Last updated: 9 October 2026
Privacy Policy
This Privacy Policy explains what information Locals collects when you use the Locals iOS app, the Locals website and related services, why, who it is shared with, how long it is kept, and what you can do about it.
Locals is published by Danila Gorbunov, a private individual, who is the data controller responsible for your personal information. "We", "us", and "our" in this policy refer to Danila Gorbunov. Locals is not operated by a company.
Summary
- The data controller is Danila Gorbunov, a private individual. Privacy requests go to privacy@localsapp.app.
- Locals is for adults. You must be 18 or older to use it.
- Locals is free. It sells nothing and does not collect payment information.
- Locals does not record where you are. Your device location is used on your device to centre the map. It is never sent to analytics and is not stored as a record of where you have been.
- Locals records what you do in the app — for example, which Collection you opened or saved — by identifier, to understand whether the product is useful. It does not record what you type, and it does not use an advertising identifier.
- Locals does not sell personal information, does not show ads, and does not track you across other companies' apps or websites.
- The Locals website sets no cookies, runs no analytics and stores nothing in your browser.
- The services Locals relies on — Apple, Google Sign-In, Firebase, Google Places, Mapbox, Zoho Mail and Cloudflare — are listed with what each receives on the Third-Party Services page.
1. Information We Collect
Account information
- Sign in with Apple: an Apple account identifier, and the name and email address Apple shares with us. If you choose to hide your email, we receive an Apple relay address instead of your real one.
- Google Sign-In: your Google account identifier, name, email address and profile photo. Locals asks Google only for this basic profile. It does not request access to your Gmail, Drive, contacts, calendar or any other Google data.
- Email and password: your email address. Your password is handled by Firebase Authentication; we never see or store it.
- For every account: an internal account identifier, a public identifier, the authentication tokens that keep you signed in, the date the account was created, and the version of the Terms of Service you accepted and when.
Profile and content
- Your username, name, bio and profile photo.
- Collections, Place Cards and Trips you create, with their titles, descriptions, tips, photos, categories and their private or public setting.
- The places your content refers to: place identifiers, names, addresses, categories and coordinates, which come from Google Places. These describe the place, not you.
- Collections you save, and people you follow.
- Photos you choose to upload, with the metadata needed to process them, such as file type, dimensions and size.
Safety information
- Reports you file: what you reported, the ground you chose, any text you added, and when. The person whose content you reported is never told who reported it.
- Users you blocked and content you hid by reporting it.
- Moderation decisions about your own content: what was removed, on which ground, and when.
Location
If you allow location access, your device's location is used on your device to show where you are on the map and to centre the map on you. You can use Locals without location access; the map then opens on the country of your device's region setting.
When you browse the map or search for a place, the app sends the area of the map you are looking at — its centre and size — to our servers so that they can return the Collections and places in that area. That area may include where you are, if the map is centred on you. It is used to answer the request and is not stored with your account. Place searches are forwarded to Google Places as described on the Third-Party Services page.
We never send your location, the map area, or anything derived from them — such as a city — to analytics. Mapbox's own usage and location telemetry is turned off in Locals. The information button on the map offers to turn it on; it stays off unless you do. See section 3.
Product analytics
We record events about how Locals is used, through Google Analytics for Firebase, so that we can tell whether people find Collections worth saving and fix what does not work. An event says what happened (for example, that a Collection was opened, saved or published), where in the app it happened, and which content it concerned, named by identifier. Events about content you opened name its author by the public identifier already shown next to the content in the app.
Events are linked to your public identifier, to the date your account was created, and to whether you allowed location access (yes or no — not where you are). They never contain:
- your location, a map area, or a city or region derived from either;
- anything you typed — titles, descriptions, tips, bios, usernames or search queries;
- your email address, name or photo;
- an advertising identifier. Locals uses the version of Google Analytics that does not collect one.
Events carry the region set in your device's language and region settings, which is not derived from your location. Like any internet service, Google receives your IP address with each request and may infer an approximate country from it.
Diagnostics
- Crash reports and error records, through Firebase Crashlytics: the state of the app and device when the problem happened (device model, iOS and app version, a stack trace), short technical messages, and your internal account identifier so that a problem affecting one account can be investigated.
- Our servers record technical information about requests, such as IP address, app version, time and the address of the request, to keep Locals secure and working.
Website
Locals has a website at localsapp.app. Links to Collections that you share from the app open there, at go.localsapp.app, so that people without the app can see them.
The website sets no cookies, runs no analytics and stores nothing in your browser. It does not count visits. Like the app's requests to our servers, requests to the website are recorded — IP address, time, the address of the page and the browser information your browser sends — to keep Locals secure and working. The website is hosted by Cloudflare, which keeps these records for us, as described on the Third-Party Services page.
2. Why We Use It, and Our Legal Basis
| Purpose | Information | Legal basis |
|---|---|---|
| Create your account, sign you in, and provide Locals: maps, search, Collections, Place Cards, Trips, saving, following, sharing | Account information, profile and content, the map area you look at | Performing our contract with you (the Terms of Service) |
| Show your public content and profile to other users | Profile and public content; that you saved a public Collection, shown to its owner | Performing our contract with you |
| Keep people safe: review reports, remove content, handle appeals, apply blocks | Safety information, the reported content | Our legitimate interest, and yours, in a safe service; legal obligations where they apply |
| Understand whether Locals is useful and improve it | Product analytics | Our legitimate interest in improving the product. You can object (section 6) |
| Keep Locals secure and working | Diagnostics, website request records, authentication tokens | Our legitimate interest in a secure, reliable service |
| Show where you are on the map | Device location, on your device | Your permission, given through iOS. You can withdraw it at any time |
| Respond to you | What you send us by email | Performing our contract with you, or our legitimate interest in answering |
| Comply with the law | What a valid legal request requires | Legal obligation |
We do not make decisions about you based solely on automated processing. Every removal of content is decided by a person.
3. Who We Share It With
We share information only as needed to run Locals, to comply with the law, or to protect people:
- Service providers that run parts of Locals for us: Apple and Google for sign-in, Firebase (Google) for authentication, analytics and crash reporting, Google Places for place search and place photos, Mapbox for maps, Zoho Mail for email you send us, Cloudflare for the website, and our hosting and database providers. The Third-Party Services page lists what each one receives. Google and Mapbox also process some data under their own privacy policies.
- Other Locals users see your profile and your public content, and the owner of a public Collection sees that you saved it.
- Anyone with a share link to a public Collection can see that Collection on the Locals website, while it stays public.
- Authorities, when the law requires it, or when it is necessary to protect someone's safety or to establish or defend legal claims.
We do not sell personal information, we do not share it for advertising, and we do not show ads.
4. International Transfers
Our service providers process information in several countries, including the United States. Where information about you is transferred out of your country, we rely on the safeguards the provider offers for such transfers, such as the European Commission's standard contractual clauses. You can ask us for details at privacy@localsapp.app.
5. How Long We Keep It
- Account information and profile: while your account exists.
- Your content: until you delete it or delete your account.
- Content removed under the Terms of Service is kept, hidden, while the removal can be reversed, and is deleted with your account.
- Reports and moderation records: while the accounts involved exist, or longer where the law requires.
- Product analytics events: for the retention period set in Google Analytics, after which they are deleted.
- Crash reports: for up to 90 days.
- Server and website request records: for as long as needed to investigate security and reliability problems.
- Email you send us, and our replies: as long as needed to answer it and to handle what follows from it.
- Backups: overwritten on a rolling schedule, so deleted information can remain in a backup for a limited time.
6. Your Choices and Rights
In the app and on your device
- Profile: edit your username, name, bio and photo in account settings.
- Content: make a Collection or Place Card private, or delete it.
- Location and photos: allow, limit or turn off access in iOS Settings.
- Mapbox telemetry: off by default. You can turn it on, and off again, from the information button on the map.
- Google account: remove Locals' access in your Google account settings. Sign in with Apple can be managed in your Apple Account settings.
- Delete your account: in account settings. Your profile and content are deleted, and others can no longer see them.
Your rights
Depending on where you live — for example under the GDPR in the European Economic Area and the United Kingdom, or the KVKK in Turkey — you have the right to access the information we hold about you, to have it corrected or deleted, to receive it in a portable format, to restrict or object to how we use it (including for product analytics), and to withdraw a permission you gave. Write to privacy@localsapp.app. We answer within one month and may need to confirm that the request comes from the account holder.
You also have the right to complain to the data protection authority in the country where you live or work. We would appreciate the chance to answer your concern first.
7. Security
Information travels between the app and our servers encrypted. Access to our systems is limited to the people who run Locals. No system is completely secure, and we cannot guarantee that information will never be accessed without permission. If a breach affects your information, we will tell you and the authorities where the law requires it.
8. Age
Locals is only for people aged 18 or older. We do not knowingly collect information from anyone younger. If you believe someone under 18 has an account, write to privacy@localsapp.app and we will close it.
9. Changes to This Policy
We will update this policy when what Locals collects or how it uses it changes. The date at the top shows when it last changed. If a change is material, we will tell you in the app before it takes effect.
10. Data Controller and Contact
The data controller for Locals is Danila Gorbunov, a private individual and the publisher of the Locals app, as shown as the seller on the App Store.
To access, correct, or delete your personal information, to object to how it is used, or to ask any question about this policy, write to privacy@localsapp.app.
We are reachable by email only. For other matters, use support@localsapp.app for general questions and legal@localsapp.app for legal notices.