Privacy Policy
Last updated: 13 July 2026
LocurAI ("the app") and the website locurai.com are developed and operated by Andor Glatt (a private individual, operating under the name "GlattSoft"). This policy explains what data we collect and how it is used.
Data we collect
- Email address (when you register an account)
- A login name you choose
- Your language preference
- Tours you create (city, tour parameters, generated content)
- If you use guest access: an anonymous device-based identifier
- Your approximate device location (app only; only if you grant permission; used on-device only to show your position on the map and to pre-fill the city in the tour planner — never stored or sent to our servers)
- Custom map sources you add (app only): the source name and the map tile URL template you type in yourself. This is content you provide, and it is stored linked to your account.
- In-app purchase transaction records (if you purchase credits)
How we use your data
- To create and sync your account across devices
- To generate and store your tour plans
- To display public tours and ratings
- To show your position on the map and pre-fill the planner (location is used on-device only; we do not store exact coordinates or send them to our servers)
- To store the custom map sources you add and sync them across your devices, so the Maps feature can offer them to you
- To process in-app credit purchases and maintain your credit balance
Custom map sources (Maps feature)
In the app's Maps feature you can add your own map sources. For each source you enter a name and a map tile URL template (for example https://…/{z}/{x}/{y}.png). This is user-provided content and we handle it as follows:
- What we store: the source name and the URL template you entered, together with your user ID and the creation timestamp. We store this data only because you chose to use the Maps feature — it is not required to use the rest of the app.
- Why we process it: solely to operate the Maps feature you chose to use — we need this data to provide the service you asked for. We do not use it for profiling, advertising or analytics.
- Where it is stored: in our app backend (Supabase, servers located in the European Union), in a table that is protected by row-level security — only you can read and modify your own sources; access on our side is limited to administrative maintenance.
- How long we keep it: until you delete the source, or until you delete your account — whichever comes first. Deleting your account automatically deletes your map sources as well.
- Sharing: your map sources are private to your account. We do not sell them and do not share them with third parties.
- Important — third-party map servers: a tile URL you enter may point to a server operated by a third party. When such a map is displayed, your device requests map tiles directly from that server, which means the server can see your requests (including which map area you are viewing) and your IP address. That server is chosen and configured by you; we neither operate nor control it, and its own privacy policy and terms apply. Only add sources you trust and are entitled to use.
The website (locurai.com)
The website lets you browse public tours and, if you sign in with your existing account, view your own tours. You cannot register on the website — accounts are created in the app.
- Cookies: a session cookie to keep you signed in, and a cookie that remembers your language choice. No advertising or cross-site tracking cookies are used on the website.
- No ads: advertising appears only in the app, not on the website.
- Tour images are served through our own server-side image proxy; no third-party keys or trackers are exposed to your browser.
- Analytics: the website does not use third-party analytics. If this changes, we will update this policy and, where required, ask for your consent.
- Hosting: the website is hosted on Vercel; standard server logs (e.g., IP address, browser type) may be processed for security and operation.
Third-party services
To provide its features, LocurAI shares limited data with:
- Supabase — database and authentication (data stored in the EU)
- Anthropic (Claude API) — receives your tour parameters to generate tour content
- Google Places API — receives place search terms to fetch images
- Vercel — website hosting and content delivery
- Google AdMob — displays advertisements within the app (app only); may collect device identifiers for ad personalisation
- RevenueCat — processes in-app purchase receipts to validate and credit your purchase (app only)
- Map tile servers you configure yourself — if you add a custom map source, your device requests map tiles directly from the server you specified (app only). These servers are not operated or controlled by us.
Data storage
- Your account and tour data are stored on Supabase servers located in the European Union.
- The custom map sources you add (name and URL template) are stored in the same Supabase database, linked to your account, until you delete them or delete your account.
- Website hosting and content delivery are provided by Vercel.
Your rights
- You can delete your account at any time from the app's Profile screen. Deleting your account removes your personal data; public tours you created remain but are shown without your name. Your custom map sources are deleted with the account.
- You can delete any custom map source individually at any time in the app's Maps screen.
- You may contact us to request access to or deletion of your data.