Privacy Notice
Last updated: 8/27/2026
1. Introduction and controller
This Privacy Notice explains how Scenik ("we", "us", "our"), the operator of the Scenik website at goscenik.com and the Scenik mobile apps on iOS and Android (the "Service"), collects, uses, discloses, and protects personal data about you. Scenik is the data controller for the personal data described in this notice. This notice reflects our obligations under the UK GDPR, the EU GDPR, the California Consumer Privacy Act (CCPA/CPRA), and similar privacy laws.
If you do not agree with this notice, please do not use the Service.
2. Summary at a glance
- We collect account, route, device, and (during navigation only) location data to run the Service.
- We do not sell your personal data and do not use advertising cookies or targeted advertising.
- Precise GPS location is only used during active navigation and is not stored as a location history.
- Payments are handled by Paddle (web), Apple (iOS), or Google (Android). We never see or store your full card number.
- You can access, correct, export, or delete your data, or delete your entire account, from Settings at any time.
3. Data we collect
3.1 Account information
When you create an account we collect: your email address, display name (optional), bio (optional), avatar image (optional), unit and language preferences, authentication provider identifiers (Google or Apple sub ID) where you sign in with a social provider, the timestamp of your account creation, the timestamp at which you accepted our Terms, and (for anonymous/guest accounts) a device-generated identifier. We use this data to identify you, secure your account, personalise your experience, and enforce our Terms.
3.2 Route data
When you plan or save routes we collect: origin and destination addresses (as text and as geocoded latitude/longitude), waypoints, mood and theme selections, generated route data (polylines, distance, duration, scenic score), route titles you set, the visibility state (private or public), saved-route metadata, comments and ratings you leave on other users' public routes, likes, and road reports you submit. If you make a route public, the route title, polyline, origin/destination area, and comments become visible to other users of the Service.
3.3 Location tracking (navigation only)
We access your device's precise GPS position only while turn-by-turn navigation is active in the foreground. Location data is processed transiently, in-session, to compute directions, snap you to the route, estimate your speed and ETA, and trigger voice guidance. Precise location fixes are not written to our database and are not built into a location history that we can browse or share. Location access requires an OS-level permission that you grant and can revoke at any time in your device settings. If you deny location access, turn-by-turn navigation will not function, but the rest of the app remains usable.
3.4 Payment processing
We store subscription state (plan identifier, status, current period end, cancellation flag, environment such as test/live), the payment processor's customer and subscription identifiers, and the timestamp of purchase events. We do not collect or store full card numbers, CVCs, or any payment instrument details. Card processing is performed entirely by Paddle (on the web), Apple (in the iOS app), or Google (in the Android app). See section 6 for their roles.
3.5 Product analytics (opt-in)
If you consent, we use PostHog to collect product analytics: page views, feature usage, funnel events (e.g. sign-up completed, route generated, subscription started), errors, and coarse device/browser information. Analytics events are associated with an internal user identifier where you are signed in, or an anonymous device identifier otherwise. You can withdraw consent at any time from Settings → Privacy, which stops future analytics collection on this device. We do not use analytics for advertising or profiling.
3.6 Technical and diagnostic data
We collect data required to operate a modern web/mobile service securely: IP address (used transiently for request routing, rate limiting, abuse prevention, and coarse locale detection), browser and OS user-agent, device type and model, app version, network type, screen size, timezone, referrer for web requests, error stack traces, and crash reports. We use this data for security, fraud prevention, debugging, and improving reliability.
3.7 Support communications
If you contact us for support, we process the content of your messages, your contact details, and any information you choose to share, in order to respond and keep a record of the issue.
3.8 Data we do not collect
We do not collect biometric data, health data, contact lists, calendar entries, photos other than the avatar you choose to upload, microphone audio, or advertising identifiers.
4. How we use your data (purposes)
- Provide the Service: create and manage your account, authenticate you, generate scenic routes, provide navigation and voice guidance, save your routes, and enable community features.
- Personalise: remember your preferences (units, language, saved locations, consent choices).
- Payments and subscriptions: confirm entitlements, apply the correct plan, and reconcile with the payment processor.
- Communicate: respond to support, send essential transactional notices (e.g. account changes, billing, security alerts).
- Improve: understand feature usage in aggregate, diagnose errors, and prioritise improvements.
- Security and fraud prevention: detect abuse, rate-limit requests, prevent unauthorised access, and investigate suspicious activity.
- Comply with law: respond to lawful requests, meet tax, accounting, and record-keeping obligations, and enforce our Terms.
5. Legal bases (UK/EU GDPR)
- Performance of a contract: account creation, delivering routes, navigation, payments, and support.
- Legitimate interests: security, fraud prevention, service reliability, service improvement, and defending legal claims — balanced against your rights and freedoms.
- Consent: optional product analytics and any non-essential cookies. You may withdraw consent at any time without affecting past processing.
- Legal obligation: tax records, responding to lawful requests, and meeting statutory retention duties.
6. Sharing and processors
We share personal data only with providers that help us run the Service, under written contracts that require appropriate security and confidentiality. We do not sell your personal data and do not share it for cross-context behavioural advertising.
- Hosting, database, authentication, and storage: our managed cloud infrastructure provider (acting as processor).
- Maps, directions, geocoding, places autocomplete: Google Maps Platform.
- AI features (route themes, waypoint facts, guidance copy): our AI model gateway and underlying model providers. Prompts sent to these providers may include the route's origin/destination area, mood, and theme; they do not include your name, email, or precise real-time location.
- Payments (web): Paddle, acting as Merchant of Record for web subscriptions.
- Payments (iOS): Apple, via App Store and StoreKit.
- Payments (Android): Google, via Google Play Billing.
- Subscription management (mobile): RevenueCat, which receives store receipts to determine your entitlement.
- Product analytics (opt-in): PostHog.
- Authorities and legal: we may disclose data where required by law, to comply with legal process, to enforce our Terms, or to protect rights, property, or safety.
- Corporate transactions: in a merger, acquisition, or asset sale, personal data may be transferred subject to this notice or an equivalent one.
7. International transfers
Some processors are located outside the UK/EEA (including the United States). Where personal data is transferred outside your jurisdiction, we rely on lawful transfer mechanisms such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, and applicable adequacy decisions. You may request more information about our transfer safeguards using the contact details below.
8. Retention
We keep personal data only as long as necessary for the purposes described:
- Account and profile: for as long as your account is active.
- Routes, ratings, comments: until you delete them or your account.
- Location fixes during navigation: processed transiently in-session and not stored.
- Support messages: up to 24 months after your query is resolved.
- Payment and tax records: retained by us and/or Paddle/Apple/Google for the period required by applicable tax and accounting law (typically 6–10 years).
- Security and abuse logs: up to 12 months.
- Analytics events (if you consented): up to 24 months, then aggregated or deleted.
When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where retention is required by law (for example, tax records) or where content has already been shared publicly (for example, comments on other users' public routes, which may be retained in an anonymised form).
9. Your rights
Subject to applicable law, you have the right to:
- request access to the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request deletion of your data ("right to be forgotten");
- request restriction or object to certain processing;
- request portability of the data you have provided to us;
- withdraw consent at any time, without affecting past processing;
- lodge a complaint with your local data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU/EEA, your national supervisory authority.
You can exercise most of these rights directly in Settings (edit profile, export data, delete account). Otherwise, contact us using the details below and we will respond within one month (extendable by two months for complex requests).
10. California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion or correction, to opt out of any "sale" or "sharing" (we do neither), and to be free from discrimination for exercising these rights. We disclose the categories of personal information we collect and our purposes in sections 3 and 4. To exercise your rights, use Settings or contact us.
11. Cookies and local storage
We use only strictly-necessary cookies and local storage: authentication tokens, session state, remembered preferences (units, language, consent choices), and remembered location-permission acknowledgement. We do not use advertising, targeting, or cross-site tracking cookies. If you opt in to analytics, PostHog stores a first-party identifier locally to deduplicate events.
12. Children
Scenik is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child under 16 has provided us data, please contact us and we will delete it.
13. Security
We use industry-standard measures to protect your data, including encryption in transit (HTTPS/TLS), encryption at rest for databases, least-privilege database access via row-level security policies, hashed and salted password storage (handled by our authentication provider), audit logging, and access controls on our infrastructure. No system is perfectly secure; please use a strong, unique password, enable OS-level device protection, and notify us immediately if you suspect unauthorised access to your account.
14. Automated decision-making and AI
Route suggestions, scenic scores, waypoint facts, and voice guidance are generated using AI models. These are informational suggestions, not decisions with legal or similarly significant effect on you within the meaning of Article 22 UK/EU GDPR. AI outputs may be inaccurate; you must independently verify anything that matters.
15. Third-party links
The Service may link to third-party websites (for example, Paddle's checkout, map data attributions, or provider policies). Those sites have their own privacy notices; we are not responsible for their practices.
16. Changes to this notice
We may update this notice from time to time. Material changes will be highlighted in-app and the "Last updated" date above will change. Continued use after the effective date constitutes acknowledgement of the updated notice.
17. Contact
Questions about this notice, or to exercise any of your privacy rights, contact us via the in-app support channel or through the contact details published on goscenik.com. Please include enough information for us to verify your identity and locate your account.