VUNO

Privacy Policy

How VUNO uses and protects data.

Effective date: July 28, 2026

This Privacy Policy explains how VUNO collects, uses and protects data when you use the application. VUNO is an adventure-navigation, route-recording, group-riding, Event, ASSIST and viewed-map caching application.

Privacy contact: info@vunoapp.com

Legal controller: Ioannis Marakakis

Contact address: Evelpidon 14, Chania, Crete, Greece

Data used by VUNO

Location data

VUNO uses your device’s GPS location to show your position on the map; provide navigation and calculate distance; record trips and tracks; display speed, elevation, heading and kilometres; provide wrong-way and steep-slope warnings; operate Group, Event, Community and ASSIST features; and show nearby points of interest such as fuel and food locations.

Continuous precise background-location recording starts only after you explicitly tap REC while the application is open. It continues when you switch applications or lock the screen and stops when you tap STOP. Android displays a persistent notification and iOS displays its corresponding active-location indicator. REC stores the track locally on the device and does not by itself share your location with a Group, Event or Community. Recording may stop if you force-quit the application, withdraw permission, disable GPS or the operating system terminates the process.

Fall Guard and emergency contacts

If you choose to configure VUNO Fall Guard, we process the name you want shown in the message; a reference name and phone number for up to two emergency contacts; consent status and time for each contact; the time, latest available precise location and technical identifier of a possible fall incident; and technical SMS sending or delivery status.

The rider enters only a contact reference name and creates a private link, which they personally share through a communication application of their choice. VUNO and Twilio do not send an invitation SMS before consent. The contact opens the link, receives the relevant information, enters their own number, selects a non-preselected consent field and verifies the number using a six-digit SMS code. Until verification succeeds, the contact does not receive incident SMS. VUNO does not request access to the phone’s address book.

The contact’s reference name initially comes from the rider creating the invitation. The phone number comes directly from the contact. Before entering a number or consenting, the contact is informed of the rider’s and VUNO’s identities.

Before adding a contact, the rider separately accepts the specific Fall Guard terms. To demonstrate this choice, we store the terms version, acceptance time, app version and language. The contact’s consent is recorded separately. Inactivity or no response is not consent.

When the rider disables Fall Guard SMS or removes a contact, the full number is deleted from the active system. A minimal record of consent or withdrawal may remain for a limited period without the full number or location: a technical identifier, last four digits, consent version, and acceptance or withdrawal times.

If a possible fall is detected and verified contacts exist, a pending incident is immediately created on the protected server with the latest location and scheduled to send after two minutes. If the rider taps “I’m OK” in time, the application requests cancellation and deletion. Cancellation succeeds only after server confirmation; if confirmation is not received, the application warns that SMS may still be sent. Otherwise, the server attempts one SMS per verified contact. The SMS contains a private link showing the rider’s chosen name, time and latest location. No second “resolved” SMS is sent and official emergency services are not called automatically.

The possible-fall assessment is performed automatically on the device using motion and safety rules. It is not a medical assessment or an automated decision producing legal or similarly significant effects under Article 22 GDPR. The user has a two-minute cancellation mechanism, but detection and sending are not guaranteed.

When you do not use sharing features such as Group, Event or Community, route and recording data remain on your device unless you choose to publish them or use another online feature.

Group, Event and Community

While you participate in a Group, Event or Community, VUNO may temporarily send to online services your nickname, temporary participant ID, device ID, current position, heading, speed, online/offline status, last-update time and ASSIST notifications you activate. This allows participants to see one another on the map, coordinate and receive safety notifications. It is not intended for continuous monitoring outside application use.

PULSE and VUNO Alerts

Creating a public PULSE profile or post requires a VUNO Account with a verified email address. The email is used to send a sign-in code, recover the same account on another device, secure the service and limit abuse. It is not publicly displayed or used for advertising tracking. The account identifier, verified email and account creation or last-sign-in times are processed through Supabase Auth. Browsing PULSE may remain available without an account.

If you publish a trip or route to PULSE, the server receives your public PULSE identity, the public track, title, description, activity categories, photos and selected points. Any start/end privacy treatment offered by the application is applied before upload.

TRACK stores which public profiles you follow. People following you appear publicly as CREW and profiles you follow as TRACKED. This relationship prioritises TRACKED posts without exposing live or historical location. Blocking or account deletion removes the relationship.

PULSE Activity creates private in-app notifications when another user TRACKs your profile, likes your post, performs a PULSE CHECK on your route or adds or confirms a related VUNO Signal. We store technical recipient and actor IDs, action type, related post or Signal, grouped-action count, time and read status. Notifications are visible only to the recipient, contain no live location and are removed between users when one blocks the other.

For a PULSE CHECK, the application locally compares a trip stored on the device with the already public route track. The complete private recorded track is not uploaded for this comparison. The server stores the account and route IDs, match percentage, ride time, declared condition, surface, difficulty and vehicle category, an optional short note, and creation or update times. These support VERIFIED RIDE, information freshness and abuse prevention. A public profile may show the number and list of public routes a user verified, with verification dates; it never shows the private recorded track. During publication, an intermediate route point may be sent through VUNO infrastructure to Nominatim/OpenStreetMap solely to derive country, administrative region and locality. That structured category is stored with the public route and used for search filters.

After a valid PULSE CHECK, a user may create a VUNO Signal on a specific public track. We store its exact position, distance along the route, structured type, optional note, reporter’s technical ID and timestamps. Others may confirm it or mark it cleared; each vote stores a technical identifier, selection and time. Active Signals may appear on other planned or active routes that pass nearby. They do not share the user’s live location.

Photos, POIs and ordinary notes remain connected to the specific post. If you mark a point as a “Temporary hazard”, the application informs you before publication that its exact position, title, description, severity, report time and expiry are additionally shared as a VUNO Alert. It may be shown to other adult users whose planned or active route passes nearby. The reporter’s live location is not shown.

Other users may vote “Still present” or “Cleared”. We store the voter’s technical identifier, choice and time so each account counts once, abuse is limited and stale reports can be withdrawn. An active Alert expires within seven days, may expire earlier through community confirmation and is withdrawn if you delete its post. The original point may remain visible inside the post until you delete it.

Routes, GPX, trips and temporary map cache

VUNO may store locally saved routes, waypoints, imported GPX files, trips and recording tracks, distance, time, speed and elevation data, and temporary map data for areas already displayed. These remain local unless you choose an online feature requiring synchronisation.

Bluetooth and external controllers

The current controller feature uses devices paired by the operating system as standard HID/keyboard input. VUNO does not currently scan for BLE devices, create its own BLE connection or store nearby Bluetooth device identifiers. Pairing and disconnection are handled in device settings. If a future version adds direct BLE scanning, this Policy and the in-app permission explanation will be updated before activation.

Purchases and subscriptions

At initial public launch all features are free and the application does not initiate a subscription transaction. If payments are enabled later, they will be made only through Apple App Store or Google Play and this Policy will be updated before activation. VUNO does not store full card details.

Support and optional updates

If you contact us by email, we process your address and message to respond. If you enable optional VUNO updates in Settings, we may store your email, application language, device platform, consent date and a technical device ID preventing duplicate entries. This is used only for important application, map, Event, feature and support updates. You can disable it in Settings at any time.

Diagnostics and crash reports

VUNO may use crash reporting to identify technical problems. When enabled, it may send app version, operating system, device model, error time, technical logs, stack traces and related app state. Diagnostics are not used for advertising or sold. Crash reporting is not configured to send screenshots or full payment details.

How we use data

We use data only to operate maps and navigation; record and store routes; display riders in Group, Event and Community; provide ASSIST and safety notifications; invite, verify and notify up to two Fall Guard contacts; improve stability and correct technical faults; support users; provide optional updates with consent; and manage free initial-launch access. We do not sell personal data.

Legal bases

Depending on the feature, processing is based on performance of the service requested by the user; the rider’s explicit optional activation of Fall Guard and each contact’s separate SMS consent; our legitimate interests in protecting the service, preventing abuse, controlling cost and demonstrating valid consent or withdrawal with data minimisation; or a legal obligation. Consent may be withdrawn for the future without affecting prior lawful processing.

Service providers and international transfers

VUNO may use:

Providers may process technical data such as IP address, map requests or device information under their own policies. Some providers or subprocessors may process data outside Greece or the EEA. Where there is no adequacy decision, transfers rely as appropriate on safeguards such as the European Commission’s Standard Contractual Clauses and supplementary security measures. Details are available from info@vunoapp.com.

For Fall Guard SMS, Twilio receives the recipient number, short SMS content and technical delivery information. The number is not returned to the application after registration; Settings shows only its last four digits. Provider secrets remain on the server and are not included in the application.

Map display may send VUNO infrastructure or ArcGIS the tile request, IP address and necessary device or application details. Displayed areas are temporarily cached up to 400 MB. Cache is not a guaranteed offline download and may be replaced or removed by the operating system, cache clearing or uninstalling. Initial launch does not provide predefined offline-area downloads.

Route search may send the typed text and an approximate reference location through VUNO infrastructure to ArcGIS/Esri for suggestions and to OpenStreetMap Nominatim for selected coordinates. VUNO applies rate limits and temporary caching for security and availability. Search request bodies are not written to VUNO access logs. Do not enter names, phone numbers, email addresses or unnecessary personal data in search.

VUNO Topo uses OpenStreetMap data with “© OpenStreetMap contributors” attribution. Satellite and Hybrid use ArcGIS/Esri World Imagery and show the providers’ required attribution on the map.

Retention

Device permissions

You can change or withdraw permissions such as location in device settings. The current HID/keyboard controller mode is managed through the operating system’s Bluetooth pairing settings and does not require VUNO to scan for nearby BLE devices. Disabling required permissions may prevent some features from working.

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, technically feasible portability and withdrawal of consent. Use “Delete account” in the application for VUNO Account deletion. For other requests, or if you cannot access the account, contact info@vunoapp.com.

You may complain to the Hellenic Data Protection Authority, 1-3 Kifisias Avenue, 115 23 Athens, www.dpa.gr, or the competent authority where you live or work.

A Fall Guard contact can withdraw consent through the original secure invitation link, by contacting us and identifying the invited number, or through STOP where supported. Withdrawal does not affect prior lawful processing. After valid withdrawal, future alerts stop and the full number is removed from the active VUNO system, subject to limited technical or mandatory records.

Children

VUNO is exclusively for adults aged 18 or over and is not designed for children. Contact us if you believe a minor’s data was submitted so it can be promptly reviewed and deleted.

Security

We apply reasonable technical and organisational security measures. No online service can guarantee absolute security.

Policy changes

We may update this Policy when features, providers or legal requirements change. The latest version will be available in the application and/or on the official VUNO website.

Contact

For privacy questions or requests, contact info@vunoapp.com.