AI-Tourguide Logo

Privacy Policy

Your Privacy is Our Priority

Effective Date: August 14, 2026  ·  Last Updated: August 14, 2026

AI-Tourguide ("we", "our", or "us") is a service of AIchievable, Daniel Gerlach, Riedmattstrasse 3b, 6030 Ebikon, Switzerland. This Privacy Policy explains how we handle your information when you visit our website ai-tourguide.net and when you use the AI-Tourguide web app at ai-tourguide.net/guide (together, the "Service"). The web app runs entirely in your browser — there is nothing to download or install.

The short version

  • No advertising, no data selling, no profiling. We do not sell, rent, or trade your personal data, and we do not build behavioral profiles.
  • Almost nothing is stored on our servers. Your account (an ID, your email if you register, your credit balance, and your purchases) is all we keep. Your tours and your conversations with the guide are stored in your own browser.
  • Voice, photos, and questions are processed transiently. They are sent to our backend and to AI providers to generate the guide's response, then discarded. We do not store them, and they are not used to train AI models.
  • Your location stays on your device. We never store or track where you are or where you have been.
  • Cookie-free website analytics. Our website uses a self-hosted, cookie-free analytics tool, and we honor your browser's "Do Not Track" setting.

Table of Contents

1. Who is Responsible (Data Controller)

The controller responsible for data processing under this policy is:

AIchievable — Daniel Gerlach
Riedmattstrasse 3b
6030 Ebikon, Switzerland
Email: [email protected]

2. Your Account

You can browse the website and start using the web app without registering. When you first use the app, an anonymous session with a random user ID is created so that your free credits and saved tours can be assigned to you. No name, email address, or other personal detail is required for this.

If you choose to register (for example, to keep your credits and purchases across devices), we additionally store your email address and a password (stored in hashed form only — we never see or store your plain-text password).

On our servers we store only: your user ID, your email address (if registered), your credit balance, your purchase history, and any active passes. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR).

3. Data Processed When You Use the Guide

The AI guide is a real-time conversation. To make it work, the following data is processed transiently — meaning it is used to generate the response you asked for and is not stored on our servers afterwards:

Voice input

When you actively use voice input, your browser records audio through your microphone (only after you grant the browser permission). The recording is sent to our backend, which passes it to a speech-recognition provider (DeepInfra, running the Whisper model) to convert it into text. The audio is processed solely for this transcription and is not stored by us. Speech recognition does not happen on your device — the audio is transmitted, encrypted, for processing.

Text questions and conversation

Your messages to the guide, together with the necessary conversation context, are sent through our backend to AI providers (OpenAI; OpenRouter for auxiliary processing) to generate the guide's spoken reply. The guide's voice is synthesized by OpenAI's text-to-speech service. According to these providers' API terms, data submitted through their APIs is not used to train their models. Your conversation history is stored in your own browser (see Section 6), not on our servers.

Photos

If you take or upload a photo (for example, "What is this building?"), it is compressed in your browser and sent through our backend to the AI provider for analysis. It is processed transiently to generate the answer and is not saved to any storage by us.

Location

If you allow location access, your GPS position is used in your browser to show your position on the map and guide you along the route. To calculate walking routes and display map tiles, coordinates are sent to Mapbox (our map provider). We do not store your location on our servers, we keep no location history, and we cannot see where you are or where you have been. The AI guide receives at most derived, coarse information (such as your distance to the next stop) as text.

Tour generation

When you generate a custom tour, the city name and your chosen theme are sent to our backend and to AI providers to create the route. Public information about sights (including images) is loaded from Wikidata and Wikimedia Commons.

4. Payments

Payments are processed by Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.). The payment form is provided by Stripe and loads only when you start a purchase. Your card or payment details go directly to Stripe — we never receive or store your payment card numbers. Stripe may set cookies that are strictly necessary for processing the payment and preventing fraud. Stripe processes your data as described in the Stripe Privacy Policy.

We store a record of your purchases (product, amount, date, and the associated Stripe transaction reference) to provide your credits and passes and to meet our accounting obligations. Legal basis: performance of contract (Art. 6(1)(b) GDPR) and legal obligation (Art. 6(1)(c) GDPR).

5. Analytics

Website (cookie-free)

On our website we use a self-hosted, cookie-free analytics tool (Umami) running on our own server in the EU. It sets no cookies and does not read or write any storage on your device. To distinguish visits, your IP address is only processed transiently in memory into a daily-changing, irreversible identifier and is never stored. This data never leaves our servers and is not shared with third parties. We honor your browser's "Do Not Track" setting: if it is enabled, nothing is collected. Legal basis: our legitimate interest in understanding and improving our service (Art. 6(1)(f) GDPR).

Web app (anonymous events)

Inside the app we count anonymous usage events (for example, how often a checkout is opened) without any user ID or device identifier. An event contains only the event name and coarse, non-identifying details such as a general browser class and, where present, the campaign parameters of the link you arrived through. "Do Not Track" is honored here as well. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

6. Data Stored in Your Browser

The app keeps your working data on your device, in your browser's local storage. This includes:

This data stays in your browser until you clear your browser data (or log out, for the session). We do not use this storage for tracking, and we set no advertising or tracking cookies anywhere on the Service.

7. Hosting and Third-Party Resources

Our website and app are served from a server operated by Hetzner Online GmbH (Germany), with Cloudflare, Inc. in front as content delivery network and security layer. Our backend (accounts, credits, AI request routing) runs on Supabase, hosted in the EU (Frankfurt, Germany). Web servers may keep short-lived technical logs (including IP addresses) for security, error diagnosis, and abuse prevention; these are deleted automatically. Legal basis: legitimate interest in a secure, reliable service (Art. 6(1)(f) GDPR).

When the app loads in your browser, some resources are fetched from third-party servers, which technically receive your IP address in the process: map tiles and routing from Mapbox, fonts from Google Fonts, the Supabase browser library from the esm.sh CDN, and sight images from Wikimedia Commons.

8. Service Providers (Recipients)

We share data only with the service providers needed to run the Service, and only to the extent described above:

ProviderPurposeData involved
Supabase (EU, Frankfurt)Backend: accounts, credits, purchases, AI request routingAccount data, transient AI requests
StripePayment processingPayment data (directly to Stripe), purchase reference
OpenAIAI responses and the guide's voice (text-to-speech)Conversation text, photos (transient)
DeepInfraSpeech recognition (Whisper)Voice recordings (transient)
OpenRouterAuxiliary AI processing (conversation summarization)Conversation text (transient)
MapboxMap display and walking routesCoordinates, IP address
Hetzner (Germany)Server hostingTechnical access data
CloudflareCDN, security, DDoS protectionTechnical access data
Google Fonts / esm.sh / WikimediaFonts, browser library, sight imagesIP address (technical)

These providers act as our processors or as independent controllers (Stripe, for payment processing) and may not use your data for their own purposes beyond what is described in their linked policies.

9. International Data Transfers

Some of our providers (Stripe, OpenAI, DeepInfra, OpenRouter, Mapbox, Cloudflare, Google) are based in the United States. Where personal data is transferred to the US or other third countries, we rely on an adequacy decision — in particular the EU–U.S. Data Privacy Framework and its Swiss–U.S. extension, under which several of these providers are certified — and/or the EU Standard Contractual Clauses as appropriate safeguards.

10. How Long We Keep Data

11. Your Rights

Under the GDPR, the Swiss Data Protection Act (DSG), and other applicable laws, you have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — have inaccurate data corrected;
  • Erasure — have your data deleted (including your account);
  • Data portability — receive your data in a machine-readable format;
  • Objection — object to processing based on legitimate interest;
  • Restriction — request that processing be restricted;
  • Withdraw consent — at any time, where processing is based on consent (for example, by revoking microphone or location permission in your browser).

To exercise any of these rights, email us at [email protected]. We respond within 30 days. You also have the right to lodge a complaint with a data protection supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, the authority of your country of residence.

If you are a California resident: we do not sell or share personal information as defined by the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. You have the rights to know, delete, correct, and non-discrimination, which you can exercise via the contact above.

12. Children's Privacy

Our Service is not directed at children under 13 (or under 16 in the EU/EEA, where consent of a parent or guardian would be required). We do not knowingly collect personal data from children below these ages. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time — for example, when we change providers or add features. The current version is always available on this page; the "Last Updated" date at the top shows when it last changed. For material changes we will provide a clear notice within the Service. This version replaces the previous policy dated August 9, 2025, which described our former iOS app; the Service is now a web app, and this policy reflects how it actually works.

14. Contact Us

AIchievable — Daniel Gerlach
Riedmattstrasse 3b
6030 Ebikon, Switzerland
Email: [email protected]
For data protection requests, please use the subject line "Data Protection Request".