Privacy Policy

Last Updated: February 3, 2026

Effective Date: February 3, 2026

Hidden Layers ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application ("App").

1. Information We Collect

1.1 Information You Provide

  • Account Information: If you create an account, we may collect your email address and display name.
  • Purchase Information: When you make in-app purchases, payment processing is handled by Apple (App Store) or Google (Play Store). We do not store your payment card details.

1.2 Information Collected Automatically

  • Location Data: With your permission, we collect your device's precise location to trigger GPS-based audio content when you arrive at points of interest. Location data is processed locally on your device and is not transmitted to our servers except as aggregated, anonymized analytics.
  • Device Information: We may collect device type, operating system version, and unique device identifiers for analytics and troubleshooting.
  • Usage Data: We collect anonymized data about which destinations, tours, and episodes you access to improve our content.

1.3 Information We Do NOT Collect

  • We do not collect your contacts, photos, or messages.
  • We do not sell your personal information to third parties.
  • We do not use your location data for advertising purposes.

2. How We Use Your Information

We use the information we collect to:

  • Provide GPS-triggered audio content at points of interest
  • Process in-app purchases and restore previous purchases
  • Improve our App, content, and user experience
  • Send service-related communications (e.g., purchase receipts)
  • Analyze usage patterns (in aggregate) to improve content

3. How We Share Your Information

We do not sell your personal information. We may share information only in these limited circumstances:

  • Service Providers: We use third-party services (RevenueCat for subscriptions, analytics providers) that process data on our behalf under strict contractual obligations.
  • Legal Requirements: We may disclose information if required by law, court order, or to protect our rights and safety.
  • Business Transfers: In the event of a merger or acquisition, user information may be transferred to the new entity.

4. Data Retention

  • Location Data: Processed in real-time on your device; not stored on our servers.
  • Account Data: Retained while your account is active. You may request deletion at any time.
  • Analytics Data: Aggregated, anonymized data may be retained indefinitely for product improvement.

5. Your Rights and Choices

5.1 All Users

  • Location Permissions: You can disable location access at any time in your device settings. Note: This will disable GPS-triggered audio playback.
  • Push Notifications: You can disable notifications in your device settings.
  • Account Deletion: Contact us at privacy@hiddenlayers.app to request account deletion.

5.2 European Economic Area (EEA) Residents — GDPR Rights

If you are in the EEA, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to Access: Request a copy of your personal data.
  • Right to Rectification: Request correction of inaccurate data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data.
  • Right to Restrict Processing: Request limitation of how we use your data.
  • Right to Data Portability: Receive your data in a portable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time (e.g., location permissions).

Legal Basis for Processing (GDPR Article 6):

  • Consent: Location data collection (you grant permission via device settings).
  • Contract: Processing necessary to provide the App and fulfill purchases.
  • Legitimate Interests: Analytics to improve our service, provided it does not override your rights.

To exercise your GDPR rights, contact: privacy@hiddenlayers.app. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

5.3 California Residents — CCPA/CPRA Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we collect.
  • Right to Delete: Request deletion of your personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights.

Categories of Personal Information Collected (last 12 months):

CategoryCollectedSoldPurpose
Identifiers (email, device ID)YesNoAccount management
GeolocationYesNoGPS audio playback
Commercial info (purchases)YesNoFulfill purchases
Usage dataYesNoImprove content

Do Not Sell or Share My Personal Information: We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.

To exercise your CCPA/CPRA rights, contact: privacy@hiddenlayers.app. We will verify your identity and respond within 45 days.

6. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption in transit (HTTPS/TLS)
  • Secure cloud infrastructure (Cloudflare R2)
  • Limited access to personal data by authorized personnel only

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

7. Children's Privacy

Hidden Layers is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@hiddenlayers.app and we will delete it.

8. International Data Transfers

Your information may be transferred to and processed in the United States or other countries where our service providers operate. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for EEA transfers.

9. Third-Party Services

Our App uses the following third-party services:

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy in the App
  • Updating the "Last Updated" date above

Your continued use of the App after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights:

Hidden Layers is operated from San Diego, California, USA.