Bearings
Privacy Policy
Effective August 21, 2026
1. Information We Collect
- Account information: the email address and display name you
sign up with.
- Location data: your device's location while using the app, to
determine what to narrate and to record the route of trips you save.
- Content you create: the trips you plan, the interests and
free-text notes on your profile and on any companions you add, the questions you
ask, and the walks you save to your Journal — which include the route you
travelled and the narration you heard along the way.
- Voice input: if you ask a question out loud, your device's
microphone records it while you speak. On iOS the recording is transcribed by
Apple's speech recognition service, which may process the audio on Apple's servers;
we receive only the resulting text, and we store that text as part of the
conversation. We never store the audio itself.
- Purchase information: subscription/purchase status and receipts
from the Apple App Store or Google Play. We never receive or store your card details --
those are handled entirely by Apple/Google.
- Usage & device data: app diagnostics and crash reports, used
to keep the Service working reliably.
- Content reports & feedback: if you report something the Service
narrated, we store that narration's text, any note you add, and a copy of the profile
details that were used to personalize it -- we can't review a report or work out what
went wrong without them.
2. How We Use It
To generate narration and answer questions relevant to where you are, save and
display your journal entries, manage your subscription entitlement, respond to
support requests, and diagnose and fix problems with the Service.
We also use it to keep the Service's narration within our acceptable use terms:
profile and trip notes are checked automatically when you save them, and reported
narration is reviewed so we can stop repeating it and improve how content is
generated.
3. Who Else Receives Your Data
Bearings is a small operation and depends on outside services to work. Each
company below receives only what its own function needs, acts on our instructions,
and is not permitted to use what it receives for its own purposes. This is the
complete list of processors that receive personal data, not an illustrative one.
Services that hold or can identify your data
- Render — runs the Bearings servers and hosts the database
they read and write. Everything the app sends us passes through their
infrastructure, and your account, profile, saved walks and routes are stored there,
encrypted at rest and in transit.
- Neon — previously hosted that database, and still holds a
copy while we finish moving it to Render. It will be deleted from Neon once the move
is complete.
- Clerk — runs sign-in. Clerk holds your email address
and your password credential; we never see or store your password.
- Apple and Google — process subscription and one-time
purchases and send us the resulting receipt and entitlement status. Your payment
details stay with them and never reach us.
- Sentry — receives error and crash diagnostics so failures
can be found and fixed, both from our servers and, since August 2026, from the app
itself when it hits an error. What Sentry receives is the error's own message and
technical stack trace, the name of the screen you were on, your app version and
device operating-system version, and your account identifier. We configure it not to
send request bodies or URL query strings, which is where location and profile text
would otherwise appear, and the app strips those from error text before sending it.
How it reaches Sentry depends on which version of the app you are running: older
versions report the error to our own servers, which pass it on, while from version
1.0.1 the app sends its diagnostics to Sentry itself. Either way the same short list
above is what Sentry receives.
- Slack — when you rate a walk, leave a comment, or report
something Bearings said, that text is posted to a private channel so we actually
read it. The message carries what you wrote and which walk it was about; it does
not carry your email address, and a report never includes your profile text.
Services that receive your location or what you have written, without
your identity
- Anthropic — generates narration, answers your
questions, screens submitted text, and titles saved walks. It receives where you
are (coordinates or a place name), the profile and trip details you wrote (the
name you chose, your age as a decade range if you gave one, interests, "about you" and
avoid-topics notes, and the same for any companions you added), the current
weather and time where you are, and the questions you ask. It does not receive
your email address or your account identifier.
- Speechify and Google Cloud Text-to-Speech
— turn the narration into the voice you hear. Each receives the narration
text to be spoken aloud and your language, accent, and voice preferences.
Speechify is used by default and Google covers the languages Speechify does not,
so which one speaks a given line depends on the language and voice you chose.
Because what they receive is the narration itself, it can include the name you
chose and the name of the place being described — whatever was written to be
read aloud. Neither receives your coordinates, your email address, or your account
identifier.
- Voyage AI — receives short narration titles and
headings, used to recognize when two pieces of content say the same thing so the
Service doesn't repeat itself. No location, no identity.
- Apple — if you ask a question out loud, your device's
own speech recognition turns it into text, and may do so on Apple's servers rather
than on the phone (see section 1).
Reference sources we query with your location
These requests are made by our servers, not from your device, and carry
coordinates or a place name with no name, email, or account identifier attached:
- Wikimedia Foundation (Wikipedia, Wikivoyage) — articles
about places near you.
- OpenStreetMap (Nominatim, Overpass) — the name of where
you are, and nearby features worth narrating.
- OpenWeather — current conditions where you are.
- Mapbox — place search while you type a location, and
the static route image on a shared journal page.
- Project OSRM — road-following route lines, used by
simulated walks.
- Ticketmaster — events happening near you.
- Spotify — looked up by track and artist name only; no
location is sent, and we don't connect to your Spotify account.
The map inside the app is drawn by your own device, using Apple Maps on iOS or
Google Maps on Android, under those companies' own privacy policies. The map on a
shared journal page is drawn by Apple MapKit JS in the viewer's browser.
We do not sell your personal information and we do not share it for
cross-context behavioral advertising. Bearings contains no advertising and
no analytics or tracking SDKs.
4. Shared Journal Links
Sharing a journal entry publishes it. The page at that link shows the entry's
title, the date, the distance and duration, the full route you walked or
drove, drawn on a map, and short excerpts of what was narrated and what you
asked during the walk. It also generates preview images at related links, which is
what makes the link unfurl into a card when it is pasted into a messaging app or
posted to a social platform.
The link is unlisted, not secret. It contains a random token that
can't be guessed or used to find anyone else's walks, but the page needs no account
and no password: anyone holding the link can open it and forward it. If you post the
link publicly, expect it to be crawled, indexed, and copied like any other public web
page.
You can revoke a link at any time from that entry in your Journal
(“Stop sharing”), and deleting the entry or your account revokes it too.
Revoking takes effect immediately: the page and its preview images stop loading. What
we can't undo is copies already made elsewhere — a preview image cached by a
browser or a social platform, a screenshot, or a page someone saved.
5. Data Retention
How long each kind of data lives, and why:
- Your account and profile — until you delete your
account.
- Saved walks, including the route — until you delete the
entry or your account. We deliberately do not expire these on a timer: the route is
the record of the walk, and quietly deleting one after a fixed period would destroy
the thing you saved it for. That does mean route history is kept indefinitely by
default, which is why deleting an entry is a one-tap action in the app and why
deletion is immediate rather than a soft delete.
- Walks you don't save — no route is stored at
all. Discarding a walk leaves only a record that it happened: start and
end time, distance, duration, and what it cost to run.
- Your location while a walk is running — used to decide
what to narrate, then discarded. It is not written to a location history. The only
coordinates we keep are the route of a walk you chose to save.
- What has already been narrated to you — a reference to
each landmark or fact, kept for the life of your account so the Service doesn't
repeat itself on a return visit, and so anything you report stays suppressed.
- Content reports and feedback — kept while we work
through them and for up to 24 months afterward, then deleted; sooner if you delete
your account.
- Error diagnostics in Sentry — up to 90 days, then
deleted by Sentry.
- Cost and usage records — how much AI and speech each
walk consumed. These outlive your account, with your account identifier removed at
deletion, because the spend really happened and the accounting has to survive it.
What remains is anonymous.
You can delete individual journal entries at any time in the app, and you can
delete your entire account from Profile → Delete Account. Deleting your account
permanently removes your profile, your saved walks and their routes, your reports and
feedback, and any journal links you have shared — shared links stop working
immediately — deletes your sign-in identity at Clerk, and takes the same email
address off our waitlist if it was on it. You can also contact
us if you would prefer we do it for you. Deletion is immediate in our live database;
residual copies in encrypted backups are overwritten in the normal backup rotation
within 30 days.
6. Your Privacy Rights
Wherever you live, you can ask us to do all of the following, and we will respond
within 30 days:
- Get a copy of your data. Email us from the address on your
account and we will send you a machine-readable file containing your profile and
companions, your trips, your saved walks and their routes, your reports and
feedback, and your subscription and purchase records.
- Correct it. Most of it is editable directly in the app under
Profile; ask us for anything that isn't.
- Delete it. Profile → Delete Account, or ask us.
- Take it elsewhere. The copy we send is in a portable,
machine-readable format.
- Object to or restrict how we use it, and withdraw permissions
you have granted — location, microphone, and notification access can each be
revoked at any time in your device settings.
We verify a request by requiring it to come from the email address on the account.
We won't charge you for a request or treat you differently for making one.
If you are in the EEA or the UK: the data controller is
McGlaflin Labs, LLC, reachable at
trevor@mcglaflinlabs.com. We
rely on the contract between us to provide the Service you asked for; on your consent
for device location, microphone, and notifications; and on our legitimate interest in
keeping the Service working, safe, and affordable to run, for diagnostics, abuse
prevention, and cost accounting. We do not use your data for automated decisions that
produce legal or similarly significant effects. You have the right to lodge a
complaint with your local supervisory authority (in the UK, the Information
Commissioner's Office).
If you are in California: the categories we collect, why, and who
receives them are described in sections 1 through 3 above. We have not sold or shared
personal information in the preceding 12 months and do not do so now. Precise
geolocation is treated as sensitive personal information; we use it only to provide
the Service you asked for and for the purposes described here, never to infer
characteristics about you.
7. Children's Privacy
The Service is not directed at children under 13, and we do not knowingly
collect personal information from children under 13.
8. International Users & Data Transfers
We operate from the United States and your information is processed there, along
with wherever the providers named in section 3 operate. Those countries may have
different data-protection laws than your own. For travelers in the EEA and the UK,
transfers out of your region rely on the European Commission's standard contractual
clauses, which form part of the data-processing terms offered by the providers we
use.
9. Security
We use reasonable technical and organizational measures to protect your
information, but no method of transmission or storage is 100% secure.
10. Your Choices
You can disable location access at any time in your device settings (narration
won't function without it), disable microphone access if you would rather not ask
questions out loud (the rest of the app keeps working), manage notification
permissions, choose not to share a journal entry or revoke a link you already
shared, and delete your account as described above.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be
reflected by an updated effective date above.
12. Contact
Questions about this Privacy Policy, and requests to access, correct, export, or
delete your data, can be sent to
trevor@mcglaflinlabs.com.