Privacy Policy
This Privacy Policy describes how Prime Indigo LLC ("Prime Indigo," "we," "us," or "our") collects, uses, shares, and protects information in connection with the BeenThere mobile application and related services (the "App"). It also explains the choices and rights you have.
BeenThere's design principle is simple: a passport, not a tracker. The App exists to show you where you have been, not to broadcast where you are. We do not sell your personal information, we do not show ads, and we do not use advertising or data-broker SDKs.
By using the App, you agree to this Privacy Policy. This Policy is incorporated into our Terms of Service.
1. Quick Summary
- Your precise GPS trail stays on your phone. The continuous, precise location trail used to compute your map is stored only on your device, in a short rolling window (currently about 7 days), and is never uploaded to our servers.
- What syncs to our servers is coarse or derived: revealed map cells on a ~170-meter grid, the stamps you confirm, coarse travel lines, and settings you provide.
- A stamp is a place name, not a coordinate. When you confirm a visit, what we keep is the public listing for that place (for example, a café's name and category) and the ~170-meter cell it sits in. We do not store the GPS coordinates of your visits. By design, the App never stamps hospitals or other medical facilities, religious venues, or schools.
- Private by default. Your map and visits are visible only to you unless you use a social feature that shares specific information (for example, your profile or leaderboards).
- Sharing sends an image, not your map. When you share an achievement card, the App creates a picture on your device and hands it to whatever app you choose. Nothing about your map is uploaded to us, and there is no link for anyone to follow back.
- You can delete everything. Deleting your account erases your data on our servers and the sensitive data on your device.
- Adults only, United States only. You must be 18 or older to use the App, and we offer it in the U.S. only.
- No sale of personal information. No advertising. No cross-app tracking.
The rest of this Policy is the detail behind that summary.
2. Information We Collect
2.1 Information you provide
| Information | Details |
|---|---|
| Account information | Email address, name, username, and a password (stored by our authentication provider in hashed form; your session token is kept in your device's secure keystore). |
| Date of birth | Entered once when you set up your account, so our server can confirm you meet the App's 18+ minimum age (Section 10). We do not keep your full date of birth: the check happens on our server and we retain only your year of birth and the fact that the check passed, with its date. It is not shown to other users and is not used for advertising or profiling. |
| Two-factor authentication (optional) | If you turn on 2FA: which methods you enabled, and, if you choose email codes, the address they go to (your account email by default, or a secondary address you verify). That destination is locked to the address that proved control when you set it up, so later changing your account email does not redirect your codes. Verification codes and recovery codes are stored only as salted hashes, never in readable form, and expire or are consumed on use. We also record that a given sign-in session cleared its 2FA challenge, so you are not asked again on every screen. Turning 2FA on signs you out of your other devices, so any session that predates it has to sign in again and pass the new challenge. |
| Profile information | Optional home town, profile/avatar imagery, and privacy settings. |
| User content | Notes on saved places, memoirs (which may include photos and voice recordings), challenge messages, and similar content you create. Memoir media is stored in access-controlled storage private to your account. |
| Avatar photo | If you request a generated avatar, the photo you supply. |
| Imported links | If you share a social video link into the App ("Save it, Prove it"), the link you shared. |
| Communications | Messages you send us (for example, support or feedback emails). |
2.2 Information collected automatically
| Information | Details |
|---|---|
| Precise location (on device) | With your permission, the App collects precise device location, including in the background if you grant "Always" access, to compute map reveals and verify visits. The raw, precise trail is processed and stored on your device only, retained for a short rolling window (currently about 7 days), and then discarded. It is never uploaded to our servers. |
| Derived location (synced) | The outputs derived from your trail that power your account across devices: revealed map cells on a ~170 m hexagonal grid (roughly a city block, not a GPS pinpoint); the stamps you confirm, each holding the public listing for an established place (its name and category), the ~170 m cell it falls in, when you arrived, how long you stayed, and the signals used to judge the match; coarse travel lines (for example, a flight path so air travel doesn't falsely reveal the map); and, if set, your home area. A stamp contains no GPS coordinates. |
| Usage analytics | Product events describing feature use (for example, "a visit was verified," "a challenge was sent") with non-identifying properties such as counts and categories. Our analytics events do not include your coordinates or the names of places you visit. |
| Diagnostics | Crash reports and performance data. Crash reports are associated with your user ID only; we scrub location coordinates from network URLs before reports leave the device. Session replay is disabled by design. |
| Device and push information | Device push notification token (if you enable notifications), device platform/version, and app version. |
2.3 Information from other users
Other users may generate information involving you, for example a friend request, a challenge sent to you, or a block. We process this to operate those features.
2.4 Guest Mode
In Guest Mode, your map data is stored locally on your device and is not associated with an account on our servers. Analytics and crash reporting may still operate.
2.5 Information we do NOT collect
We do not collect: contacts or address books; the content of your social-media accounts; advertising identifiers; or biometric data. We do not use your photos for anything other than the features you invoke.
3. How We Use Information
We use information to:
- provide the App's core features: revealing your map, verifying visits, awarding stamps, badges, and levels;
- operate optional social features you use: friends, leaderboards, challenges, and profiles, subject to your privacy settings;
- generate content you request (for example, an avatar from your photo, or place extraction from a video link you share);
- send push notifications you have enabled and transactional emails (such as welcome and account-deletion confirmations);
- maintain safety and integrity: preventing GPS spoofing and cheating, enforcing our Terms, rate-limiting abuse, and securing accounts;
- diagnose crashes, monitor performance, and understand aggregate feature usage to improve the App; and
- comply with legal obligations.
We do not use your information for third-party advertising, and we do not sell it or share it for cross-context behavioral advertising.
4. What Other People Can See
Visibility is controlled by your privacy settings (public, friends-only, or private) and by the features you choose to use:
| Surface | Who can see it | What they see |
|---|---|---|
| Profile (name, username, avatar, level, badge count, home town) | Depends on your privacy mode; "private" hides stats and hometown even from friends | Profile fields only, never your map, trail, or visit history |
| Local leaderboard | Others in your area, only if you opt in | Display name, avatar, rank metric |
| Friend features | Your accepted friends | Profile fields; challenge activity between you |
| Challenges | The specific recipient/sender | The place, your note, and challenge status (including when you prove it) |
| Share cards you create | Whoever you send the image to | An image only. The card is rendered on your device and shared as a picture. We do not upload it, store it, or create a link to it, so there is nothing on our side to expose, revoke, or expire |
Your verified visit history and your map are never visible to other users, including friends. (A challenge you accept necessarily reveals to its sender whether you completed it at that place.)
5. How We Share Information
We share personal information only with service providers that process it on our behalf under contractual restrictions, and in the limited legal circumstances below. We never sell it, and no third party receives it for advertising.
| Provider | Role | What it processes |
|---|---|---|
| Supabase | Database, authentication, file storage | Account data, synced (derived) location data, user content |
| Google (Maps / Places) | Map data and place lookups | Coordinates sent to look up nearby places and render map content; governed also by Google's terms (see our Terms of Service §11) |
| Mapbox | Map rendering and geocoding | Map tile requests and region lookups (coordinates) |
| Sentry | Crash reporting | Crash/diagnostic data (user ID only; coordinates scrubbed from URLs) |
| PostHog | Product analytics | Usage events (no coordinates, no place names) |
| Expo | Push notification delivery | Push token and notification payloads |
| Resend | Transactional email | Your email address and email content, including two-factor verification codes if you enable email-code 2FA |
| Supadata | Social-video metadata for imports you request | The public video link you shared |
| Replicate | Avatar generation you request | The photo you submit, processed solely to generate your avatar |
| Apple / Google | App distribution, and payment processing if paid features launch | Per their own policies |
We may also disclose information: (a) to comply with law, legal process, or enforceable governmental requests; (b) to enforce our Terms or protect the rights, safety, or property of users, the public, or Prime Indigo; and (c) in connection with a merger, acquisition, or sale of assets, in which case this Policy will continue to apply to your information until a successor policy takes effect with notice to you.
6. Location Data: the Details
6.1 Permissions. The App requests foreground location permission to function, and offers background ("Always") permission so your map stays accurate while your phone is locked or the app is closed. Background permission is optional; without it, reveals and visit verification work only while the App is open. You can change permissions at any time in your device settings.
6.2 Two-tier storage. Precise trail data (exact coordinates, speed, timestamps) is processed and retained only on your device for a short rolling window (currently about 7 days) and is protected in transit and, for sensitive stores (your revealed-hex set, home coordinates, and stop locations), encrypted at rest on the device with a key held in the operating system's secure keystore. Only coarse and derived outputs (Section 2.2) sync to our servers, where access is enforced per-user by database row-level security.
6.3 Avatar photos. If you request a generated avatar, the photo you submit is sent to Replicate, our image-generation provider, where it passes through an image-generation model and then a background-removal model to produce your avatar. We use that photo solely to produce the avatar you asked for. We do not use it for any other purpose, we do not sell it, and we do not use it to train any model of ours. Replicate processes it as our service provider under its own Privacy Policy.
6.4 Encrypted map backup. To restore your exact map after a reinstall, the App can back up your fog data to our servers encrypted on your device with a key stored in your device's secure keystore. We never receive the key, and cannot read the backup's contents.
6.5 Sensitive places. The App verifies visits only at categories of established places oriented around exploration and everyday errands. By deliberate design, the App does not verify or record visits at hospitals or other medical facilities, religious venues, or schools.
7. Retention
| Data | Retention |
|---|---|
| Precise on-device trail | Rolling window, currently about 7 days, device-only |
| Synced map cells, visits, travel lines, user content | Until you delete the content or your account |
| Two-factor verification codes | Minutes (single use), and purged automatically within a day |
| Two-factor session records | Up to 90 days, then purged automatically; recovery codes last until used or regenerated |
| Analytics and diagnostics | Retained per our providers' configured retention, in identified form no longer than needed for the purposes above |
| Transactional email records | Kept as business records for a reasonable period |
| Backups | Deleted data ages out of routine backups within a limited period |
8. Your Rights and Choices
8.1 Access, correction, deletion. You can view and edit profile information in the App. You can delete individual content (notes, memoirs, saved places) in the App. Deleting your account (Settings → Account) erases your personal data from our servers and wipes the sensitive location data stored on your device. You may also exercise rights by emailing support@beentherenow.app; we will verify your request using the email associated with your account.
8.2 Permissions and notifications. Location and notification permissions are controlled in your device settings. Push notification categories can be managed in the App.
8.3 Visibility. Privacy mode (public / friends-only / private) and local-leaderboard participation are controlled in Settings → Privacy. Sharing requires no management: share cards are images created on your device, so there is nothing stored on our side to revoke.
8.4 U.S. state privacy rights. Depending on your state of residence (including Connecticut, California, Colorado, Virginia, and others with comprehensive privacy laws), you may have rights to access, correct, delete, or obtain a copy of your personal data, and to opt out of sales, targeted advertising, or profiling. We do not sell personal data or process it for targeted advertising. We honor verified access, correction, and deletion requests from all users regardless of state. If we decline a request, you may appeal by replying to our decision email; Connecticut residents may also contact the Connecticut Attorney General.
8.5 Do Not Track / opt-out signals. The App does not engage in cross-site tracking, so browser-style tracking signals do not apply. We do not sell or share personal information within the meaning of the California Consumer Privacy Act.
9. Security
We take security seriously and have designed for it from the start: encryption in transit (TLS) everywhere; per-user row-level security enforced inside our database (so access control does not depend on the secrecy of the app's API key); authentication tokens stored in the operating system keystore; optional two-factor authentication (an authenticator app or emailed codes, with one-time recovery codes), where codes are stored only as salted hashes and the requirement is enforced inside our database rather than by the app alone, so a sign-in that has not cleared its challenge is refused your data at the source; on-device encryption of the sensitive location stores described in Section 6.2; and scrubbing of coordinates from crash telemetry. No system is perfectly secure, and we cannot guarantee absolute security; we will notify you and regulators of a breach as required by applicable law.
10. Age Requirement (18+)
The App is for adults. You must be 18 or older to use it. The App is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. You confirm you are 18 or older when you create an account, and we ask for your date of birth when you set it up, before the App is available to you, to confirm this.
What we keep. Your date of birth is sent to our server, used once to work out whether you are 18 or older, and then discarded. We store only your year of birth, the confirmation itself, and when it was made. If the answer is that you are under 18, we do not create an account at all, and where one was already created we delete it and its data. Your age answer cannot be edited in the App; contact us at support@beentherenow.app if you entered it incorrectly.
If you believe someone under 18 has created an account, contact us at support@beentherenow.app and we will delete the account and its data.
11. International Users
The App is operated from the United States, and information is processed and stored in the United States (including by the service providers in Section 5). If you use the App from outside the U.S., you understand that your information will be transferred to and processed in the U.S., where privacy laws may differ from those of your jurisdiction.
12. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will provide notice through the App or by email before the changes take effect, and we will update the "Last updated" date above. Your continued use of the App after the effective date constitutes acceptance of the updated Policy.
13. Contact Us
Prime Indigo LLC
Attn: Emmanuel Kurinaah, Privacy
2389 Main St., Ste 100
Glastonbury, CT 06033
Email: support@beentherenow.app
© 2026 Prime Indigo LLC. All rights reserved.