← Story Places

Privacy Policy

Last updated: 23 August 2026

Story Places is a travel app that tells you about places. This policy says what data comes up along the way, what it is used for, and how long it stays. It is deliberately written in plain language.

1. Who is responsible

Roman Kotzsch
c/o Milengo GmbH
Wilhelmine-Gemberg-Weg 5–7
10179 Berlin
Germany

Email: hello@storyplaces.app

We have no data protection officer; the legal conditions requiring one are not met.

2. What the app processes

Account

You can use Story Places without an account. For that we create an anonymous account with Firebase Authentication — an identifier with no name, no address and no link to you as a person. It holds your saved places and your passport together.

If you use Sign in with Apple, a display name and an email address are added. If you choose “Hide My Email” at Apple, we only receive Apple's relay address — the more private choice, and it works fully with us.

Legal basis: Art. 6(1)(b) GDPR (performance of the service).

Location

The map shows places near you, which needs your location. On walking tours the app can also use it in the background to check off stops automatically — you decide that when granting access and can withdraw it any time in iOS settings.

Your location is not stored permanently and not passed to third parties. It is used for the display and to check whether you were at a stop; only the result is stored — which place, and when.

Legal basis: Art. 6(1)(a) GDPR (consent via the system prompt).

Photos on your device

Your passport can pick up cities and travel dates from your photo library. This happens entirely on your iPhone: place and date of the photos are read; no photo is uploaded, transmitted or shared.

Contributions

When you send a note, suggest a place or contribute your own picture, we store the content, the place concerned and your identifier. These contributions are not public — only you and our editorial team can see them.

Local Guides

Anyone looking after a neighbourhood additionally provides:

Before publication we check the profile photo automatically with Google Cloud Vision (SafeSearch) for adult content, racy imagery or violence. The check happens inside Google Cloud. If a picture is rejected, we delete it immediately.

If you give the role back, we remove these details along with the role record.

Legal basis: Art. 6(1)(b) GDPR and our legitimate interest in a service free of unlawful content (point (f)).

Reports

You can report Local Guide profiles to us. We store the reason you chose, your optional text, the profile concerned and the time. If you are signed in, we link the report to your account; if you are not, we ask for an email address so we can follow up and tell you the outcome.

If your report concerns a child's safety, you can reach us without giving any details at hello@storyplaces.app.

Legal basis: compliance with a legal obligation under Article 16 of Regulation (EU) 2022/2065 on a Single Market For Digital Services (Art. 6(1)(c) GDPR) and legitimate interest (point (f)).

Usage statistics

We use Google Analytics for Firebase to see which features are used — how often a walking tour is started, for instance. The events carry no content and no names.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a working service).

3. Recipients and processors

WhoWhat forWhere
Google Ireland Limited — Firebase accounts, database, file storage, server functions, usage statistics EU (europe-west3, Frankfurt)
Google — Cloud Vision automatic checking of profile photos Google Cloud
Google — Places API details and pictures for venues and shops global
Google — Gemini generating place texts, introduction sentences and speech global, see below
Resend sending confirmation and notification emails EU (Ireland)
Apple Sign in with Apple, app distribution see Apple's privacy policy

Transfers to third countries

Text and speech generation runs through Google's Gemini API. This processing is not limited to the EU and may take place in third countries, in particular the United States. It is based on the European Commission's Standard Contractual Clauses, which form part of Google's data processing terms.

What goes into the generation are the details you gave as a Local Guide — how long you have lived there, your favourite place, city and neighbourhood — along with editorial details about places. Contact details do not.

4. How long we keep things

WhatHow long
account, saved places, passportuntil you delete the account
Local Guide details and profile photountil you give the role back
rejected profile photodeleted immediately
confirmation code for the email address15 minutes
reports6 months from receipt
contributions (notes, suggestions, pictures) as long as the content is in use; deleted on request

5. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Any consent you have given can be withdrawn at any time with effect for the future.

You can delete your account and everything attached to it inside the app — under “Passport” → “Your profile” → “Delete account”. For anything else, write to hello@storyplaces.app.

You may also lodge a complaint with a supervisory authority. The competent one at the controller's seat is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany.

6. Changes

As the app grows, this policy grows with it. The version in force is the one here; the date above says when it last changed.

This is a translation for convenience. In case of doubt, the German version applies.