Footnotes Privacy Policy
Last updated: 26 August 2026
Footnotes is a location-based app that surfaces true stories tied to the place you're standing in, and lets you share the places you've stood with friends you've chosen. This policy explains what Footnotes collects, why, who else sees it, and the choices you have. It is written to match what the app actually does. Plain English first; the legal basis is noted where it matters.
The data controller. Kyra Wells, trading as Footnotes, an individual based in the United Kingdom, is the data controller. Contact: kyra@footnotes.world. Footnotes treats the UK GDPR and EU GDPR as the governing regime.
The one-line version. Footnotes keeps moments, not movements: the places you chose to stand, not a record of where you went.
What Footnotes collects
Your account
- Email address and password. Used to sign you in. Passwords are hashed by Footnotes' authentication provider; Footnotes never sees them.
- First name and username. Your username is public within the app: it appears on your posts and comments, and anyone who knows it can find your profile and send you a friend request.
- Profile picture, if you set one. Please read this carefully: profile pictures are stored in a public storage area. That means the image has a web address that will work for anyone who has it, including people who are not your friends and people without the app. Choose a picture you are comfortable being public. Everything else you upload, your footprint photos, is private (below).
- A friend code, generated for you, which you can share to let someone add you.
- Your preferences: notification frequency, the topics you're interested in, story depth, and whether you've opted in to heavier historical material (deaths, executions, disasters).
How findable you are. Your username is searchable. Any signed-in user who types the first few letters of it can see your first name, username, profile picture and friend code, and can send you a friend request. If you and they have friends in common, they can see which. If you want to be hard to find, pick an unguessable username.
Your location
With your permission, Footnotes uses your device location in two modes:
- While you're using the app, to show stories near you and to detect when you arrive at one.
- In the background ("Always"), if you allow it, so that Footnotes can quietly notify you when you're near a hidden story even when the app is closed.
- While you are walking to a story you chose, Footnotes reads your location continuously until you arrive or end the walk, so it can tell you when you get there even with the phone in your pocket. iOS shows its own location indicator for the whole of that walk. This stops the moment the walk ends and never runs otherwise.
How that location is handled, precisely:
- The work of deciding what's near you and watching the small geofences around nearby stories happens on your device.
- To fetch the set of stories around you, and to check you really are standing at a story before it unlocks, your coordinates are sent to Footnotes' server for that request. They are used to answer that request and are not written to your record. Footnotes does not build or keep a trail of your movements.
- Maps in the app are drawn by Apple Maps, built into your iPhone; that happens through Apple's own system frameworks on your device, not through any Footnotes account. Your coordinates are also sent to third parties for specific features you trigger: to OpenRouteService to work out a walking route when you start a hunt, and to Open-Meteo to check whether it is actually raining where you are standing (for the rainy-day badge). These providers receive a location, not your name or account.
- A list of stories you have simply walked past is kept only on your phone and is never uploaded. If you delete the app, it goes with it.
- One coordinate is stored. When you finish setting up, the app pins a "welcome" footnote at the spot you were standing in, so your first story is your own. That single location is kept with your account, and is deleted when you delete your account.
What you do in the app
- Stands (unlock events). When you arrive at a story's spot, Footnotes records which story and when. That is a discrete event, a story id and a timestamp, not a coordinate and not a trail. This is your history.
- Footprint photos. If you take a footprint at a story, the app takes a photo with the rear camera and then, after a countdown, automatically takes a second photo with the front (selfie) camera. The two are composed into a single image. Please be aware of who else is in the frame. Footprints are stored in a private area, in a folder that belongs to you, and are shown through short-lived links. They are not saved to your phone's photo library.
- Posts. If you share a stand, you create a post: the story and place, the place's coordinates, your caption if you write one, your footprint photo if you attach one, and the time. Posts are visible to your accepted friends only. There is no public feed and no public setting. Friends see your posts in their feed and as pins on a map of your profile, so a friend can see the map of places you have posted from. A friend can also share a post of yours out of the app using their phone's share sheet; the photo, your caption, the time and the place go with it. Post accordingly.
- Comments, cheers and reactions, including who made them and when. The author of a post can delete any comment on their own post.
- Activity and mentions. When someone cheers, comments on, replies to or @-mentions you, Footnotes stores a notification (who did it, what kind, when, and a short preview of their words) and shows it to you when you open the app.
- Friendships and blocks. Who you are friends with, and pending requests. Declining a request deletes it. Footnotes does not keep a record, and the person is not told. If you block someone, Footnotes stores that, and it stays until you undo it in Settings. Friends are added by friend code, QR code, invite link, or username search. The app may suggest people you might know based on friends you have in common. Footnotes never uploads or reads your phone's contacts.
- Saved spots and private notes. Your notes are yours alone. When you save someone's post, the person who wrote it can see that you saved it, though they are not notified.
- Reports. If you report a post, Footnotes stores which post, that you were the reporter, and the reason you wrote.
- Story feedback. If you flag a problem with a Footnotes story, Footnotes stores the text you send.
- App feedback. If you use the Feedback screen in Settings, Footnotes stores the text you send, together with the app version and platform (iOS or Android) so that what you saw can be reproduced.
Technical and diagnostic data
- Usage events: a small set of events (app opened, a nudge fired or held back, a nudge tapped, a hunt started, a hunt arrival, a welcome sent) tied to your account id, with the story, the time, and a short technical tag. Never a coordinate, and never anything you have typed.
- Crash and error reports: if the app hits a problem, a diagnostic report (device model, OS version, technical detail of the error). These are not tagged with your account.
- Notifications. The nudges that tell you a story is nearby are scheduled and fired on your own device. Footnotes holds no push token for you and sends you nothing from its servers. Notifications about other people's activity (cheers, comments, mentions) are made on Footnotes' servers and shown when you open the app. The daily "Today in London history" notification is scheduled on your device in the same way, at 9am local time, and can be turned off in Settings. Note that a nudge's text can name a place, so it may be visible on your lock screen to someone standing next to you.
- Authentication tokens, held in your device's secure keychain.
What Footnotes deliberately does not do
- Footnotes does not store a trail of where you go, only the discrete stories you chose to unlock.
- Footnotes does not upload the list of stories you merely walked past.
- Footnotes does not read or upload your contacts.
- Footnotes does not use advertising or cross-app tracking SDKs, and does not sell your data.
- Footnotes does not make anything you post public. Posts are friends-only, always.
Why Footnotes is allowed to use it (legal basis)
- Location and notifications: your consent, given through your phone's permission prompts and withdrawable at any time in your phone's settings.
- Heavier historical content: your consent, given at onboarding and changeable in Settings.
- Your account, your stands, footprints, posts, comments, friendships and preferences: to perform the service you asked for (contract).
- Reports, moderation, security, rate limiting and abuse prevention: Footnotes' legitimate interest in keeping the service safe, and its legal obligation where one applies.
- Usage events and crash reports: Footnotes' legitimate interest in knowing the app works and fixing it when it does not.
Who else processes your data
Footnotes uses a small number of providers, only as needed to run the service:
- Supabase: database, authentication and file storage. Holds your account, stands, posts, comments, friendships, preferences, footprint photos and profile picture.
- Sentry (servers in Germany): crash and error reports.
- Google: used server-side, by Footnotes, to place stories on the map when the story library is built. The app on your device does not talk to Google, and Google receives nothing about you or your location.
- OpenRouteService: when you start a hunt, Footnotes sends the start and destination coordinates to generate a walking route. No account data is sent.
- Open-Meteo: when a rainy-day badge is being checked, Footnotes sends a coordinate to ask whether it is raining there. No account data is sent.
- Apple: the App Store and TestFlight, and Apple Maps, which draws the maps in the app through your iPhone's own system frameworks.
Footnotes will update this policy before using your data in a materially new way, and will ask for your consent where the law requires it.
Where your data lives. Footnotes' providers may process data outside the UK. Where they do, transfers are covered by the safeguards those providers offer (UK/EU adequacy or standard contractual clauses).
How long Footnotes keeps it
Footnotes keeps your data for as long as your account exists. When you delete your account in the app (Settings โ Manage account โ Delete account), Footnotes deletes your profile, your stands, your posts and comments, your footprint photos and your profile picture. Backups are retained for a short period and then overwritten.
Two exceptions, stated plainly:
- If you deleted a post before deleting your account, that post is hidden from everyone immediately but its row is retained so that the conversation around it does not break mid-thread. It goes when your account goes.
- If you type a reason when you delete your account, that reason is kept without any link to you, so that Footnotes can learn from it. Please do not put anything identifying in that box.
Your rights
Under UK and EU GDPR you can: access your data, export it (in the app, Settings โ Manage account), correct it, delete it (in the app), object to or restrict processing, and withdraw consent (turn off location or notifications in your phone's settings).
To exercise any right, or to raise a concern, contact kyra@footnotes.world. Footnotes will respond within one month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.
Other people's data
Footnotes is social, so some of what you create is about other people. When you take a footprint in public, other people may be in the shot. When you comment, your words sit under someone else's post. Please use the app kindly and lawfully: do not post photos of identifiable people who would not want it, and do not post anything that reveals where a specific person lives or works. If something about you appears in Footnotes and should not, tell Footnotes at kyra@footnotes.world and it will be dealt with.
Age
Footnotes is for people aged 16 and over. It is not designed for children and Footnotes does not knowingly collect data from anyone under 16. If you believe a child has an account, email kyra@footnotes.world and Footnotes will remove it.
Security
Data is stored with Footnotes' providers under industry-standard protections. Access to your stands, posts and comments is enforced at the database level: only you and the friends you have accepted can retrieve them. Footprint photos are held in a private area and served through short-lived links. Profile pictures, as noted above, are the one deliberate exception and are public. No system is perfectly secure, but Footnotes takes reasonable measures and will tell you promptly if something goes wrong that affects you.
Changes
Footnotes will update this page and the date at the top when this policy changes, and surface significant changes in the app.
Contact
Kyra Wells, trading as Footnotes: kyra@footnotes.world