Privacy Policy
This draft describes the current Muntside service and identifies decisions that have not yet been made. It is not a final legal notice.
Draft updated: 26 September 2026
Who is responsible
Muntside is operated by Gerson Paulo as an individual, based in Sion, Switzerland. For privacy questions, contact muntside@gmail.com. Sion is a locality, not a complete postal address; the full address remains to be supplied.
Account and profile
An email address and authentication details are required for an email account. If you choose an available external sign-in option, that provider processes sign-in information under its own terms. The interface offers email/password, Google and Apple; availability and provider settings require confirmation. A display name, username, biography, location and avatar may be added to a profile. Profile information and contributions can be visible to other people according to the feature and profile visibility settings; your email and sign-in credentials are not displayed as public profile fields.
Your activity and contributions
To provide the features you choose, Muntside associates saved items and likes, lists, itineraries and their checklists, personal notes, completed activities, routes, comments, ratings, photos and content reports with your account. These are optional uses of the service, not required for browsing.
- Personal notes and completed-activity records are account-specific. Lists and itineraries may have a public/private setting; for saved items and likes, profile settings only control who can see how many you have (everyone, signed-in users, or only you); which activities you saved or liked is never shown to other people. Check list and itinerary visibility before sharing.
- Community routes, comments, ratings and approved photos may be shown publicly; profile settings also offer visibility choices for comments. Drafts and pending moderation are not intended to be public. Free text, routes and photos may themselves disclose personal information.
- Reports about incorrect content are used for review; internal triage notes are restricted to administrators. Your report is not itself a public contribution.
Location, searches and maps
You can search for places without granting device location. GPS is requested only after you choose a location action. If it fails or you decline, you can search manually or separately choose approximate location. Only after that explicit choice does your browser contact ipapi.co, which receives your IP address to estimate a town. A location saved on your device expires after 24 hours and can be cleared. Search terms and a coarse location may be included in navigation URLs; avoid sharing links that reveal your location.
Map tiles come from OpenStreetMap. Opening a map or an external directions link may disclose your IP address and map area or destination to the relevant provider. Google Maps directions open only when you select that link. Open-Meteo geocoding is used for place searches; providers may receive the searched place.
Weather, alerts, events and other sources
Forecasts use Open-Meteo; official weather alerts are fetched from MeteoAlarm and named national sources where connected. The forecast may be requested from your browser, disclosing your IP address and queried coordinates to Open-Meteo; other requests can run through the service. Event pages can link to official organizers or ticket sites: opening those links takes you to those sites under their own privacy terms. Other catalogue facts may originate from identified external sources. Provider contracts, complete recipients and their processing locations remain to be confirmed.
Device storage and sessions
The app stores the language preference, authentication state and, where used, cached content and offline action queues on your device; those queues are linked to the account that created them. Session sign-out and account changes clear private local caches and saved location, while keeping non-sensitive preferences such as language. If offline actions are pending on voluntary sign-out, the app offers a choice to stay or discard them. An expired or revoked session must not sync pending actions; recovery is limited to signing in again as the same account. Multi-tab cleanup and late-response protection have been implemented and tested in a browser, but not on a physical iPhone; device and browser behaviour can vary. Hosting-level cookies, analytics, logs and retention need separate verification.
Photos and metadata
New uploads pass through a private quarantine and are decoded and re-encoded on the server before being made available; orientation is corrected and embedded metadata, including GPS EXIF, is removed. A failed upload is not published. This does not mean every older photo has been checked or cleaned. Older files have been inventoried in simulation and any bulk treatment awaits a separate decision. Image content itself can still reveal a person or location. Public editorial images and moderated community photos have different visibility rules; private account files require an authenticated owner check when downloaded.
Export and access
A signed-in user can request an export from account settings. The app assembles a ZIP on that device, containing structured JSON and the account’s own downloadable files. Each private file request checks the current sign-in and ownership; the export does not use shareable signed photo URLs. Keep your downloaded ZIP secure. Export excludes passwords, tokens, other people’s private data and internal administrator notes. This feature has been implemented and tested with disposable accounts, but not every device or account history has been validated.
Deletion requests and intended treatment
Account settings accepts a deletion request tied to the signed-in account; email can be used to ask about a request. Receiving a request is not deleting an account. Automatic permanent deletion of real accounts remains disabled while retention rules are decided. The intended approach is to remove private account data (including profile, saved items, private lists, itineraries, personal notes and private records) unless a specific retention exception is justified. Public contributions would be retained only if effectively anonymized; merely detaching an account ID is not enough. Photos, free text and tracks can still identify someone, and content that cannot be adequately anonymized would need editing or removal. This intended process is not yet operational for real accounts.
Reports, administrative history and backups need separate retention and deletion rules. A tested cleanup process exists for disposable test accounts only; it does not establish how real accounts or backups will be handled.
Retention, transfers and legal basis
Retention periods by category, backup lifetimes and deletion procedures, recipients, hosting and storage locations, and any international transfers have not been confirmed. An observed technical database region does not establish where all services store or process data. The legal grounds for each processing purpose—including account provision, community features, optional location, safety and moderation—require legal review; not every use should be treated automatically as consent. No period, transfer safeguard or comprehensive analytics claim is asserted by this draft.
Your requests
Contact muntside@gmail.com to ask for access, correction, deletion or other applicable privacy rights. You can change some profile information in the app and download the ZIP described above. Requests requiring manual review can be recorded for an administrator, but this draft does not promise a response deadline or a complete self-service deletion process. Eligibility, verification and any exceptions require review.
Updates to this draft
This draft was updated on 26 September 2026; no effective date has been set. Material changes to the policy and how they will be communicated will be determined before a final version is adopted.
