← Empty Pockets · Česky · Terms of use
Privacy policy
This policy explains how we process personal data on emptypockets.eu and wanderway.emptypockets.eu, in the Wander Way mobile app and in our Discord bot. If anything is unclear, write to us.
1. Who is responsible
Controller: [company name] s.r.o., company ID [·], registered office [address], entered in the Commercial Register kept by the [Regional / Municipal] Court in [·], section C, file [·] ("we", "Empty Pockets"). Contact for anything about personal data: info@emptypockets.eu. We have not appointed a data protection officer — the law does not require one for us.
2. What we process, why, and on what legal basis
| Data | Why | Legal basis |
|---|---|---|
| Account: email, password (we store only its hash, never the password), or the Google / Authentik account you sign in with | creating and running your account, sign-in, security emails (address verification, password reset) | performance of a contract (Art. 6(1)(b) GDPR) |
| Profile: first and last name, nickname, tag, country, home city, gender, year of birth, profile photo, whether the profile is public | your profile, finding friends, age limits for events. Everything except the tag is optional. | performance of a contract |
| Activity in Wander Way: check-ins (which place, the day and the time it was saved), favourite places, place ratings (thumbs up/down), your routes, events you organise or attend, friends, requests and blocks | running the app: badges, statistics, the Wrapped summary, sharing with friends, community events | performance of a contract |
| Notifications: in-app and web notifications, device push token, app version, language, your channel choices | sending the notifications you turned on | performance of a contract; push only after your consent on the phone; service news legitimate interest (can be turned off) |
| Error reports and place suggestions: text, photos, report type, app language, home city, and your name and email if you fill them in | fixing and extending the place catalogue, spam protection | legitimate interest in an accurate catalogue (Art. 6(1)(f)) |
| Diagnostics and app crashes: app and OS version, device type, error description, account ID | finding and fixing bugs | legitimate interest in a working app |
| Discord link: Discord ID and name | notifications and roles on our Discord | consent — linking is optional and you can unlink at any time |
| Technical logs: IP address, browser, visited address and time; sign-in records | protecting the service against attacks and account abuse | legitimate interest in security |
| Communication with us: email and message content | replying and support | legitimate interest or performance of a contract |
We do not intentionally process special categories of data (e.g. health) — please do not put them in reports or your profile.
Location. The app uses your phone's location to show nearby places and let you check in; if you turn on nearby-place alerts, it also uses location in the background. Location is processed on your phone — we do not send your position or movement to our server. Only what you deliberately save is stored: a check-in (place and day), an event or a route.
Where the data comes from. Mostly from you. When you sign in with Google or Authentik, we receive your email and name from them. Technical data is created automatically when you use the service.
3. Who we share data with
We do not sell data or use it for advertising. We share it only with these providers, and only as far as their service requires:
- Server hosting — [velcord, Czech Republic]: all service data.
- Backups — Hetzner Online GmbH, Germany: encrypted backups.
- Push notifications — Expo (650 Industries, Inc., USA) and Google Firebase Cloud Messaging (Google, USA/EU): device token and notification content.
- Maps and routes — Google (USA): the map in the Android app, place search and route calculation (only the coordinates of route points, not your identity). On the web, OpenStreetMap map tiles (OSMF, United Kingdom).
- Wrapped summary — Anthropic PBC (USA): only aggregated check-in statistics (counts, categories, distances), no name, email or account ID.
- Report triage — TypeSafe AI, Inc. (USA): the text of a report or suggestion and the name of the place concerned, without author details. The result (priority, spam) only assists an administrator; a human decides.
- Google sign-in — Google (USA), if you use it.
- Discord (Discord Inc., USA) — only if you link your account; Discord then acts as an independent controller.
- Home city search — Open-Meteo (Switzerland): in the app, only the text you type into the search field and your device's IP address.
- Internal operational alerts — Discord Inc. (USA): for security events (such as an account deletion or a change of permissions) only the tag or a shortened account identifier; server error reports without personal data.
- The sign-in library on the web is loaded from esm.sh; that provider sees your browser's IP address.
Other users see only what is part of a feature: your public profile (if you turn it on), check-ins for your friends, events and routes according to their visibility.
Transfers outside the EU. We transfer data to the USA only to providers certified under the EU–US Data Privacy Framework or on the basis of standard contractual clauses approved by the European Commission. We will send you a copy of the safeguards on request.
4. How long we keep data
- Account, profile and Wander Way activity until you delete your account.
- Notifications 12 months, sign-in records 90 days, diagnostics and crash reports 90 days, server logs 7 days.
- Device push token while you use the app (deleted after 9 months of inactivity or when you sign out).
- Reports and place suggestions remain as catalogue history, but author details (name, email, city) are deleted 12 months after resolution or immediately when you delete your account. Report photos 90 days after resolution; a photo we add to a place becomes part of the catalogue and stays there without author details.
- Data from the previous version of the service, which ran on Google Firebase, has been moved to our own server; we will delete the original storage at Google by 31 December 2026 at the latest.
- Encrypted backups at most 6 months — a deleted account stays in them until then but is not used, and is deleted again if a backup is ever restored.
5. Your rights
You have the right to access your data, to have it corrected or erased, to restrict processing, to data portability and to object to processing based on legitimate interest. You can withdraw consent (push notifications, Discord) at any time.
- Download your data (JSON file): My account → Security → "Download my data".
- Delete your account: My account → Security → "Delete account", or in the app's account settings. You can also just leave Wander Way and keep your account.
- Edit your profile and notifications: My account or in the app.
- Anything else: info@emptypockets.eu. We reply within one month at the latest.
If you believe we process data unlawfully, you can complain to the Czech Office for Personal Data Protection (uoou.gov.cz) or to the authority in the country where you live.
6. Do you have to give us data?
Wander Way can be used without an account. For an account we need an email (or Google/Authentik sign-in) — without it an account cannot be created. Other profile data is optional; without a year of birth you cannot join events with an age limit.
7. Automated decisions
We make no automated decisions about you with legal or similarly significant effects. We use AI to create a playful caption in the Wrapped summary (from aggregated statistics) and to pre-sort reports by urgency — a human always decides on a report.
8. Age
You can create an account if you are at least 15 years old. If we learn that an account belongs to a younger child, we delete it.
9. Cookies and browser storage
The website uses only necessary cookies and local browser storage: sign-in (your account session), your chosen language and small interface settings. We use no analytics or advertising cookies and do not track you across websites — that is why we do not ask for cookie consent. Fonts and libraries are served from our own server (except the sign-in library from esm.sh). If we ever turn on advertising or visitor analytics, we will ask for your consent first.
10. Security
Connections are encrypted (HTTPS), passwords are stored only as hashes, access to data is enforced by rules in the database itself, backups are encrypted and the server is continuously monitored. If a breach could harm you, we will notify the supervisory authority within 72 hours and inform you.
11. Changes
We may update this policy, for example when we add a feature or a provider. We will announce significant changes in the app or by email. The date of the last change is shown at the top.