LocalSay
Privacy Policy
Last updated: 26 September 2026
Who is responsible: Basem Abouzeid, Kurfürstenstraße 135, 10785 Berlin, Germany. Contact: privacy@localsay.app
Every factual claim here was read out of this app's code and database rather than written from intention. Where a statement stops being true, the statement is wrong and gets fixed.
Not legal advice. A lawyer should read this before you rely on it.
The short version
LocalSay is a question app. A traveller asks the people who live in a city a question, locals vote, and the answer is whatever the city chose. To do that we need to know who you are (Apple tells us), what to call you (a handle you pick) and which city you live in. If you allow it, we also check whether you are in that city when you vote, which earns your account a verified mark.
We do not build a profile of where you go. Your coordinates are used for that one check and thrown away; what stays is a distance and a yes or no. We do not sell anything to anybody, and we do not run advertising.
What we hold, and why
Your account
- Sign in with Apple. Apple tells us an account identifier and an email address, which is a relay address like
abc123@privaterelay.appleid.comif you chose to hide yours. There is no password, because we never see one. We use this to know it is you next time. - A handle you choose. Shown next to your questions, votes, suggestions and plans. Pick one you are happy for strangers to see.
- A profile photo, if you upload one. Optional, and stored in a public bucket: anyone with the link can open it, whether or not they use LocalSay. That is the trade for a photo you chose to show people, and you should know it before uploading.
- Your home city, if you set one. This is what makes you a local: it decides which questions you may vote on.
- Your standing — points earned for votes, suggestions and plans, and your position on that city's leaderboard, which other users can see.
What you write
Questions, the options on them, suggestions, plans you write, messages you send about a plan, and reviews. Other users see these, with your handle. A settled question and a chosen plan can also appear on a public web page that needs no account, so a traveller can show somebody what the city chose — those pages carry the city's name and never the asker's handle.
Where you are
- When you vote or suggest a place, the app sends your coordinates, if you allowed it, so the server can work out whether you are inside that city. What is kept is the distance, rounded, and whether it was inside — never the coordinates, and no vote carries a position. Being inside marks your account as a verified local. Refusing location changes nothing else: you can still vote on your own city's questions.
- Your home city is a city, not a place: we know "Berlin", never where in Berlin.
What you pay
Purchases go through Apple. We never see your card, your name on it, or your Apple ID. What we keep is what RevenueCat tells us: which pass you bought, when it started, when it ends, and Apple's transaction reference, so the app knows your pass is on.
Your phone
- A push token, if you allow notifications, so we can tell you your question was answered. Deleted when you turn notifications off or delete your account.
- App version and platform, in usage statistics.
Who else sees it
Each of these gets only what the job needs.
| Who | What for | What they get | Where |
|---|---|---|---|
| Supabase (AWS) | The database, sign-in and file storage | Everything above | London, UK |
| Apple | Sign in with Apple, payments | Their own account and payment data | Their terms |
| RevenueCat | Keeping track of passes | Your account id, which pass, when it ends | USA |
| PostHog | Usage statistics | Shape, never content: that a question was asked, not what it said. Plus daily totals per city and per question (counts and times, no text) | EU |
| Google Places | The place search when you name an option | What you type into that field, and the city it searches near | Global |
| Anthropic | Writing a suggested plan, if you ask for one | The places already in that city's archive, and what you wrote in the request: your starting point, hours, budget, mood and notes | USA |
| Cloudflare | Serving the public share pages | The usual web request data, including IP addresses | Global |
| Expo | Delivering push notifications | Your push token and the message | USA |
Transfers to the USA rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses, depending on the provider.
We do not sell personal data. We do not share it for advertising. Nobody gets it for their own purposes.
Usage statistics, and how to turn them off
We record that things happened, never what they said: a question was asked (with its length and how many options), a vote was cast, the paywall was seen, a plan was requested. No titles, no option names, no plan text, no messages. Events carry your account id so a funnel can tell one person's journey from another's.
Settings → Privacy has a switch that turns this off, and nothing is sent after you do.
We also sync daily figures from the database — questions per city, votes per question, how long questions took to be answered — to the same statistics tool. Those rows carry account ids, cities and timings; they carry no text anybody wrote.
Guide accounts
Some accounts in each city are run by LocalSay rather than by a person who lives there. They vote, they suggest places that have been chosen here before, and they ask about one question a day, which is how a new city has anything on it at all. A place suggested by one says so on the option. Settings → About explains it in full. This is here because it affects what you are reading when you read the app.
How long we keep it
- While your account exists, we keep it.
- When you delete your account (Settings → Delete account), your login is destroyed at Apple's end and ours, your handle is replaced with one nobody can trace, and your photo, home city, notifications, push tokens, passes, chat messages and reputation ledger are deleted. Open questions are cancelled and unawarded plans withdrawn.
- What stays, attached to an account that is now nobody: your votes, questions that ran to the end, options you suggested, and plans somebody chose. Those numbers are other people's results, standing and days out, and rewriting them would rewrite other people's history. A deleted account leaves votes that still add up and a handle nobody can read.
- Usage statistics already sent stay in PostHog under their retention, with your account id and no content.
Your rights
Under the GDPR you can ask us to show you what we hold, correct it, delete it, give you a copy to take elsewhere, or object to how we use it. Write to privacy@localsay.app and we answer within a month.
The deletion limit above is real and worth naming: we can destroy your identity completely, but we cannot remove a vote from somebody else's result without falsifying it. If that is not acceptable to you, do not vote.
You can also complain to a supervisory authority. In Berlin that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Legal bases: running the app you asked for (contract) covers your account, your content, votes and payments. Usage statistics rely on your consent, which the switch in Settings withdraws. Checking you are in the city relies on our legitimate interest in answers that come from people who actually live there.
Children
LocalSay is for people aged 16 and over. We do not knowingly hold data about anyone younger; if you believe we do, write to us and we will delete it.
Changes
If this policy changes in a way that matters, the app will say so before the change takes effect. The date at the top always reflects the current version.