Last updated 9 September 2026. Effective on the first public release of Farhop 1.0.
Farhop is a travel tracker. You log the places you have been; the app draws them on a map and counts them. This policy explains exactly what leaves your phone, what does not, and why.
The short version: your photos never leave your phone, and Farhop never stores a precise coordinate. Not on our servers, not anywhere. The rest of this document is the detail behind those two sentences.
Farhop is operated by LEGAL ENTITY, REGISTERED ADDRESS.
For anything in this policy, including data requests: hello@farhopapp.com.
For EU and UK data protection purposes, LEGAL ENTITY is the data controller.
Farhop signs you in with Sign in with Apple and nothing else. There is no password, because we never receive one.
Apple tells us a stable user identifier and an email address. If you chose Hide My Email, that address is an Apple relay address and we never learn your real one. You may also set a display name and a handle.
When you log a place, we store the place name, the country, the date, and a coarse coordinate.
The coordinate is rounded to 0.01 degrees (a grid of roughly 1.1 kilometres, a little narrower east to west the further you are from the equator) before it is written anywhere, including to the database on your own phone. This is not a display filter that hides a precise value underneath. The precise value exists for a moment in memory, on your phone, and is then discarded. To turn a coordinate into a place name, Farhop asks Apple Maps, and it asks about the rounded coordinate, never the precise one. There is no precise coordinate for us to disclose, lose in a breach, or be compelled to hand over, because we never wrote one down and never sent one anywhere.
From that we also keep the counts on your passport screen: countries, cities, trip days and the like.
If you use photo import, Farhop reads the date and location metadata attached to photos you select, on your phone, to work out where you have been.
The photographs themselves are never uploaded. Farhop servers have no photo storage at all. Earlier test builds could upload a photo; that code was removed before the public release and every stored image was deleted, so no released version has ever uploaded one. Every image you see in the app is read from your phone's own photo library.
Location metadata drawn from a photo is subject to the same 1.1 km rounding described above before anything is stored.
Farhop Pro is sold through Apple. Apple processes the payment; we never see your card, bank details, or billing address.
We use RevenueCat to tell us whether your subscription is active. RevenueCat holds your purchase history (which plan, when it started, whether it renewed) linked to your account, and sends us a copy of each purchase event, which we keep as a reconciliation record. See section 6 for how long.
Farhop requests location access only while you are using the app, and only takes a single reading at the moment you check in, to find places near you. That reading is rounded to the same 1.1 km grid and sent to Apple Maps as the centre of your place search, together with what you typed. It is never written down and it is never sent to our servers. There is no background tracking, no Always permission, and no location history stream. If you decline, check-in still works; you search for the place by name instead.
These are decisions, not oversights:
Legal bases under EU and UK data protection law.
| What | Basis |
|---|---|
| Account identifier and email | Performance of a contract; you cannot have an account without one |
| Trips, check-ins, coarse coordinates | Performance of a contract; this is the product |
| Purchase records | Performance of a contract, and legal obligation (tax and accounting records) |
| Place names and search, sent to Apple Maps | Performance of a contract; a check-in needs a name |
| Server logs (IP address, time of request, app version) | Legitimate interests; keeping the service secure and available |
We do not sell your data, and we do not share it for advertising. Three companies handle your data to run Farhop. Supabase and RevenueCat act only on our instructions. Apple acts under its own terms and privacy policy.
| Who | What it handles | Where |
|---|---|---|
| Apple | Sign in with Apple, payment processing, App Store delivery, and Apple Maps place search and naming (rounded coordinates and your search text) | Per Apple's privacy policy |
| Supabase | Our database and backend | REGION |
| RevenueCat | Subscription status and purchase records | United States |
We will also disclose data where the law requires it. Given section 2.2, a lawful request for your movements would yield place names, dates, and 1.1 km grid squares, because that is all that exists.
You can export everything and delete your account from inside the app, without emailing anyone: Profile, then your account. Deletion removes your profile, trips, check-ins and stats, and revokes the Sign in with Apple token, as Apple requires. It does not remove purchase records; section 6 explains why, and for how long they stay.
You also have the right to access, correct, delete, port, restrict, or object to our processing of your data, and to withdraw consent where we rely on it. Write to hello@farhopapp.com; we answer within a month, and tell you if a complicated request needs longer. If you can no longer sign in, email us and we will delete the account for you once we have checked it is yours. We make no automated decisions about you.
If you are in the EU, UK, or another jurisdiction with a data protection authority, you may complain to it. We would rather you told us first.
The database on your phone is covered by iOS data protection: it is encrypted on disk and cannot be read until you first unlock the phone after a restart. Authentication tokens are held in the iOS Keychain, marked non-syncing and device-only, under the same unlock rule.
On the server, every table is protected by row-level security that denies access by default, and those rules are tested automatically on every change, because an untested access rule is a guess. All traffic uses TLS.
Farhop is rated 13+ and is not directed at children under 13. We do not knowingly collect data from them. If you believe a child has given us data, write to hello@farhopapp.com and we will delete it.
Our processors may handle data outside your country: RevenueCat in the United States, and Supabase in REGION (with support staff in the United States). Where required, these transfers rely on the European Commission's Standard Contractual Clauses, with the UK Addendum for UK users.
If we change this policy materially, we will tell you in the app before the change takes effect. The date at the top always reflects the current version.
hello@farhopapp.com
LEGAL ENTITY, REGISTERED ADDRESS