs, device/OS type, and performance metrics) to find and fix problems. This is diagnostics only — it is not advertising, and we do not use it to track you across other apps. (Privacy-respecting product analytics is planned but not yet active. If we add it, we will update this Policy and our store data declarations first.)

2.5 Payments and subscriptions

Roamlore offers optional paid "Pro" subscriptions (weekly, monthly, and annual, with a free trial where offered). Purchases are handled entirely by the Apple App Store / Google Play and our subscription manager RevenueCat. We receive your subscription and purchase status (for example, whether you have an active subscription or free trial and which plan), not your card or bank details, which stay with Apple and Google. Business "ad campaign" tiers shown in the app are currently preview-only and collect no money.

2.6 Children

The app is not directed to children under 13 (or the higher minimum age where you live, such as 16 in parts of the EU/EEA). We do not knowingly collect data from children under that age. There is no separate child experience. If you believe a child has provided us data, contact roamlore.app@gmail.com and we will delete it.


3. How we use your information

We use personal information to: - Create and secure your account and sign you in; - Provide core features: record routes (including background recording), show nearby and community routes, attribute public routes, save favorites, rate routes, and connect you with friends; - Generate AI-assisted route descriptions, difficulty classification, and personalized ranking (see §4); - Operate the referral and creator programs and the business/advertising features; - Keep the community safe — process reports, demote heavily-reported routes, and honor user blocks; - Provide support, prevent fraud and abuse, debug, and comply with law.

Legal bases (GDPR/UK GDPR), where applicable: performance of a contract (to provide the app), consent (e.g. background location, and notifications if enabled — withdrawable any time), legitimate interests (security, abuse prevention, improving the app), and legal obligation.


4. AI processing

AI features run only on our secure backend (Supabase Edge Functions calling Anthropic's Claude) — never directly from your device, and the AI provider key is never in the app. Specifically: - Difficulty classification sends a route's distance, duration, point count, and its name/description (if any). No coordinates. - Route description sends the route's name, description, distance, duration, and 5 sampled coordinate points (not the full trace) to generate terrain/scenery tags. - Route ranking sends candidate routes' names and stats plus a summary of your recent activity to order results for you. No raw coordinates.

Your photos are never sent to the AI. We do not use your data to train third-party AI models.


5. How we share information

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under CCPA/CPRA).

We disclose information only as follows: - Publicly / with other users. Your profile (name, avatar, bio, social links) is visible to all users. Routes you mark public — including the path, place, photos, and your attribution — are visible to everyone; friends-only routes are visible to your accepted friends; private routes are visible only to you. - Service providers (processors) that operate the app under contract: - Supabase — database, authentication, file storage, and backend functions (hosts your account data and content); - Mapbox — maps and place search. We send the place text you type (search), a route's approximate center coordinate (to label a place), and map-tile requests; - Anthropic (Claude) — AI features, as described in §4; - open-elevation.com — when an elevation feature is used, we send route coordinate points to retrieve elevation values; - Apple — Sign in with Apple; - RevenueCat — subscription management (we receive your subscription/entitlement status, not your payment details); - Sentry — crash and performance diagnostics; - Expo push service — push notifications; - (Planned, not yet active: a product-analytics provider. We will update this Policy first.) - For legal reasons — to comply with law or lawful requests, or to protect the rights, safety, and security of users, the public, or us. - Business transfers — in a merger, acquisition, or asset sale, subject to this Policy.

A current list of subprocessors is available on request at roamlore.app@gmail.com.


6. International transfers

We and our providers may process your information in countries other than yours, including the United States (where Supabase hosts the project, in the us-east-1 region). Where required, we use appropriate safeguards (such as the EU Standard Contractual Clauses) for transfers out of the EEA/UK.


7. Data retention

We keep personal information while your account is active and as needed to provide the app. When you delete your account (see §8), we delete your data as described there, except where we must retain limited information to comply with law, resolve disputes, or enforce our terms. Content you shared publicly may persist where others have saved it.


8. Your choices and rights

8.1 In-app controls

  • Location: grant, deny, or change location permission (including background) any time in your device settings. Denying it limits recording and nearby features.
  • Route visibility: choose public / friends-only / private per route; public routes are attributed to you.
  • Blocking & reporting: block another user, and report routes that violate our Community Guidelines.
  • Account & data deletion: delete your account and its data in-app at Settings → Delete account. See our Account & Data Deletion Policy for exactly what is removed.

8.2 Your legal rights

Depending on where you live (e.g. GDPR/UK GDPR in the EEA/UK, CCPA/CPRA in California, and similar laws elsewhere), you may have the right to access, correct, delete, port, restrict, or object to processing of your personal information, to withdraw consent, and to not be discriminated against for exercising your rights. We do not sell or "share" your data as defined under CCPA/CPRA, so there is nothing to opt out of in that respect.

To exercise any right, use the in-app controls or email roamlore.app@gmail.com. We will verify and respond within the time the law requires. EEA/UK users may also complain to their local data-protection authority.


9. Security

We protect your information with industry-standard measures: encryption in transit (HTTPS/TLS), authenticated access, database Row-Level Security so users can only reach data they're authorized to see, privileged keys held only on the server (never shipped in the app), and contact details such as business phone/email gated behind membership checks. No system is 100% secure, but we work to protect your data and to notify you and regulators of breaches where the law requires.


10. Apple App Store & Google Play disclosures

The practices above are reflected in our Apple App Privacy labels and Google Play Data Safety declarations. Data we collect maps to these categories: - Contact info — email (and name via Sign in with Apple); - User content — profile, routes/GPS traces, photos, ratings, reports, messages to support; - Location — precise location, including background only while recording; - Identifiers — account ID (and, if notifications launch, a push token); - Diagnostics — limited technical/app data needed to run the service.

Location data is used for app functionality and account-linked storage of routes you create; it is not sold and not used for advertising or cross-app tracking. We provide in-app account and data deletion, as both stores require.


11. Changes to this Policy

We may update this Policy. Material changes will be signalled in-app or by updating the "Last updated" date (and, where required, by asking for your consent). Please review it periodically.


12. Contact us

Roamlore (Zaviyaa Ellis), governed by the laws of Jamaica. Privacy & data requests: roamlore.app@gmail.com General support: roamlore.app@gmail.com