Privacy Policy
Last updated: 15 June 2026
Guio is a marketplace for audio tours created by local guides. This Privacy Policy explains what data we collect when you use Guio, how we use it, who we share it with, and what rights you have over it. Plain language, no surprises.
Guio is operated by Basis Lda, a company registered in Portugal. If you have questions about anything here, write to [email protected].
1. What we collect
When you use Guio, we collect:
- Account data: email, display name, optional profile photo. Required to create an account.
- Authentication identifiers: if you sign in with Apple or Google, we receive an identifier (Apple sub, Google ID), name and email from the provider.
- Location: precise location only while a tour is playing, used to trigger audio at each stop. Location is processed on-device and is not stored on our servers.
- Audio content: if you are a guide, the recordings you upload are stored so they can be played back by buyers.
- Purchases: we receive a record of completed in-app purchases from Apple via RevenueCat (which tour, when, and a transaction identifier). We do not see your card number or billing address.
- Diagnostics: if you opt in (Settings → Privacy → Analytics), we collect crash reports and performance traces via Sentry. This is off by default.
- App preferences: language, theme, audio settings, etc. Stored locally on your device only.
2. How we use it
- To run your account and let you buy, save and play tours.
- To trigger audio at each stop while you walk a tour.
- To deliver transactional emails (purchase confirmation, recommendations after a tour, account-related notifications).
- To pay guides their share of sales.
- To detect and fix bugs (only if you opted into diagnostics).
We do not sell your data. We do not use it to train AI models. We do not show ads inside Guio.
3. Third parties we share data with
Guio relies on a small number of trusted services. Each has its own privacy policy:
- Supabase — hosts our database, authentication and file storage. Privacy policy
- RevenueCat — manages in-app subscriptions and purchases via Apple. Privacy policy
- Resend — delivers transactional emails on our behalf. Privacy policy
- Sentry — collects crash reports if you opt in. Privacy policy
- Apple — provides Sign in with Apple and handles in-app purchases. Privacy policy
- Google — provides Sign in with Google (only if you choose to use it). Privacy policy
4. Where your data lives
Our database and file storage run in the European Union. Some of our processors (Sentry, RevenueCat) may process data in the United States under standard contractual clauses approved by the European Commission.
5. How long we keep it
- Account data: until you delete your account.
- Purchase records: 7 years (required by Portuguese tax law).
- Crash reports: 90 days.
- Tour content uploaded by guides: as long as the guide keeps it published; archived for 30 days after deletion in case of recovery.
6. Your rights (GDPR)
If you live in the European Economic Area, the UK or Switzerland, you have the right to:
- Access a copy of the data we hold about you.
- Correct data that is wrong or out of date.
- Delete your account and associated data (Settings → Delete Account, or email us).
- Object to certain types of processing.
- Withdraw consent for analytics at any time (Settings → Privacy).
- Port your data to another service in a machine-readable format.
- Lodge a complaint with your local data protection authority. In Portugal that is the CNPD.
To exercise any of these rights, write to [email protected]. We respond within 30 days.
7. Local storage on your device
Guio stores preferences (language, theme, audio settings) locally on your device using your operating system's storage. These never leave your device. We do not use cookies because Guio is a native app, not a website.
8. Children
Guio is not directed at children under 13. Some tours are marked "Kid-friendly", meaning they are appropriate for families to listen to together, but the account holder must be at least 13 years old (or the local minimum age for data processing). If you believe a child has created an account, contact us and we will delete it.
9. Security
We use industry-standard encryption in transit (TLS 1.2+) and at rest. Authentication tokens are short-lived and refreshed securely. Database access is governed by row-level security so that one user can never read another user's data. Crash reports are scrubbed of identifying information before storage.
10. Changes to this policy
If we make material changes to this policy, we will notify you in the app and by email at least 14 days before the changes take effect. The current version is always available at getguio.com/privacy.
11. Contact
Questions, complaints, deletion requests: [email protected].