FARHOP

Privacy Policy

Last updated 9 September 2026. Effective on the first public release of Farhop 1.0.

Farhop is a travel tracker. You log the places you have been; the app draws them on a map and counts them. This policy explains exactly what leaves your phone, what does not, and why.

The short version: your photos never leave your phone, and Farhop never stores a precise coordinate. Not on our servers, not anywhere. The rest of this document is the detail behind those two sentences.

1. Who we are

Farhop is operated by LEGAL ENTITY, REGISTERED ADDRESS.

For anything in this policy, including data requests: hello@farhopapp.com.

For EU and UK data protection purposes, LEGAL ENTITY is the data controller.

2. What we collect

2.1 Your account

Farhop signs you in with Sign in with Apple and nothing else. There is no password, because we never receive one.

Apple tells us a stable user identifier and an email address. If you chose Hide My Email, that address is an Apple relay address and we never learn your real one. You may also set a display name and a handle.

2.2 Your travels

When you log a place, we store the place name, the country, the date, and a coarse coordinate.

The coordinate is rounded to 0.01 degrees (a grid of roughly 1.1 kilometres, a little narrower east to west the further you are from the equator) before it is written anywhere, including to the database on your own phone. This is not a display filter that hides a precise value underneath. The precise value exists for a moment in memory, on your phone, and is then discarded. To turn a coordinate into a place name, Farhop asks Apple Maps, and it asks about the rounded coordinate, never the precise one. There is no precise coordinate for us to disclose, lose in a breach, or be compelled to hand over, because we never wrote one down and never sent one anywhere.

From that we also keep the counts on your passport screen: countries, cities, trip days and the like.

2.3 Your photos: read on the device, never uploaded

If you use photo import, Farhop reads the date and location metadata attached to photos you select, on your phone, to work out where you have been.

The photographs themselves are never uploaded. Farhop servers have no photo storage at all. Earlier test builds could upload a photo; that code was removed before the public release and every stored image was deleted, so no released version has ever uploaded one. Every image you see in the app is read from your phone's own photo library.

Location metadata drawn from a photo is subject to the same 1.1 km rounding described above before anything is stored.

2.4 Purchases

Farhop Pro is sold through Apple. Apple processes the payment; we never see your card, bank details, or billing address.

We use RevenueCat to tell us whether your subscription is active. RevenueCat holds your purchase history (which plan, when it started, whether it renewed) linked to your account, and sends us a copy of each purchase event, which we keep as a reconciliation record. See section 6 for how long.

2.5 Location permission

Farhop requests location access only while you are using the app, and only takes a single reading at the moment you check in, to find places near you. That reading is rounded to the same 1.1 km grid and sent to Apple Maps as the centre of your place search, together with what you typed. It is never written down and it is never sent to our servers. There is no background tracking, no Always permission, and no location history stream. If you decline, check-in still works; you search for the place by name instead.

3. What we do not collect

These are decisions, not oversights:

4. Why we are allowed to hold it

Legal bases under EU and UK data protection law.

WhatBasis
Account identifier and emailPerformance of a contract; you cannot have an account without one
Trips, check-ins, coarse coordinatesPerformance of a contract; this is the product
Purchase recordsPerformance of a contract, and legal obligation (tax and accounting records)
Place names and search, sent to Apple MapsPerformance of a contract; a check-in needs a name
Server logs (IP address, time of request, app version)Legitimate interests; keeping the service secure and available

5. Who we share it with

We do not sell your data, and we do not share it for advertising. Three companies handle your data to run Farhop. Supabase and RevenueCat act only on our instructions. Apple acts under its own terms and privacy policy.

WhoWhat it handlesWhere
AppleSign in with Apple, payment processing, App Store delivery, and Apple Maps place search and naming (rounded coordinates and your search text)Per Apple's privacy policy
SupabaseOur database and backendREGION
RevenueCatSubscription status and purchase recordsUnited States

We will also disclose data where the law requires it. Given section 2.2, a lawful request for your movements would yield place names, dates, and 1.1 km grid squares, because that is all that exists.

6. How long we keep it

7. Your rights, and how to actually use them

You can export everything and delete your account from inside the app, without emailing anyone: Profile, then your account. Deletion removes your profile, trips, check-ins and stats, and revokes the Sign in with Apple token, as Apple requires. It does not remove purchase records; section 6 explains why, and for how long they stay.

You also have the right to access, correct, delete, port, restrict, or object to our processing of your data, and to withdraw consent where we rely on it. Write to hello@farhopapp.com; we answer within a month, and tell you if a complicated request needs longer. If you can no longer sign in, email us and we will delete the account for you once we have checked it is yours. We make no automated decisions about you.

If you are in the EU, UK, or another jurisdiction with a data protection authority, you may complain to it. We would rather you told us first.

8. Security

The database on your phone is covered by iOS data protection: it is encrypted on disk and cannot be read until you first unlock the phone after a restart. Authentication tokens are held in the iOS Keychain, marked non-syncing and device-only, under the same unlock rule.

On the server, every table is protected by row-level security that denies access by default, and those rules are tested automatically on every change, because an untested access rule is a guess. All traffic uses TLS.

9. Children

Farhop is rated 13+ and is not directed at children under 13. We do not knowingly collect data from them. If you believe a child has given us data, write to hello@farhopapp.com and we will delete it.

10. International transfers

Our processors may handle data outside your country: RevenueCat in the United States, and Supabase in REGION (with support staff in the United States). Where required, these transfers rely on the European Commission's Standard Contractual Clauses, with the UK Addendum for UK users.

11. Changes

If we change this policy materially, we will tell you in the app before the change takes effect. The date at the top always reflects the current version.

12. Contact

hello@farhopapp.com
LEGAL ENTITY, REGISTERED ADDRESS