Privacy Policy
This Privacy Policy explains how Mon App Studio (“we”, “us”, “our”) handles information in connection with the PinFinder iOS application (the “App”). PinFinder is built to work without knowing who you are: there is no sign-up, no name, no email address and no password.
No account, no personal profile. PinFinder identifies your device with an anonymous ID so your saved places and unlocks follow you between sessions. That ID is not linked to your name, email, phone number or Apple ID.
1. What We Collect
We deliberately collect as little as possible. In normal use, the App handles:
| Data | Why | Where it lives |
|---|---|---|
| Approximate location | To determine which neighbourhood you are in and search it | Sent to our servers for the duration of a search; not stored as a location history |
| Your searches | To return results and, for AI search, to understand what you asked for | Processed on our servers; recent searches may be kept on your device |
| Saved places & lists | So your favourites are there when you come back | Stored against your anonymous ID in our database |
| Unlocked areas & purchases | To know which neighbourhoods and passes you own | Stored against your anonymous ID; verified server-side |
| Anonymous device & usage data | Crash reports, app version, feature usage, marketing measurement | Held by our analytics providers (see §5) |
We do not collect your name, email address, phone number, contacts, photos, or payment card details.
2. Location
The App asks for location access while you are using it (“When In Use”). Your coordinates are used for two things: working out which named neighbourhood you are standing in, and searching for places near you. Coordinates are sent to our backend to perform that search and are not retained as a movement trail or profile.
You can decline location access, or revoke it later in iPhone Settings → Privacy & Security → Location Services. PinFinder still works — you simply choose the area you want to explore yourself instead of having it detected.
3. Anonymous Sign-In
On first launch, the App creates an anonymous Firebase Authentication account. This is a random identifier for your installation; it carries no personal information. It exists so the server can tell your saved places and unlocked areas apart from someone else's, and so purchases can be verified securely.
4. How Search Works — and What Leaves Your Device
The App never talks to mapping or AI providers directly. Every request goes through our own backend, which acts as a proxy. That design lets us keep requests minimal and delete third-party content on a schedule.
Place data (Google Maps Platform)
Place names, addresses, ratings, opening hours, photos and coordinates come from Google Maps Platform (Places API, Geocoding API and the Maps SDK for iOS). We send a search — a location, a category, and filters — and receive results. Under Google's terms we do not keep this content indefinitely: cached Google place content is automatically purged within 30 days by a scheduled job. See Google's Privacy Policy.
Natural-language search (Anthropic Claude)
When you type a request in your own words, the text of that request and the name of the area you are searching are sent from our backend to Anthropic's Claude model, which converts the sentence into a structured query (category, price range, vibe, opening hours). The request contains no account data, no identifiers and no precise coordinates — only the words you typed and the area name. See Anthropic's Privacy Policy.
5. Third-Party Services
Google Firebase
We use Firebase for our backend: Cloud Functions, Firestore (your saved places and entitlements), Authentication (anonymous), Remote Config, Crashlytics and Google Analytics for Firebase. Firebase may process standard technical data such as device model, OS version, app version, language, region and anonymous usage events, in line with Firebase's privacy documentation.
RevenueCat
Purchases and entitlements are managed with RevenueCat. It receives anonymised transaction data (which product was bought, when, and the anonymous ID it belongs to) so the App can unlock what you paid for on any of your devices. It never receives payment card details. See RevenueCat's Privacy Policy.
Apple
All payments are processed by Apple through the App Store's in-app purchase system and are governed by Apple's Privacy Policy. We never see or store your payment details.
Advertising & marketing measurement
The App includes the Google Mobile Ads (AdMob) and Meta SDKs. We use them for attribution and campaign measurement — that is, to understand which advertisement led someone to install PinFinder — and they may process an advertising identifier and anonymous install/usage events for that purpose. See Google's advertising policy and Meta's Privacy Policy.
If the App asks for permission to track you across other companies' apps and websites (Apple's App Tracking Transparency prompt), declining it is fine — the App works exactly the same. You can change your answer at any time in iPhone Settings → Privacy & Security → Tracking.
6. What We Do Not Do
- We do not sell your data. Ever.
- We do not build advertising profiles of you from your searches or your saved places.
- We do not keep a history of where you have physically been.
- We do not ask you to identify yourself in order to use the App.
7. Data Retention
Your saved places, lists and unlocked areas are kept for as long as your anonymous account exists, so that they are still there next time you open the App. Cached third-party place content is deleted within 30 days as described in §4. Anonymous analytics and crash data are retained by our providers according to their own retention policies.
8. Deleting Your Data
You can delete everything from inside the App: Account → Delete Account. This removes your anonymous identity together with the data stored against it — saved places, lists, search history and entitlement records — from our servers. The deletion is permanent and cannot be undone; unlocked areas and passes are lost with it, and purchases already consumed are not refundable by us (refunds are handled by Apple).
If you prefer, write to support@monappstudio.com and we will carry out the deletion for you.
9. Your Rights
Depending on where you live, you may have rights under the GDPR, the Turkish KVKK, the CCPA or similar laws — including access, correction, deletion, restriction, objection and data portability. Because we hold no information that identifies you personally, the practical route to exercising these rights is the in-app deletion described in §8. For anything else, contact us and we will respond as required by applicable law.
10. International Transfers
Our backend and our service providers (Google, Anthropic, RevenueCat, Apple, Meta) operate servers in several countries, including the United States and the European Union. Using the App means the limited data described here may be processed outside your own country, under the safeguards those providers maintain.
11. Children's Privacy
PinFinder is not directed at children under 13 and we do not knowingly collect information from them. If you believe a child has provided us with data, contact us and we will remove it.
12. Security
Traffic between the App and our servers is encrypted in transit. API keys for third-party services are held in a managed secret store on the server side and are never shipped inside the App where they could be extracted. Access to our database is restricted by server-side rules so one user cannot read another's data.
13. Changes to This Policy
We may update this Privacy Policy as the App evolves. When we do, we revise the “Last updated” date at the top of this page. Material changes will also be signalled inside the App.
14. Contact
Questions about this Privacy Policy? Write to support@monappstudio.com.