WayBack ("we", "us", "our") is a social memory app that helps you rediscover shared experiences with friends. We are committed to protecting your privacy and being transparent about how your data is used.
This policy applies to the WayBack mobile application and associated services. WayBack is operated from Copenhagen, Denmark and complies with the EU General Data Protection Regulation (GDPR).
When you sign up via Apple Sign In, we store your name, email address, username, date of birth, and profile photo. Your profile photo is stored in our cloud infrastructure (Supabase).
Your photos never leave your device. WayBack reads the timestamp and GPS coordinates from your photo library to build your timeline. Photo analysis is performed locally on your phone using Apple's MapKit framework. No photo files are uploaded to our servers.
When you compare timelines with a friend in person, location timestamps are temporarily sent to our database in encrypted form. This data is used only to find matching memories and is deleted immediately after the comparison session ends.
If you enable Interest Detection, WayBack automatically identifies your interests based on the types of venues and events in your timeline. Interests are stored locally on your device. If you enable Interest Sharing, a copy of your interests is stored in our cloud database so friends can receive relevant friend recommendations. Your specific interests are never shown to other users.
Activities you create, friend connections, and activity invitations are stored in our cloud database to enable the social features of WayBack.
With your permission, we access your device location to show nearby venues and events on the Explore page. Location access is optional and can be revoked at any time.
We use your data to provide and improve the WayBack experience, specifically to:
WayBack gives you granular control over how your data is processed. You can toggle these at any time in the app under Settings → Privacy & Data:
Disabling a toggle immediately stops the associated processing. Disabling Interest Sharing deletes your interests from our cloud database.
The WayBack Explore page may display promoted venues and events from business partners. In the future, businesses may be able to target promotions to users based on proximity, profile match, or previous visits. We will never sell your personal data to advertisers. You will always be able to distinguish promoted content from organic recommendations.
Your data is stored using Supabase, a secure cloud platform with data centers in the EU. We use row-level security policies to ensure users can only access their own data. Timeline comparison data is encrypted in transit and at rest, and is deleted after each session.
We do not sell your personal data to any third party. We share data only in these limited circumstances:
As a user in the EU, you have the right to:
Your account data is retained for as long as your account is active. Timeline comparison data is deleted immediately after each session. When you delete your account, all associated data is permanently removed from our servers, including your profile, friends, activities, invitations, interests, and stored avatar image.
WayBack requires users to be at least 16 years old. We do not knowingly collect data from users under 16. If we become aware that a user is under 16, we will delete their account and data.
We may update this privacy policy from time to time. We will notify you of significant changes through the app or by email. Continued use of WayBack after changes constitutes acceptance of the updated policy.
If you have questions about this privacy policy or want to exercise your data rights, contact us at:
Email: info@waybackapp.dk
Address: WayBack, Copenhagen, Denmark