Privacy Policy
In short: SeekBone does not sell data, does not track you, and does not require an account. Your trips stay on your phone.
Key points
- No accounts. The app works without registration, e-mail, or password.
- No tracking or analytics. We do not measure your behaviour and use no advertising or analytics SDKs, and no third-party cookies.
- No ads, no data selling. The app contains no advertising and we never sell your data.
- Data stays on your device. Profile, trip plans, favourite places, checklists, journal, photos, documents, recorded routes, and health cards are stored locally on your phone (localStorage / IndexedDB), not on our servers.
Who processes the data
SeekBone is developed and operated by Pavel Večerek (SeekBone). This policy describes how the app handles information on your device and which data, if any, passes through our servers. Contact: photobone.software@gmail.com.
What data the app handles and where it lives
- Content you create (traveller profile, plans, favourite places, checklists, journal notes, photos, documents, health cards for crew members and the dog, recorded GPS route) — stored exclusively and locally on your device (localStorage / IndexedDB). It is not sent to our server.
- Location (GPS) — used only when you turn it on: to show your position on the map and for the trip route recording feature. Route coordinates are stored locally on your device. See “Background location” below.
- Camera — used only on your action: to take a journal photo, scan a QR code, or photograph a document. The app never uses the camera in the background.
- Voluntary reports — if you send us an improvement idea or a correction to a place, only the text of your message is sent. We do not attach your identity to it.
None of the above is stored permanently on our servers — except the voluntary text reports you choose to send.
Optional sync between your own devices (end-to-end encrypted)
If you want to share your plan and data across your own phones (e.g. a partner, a tablet), you can enable sync via a pairing code. It is off until you turn it on yourself.
- End-to-end encryption. The encryption key is derived from your pairing code right on the device (PBKDF2 → AES-GCM 256, Web Crypto). Data is encrypted before it leaves the phone.
- The server only sees an encrypted blob. Our server (Redis/Upstash via Vercel) stores only ciphertext under a non-identifying key (SHA-256 of the pairing code). The server never sees the pairing code or the content and cannot decrypt them.
- In your control. You can turn sync off anytime, and a disconnected device deletes its blob from the server. Abandoned data self-expires after 180 days.
AI server features
Some features (e.g. the voice guide, translation, reading fields from a document photo) run through our serverless /api/* endpoints, which call Google Gemini. Only the text or photo you yourself send for that task is transmitted.
- We do not store the content permanently. The request is processed once (request → AI → response). For abuse protection our server keeps only a technical request counter, not the content.
- Document OCR and health texts are NEVER logged or stored. A document photo and sensitive health fields are processed once and saved nowhere.
- The model operator (Google) processes data under its own policies only to fulfil the request.
Background location (route recording)
A core feature is trip route recording — it records the path you actually drove, even when the screen is off and the phone is in your pocket. This requires access to location in the background.
- You start recording yourself with the “Start route recording” button. It never starts without your action.
- While recording, a persistent notification “route recording running” is shown in the status bar.
- Coordinates are stored only on your device and are used to draw the route on the map and in your statistics. We do not transmit them anywhere (unless you enable encrypted sync above).
- You can stop recording anytime with “Stop recording”, and revoke location permission anytime in your phone settings.
Network communication
To work, the app loads map tiles, weather forecasts, place information, and photos from the internet. Map tiles go through our own proxy (Mapy.cz / OpenStreetMap), so neither the key nor your identity leaves the server. Other requests go to providers such as Open-Meteo (weather), Wikipedia, and Google (place photos / info). Those providers may process technical data (e.g. IP address) to deliver the service, under their own policies. The app does not send them your identity.
Coming soon
Connecting Google services (optional)
These features are still in preparation. They activate only if you connect them yourself — nothing runs without your explicit consent.
- Google Photos Picker — if you connect it. It serves only to let you pick specific photos from Google Photos into your journal. The app gains access only to the photos you select yourself (scope
photospicker.mediaitems.readonly), never to your whole library. Access tokens are held by our server; the client never sees them. You can disconnect anytime in the app settings or at myaccount.google.com/permissions.
- Google Calendar. Reminders and events are created via a pre-filled link to Google Calendar (a pre-filled form opens for you). The app does not gain access to your calendar or your account and changes nothing in it itself.
Principle: narrowest possible scope, no access to the whole library, tokens only on the server, disconnectable anytime.
Permissions and why the app requests them
| Permission | Purpose |
| Location (fine & coarse) | Show your position on the map and record the trip route. Only when you enable the feature. |
| Background location / foreground service | Continue route recording with the screen off, accompanied by a persistent status-bar notification. |
| Camera | Take a journal photo, scan QR codes, and photograph a document. Only on your action. |
| Notifications | Inform about downloaded updates and severe weather alerts (wind, storms). |
| Internet / network state | Load maps, weather, place info, and photos; download content updates. |
| Install packages | Open the installer for a downloaded app update (outside the store). |
| Wake / boot completed | Reliable operation of the route-recording service. |
Children
The app is not directed at children and does not knowingly collect any data from children. The content helps plan family trips, but all data stays on the parent's device.
Your rights: export and data deletion
Because data stays on your device, you have full control. You can export your data right in the app. You can delete it by uninstalling the app or clearing the app's data in your phone settings; if you used sync, a disconnected device deletes its encrypted blob from the server. For privacy questions, contact us below.
Changes to this policy
This policy may change over time. We will publish any changes here and update the effective date in the header of this page.