Privacy Policy
How VUNO uses and protects data.
Effective date: July 28, 2026
This Privacy Policy explains how VUNO collects, uses and protects data when you use the application. VUNO is an adventure-navigation, route-recording, group-riding, Event, ASSIST and viewed-map caching application.
Privacy contact: info@vunoapp.com
Legal controller: Ioannis Marakakis
Contact address: Evelpidon 14, Chania, Crete, Greece
Data used by VUNO
Location data
VUNO uses your device’s GPS location to show your position on the map; provide navigation and calculate distance; record trips and tracks; display speed, elevation, heading and kilometres; provide wrong-way and steep-slope warnings; operate Group, Event, Community and ASSIST features; and show nearby points of interest such as fuel and food locations.
Continuous precise background-location recording starts only after you explicitly tap REC while the application is open. It continues when you switch applications or lock the screen and stops when you tap STOP. Android displays a persistent notification and iOS displays its corresponding active-location indicator. REC stores the track locally on the device and does not by itself share your location with a Group, Event or Community. Recording may stop if you force-quit the application, withdraw permission, disable GPS or the operating system terminates the process.
Fall Guard and emergency contacts
If you choose to configure VUNO Fall Guard, we process the name you want shown in the message; a reference name and phone number for up to two emergency contacts; consent status and time for each contact; the time, latest available precise location and technical identifier of a possible fall incident; and technical SMS sending or delivery status.
The rider enters only a contact reference name and creates a private link, which they personally share through a communication application of their choice. VUNO and Twilio do not send an invitation SMS before consent. The contact opens the link, receives the relevant information, enters their own number, selects a non-preselected consent field and verifies the number using a six-digit SMS code. Until verification succeeds, the contact does not receive incident SMS. VUNO does not request access to the phone’s address book.
The contact’s reference name initially comes from the rider creating the invitation. The phone number comes directly from the contact. Before entering a number or consenting, the contact is informed of the rider’s and VUNO’s identities.
Before adding a contact, the rider separately accepts the specific Fall Guard terms. To demonstrate this choice, we store the terms version, acceptance time, app version and language. The contact’s consent is recorded separately. Inactivity or no response is not consent.
When the rider disables Fall Guard SMS or removes a contact, the full number is deleted from the active system. A minimal record of consent or withdrawal may remain for a limited period without the full number or location: a technical identifier, last four digits, consent version, and acceptance or withdrawal times.
If a possible fall is detected and verified contacts exist, a pending incident is immediately created on the protected server with the latest location and scheduled to send after two minutes. If the rider taps “I’m OK” in time, the application requests cancellation and deletion. Cancellation succeeds only after server confirmation; if confirmation is not received, the application warns that SMS may still be sent. Otherwise, the server attempts one SMS per verified contact. The SMS contains a private link showing the rider’s chosen name, time and latest location. No second “resolved” SMS is sent and official emergency services are not called automatically.
The possible-fall assessment is performed automatically on the device using motion and safety rules. It is not a medical assessment or an automated decision producing legal or similarly significant effects under Article 22 GDPR. The user has a two-minute cancellation mechanism, but detection and sending are not guaranteed.
When you do not use sharing features such as Group, Event or Community, route and recording data remain on your device unless you choose to publish them or use another online feature.
Group, Event and Community
While you participate in a Group, Event or Community, VUNO may temporarily send to online services your nickname, temporary participant ID, device ID, current position, heading, speed, online/offline status, last-update time and ASSIST notifications you activate. This allows participants to see one another on the map, coordinate and receive safety notifications. It is not intended for continuous monitoring outside application use.
PULSE and VUNO Alerts
Creating a public PULSE profile or post requires a VUNO Account with a verified email address. The email is used to send a sign-in code, recover the same account on another device, secure the service and limit abuse. It is not publicly displayed or used for advertising tracking. The account identifier, verified email and account creation or last-sign-in times are processed through Supabase Auth. Browsing PULSE may remain available without an account.
If you publish a trip or route to PULSE, the server receives your public PULSE identity, the public track, title, description, activity categories, photos and selected points. Any start/end privacy treatment offered by the application is applied before upload.
TRACK stores which public profiles you follow. People following you appear publicly as CREW and profiles you follow as TRACKED. This relationship prioritises TRACKED posts without exposing live or historical location. Blocking or account deletion removes the relationship.
PULSE Activity creates private in-app notifications when another user TRACKs your profile, likes your post, performs a PULSE CHECK on your route or adds or confirms a related VUNO Signal. We store technical recipient and actor IDs, action type, related post or Signal, grouped-action count, time and read status. Notifications are visible only to the recipient, contain no live location and are removed between users when one blocks the other.
For a PULSE CHECK, the application locally compares a trip stored on the device with the already public route track. The complete private recorded track is not uploaded for this comparison. The server stores the account and route IDs, match percentage, ride time, declared condition, surface, difficulty and vehicle category, an optional short note, and creation or update times. These support VERIFIED RIDE, information freshness and abuse prevention. A public profile may show the number and list of public routes a user verified, with verification dates; it never shows the private recorded track. During publication, an intermediate route point may be sent through VUNO infrastructure to Nominatim/OpenStreetMap solely to derive country, administrative region and locality. That structured category is stored with the public route and used for search filters.
After a valid PULSE CHECK, a user may create a VUNO Signal on a specific public track. We store its exact position, distance along the route, structured type, optional note, reporter’s technical ID and timestamps. Others may confirm it or mark it cleared; each vote stores a technical identifier, selection and time. Active Signals may appear on other planned or active routes that pass nearby. They do not share the user’s live location.
Photos, POIs and ordinary notes remain connected to the specific post. If you mark a point as a “Temporary hazard”, the application informs you before publication that its exact position, title, description, severity, report time and expiry are additionally shared as a VUNO Alert. It may be shown to other adult users whose planned or active route passes nearby. The reporter’s live location is not shown.
Other users may vote “Still present” or “Cleared”. We store the voter’s technical identifier, choice and time so each account counts once, abuse is limited and stale reports can be withdrawn. An active Alert expires within seven days, may expire earlier through community confirmation and is withdrawn if you delete its post. The original point may remain visible inside the post until you delete it.
Routes, GPX, trips and temporary map cache
VUNO may store locally saved routes, waypoints, imported GPX files, trips and recording tracks, distance, time, speed and elevation data, and temporary map data for areas already displayed. These remain local unless you choose an online feature requiring synchronisation.
Bluetooth and external controllers
The current controller feature uses devices paired by the operating system as standard HID/keyboard input. VUNO does not currently scan for BLE devices, create its own BLE connection or store nearby Bluetooth device identifiers. Pairing and disconnection are handled in device settings. If a future version adds direct BLE scanning, this Policy and the in-app permission explanation will be updated before activation.
Purchases and subscriptions
At initial public launch all features are free and the application does not initiate a subscription transaction. If payments are enabled later, they will be made only through Apple App Store or Google Play and this Policy will be updated before activation. VUNO does not store full card details.
Support and optional updates
If you contact us by email, we process your address and message to respond. If you enable optional VUNO updates in Settings, we may store your email, application language, device platform, consent date and a technical device ID preventing duplicate entries. This is used only for important application, map, Event, feature and support updates. You can disable it in Settings at any time.
Diagnostics and crash reports
VUNO may use crash reporting to identify technical problems. When enabled, it may send app version, operating system, device model, error time, technical logs, stack traces and related app state. Diagnostics are not used for advertising or sold. Crash reporting is not configured to send screenshots or full payment details.
How we use data
We use data only to operate maps and navigation; record and store routes; display riders in Group, Event and Community; provide ASSIST and safety notifications; invite, verify and notify up to two Fall Guard contacts; improve stability and correct technical faults; support users; provide optional updates with consent; and manage free initial-launch access. We do not sell personal data.
Legal bases
Depending on the feature, processing is based on performance of the service requested by the user; the rider’s explicit optional activation of Fall Guard and each contact’s separate SMS consent; our legitimate interests in protecting the service, preventing abuse, controlling cost and demonstrating valid consent or withdrawal with data minimisation; or a legal obligation. Consent may be withdrawn for the future without affecting prior lawful processing.
Service providers and international transfers
VUNO may use:
- Supabase for Group, Event, Community, ASSIST, VUNO Account, PULSE and secure Fall Guard records,
- Twilio for consent-based verification and possible-fall SMS,
- VUNO infrastructure for VUNO Topo, routing, search mediation and map-tile delivery,
- ArcGIS/Esri for Satellite and Hybrid maps and temporary place or address suggestions,
- OpenStreetMap Nominatim through VUNO infrastructure to resolve a selected search result to coordinates,
- Sentry for crash reporting and diagnostics when enabled,
- routing and elevation services,
- Apple and Google for installation, store services and future purchases.
Providers may process technical data such as IP address, map requests or device information under their own policies. Some providers or subprocessors may process data outside Greece or the EEA. Where there is no adequacy decision, transfers rely as appropriate on safeguards such as the European Commission’s Standard Contractual Clauses and supplementary security measures. Details are available from info@vunoapp.com.
For Fall Guard SMS, Twilio receives the recipient number, short SMS content and technical delivery information. The number is not returned to the application after registration; Settings shows only its last four digits. Provider secrets remain on the server and are not included in the application.
Map display may send VUNO infrastructure or ArcGIS the tile request, IP address and necessary device or application details. Displayed areas are temporarily cached up to 400 MB. Cache is not a guaranteed offline download and may be replaced or removed by the operating system, cache clearing or uninstalling. Initial launch does not provide predefined offline-area downloads.
Route search may send the typed text and an approximate reference location through VUNO infrastructure to ArcGIS/Esri for suggestions and to OpenStreetMap Nominatim for selected coordinates. VUNO applies rate limits and temporary caching for security and availability. Search request bodies are not written to VUNO access logs. Do not enter names, phone numbers, email addresses or unnecessary personal data in search.
VUNO Topo uses OpenStreetMap data with “© OpenStreetMap contributors” attribution. Satellite and Hybrid use ArcGIS/Esri World Imagery and show the providers’ required attribution on the map.
Retention
- Local routes, trips and related data remain until you delete them or uninstall; cached tiles may be removed earlier.
- Live Group and Community data is temporary and refreshed while you participate. Event data may remain until expiry or event management.
- An active VUNO Alert is displayed for up to seven days unless withdrawn earlier. Source and community votes remain as needed for the post, abuse prevention and service security or until the related post is deleted, subject to lawful retention.
- PULSE Checks, Signals and confirmations remain linked to the post and Account to preserve condition history and prevent abuse. They are deleted with the related post or creator account, except for strictly limited lawful retention.
- Private PULSE Activity is retained up to 180 days and limited to the newest 500 entries per account. It may be deleted earlier with the related account or post and is removed between blocked users.
- Verified email and VUNO Account identity remain while the account is active. In-app permanent deletion removes sign-in email, PULSE profile, posts and files, and related Fall Guard personal data. Groups or Events owned by the account are closed. Strict mandatory retention may still apply.
- ASSIST data may remain until resolved or cleared for technical, safety or organisational reasons.
- An incomplete Fall Guard invitation expires and is deleted after 48 hours. No number exists before the contact enters it. A verification code expires after 10 minutes and attempts and resends are limited.
- Verified-contact consent lasts up to 12 months, after which fresh verification is required or the full number is deleted. Earlier deletion may be requested by the rider or contact.
- A minimal Fall Guard consent or withdrawal record, without full number or location, may be retained up to 24 months solely for security, abuse investigation, proof of consent and legal claims where permitted.
- An incident location link expires after 24 hours. Incident location and technical records are deleted no later than 30 days after creation unless a legal obligation requires otherwise.
- Minimized SMS-budget reservation logs, without full number or location, are retained up to 90 days. The SMS provider may retain message metadata under its own policy and telecommunications obligations.
- Crash diagnostics, support email and optional-update data are kept only as long as needed for their stated purpose or until opt-out where applicable.
Device permissions
You can change or withdraw permissions such as location in device settings. The current HID/keyboard controller mode is managed through the operating system’s Bluetooth pairing settings and does not require VUNO to scan for nearby BLE devices. Disabling required permissions may prevent some features from working.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection, technically feasible portability and withdrawal of consent. Use “Delete account” in the application for VUNO Account deletion. For other requests, or if you cannot access the account, contact info@vunoapp.com.
You may complain to the Hellenic Data Protection Authority, 1-3 Kifisias Avenue, 115 23 Athens, www.dpa.gr, or the competent authority where you live or work.
A Fall Guard contact can withdraw consent through the original secure invitation link, by contacting us and identifying the invited number, or through STOP where supported. Withdrawal does not affect prior lawful processing. After valid withdrawal, future alerts stop and the full number is removed from the active VUNO system, subject to limited technical or mandatory records.
Children
VUNO is exclusively for adults aged 18 or over and is not designed for children. Contact us if you believe a minor’s data was submitted so it can be promptly reviewed and deleted.
Security
We apply reasonable technical and organisational security measures. No online service can guarantee absolute security.
Policy changes
We may update this Policy when features, providers or legal requirements change. The latest version will be available in the application and/or on the official VUNO website.
Contact
For privacy questions or requests, contact info@vunoapp.com.