Part 1 Privacy Policy draft

English review edition · 2 October 2026

Sections in this draft
  1. 1 Who we are and what this policy covers
  2. 2 Information we collect and where it comes from
  3. 3 Location and social visibility
  4. 4 Advertising and device storage
  5. 5 Sherpa Assistant and AI data sharing
  6. 6 Why we use data and our legal grounds
  7. 7 Who receives personal data
  8. 8 International transfers
  9. 9 How long we keep information
  10. 10 Your choices and privacy rights
  11. 11 Security and adults only
  12. 12 Changes and contact

Effective date: [INSERT DATE AFTER APPROVAL]

1 Who we are and what this policy covers

Working draft · facts or wording marked below still need confirmation

Bar Sherpa helps adults discover nightlife venues, plan expeditions, keep a record of visits and passport stamps, connect with friends, and use optional AI guidance. This policy explains how personal data is handled when you use the Bar Sherpa app, related web services and support channels.

The controller responsible for Bar Sherpa is Bar Sherpa LLC, at [INSERT POSTAL ADDRESS AND COUNTRY]. Contact us at BarSherpa@proton.me.

[IF REQUIRED: Our representative in the European Economic Area is NAME, ADDRESS AND EMAIL. Our UK representative is NAME, ADDRESS AND EMAIL.] [IF APPOINTED: Our data protection officer can be contacted at CONTACT DETAILS.]

Accepting our Terms and Conditions is not consent to optional location, advertising, AI data sharing or other optional processing. Those choices are explained separately when relevant.

2 Information we collect and where it comes from

Working draft · facts or wording marked below still need confirmation

Account and device records. We process an account identifier, installation or device identifier, authentication and session records, and the information needed to keep your account connected to the app. The web service also supports a device-based account with an identifier and authentication token stored in the browser; not every account uses Apple. Sign in with Apple provides an Apple account identifier and authentication information. Apple may provide an email address, including a relay address, and other information permitted by your choices. [CONFIRM WHAT TOKEN CLAIMS ARE RECEIVED, RETAINED OR LOGGED.]

Profile and social information. This includes your chosen climber name, avatar or profile photo, guild, language, friends and crew relationships, invitations, sharing choices, presence preferences, expedition membership, and content you submit. It may also include reports, blocking actions and moderation decisions.

Age eligibility. On the native onboarding flow, a date of birth is used locally to assess age, while an age-confirmed flag and selected country are saved on the device. The reviewed native flow does not send that date of birth to our server. The web entry flow instead uses an age self-attestation. [VERIFY BOTH RELEASED FLOWS AND COUNTRY REQUIREMENTS.]

Nightlife activity. This includes places you search for or save, favorites, routes and expeditions, check-ins, visit times, ratings or reviews, passport photos, stamps, XP and badges, and activity used for features such as leaderboards. The app may keep some information locally and synchronize other information with your account.

Location. With the relevant permissions and choices, the app uses device location for nearby discovery, distance calculations, check-in verification, Smart Check-In and directions or Ride Home links. Location-related records can include coordinates, accuracy, time, a venue identifier and presence at a venue. Section 3 explains the distinction between background suggestions and confirmed check-ins.

AI requests. If you choose the Sherpa Assistant, we process your messages and the context assembled for your request. Depending on the feature and plan, this can include recent conversation, city or search area, time context, route or destination labels, candidate venues and distances, and preference signals from favorites, visits and expeditions. See section 5.

Purchases and technical information. We process product and purchase identifiers, entitlement status, purchase and expiry times and information needed to verify or restore access. Apple handles payment information for Apple purchases. We also process app and operating-system information, service and security logs, and account-linked product events such as opening a feature, viewing an offer, selecting a plan or completing a purchase, including event name, source, plan, entitlement/test flags and timestamp. First-party usage counters are also processed. Advertising partners may process additional data as explained in section 4. [CONFIRM IP, LOG, DIAGNOSTIC AND ANALYTICS FIELDS IN PRODUCTION.]

Support and information from others. We receive information you send us for support or privacy requests. Other users may identify you in invitations, relationships, shared content or reports. We also receive authentication, purchase, venue and service information from the providers described below. Please do not submit someone else’s private information unless you have an appropriate reason and permission where required.

Optional contacts and voice. If you choose the contacts invitation feature and allow access, the native app reads contact names and available phone numbers or email addresses locally to help you select a recipient. The reviewed flow opens your chosen SMS or email composer rather than uploading your address book to Bar Sherpa. Optional voice input uses device or browser speech-recognition services; those services may process audio remotely. Transcripts become search text or message drafts, and interim search text can be sent for autocomplete. [CONFIRM SPEECH PROVIDERS AND THEIR PROCESSING BEFORE RELEASE.]

3 Location and social visibility

Working draft · facts or wording marked below still need confirmation

Nearby discovery and confirmed check-ins. Location helps find nearby venues and assess whether a check-in is plausible. A confirmed check-in can be stored against your account with the venue, time and location evidence. Turning location permission off stops future location access through that permission; it does not automatically erase earlier check-ins or other retained records.

Smart Check-In. On supported iOS devices, this optional feature uses background geofencing when enabled and when you grant the required background location permission. It can detect arrival or dwell near a venue while the app is not on screen and prepare a suggestion or local notification. Local evidence and pending suggestions can include location, accuracy and timestamps. A suggestion is not itself a silently published server check-in; you decide whether to confirm it. [CONFIRM THE RELEASED FLOW AND SEPARATE OPT-IN BEFORE PUBLICATION.]

You can turn off Smart Check-In in the app and change location permissions in your device settings. Disabling the feature is intended to stop background monitoring and remove its local pending evidence. [VERIFY THIS ON THE RELEASE BUILD, INCLUDING SIGN-OUT AND ACCOUNT DELETION.] Where the app provides city search or manual selection, you can use that without granting precise location; features that need location evidence may be unavailable.

Sharing with people. Visibility differs by feature. The following describes the reviewed implementation. [VERIFY THE RELEASED DEFAULTS; CHANGE THE IMPLEMENTATION WHERE NEEDED BEFORE PUBLISHING THIS POLICY.]

Blocking limits supported signed-in interactions and social views; it does not guarantee that a person cannot view publicly accessible content outside those controls. Removing a post from view or unsharing it may leave underlying text, reaction or moderation records. Removing a comment currently marks it removed while retaining its body and mention records. Retention and deletion requests are addressed in sections 9 and 10.

Do not include a home address or another person’s private information in a profile, photo, route name or public post. Someone who can view shared content may save or forward it. We cannot withdraw copies that another person has already saved, but this does not remove our obligations to handle deletion requests for data we control.

4 Advertising and device storage

Working draft · facts or wording marked below still need confirmation

The Free experience includes advertising supplied through Google AdMob. The reviewed native app requests non-personalized ads. Depending on the actual configuration, your region and your choices, Google and any disclosed advertising partners may process device or advertising identifiers, IP address, app and device information, ad impressions and interactions, approximate location derived from technical data, and privacy-choice signals to deliver, measure and protect advertising. [VERIFY THE COMPLETE SDK AND MEDIATION PARTNER DATA INVENTORY; DO NOT ASSUME THIS LIST IS EXHAUSTIVE.]

Where consent is required, optional advertising storage, access or processing must wait for your choice. You can review or change advertising choices through the app’s privacy-options control where available and your device settings. An operating-system tracking permission is separate from advertising consent required by privacy law. Declining optional advertising consent does not mean you must accept it to use core features. [CONFIRM THE ACTUAL NO-CONSENT EXPERIENCE, CONTROL LABEL AND WITHDRAWAL BEHAVIOR.]

Non-personalized advertising can still process personal data or use device storage. We do not treat that label as a blanket exemption from consent requirements. [INSERT VERIFIED WHETHER PERSONALIZED ADS, APPLE TRACKING, IDFA OR MEDIATION ARE ENABLED. DO NOT PUBLISH A “NO TRACKING”, “NO SALE” OR “NO SHARING” CLAIM WITHOUT A JURISDICTION-SPECIFIC CHECK.]

The app and website use local storage and similar technologies for functions such as sessions, preferences and caches. Optional measurement or advertising technologies are subject to the choices and legal requirements that apply to them. [LIST ANY ADDITIONAL WEB COOKIES, ANALYTICS OR EMBEDDED SERVICES.]

5 Sherpa Assistant and AI data sharing

Working draft · facts or wording marked below still need confirmation

Sherpa Assistant uses Google Gemini. When you enable and use it, Bar Sherpa sends the request and relevant context described in section 2 through its server to Google to generate an answer. Some context is generated automatically by the app, so the information sent can be more than the words you type. In the web flow, selected-location context can include raw latitude and longitude. Native context includes location-related labels and venue distances. A direct Bar Sherpa account identifier is not intentionally added to the reviewed AI prompt; your message or context can still identify you.

Please do not enter passwords, payment-card details, identity documents, health information or other sensitive personal data, or private information about someone else. AI output can be inaccurate; our Terms explain important limits.

In the native app, you can withdraw the AI data-sharing permission in settings. [CONFIRM EQUIVALENT WEB CONSENT AND WITHDRAWAL.] That stops future AI requests controlled by that permission. It does not itself delete earlier requests already received by a provider. For deletion or access requests, contact us. [CONFIRM THE EXACT CONTROL AND ALL-DEVICE CONSENT RECORDS.]

The reviewed chat components keep the current conversation in session memory rather than a demonstrated permanent chat database. This does not mean providers, infrastructure or logs retain nothing. We also use Gemini to generate venue descriptions and extract information from menu source material, separately from your chat.

[INSERT VERIFIED GEMINI SERVICE TIER, LOGGING/FEEDBACK SETTINGS, PROVIDER USES, HUMAN ACCESS, TRAINING POSITION AND RETENTION. DO NOT PROMISE ZERO RETENTION OR NO MODEL TRAINING BASED ON SOURCE CODE ALONE.] Provider information is available in the Gemini API terms at https://ai.google.dev/gemini-api/terms and Google’s Privacy Policy at https://policies.google.com/privacy.

6 Why we use data and our legal grounds

Working draft · facts or wording marked below still need confirmation

Where the GDPR or UK GDPR applies, we need a legal ground for each purpose. The following is the proposed purpose-by-purpose description. [CONFIRM EACH BASIS AGAINST THE RELEASED SERVICE AND DOCUMENT ANY LEGITIMATE-INTERESTS ASSESSMENT BEFORE PUBLICATION.]

Purpose and data

Legal ground and choice

Provide accounts, requested searches, saved content, expeditions and purchase entitlements using the records necessary for those features

Performance of our contract with you, only where the particular processing is objectively necessary to provide the requested feature.

Access precise location and provide optional background Smart Check-In; optional sharing of live venue presence

Consent for the defined optional location or presence purpose. Device permissions are used in addition to any in-app explanation and choice needed for valid consent.

Send requests and relevant context to Gemini for optional AI guidance

Consent to optional AI data sharing, separate from accepting the Terms. Withdrawal stops future permission-controlled requests.

Personalize advertising and use advertising or optional measurement technologies where consent is required

Consent for the identified purposes and partners. Essential ad security or other separate purposes require their own valid assessment and disclosure.

Optional product analytics beyond necessary service delivery

Consent where device-storage/access rules require it. [CONFIRM whether consent is the selected basis for all such analytics; do not treat conversion analytics as contractually necessary.]

Protect accounts, prevent abuse and fraud, investigate reports and maintain service security

Our legitimate interests in protecting users and the service, after balancing those interests against your rights. Legal obligation only where a specific applicable law requires the processing.

Reply to support requests, enforce rights or handle legal claims

Contract where necessary to resolve a service request; otherwise legitimate interests in support and establishing, exercising or defending legal claims.

Comply with tax, accounting, consumer-law or privacy obligations that apply to us

Compliance with the particular legal obligation. [CONFIRM applicable obligations and records.]

You do not have to provide optional profile content, photos, precise location, AI requests or optional advertising consent. Declining may make the related optional feature unavailable. Information essential to create a session, deliver a request or verify a purchase is needed for that feature; without it we may be unable to provide the feature.

Recommendations, friend suggestions and rankings can use your choices and activity, including shared venues, mutual friends or guild, to suggest relevant content or connections. Automated content checks can reject images, record a moderation strike and, for repeated or severe results, restrict posting, suspend an account or cancel shared expeditions. [ASSESS WHETHER ANY DECISION HAS LEGAL OR SIMILARLY SIGNIFICANT EFFECTS UNDER ARTICLE 22; EXPLAIN THE RELEVANT LOGIC, CONSEQUENCES AND HUMAN-REVIEW RIGHTS WHERE REQUIRED. CONFIRM A WORKING WAY TO CONTEST A DECISION.]

7 Who receives personal data

Working draft · facts or wording marked below still need confirmation

We share data only for the purposes described in this policy and on an appropriate legal basis. Recipients include:

A provider may act as our processor for some purposes and as an independent controller for others. [CONFIRM THESE ROLES, CONTRACTS AND ANY JOINT-CONTROLLER ARRANGEMENT.] A provider’s own privacy policy does not replace our responsibility for processing that we control.

8 International transfers

Working draft · facts or wording marked below still need confirmation

[COMPLETE BEFORE PUBLICATION: Identify the countries where Bar Sherpa and its providers process personal data, including remote support access. For each restricted transfer from the EEA or UK, identify the actual applicable adequacy decision or contractual safeguards and any necessary supplementary measures. State how a user can obtain a copy or meaningful information about those safeguards, with justified redactions.]

You can ask about international processing and applicable safeguards at BarSherpa@proton.me. We do not treat accepting this policy as blanket consent to international transfers.

9 How long we keep information

Working draft · facts or wording marked below still need confirmation

We keep personal data only for as long as needed for the stated purpose, subject to applicable legal requirements. Different records need different periods; an active account does not justify keeping every location or technical record indefinitely. [REPLACE THE FIELDS BELOW WITH THE APPROVED, IMPLEMENTED SCHEDULE.]

Record

Retention rule to finalize

Account, profile, saved venues and user content

While needed to provide the account and chosen features; deletion handling: [TIME AND EXCEPTIONS]. Inactive accounts: [RULE].

Precise check-in evidence and confirmed visit history

Verification coordinates/accuracy: [SHORT JUSTIFIED PERIOD OR MINIMIZATION RULE]. User-visible venue history/stamps: [RULE].

Local Smart Check-In candidates and background evidence

[EXPIRY]. Removal on disabling, sign-out and deletion: [VERIFIED BEHAVIOR].

AI prompts, responses and context

Current chat session: held in memory in reviewed components. Logs/other stored context: [RULE]. Gemini and optional provider logs: [VERIFIED PERIODS OR CRITERIA].

Analytics, security, moderation and support records

[SEPARATE PERIODS OR MEANINGFUL CRITERIA FOR EACH PURPOSE].

Purchase, tax and legal records

[APPLICABLE RECORDS, LEGAL REQUIREMENTS AND PERIODS].

Backups and deleted records

Production deletion: [TIME]. Backup expiry: [TIME]. Restores must reapply deletions; restricted legal holds: [PROCESS].

Data kept for a legal obligation or a specific dispute is limited to what is necessary for that purpose. Data is deleted or made genuinely anonymous when no longer needed. Removing the app does not automatically delete server records or cancel an Apple subscription. Changing a permission does not by itself delete earlier data.

10 Your choices and privacy rights

Working draft · facts or wording marked below still need confirmation

Use the app’s available profile, sharing, privacy and account controls, or email BarSherpa@proton.me. You may request access to your personal data, correction, deletion, restriction of processing and, where applicable, a portable copy of data you provided that we process by automated means on consent or contract grounds. You may also object to processing based on legitimate interests. You can object to direct marketing at any time, including related profiling.

Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. Withdrawal should be as easy as giving consent. Use the relevant control or contact us if you cannot find it. Some rights have legal exceptions; if we cannot fully grant a request, we will explain why and how you can challenge the decision.

In the native app, you can request account deletion in Settings; an Apple-linked account may require Apple reauthentication. The server deletion flow removes the account and associated records, but some reports or mentions, provider records, backups and local preferences may need separate handling. [CONFIRM COMPLETE SCOPE AND LEGAL EXCEPTIONS. VERIFY A WORKING DELETION ROUTE FOR WEB DEVICE-BASED ACCOUNTS.] You can also contact us for account deletion, a data copy or help with information not covered by the in-app control. We may ask for proportionate information to verify your identity; do not send a government ID or other sensitive document unless we explain why it is necessary and provide a suitable secure route.

For requests governed by the GDPR, we respond without undue delay and normally within one month. If the law allows extra time because of complexity or the number of requests, we will explain that within the first month. Requests are normally free. We will only charge or refuse where the law permits it and will explain the reason.

You can complain to a supervisory authority, including in the EEA country where you habitually live or work or where you believe an infringement occurred. Find EEA authorities at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, contact the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/. You do not have to contact us first.

11 Security and adults only

Working draft · facts or wording marked below still need confirmation

We are responsible for using technical and organizational measures appropriate to the risks of processing your information. [INSERT ONLY VERIFIED HIGH-LEVEL SAFEGUARDS, WITHOUT SECURITY-SECRETS OR ABSOLUTE GUARANTEES.] No service can eliminate every security risk. If you suspect unauthorized access, contact us promptly. We will make notifications required by applicable data-breach law.

Bar Sherpa is for people who are at least 18 and meet the higher legal drinking-age or service-access requirement that applies where they use it, including 21 in the United States. It is not intended for children. If you believe an ineligible person has provided personal data, contact us so we can investigate and take appropriate action. [VERIFY AGE AND COUNTRY CONTROLS AGAINST THIS RULE.]

12 Changes and contact

We will update this policy when our processing changes and show its effective date. For material changes we will provide appropriate notice, and seek a new choice where the law requires one. A policy update does not retroactively authorize a new use of your data. Privacy requests and questions: BarSherpa@proton.me.