Legal
Privacy Policy
Effective July 30, 2026
The short version: almost everything you do in FestiScout stays on your phone. Creating an account is optional; if you do, we store your email, a display name, and anything you choose to publish to the community — nothing else. No ads, no analytics trackers, and we never sell or share your data for marketing.
Data that stays on your device
FestiScout is built local-first. The following never leaves your phone and is never sent to our servers: your trip plans, festival check-ins (including the coordinates recorded when you check in), festival reminders, favorites, and app settings. Reviews written in older versions of the app before public reviews launched also remain only on your device. If you delete the app, this data is deleted with it — we hold no copy and cannot recover it for you.
If you add a festival reminder to your calendar, the event is created in your device's calendar by the system. We only add the events you ask for; we never read your existing calendar entries.
Data we store if you create an account
An account is only needed to publish trip routes to the community and to like other travellers' routes. If you sign in, our backend (hosted by Supabase) stores:
- Your email address and a display name (an auto-generated "Traveler" name, or the name your Apple/Google account provides). You can change the display name to any nickname at any time in the Profile tab — it does not need to be your real name.
- Routes you publish: the route title, city/country label, and list of stops. Published routes are public — anyone using the app can see them along with your display name, until you unpublish them. You can also publish a route anonymously: other users then see "Anonymous traveler" instead of your name. Anonymity is display-only — the route is still linked to your account on our backend so that only you can edit or delete it, and so we can act on abuse reports.
- Festival reviews and photos you post: your rating, review text, and any photos
you attach are uploaded to our backend and held privately in a moderation queue.
A review becomes publicly visible only after a human moderator approves it; rejected reviews are
never shown to anyone but you, and their photos are deleted from our servers. You can post
reviews anonymously (display-only, same as routes), and you can delete your own review at any
time — deleting it also deletes its photos from our servers.
Automated pre-screening. To help us triage that queue, the text of a pending review or route is sent to DeepSeek (an external AI service) which returns a suggestion of "looks fine" or "needs a closer look". Only the item's internal id, star rating and text are sent — never your name, email, account id, device id or IP-linked identifier, and never your photos. The suggestion is advisory only: nothing is ever published or rejected automatically, and a human decides every case. This runs on our own machine as a scheduled job, not inside the app; the app itself contains no AI code and makes no AI calls. - Likes you give to published routes.
- Reports and blocks you submit, so we can moderate public content.
Sign-in works via a one-time email code, Sign in with Apple, or Google Sign-In. We never see or store a password. With Apple or Google we receive only your name and email address (Apple lets you hide your real email). One-time code emails are delivered through Resend, our email provider, which processes your email address for that purpose only.
Location
FestiScout asks for location permission only when you use one of two features: checking in at a festival (we compare your position to the festival city — within 50 km counts as attended) and the optional "use current location" shortcut in search. Your position is processed on the device; check-in coordinates are stored only on your phone. When you use "use current location", the coordinates are sent to the geocoding service (see below) solely to look up the place name. We do not track your location in the background, and your location is never stored on our servers.
Services the app talks to
Like any map app, FestiScout loads content from a few external services. When it does, those services receive the technical minimum a web request carries (such as your IP address):
- Supabase — authentication and database for community features.
- Resend — sends one-time sign-in code emails.
- Apple / Google — only if you choose them for sign-in, under their own terms.
- OpenFreeMap / OpenMapTiles — map tiles, built from OpenStreetMap data; the tile server sees which map areas you view.
- Photon (komoot) and Nominatim (OpenStreetMap) — place search and reverse geocoding; they receive the text you search and, for "use current location", your coordinates.
- Overpass API — looks up restaurants and shops around a festival, but only for areas outside the offline data bundled in the app; it receives the map area you are viewing.
- DeepSeek — automated pre-screening of submitted review and route text, as described above. Text only; no identifiers, no photos.
- Booking.com — hotel links are affiliate links. Nothing is shared until you tap one; tapping opens Booking.com with a code identifying FestiScout as the referrer, and their privacy policy applies from there. We may earn a commission on bookings.
- GetYourGuide — the "Local tours & tickets" links are affiliate links, labelled as ads in the app. Nothing is shared until you tap one; tapping opens GetYourGuide with a code identifying FestiScout as the referrer, and their privacy policy applies from there. We may earn a commission on bookings, at no extra cost to you.
What we don't do
No advertising, no ad tracking, no analytics SDKs, no selling or renting personal data, no reading your contacts, photos, or calendar. We don't use your data to train AI models, and we don't send your photos or any account identifier to an AI service — the only thing that leaves for automated pre-screening is the text of content you have chosen to publish.
Deleting your data
You can delete your account inside the app: Profile → Account → Delete account. This immediately and permanently removes your profile, email, published routes, and likes from our servers. Data on your phone is removed by deleting the app. You can also email us to exercise any data right (access, correction, deletion) — we honor these requests regardless of where you live.
Data retention & security
Account data is kept only while your account exists. All traffic between the app and our backend is encrypted in transit (HTTPS). Our backend is hosted by Supabase on infrastructure in the United States.
Children
FestiScout is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If we change what data the app handles (for example, adding photo uploads), we will update this policy and the effective date above before the change ships.
Contact
Questions or requests: hello@festiscout.com