Privacy Policy

Effective date: 21 June 2026  ·  Last updated: 25 July 2026

Short version: NearWise uses your location only to find nearby places. We do not sell your data. We do not share it with advertisers. You can delete your account at any time.

1. Who we are

NearWise is a nearby services discovery application operated as an individual project. For any privacy-related questions, contact us at: [email protected]

As a service accessible to users in the European Economic Area (EEA), this policy complies with the General Data Protection Regulation (GDPR) and Norway's Personal Data Act (Personopplysningsloven).

2. What data we collect and why

DataWhy we collect itWhere it's storedHow long
Location (GPS coordinates)To search for nearby placesSent in the request body (POST) to our server — not in the URL, so coordinates do not appear in server access logs or browser history. Not persisted.Not stored — discarded after each search
Device compass heading (walking direction)When walking mode is active, to identify which nearby places are in your direction of travelComputed on your device from the built-in compass sensor (DeviceOrientation API). The computed bearing (0–360°) is included in place-search requests only while walking mode is on — it is never stored on our servers.Not stored — used only for the duration of a single search request
Search query text (words you type to find places, e.g. "pharmacy", "vegan food", "bike shop")To find places matching what you're looking for near youSent to our server and passed on to the places provider (OpenStreetMap and/or Google Places) to run the search. Briefly cached on our server keyed by map area (geohash) — not linked to your account or identity.Not stored long-term — transient area cache only (up to 20 minutes)
Full nameTo personalise your account displayOur backend server (EU, Germany)Until you delete your account
Email addressTo create and identify your account, and to send transactional emails (password reset)Our backend server (EU, Germany)Until you delete your account
PasswordTo authenticate youStored as a bcrypt hash only — never in plain textUntil you delete your account
Password reset tokenTo verify a password reset request sent by youOur backend server — one-time use only. The token is also removed from your browser URL bar immediately after it is read, so it does not persist in browser history.1 hour or until used, whichever comes first
Guest session tokenTo allow anonymous use without creating an accountYour device only (browser localStorage) — no personal data associated7 days from issue (the app shows how many days remain in your profile panel), or until you clear browser data or sign in to a named account — whichever comes first
Saved placesTo build your personal shortlist and sync it across your devicesYour device (localStorage) for guests; our backend server for logged-in usersUntil you remove them, clear browser data (guests), or delete your account (logged-in users)
Emergency contacts (names and phone numbers you add)To let you quickly call a personal emergency contact from the SOS screenOnly available to logged-in accounts. Stored on our backend server (EU, Germany) and cached on your device so they sync across your devices. Guests cannot add them.Until you remove them or delete your account
Ranking preferences and settings (mode, lifestyle, priority preset, radius, language, dark mode, kid mode)To personalise search ranking and appearance across sessionsYour device (localStorage) for guests; our backend server for logged-in usersUntil you reset preferences, clear browser data (guests), or delete your account (logged-in users)
Security events (login attempts, password resets)To detect and respond to suspicious activity such as brute-force attacks or account takeoversOur backend server — anonymised event log (no content recorded)30 days
Push notification subscriptionTo deliver closing-soon alerts for your saved placesOur backend server (encrypted endpoint URL and push keys — no personal data)Until you disable notifications in Settings, or delete your account
Notification permissionTo alert you when saved places are closing soonYour device onlyUntil you revoke permission in your browser or device settings

3. Legal basis for processing (GDPR)

4. Third parties we use

ServicePurposeData sharedLocation
Neon.techPostgreSQL database — stores user accountsFull name, email address, hashed password, account metadataFrankfurt, Germany (EU — AWS eu-central-1)
ResendTransactional email — delivers password reset emailsEmail address (only when a reset is requested)United States (processed under Standard Contractual Clauses)
Render.comBackend hostingAll server traffic passes through RenderFrankfurt, Germany (EU)
CloudflareFrontend CDNIP address, browser info (standard CDN logs)Global edge network
OpenStreetMapPlaces data, address search, and free-text place searchApproximate location and your typed search queryEU servers
Google Places API (optional)Enhanced places data with photos and ratings, and free-text place searchApproximate location and your typed search query (server-side only)Google global infrastructure

We do not sell your data to any third party. We do not use advertising networks.

5. International data transfers

Our backend server is located in Frankfurt, Germany (European Union). If you access NearWise from outside the EU, your data is transferred to the EU for processing. This transfer is covered by standard contractual clauses and the GDPR adequacy framework.

6. Your rights

Under GDPR you have the right to:

The "Export my data" and "Delete account" tools in the Account panel let you exercise your Access, Portability, and Erasure rights instantly. For anything else, email us at [email protected] and we will respond within 30 days.

7. How to delete your account

In-app (instant): Open the Account panel → scroll to the bottom → tap "Delete account". You will be asked to confirm with your password. Your account and all associated server-side data are deleted immediately.

By email: If you cannot access your account, email [email protected] with the subject line "Delete my account" and include the email address you registered with. We will permanently delete your account within 7 days.

Locally stored data (saved places and preferences) can be cleared at any time by clearing your browser's site data for nearwise.madhumagiclabs.com.

8. Children

NearWise is not intended for users under the age of 15. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it immediately.

9. Cookies and local storage

NearWise does not use tracking cookies. We use browser localStorage to store your preferences, saved places, and session token (registered or guest) on your own device. For logged-in users, saved places and ranking preferences are additionally synced to our backend so you can access them across devices. This sync only happens when you are signed in and perform an action that requires it.

10. Security

We use HTTPS for all data in transit. Passwords are hashed with bcrypt (cost factor 12) and are never stored or transmitted in plain text. Our API uses rate limiting and brute-force protection on all authentication endpoints.

Password reset tokens are delivered by email and are valid for one hour. When you open the reset link, the token is immediately removed from your browser's URL bar (using history.replaceState) so it does not appear in your browser history or server access logs.

GPS coordinates are sent in the request body (not the URL) so they do not appear in server access logs or browser history. Compass heading data used for walking direction is processed on-device and transmitted only in search request bodies — it is never logged or stored.

11. Data accuracy and estimates

Some information displayed by NearWise is estimated or sourced from third parties and may not reflect real-time conditions:

12. Changes to this policy

If we make significant changes, we will update the effective date at the top of this page. Continued use of NearWise after changes are posted constitutes acceptance of the updated policy.

13. Contact and complaints

For privacy questions: [email protected]

If you are in Norway and believe we have not handled your data correctly, you have the right to lodge a complaint with the Norwegian Data Protection Authority:

← Back to NearWise