This Privacy Policy explains how Locaro ("Locaro", "we", "our", "us") collects, uses, shares, and protects your information when you use the Locaro iOS application. Locaro is operated by an individual founder based in Canada. If you do not agree with this policy, please do not use the app.
1. Information we collect
- Authentication identifiers. When you sign in with Sign in with Apple or Google Sign-In, Firebase Authentication captures an account identifier and (depending on the provider) an email address. Important: your email is stored only inside Firebase Authentication — Locaro's own database does not store your email address. We only persist a stable account ID (UID) on our user record.
- Profile content. Display name, username, bio, avatar URL, privacy level (public / friends / private), creator tier (if granted), and an admin flag (only for our moderation staff).
- User-generated content. Posts, reviews, comments, guides, and the list of places you mark as visited or saved to your wishlist.
- Photos. Avatar, post photos, and guide photos you upload. Before upload, the app re-encodes each image to JPEG using a graphics renderer, which strips all EXIF and GPS metadata. We never see your camera location or device metadata.
- Device data. Firebase Cloud Messaging push token (used to deliver notifications), app version, locale, and crash diagnostics via Firebase Crashlytics.
- Analytics events. Pseudonymous usage events such as which screens you open, searches you perform, and places you view, via Firebase Analytics. Events may include place IDs, place names, and an app-instance or account identifier.
- Location. If you grant permission, the app uses your device location only while you are using Locaro(CLLocationManager "When In Use") to center the map and to find nearby places. Coordinates are transmitted securely to Locaro's Firebase Cloud Functions and Google Places when you use nearby search, recommendations, group picks, itineraries, or place Q&A. Locaro does not collect continuous background location. For Pro history and digest features, recent requests may retain the coordinates used for up to 30 saved results. If you do not grant permission, the app uses the city you select or Toronto as a fallback; that approximate location may be transmitted when you use those features.
- Taste preferences. Cuisine preferences, price-level preference, and dietary flags (for example vegetarian, vegan, gluten-free, or halal) that you set during onboarding or later. These personalize your recommendations and are included in the request sent to our AI provider (see Section 5). A dietary flag such as halal may indicate a dietary or religious preference; you can change or clear these at any time.
- Taste Passport / check-ins.When you record a visit, we store the restaurant, the visit date, your rating, and any optional note, favorite dish, or tags you add. The coordinates saved with a check-in are the restaurant's location, not your device location.
- Subscription data.If you subscribe to Locaro Pro, we store your subscription tier, product identifier, and expiry date, derived from Apple's cryptographically signed transaction. Payment is processed by Apple — we never see or store your card or payment details.
2. What we do not collect
- We do not sell your personal data. Ever.
- We do not use advertising trackers, AdMob, or any third-party advertising network. Locaro has no ads.
- We do not record continuous location history.
- We do not access your phone book, contacts, calendar, microphone, or health data.
- We do not store your email address in our own database (see Section 1).
3. How we use your information
- Operate the core features of the app (map, profile, follows, posts, guides).
- Send push notifications when someone interacts with your content (likes, comments, follows, new guides from creators you follow).
- Detect and moderate abuse via community reports.
- Diagnose crashes and fix bugs.
- Understand which features people use via anonymous analytics.
4. Push notifications
Push notifications are delivered via Firebase Cloud Messaging (FCM) to Apple Push Notification service (APNs). A Cloud Function (onActivityCreated) generates notifications when another user likes, comments on, follows, or otherwise interacts with your content. Ambient activities (someone marking a place visited or wishlisted) are intentionally silent to reduce notification fatigue.
You can disable Locaro notifications at any time in iOS Settings → Notifications → Locaro.
5. Sub-processors and third-party services
Locaro relies on the following providers to operate. Your data flows through them subject to their own privacy policies, which we encourage you to read.
- Google LLC — Firebase platform. Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging (FCM), Analytics, Crashlytics, and Remote Config. Privacy: policies.google.com/privacy.
- Google LLC — Maps SDK for iOS and Places API. Used to render the map and to look up restaurant details (name, hours, coordinates, photos, rating). Privacy: policies.google.com/privacy.
- Apple Inc. — Sign in with Apple and Apple Push Notification service (APNs). Used as an authentication provider and to deliver push notifications. Privacy: apple.com/legal/privacy.
- Anthropic PBC — Claude API.Our AI features (Pick for Me, Ask Locaro, and itinerary planning) send the request you make — such as the cuisine or mood you type, your saved taste preferences and dietary flags, and a list of nearby candidate restaurants with their distance from you — to Anthropic's Claude models to generate recommendations. We do not send your name, email, or account identifier. Privacy: anthropic.com/legal/privacy.
- Resend (Plus Five Five, Inc.) — transactional email. Used to deliver system and moderation emails (for example, when a report is filed). Privacy: resend.com/legal/privacy-policy.
We do not use advertising or cross-app tracking SDKs, and we do not use the Advertising Identifier (IDFA). We do not use analytics providers such as Mixpanel, Amplitude, or Segment beyond the Firebase and provider services listed above.
6. Place data
Restaurant and venue data displayed in Locaro is sourced from the Google Places API. To manage cost and reduce request volume, place records are cached in our Firestore database for up to 30 days. Server-side place lookups are quota-capped (currently 300 tile fetches per user per day and 10,000 globally per day) via the writeTile Cloud Function.
7. Public content and profile visibility
Your profile is public by default. Posts, reviews, comments, guides, and other content you publish to Locaro's community surfaces can be viewed by signed-in users. The profile visibility setting in Settings → Privacy controls access to your profile and user-media paths:
- Public — your profile and content appear in search and on the public map.
- Friends only — only people who follow you see your profile.
- Private — your profile is hidden from search and other users.
Admins of Locaro (a small group of moderation staff) can review reported content. Reports themselves are not readable by other users (enforced at the database level via Firestore security rules).
8. Reports and moderation
When you report a post, review, comment, guide, or user, a record is written to our reports collection. The Cloud Function onReportCreated automatically sends a formatted notification email to support@locaroapp.com. Blocking another user is bidirectional: both sides automatically stop following each other and stop seeing each other's content.
9. Data retention
- User content — kept until you delete it or your account.
- Cached place data — automatically refreshed after 30 days.
- Analytics events — retained according to Firebase Analytics defaults (currently 14 months).
- Crash reports — retained for approximately 90 days by Firebase Crashlytics.
- Reports — retained for moderation audit until the reporting or reported account is deleted, unless longer retention is required to comply with law or protect users from fraud or abuse.
10. Account deletion
You can delete your account at any time via Settings → Account → Delete Account. This triggers the deleteUserAccount Cloud Function, which removes:
- Your profile, posts, comments, reviews, guides, reports, blocks, and claims.
- Your Taste Passport check-ins, taste preferences, and subscription records.
- Follow relationships, activity records, recommendation history, and quota/log data.
- Your avatar, post photos, and guide photos from Firebase Storage.
- Your Firebase Authentication identity.
The operation keeps your sign-in active until required Firestore and Storage cleanup has completed. If a step fails, the app reports an error so you can retry. You may also email support@locaroapp.com for assistance.
11. Your rights
Depending on where you live, you have specific rights over your personal data. You can exercise any of these rights by emailing support@locaroapp.com.
Canada (PIPEDA — primary framework). You may request access to your personal information, correction of inaccuracies, and withdrawal of consent. You may also file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca).
European Economic Area and United Kingdom (GDPR / UK GDPR). You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. You can lodge a complaint with your national supervisory authority. Our lawful bases are: contract (to provide the Service you requested), legitimate interests (to keep the Service safe and improve it), and consent (for push notifications and any optional features that ask for it).
California (CCPA / CPRA). You have the right to know what we collect, delete it, correct it, and opt out of sale or sharing. Locaro does not sell personal information and does not share it for cross-context behavioural advertising. We do not discriminate against users who exercise these rights.
12. Security
All traffic between the app and our servers is encrypted in transit (HTTPS/TLS). Data at rest in Firebase is encrypted by Google. Access to user records is enforced via Firestore security rules. We do not claim our systems are immune to breach; if a breach affects you, we will notify you as required by applicable law.
13. International data transfers
Locaro runs on Google Cloud. Cloud Functions are deployed in the us-central1 region. Firestore and Storage operate in regions chosen at project setup. Your data may therefore be processed outside your country of residence.
14. Children
Locaro is not directed to children under 13. We do not knowingly collect personal data from anyone under 13. If we learn that an account belongs to a child under 13, we will delete it. If you believe a child is using Locaro, please email support@locaroapp.com.
15. Changes to this policy
We will notify users of material changes via an in-app banner or App Store release notes and update the "Effective" date at the top of this page. Continued use of the app after a change constitutes acceptance.
16. Contact
Questions about this Privacy Policy, or about your data: support@locaroapp.com.