Flaneur — Privacy

Last updated 2026-09-21 · English is the binding text

Flaneur is a walking app. You walk, you say what you notice, and it paints you a postcard of it. This page says where your words and pictures go, what we can see (almost nothing), and what your rights are.

The short version

1. Who is responsible

DREi Studio GmbH, Bahnhofstrasse 16, 6300 Zug, Switzerland · UID CHE-367.142.563 (renamed from DREI Solutions GmbH on 2026-04-29, same company)
Email: hello@dreistudio.ch

We have no data protection officer; the company is far below the thresholds that require one. We are established in Switzerland and have not appointed a representative in the EU or the UK; if you are there and would rather not write to a Swiss company, your local supervisory authority (§ 5) can reach us too.

2. What DREi processes, and on what basis

what when data legal basis kept for
Prompt-config fetch — the app reads its question list from our Firebase project (egress E3) on launch, when the network is up your IP address and request metadata, in Google's server logs for our project — logs Google also keeps for its own purposes as service data under its Cloud Privacy Notice, outside our processor terms and beyond our reach; nothing that identifies you, nothing you said legitimate interest, GDPR Art. 6(1)(f): keeping the fallback questions updatable without an app release for Google Cloud's standard log retention for our project — we add no logging of our own
Support email — when you write to us only if you do your email address and what you wrote Art. 6(1)(b) where it is about your use of the app, otherwise 6(1)(f) until your question is closed, then deleted at the latest 12 months after
The website paintedwalks.com when you visit IP address, user agent, requested page, in the network logs of our host, Cloudflare. No cookies, no analytics, no embedded fonts or scripts from third parties Art. 6(1)(f): running the site securely Cloudflare processes this metadata, in its words, "for a limited period of time" — it publishes no fixed number: https://www.cloudflare.com/trust-hub/gdpr/
Crash reports via Apple only if you have Share With App Developers on in iOS Settings → Privacy → Analytics anonymised crash logs as Apple provides them Art. 6(1)(f); the sharing itself is your iOS setting as long as needed to fix the crash

Processors: Google (Firebase/Google Cloud; Data Processing Addendum accepted in the Firebase console) and Cloudflare, Inc. (hosting, via Cloudflare Pages; its Art. 28 DPA, carrying the EU Standard Contractual Clauses, is incorporated by reference into the Self-Serve Subscription Agreement and applies without a separate signature: https://www.cloudflare.com/trust-hub/gdpr/). Google Cloud may process the fetch outside Switzerland/the EEA, including in the United States, and Cloudflare processes visitor metadata in its US and European data centers; each transfer rests on the company's EU-US and Swiss-US Data Privacy Framework certification — "Google LLC (and its wholly-owned US subsidiaries unless explicitly excluded) has certified that it adheres to the DPF Principles" (https://policies.google.com/privacy/frameworks, effective 2025-08-23; Cloudflare states its own on the page cited above) — and the EU Standard Contractual Clauses in the DPA.

We make no decisions about you by automated means (GDPR Art. 22). The postcard is generated automatically, but it has no legal or similar effect on you.

3. What leaves your phone — the closed list

This is the complete list. The app cannot send anything by a road that is not on it; the source of the list is our spec, and the app's own privacy screen (Settings → Privacy) shows the six that carry anything of yours, and points here for the rest.

# what leaves to whom carries your words or pictures?
E1 the postcard prompt — your notes and the style you chose: distilled on your phone into a short description where your phone can, word-for-word where it cannot (§ 3, Google) Google (Gemini), with your own API key yes — at your request, for the one thing you asked for
E2 a key check — one request that lists models, so the app can tell you whether the key you pasted works Google (Gemini) no — no prompt, no notes; once, when you paste a key
E3 the question-list fetch described in § 2 Google (our Firebase project) no
E4 your audio, only when on-device recognition is unavailable on your phone (fresh install before the model is downloaded, some iOS updates, a Siri-language change) Apple's speech servers yes — raw audio
E5 your journal — walks, notes with their times, titles, prompts and postcard images — only if you have iCloud Backup on, by backup, not by sync your own iCloud account yes, into your own storage; we never see it
E6 a postcard you share whatever app you pick in the share sheet yes — you choose the destination and watch it happen
E7 the speech-model download — a request for the on-device recognition model for your language Apple's asset servers no — the model comes down; nothing goes up
E8 the voice-model download — only when you download the companion voice in Settings → Voice Hugging Face (pinned, immutable files) no — a file request, and the IP address any download reveals
E9 the keyless postcard prompt — the same distilled prompt as E1, when you paint without a key of your own: on your free postcards, a credit pack, or a code we gave you Google (Gemini, via Google's Firebase AI Logic gateway, billed to us) yes — E1's answer, with the bill moved to us
E10 your paint counts — how many free postcards you used and how many credits you hold; a number and an anonymous account identifier, never a word of yours Apple (iCloud, our app's public database) no — counts, not content

What the other party does with it — quoted, not paraphrased

Apple, speech (E4). Apple's Siri, Dictation & Privacy notice (updated 2026-02-11) says: "If you choose to allow apps to use Speech Recognition for transcription, the audio data to be transcribed may be sent to Apple." and "Unless you opt in to Improve Siri and Dictation, your audio data is not stored by Apple." That opt-in is your iOS setting, not ours (Settings → Privacy & Security → Analytics & Improvements → Improve Siri & Dictation). If you have it on, Apple may keep the audio and transcript for up to two years under a rotating, device-generated identifier. https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/ The app asks for on-device recognition whenever your phone supports it, and then no audio leaves the phone. (Source in code: requiresOnDeviceRecognition is set whenever supportsOnDeviceRecognition is true.)

Google, Gemini keyless (E9). When you paint without a key, the same distilled prompt goes to Google through its Firebase AI Logic gateway and is processed on Google's Vertex AI service, billed to our project. No server of ours sees the prompt; it travels from your phone to Google directly. Google's Cloud terms and its Data Processing Addendum govern this road; Google's published position is that customer data on Vertex AI is not used to train its models (see cloud.google.com/terms/service-terms). The request goes to Google's global endpoint, so Google chooses where it is processed — assume that can be outside Switzerland, the EEA and the UK, including the United States; cross-border transfers then run under the standard contractual clauses in Google Cloud's Data Processing Addendum.

Google, Gemini (E1, E2). The postcard is painted with your Gemini API key, under your agreement with Google — we are not a party to it and never see the prompt, the image or the key. One of Google's terms is worth knowing: in the European Economic Area, Switzerland and the UK its paid-service terms apply to all Gemini API use, so Google does not use your prompts or the images to improve its products; on the free quota elsewhere, its terms say it may, including with human review. Google's terms and logging policy: https://ai.google.dev/gemini-api/terms · https://ai.google.dev/gemini-api/docs/logs-policy Whether your sentences travel verbatim depends on your phone. On a phone with Apple Intelligence, your notes are first distilled on the phone into one short image prompt, and that distilled text — which may still quote your words — is what Google receives. On a phone without it, or when the on-device model declines or fails, the prompt contains your notes word-for-word and in order, framed only by the style you chose and our picture-making rules. So yes: your sentences can reach Google verbatim. Either way it happens only at your tap, for the postcard you asked for. (Source in code: PaintPrompt.descriptive — "their own words, verbatim and in order" — is the fallback of DistillerCore.paintPrompt, the one function that decides what Gemini is sent.)

Apple, iCloud Backup (E5) is your backup under Apple's iCloud terms; we have no access to it. Hugging Face (E8) receives a plain file download; their privacy policy governs what a download reveals: https://huggingface.co/privacy.

4. How long, and how to delete

5. Your rights

Under the Swiss FADP and, where it applies to you, the GDPR (Art. 15–21), you can ask us for access to the data we hold about you, its correction or deletion, a restriction of its processing, a copy in a portable format, and you can object to processing based on legitimate interest. You can withdraw a consent at any time, without affecting what was done before. Write to the address in § 1. You also have the right to complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, https://www.edoeb.admin.ch); in the EU/EEA the authority of your country of residence.

Nothing in the app requires you to give us personal data; the app works without a key, without an account and without any contact with us.

6. Children

Flaneur is not directed at children under 13, and we do not knowingly process data about them. There is no age gate in the app.

7. Changes

We change this page when the list in § 3 changes, and never silently: the version date at the top moves. If you want to know what an earlier version said, write to us and we will send it — every version is in the site's version history.