Legal

Privacy Policy

TourTour stores almost nothing about you on our servers. Apple handles identity and payments. Your progress and preferences live in your own private iCloud, and the routes you build stay on your device.

Last updated: July 2026 · TourTour, operated by an independent developer based in Vietnam

The short version

No accounts on our servers. We never receive your name, email, or Apple ID. Sign in with Apple gives us only an opaque, anonymous identifier.
Playback progress and preferences live in your own private iCloud (CloudKit), which only your Apple-ID-signed devices can read. The routes you build stay on your device and are never uploaded.
The only personal data on our servers are access logs (IP address), kept 90 days for security.
No cookies, no analytics, no ads, no third-party tracking, no selling of data on this website or in the app.

1. Who we are

TourTour is operated by an independent developer (a sole individual) based in Vietnam. "We", "us", and "our" refer to TourTour. Under GDPR we are the data controller for the data described below.

You can reach us about anything in this policy at [email protected]. Our postal address for written correspondence is on the Legal & Contact page.

2. The short version, with detail

TourTour is built so we cannot see your personal data. Identity comes from Sign in with Apple. Purchases run through StoreKit. Playback progress and preferences are written to your private iCloud using CloudKit, which only your Apple-ID-signed devices can read. The routes you build stay on your device and are never uploaded. Our servers store access logs for 90 days and nothing else about you.

This page explains exactly what we hold, why, where, for how long, and how to get rid of it.

3. Data we process & legal basis

Data Where it lives We can read it? Lawful basis (GDPR Art. 6)
Sign in with Apple opaque identifierYour device + your private iCloud (CloudKit)No, only your devicesContract performance, 6(1)(b)
Subscription & purchasesApple (StoreKit) + Apple-signed receipt on your deviceNoContract performance, 6(1)(b)
Playback progress and preferencesYour private iCloud (CloudKit) and on your deviceNo, only your devicesContract performance, 6(1)(b)
Routes you build or editYour device onlyNoContract performance, 6(1)(b)
Location (precise and continuous while navigating, including in the background, only when you allow it)iOS device memory; route ends go to Apple MapKitNo, never leaves your device except Apple routingContract performance, 6(1)(b) + iOS consent prompt
Downloaded city packs (audio, text, images) for offline playYour device onlyNoContract performance, 6(1)(b)
Listen history (in-app debug)Your device onlyNoContract performance, 6(1)(b)
Server access logs (IP, path, timestamp, response code)Cloudflare edgeYes, 90 days, then auto-deletedLegitimate interest, 6(1)(f)

4. How Sign in with Apple works

When you tap "Sign in with Apple" in TourTour, Apple authenticates you and hands the app a single string: an opaque user identifier. We do not request your name or email Apple withholds them and we have no way to ask later.

The app stores that identifier locally on your device, and mirrors it into your private iCloud so the same identity works on your iPad or a replacement iPhone. It never reaches our servers. To us it is meaningless, because there is no account on our side it is linked to.

You can revoke Sign in with Apple at any time at Settings → Apple ID → Sign-In & Security → Sign in with Apple. We never receive your email or your real Apple ID, so we have nothing to delete from a server.

5. CloudKit: your data in your iCloud

Playback progress and preferences are written to your private CloudKit database inside an iCloud container we own (iCloud.app.tourtour.TourTour). Apple's CloudKit is the storage layer. Your Apple-ID-signed devices are the only readers. The routes you build stay on your device and are never written to CloudKit.

To be fully honest: under GDPR we are still the data controller, because we designed the schema records like PlaybackProgress and UserPreferences exist because we defined them. Apple is our processor. But we have no servers that can read these records, and we cannot subpoena them out of Apple. Only you, signed into your Apple ID, can.

CloudKit records stay in your iCloud until you delete them. See section 12 for how to remove them.

6. Location, maps & navigation

Finding your city. When you open TourTour we ask iOS for your location so the app can surface the city closest to you. A coarse, one-off fix is all that needs. iOS shows its standard system permission prompt; if you decline, the app still works and you pick a city manually.

In-app navigation. TourTour now includes its own walking turn-by-turn navigation that guides you between the stops on a route. While you navigate it uses your precise location continuously, and it keeps doing so in the background, when the app is off screen or your phone is locked, so the spoken directions and the lock-screen Live Activity carry on as you walk. Navigation works only when Location Services is enabled for TourTour; with it off, the rest of the app still works but the turn-by-turn guidance does not.

Where your location goes. Your location is used on your device, in real time. TourTour itself holds it in memory, never writes it to disk, never transmits it to our servers, keeps no location history and builds no profile of where you have been. The one exception is routing. To draw a route, its start and end points are sent to Apple’s MapKit, governed by Apple’s privacy policy, the same as any app that uses Apple maps. Revoke or change access any time in iOS Settings → Privacy & Security → Location Services → TourTour.

Maps & offline navigation. Maps are drawn with Apple MapKit. To navigate offline, download the region in the Apple Maps app first; with that region downloaded, TourTour’s navigation works from it with no live connection needed.

Look Around (VR). Some landmarks offer Apple “Look Around” street-level imagery. It streams live from Apple Maps each time you open it, so it needs an internet connection and is the one part of a tour that does not work offline. That request goes to Apple under Apple’s privacy policy; the imagery is not stored on your device and never reaches our servers.

Offline. Once a city pack is downloaded, its narration audio, text and cover images live entirely on your device and play with no connection. Live map tiles and Look Around are the only exceptions, as noted above.

7. Purchases (StoreKit)

One-time purchases (city packs and the Pro Voices upgrade) are handled by Apple via StoreKit. There are no subscriptions. We do not see your card, billing address, name or email. Your device receives an Apple-signed receipt (a JWS token) proving entitlement, and a small Cloudflare Worker we operate checks the signature so we can confirm the purchase is valid without holding any payment data. When you download Pro Voices audio for a city you own, that same signature check runs and the audio files are stored on your device.

Refund requests go through Apple's standard process (Settings → Apple ID → Subscriptions or reportaproblem.apple.com).

8. Server access logs & security

Every API request the app makes catalogue lookups, city-pack downloads, entitlement checks creates a single line in our access log: timestamp, IP address, URL path, HTTP response code. We keep these for 90 days and then they are automatically deleted. Lawful basis: legitimate interest under GDPR Art. 6(1)(f), specifically security and abuse prevention.

We do not log request bodies. We do not link access logs to any user identity. We do not sell, share or enrich them.

9. Sub-processors & international transfers

The companies below process data on our behalf. Each handles only the slice listed.

Some of these providers process data outside the EU (for example certain Apple services). Those transfers rely on Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

10. Marketing website (this site)

This marketing website uses no cookies, no analytics SDK, no advertising pixels and no third-party trackers. We do not run Google Analytics, Facebook Pixel, Hotjar, Mixpanel, Segment or anything similar.

Standard server access logs apply (see section 8).

11. The iOS app: no analytics, no SDKs

The TourTour iOS app ships with no analytics SDK, no advertising framework, no crash-reporting SDK and no third-party data sharing. There is no Firebase, no Mixpanel, no Segment, no Amplitude, no Sentry. We have built the app so there is nothing to disclose here beyond what is in this policy.

No automated decision-making or profiling in the sense of GDPR Art. 22 takes place.

12. Account & data deletion

Inside the app, Settings → Delete Account wipes your TourTour data and signs you out. On your device it removes playback progress, listen history, downloaded packs, the routes you built, catalogue cache, app preferences, and the stored Sign in with Apple identifier. It also removes your private CloudKit records for you, namely the preferences record that carries your Apple identifier and every playback-progress record. That CloudKit cleanup is best effort, so if your device happens to be offline from iCloud in that moment it may not finish.

To be completely sure nothing lingers in your iCloud afterwards, you can also:

If anything here is unclear, email [email protected] and we will walk you through it.

Server access logs (which only contain your IP) age out automatically after 90 days. If you want them purged sooner, email us with the rough timeframe and we will clear matching entries.

Purchase history sits with Apple contact Apple Support if you want that erased.

13. Your GDPR rights

If you are in the EU, EEA, UK, or anywhere else that grants similar rights, you have the right to:

To exercise any of these, email [email protected]. We respond within 30 days. For data Apple holds (your Apple ID, purchase records, CloudKit content as the storage layer), Apple is the direct contact: apple.com/legal/privacy.

You also have the right to lodge a complaint with a supervisory authority. If you are in the EU/EEA or the UK, you can lodge it with your own national data-protection supervisory authority.

14. Children

TourTour is not directed at children under 16. We do not knowingly collect data from anyone under 16, and Sign in with Apple already enforces Apple's age-based account rules. If you believe a child has used the app and you want anything removed, email us and we will help.

15. Changes

When this policy changes, we update the "Last updated" date at the top. Material changes are surfaced in-app before they take effect.

Questions?

Reach out if anything here is unclear, or if you want to exercise any of your rights.

[email protected]