Privacy Policy
Last updated 3 August 2026
We collect as little as the App can work with. This policy explains exactly what that is.
1. What we collect
Account information. Your email address, a display name, and — if you sign in with Apple or Google — the account identifier that provider gives us. We never receive your Apple or Google password.
Photos you take. When you tap the shutter, the photo is sent to our server and forwarded to Google's Gemini API to be analysed. The photo is not saved. It exists only for the seconds it takes to generate a description, on our server and on Google's, and is then discarded. We do not keep it. The description and narration we generate are saved to a shared library of artworks, so the next visitor who scans the same piece sees it instantly instead of paying to regenerate it. That library records the artwork only — it is not linked to you, your account, or your photo.
Technical data. Standard server logs (timestamp, an anonymised request identifier, error codes) kept for up to 30 days for security and debugging. These do not contain your photos.
We do not collect your location, contacts, or advertising identifiers. We do not use cookies or third-party analytics or advertising SDKs, and we do not track you across other apps or websites.
2. Why we collect it
- To create and secure your account, and to sign you in.
- To generate artwork descriptions when you take a photo.
- To prevent abuse and enforce rate limits on our AI service, which is what your account is for.
- To meet legal obligations.
Where the GDPR applies, our legal bases are performance of a contract (running the App for you), legitimate interests (security and abuse prevention), and consent where required.
3. Who we share it with
- Supabase — hosts our database, authentication, and server functions. See supabase.com/privacy.
- Google (Gemini API) — receives the photo to analyse it and returns the description. Google's terms for paid API use provide that this content is not used to train its models. See ai.google.dev/gemini-api/terms.
- ElevenLabs — receives the narration text to turn it into speech. It never receives your photo or your account details. See elevenlabs.io/privacy.
- Sentry — receives crash and error reports, including your device model, operating system, account identifier and the screens you visited before the fault. Hosted in the EU. See sentry.io/privacy.
- RevenueCat — receives your account identifier and purchase events so we know what you have bought. Card details go to Apple or Google, never to us. See revenuecat.com/privacy.
- Apple and Google — only if you choose to sign in with them.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
4. Where your data is processed
Our providers may process data in the United States and other countries. Where personal data leaves the European Economic Area or the UK, it is transferred under Standard Contractual Clauses or another approved mechanism.
5. How long we keep it
Diagnostics. When the App crashes or hits an error, a report is sent to Sentry (sentry.io, servers in the EU) so we can fix it. It contains the error and where it happened in the code, your device model and OS version, your account identifier, and a list of the screens you visited beforehand. The App does not record your screen and diagnostics never contain your photos. This is used only to find faults, never for advertising.
Your account information is kept until you delete your account. Photos are never stored. Server logs are deleted within 30 days.
6. Deleting your account
Open the App, swipe to your profile, and choose Delete account. This permanently deletes your account and profile from our systems, usually immediately and always within 30 days. It cannot be undone. You can also email museumcompanionapp@gmail.com to request deletion. For the full list of what is deleted and what is kept afterwards, see museumcompanion.hybriddev.io/delete-account.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, to object to processing, and to withdraw consent. Email museumcompanionapp@gmail.com and we will respond within 30 days. If you are in the EEA or UK, you may also complain to your local data protection authority.
8. Children
The App is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us data, email museumcompanionapp@gmail.com and we will delete it.
9. Security
Data is encrypted in transit with TLS and at rest by our hosting provider. Access to production systems is restricted and authenticated. No system is perfectly secure, but we will notify you and the relevant authority if a breach affects your data, as the law requires.
10. Changes
We will post any update here with a new date, and tell you in the App or by email if the change is material.
11. Contact
Museum Companion, operated from North Macedonia. Contact us at museumcompanionapp@gmail.com or through museumcompanion.hybriddev.io. If you need our postal address for a formal data request, ask by email and we will provide it.