Legal
Privacy Policy
Last updated: March 8, 2026
1. Information We Collect
When you create an account, we collect your name, email address, and authentication credentials. When you use our services, we collect itinerary preferences, chat messages with the AI explorer, and location data when you opt into the walking guide feature. We do not sell your personal data.
2. How We Use Your Data
We use your data to provide and improve our services, including generating personalized itineraries, powering the AI chat explorer, and delivering walking guide navigation. Your preferences and history help us create better travel recommendations.
3. Data Storage & Security
All data is stored in AWS EU-Central-1 (Frankfurt, Germany) using encrypted connections. Authentication is managed through AWS Cognito with industry-standard security protocols. We use DynamoDB for data storage with encryption at rest enabled.
4. Third-Party Services
We use the following third-party services to deliver our product:
- Google Maps API — map rendering and directions
- Mapbox GL — walking guide navigation
- Google Generative AI (Gemini) — AI chat explorer
- OpenAI API — itinerary generation, document analysis, and place extraction
- Stripe — web payment processing
- RevenueCat — mobile in-app purchase management
- Firebase — push notifications
- Google Analytics 4 — web analytics (consent required)
Each service processes only the minimum data necessary for their function.
5. AI Data Processing
When you use AI-powered features (chat explorer, itinerary generation, document analysis, place extraction), your input data is processed by third-party AI providers (Google Generative AI, OpenAI). Data is sent in real-time for processing and is subject to each provider's privacy policy. We do not use your data to train AI models.
6. Your Rights (GDPR)
As a user in the European Union, you have the right to access, correct, delete, and export your personal data. You may also restrict processing and object to automated decision-making. To exercise these rights, contact us at contact@naviraguides.com.
7. Cookies & Analytics
We use essential cookies required for authentication and session management. We use Google Analytics 4 with consent mode enabled — analytics data is only collected after you grant consent via the in-app cookie banner. We do not use third-party advertising cookies.
8. Data Retention
Your account data is retained as long as your account is active. Chat messages and itineraries are stored until you delete them or your account. Upon account deletion, all associated data is removed within 30 days.
9. Age Requirement
You must be at least 16 years old to create a Navira account, in accordance with GDPR Article 8.
10. Contact
For privacy-related questions or to exercise your data rights, contact us at contact@naviraguides.com.