Privacy
What we collect, and what we don’t.
Last updated 9 September 2026 · applies to the See the City app and this website
Who we are
See the City is a walking-route app currently in private beta in Denver, Colorado. It is operated by Summit Technology Group LLC, a Colorado limited liability company. In this policy “we” and “us” mean that company. For anything here — including a request to see or delete your data — write to mark@stgengineer.com.
What the app collects
Your account
The first time you open the app it generates a random identifier — an arbitrary number, not your device’s serial, hardware ID or advertising ID — and keeps it in your operating system’s secure store (Keychain on iOS, Keystore on Android). That identifier is your account. We do not know who you are.
You may optionally add an email address and password so the same account works on a second phone. That is handled by Microsoft PlayFab; the password is set with PlayFab directly and we never receive or store it. If you never link an account, we never have your email.
What you make
Routes you build and the stops, activities, prices, times and notes in them; reviews you write; routes you favourite; and photos you upload. A route you publish is public, along with the maker name attached to it. A route you keep private is visible only to you and to anyone you send the link to.
What you do
When you check in at a stop we record which stop, and when, and tie it to the route you are currently walking so the app knows the route is finished. We record stops you skip, for the same reason. When a coupon is issued to you we record the code and the time.
Your age
The app asks your age once, on first launch, so it can leave out routes that are 21+ or plainly not for children. That number is stored on your device and is not attached to your account. It is sent to our server as a filter each time you browse routes, so it appears in ordinary server request logs, but nothing keeps it against your account afterwards. You can skip the question entirely and see everything.
Ads
The free app shows banner ads through Google AdMob. Google’s SDK may use your device’s advertising identifier to choose them. On iOS you get Apple’s tracking prompt first; decline it and the app works identically, with less relevant ads. We do not send Google anything about who you are or what you have walked, because we do not have it.
Payments
If a paid subscription ever goes on sale, billing is handled entirely by the App Store or Google Play. We receive a receipt token to check that a subscription is active. Card numbers never reach us, at any point.
Server logs
Our servers keep ordinary request logs — the path requested, the time, an IP address, and error detail when something breaks. These are held by Microsoft Azure and are used to keep the service running and to fix bugs.
What the app does not collect
This list is specific on purpose, because “we care about your privacy” is not information.
- Your location. The app declares no location permission on Android and none on iOS. It cannot read your position, and does not.
- Analytics of any kind. There is no analytics, crash-reporting or attribution SDK in the app.
- Your contacts, calendar, microphone or camera roll at large. Photo access is only ever the single picture you choose to upload.
- Your real name, date of birth, address or phone number. The app never asks.
- Any sale of personal data. We do not sell it, rent it, or trade it.
A note on honesty: our database has empty columns for check-in coordinates, left over from a location feature that is built on the server but not wired up in the app. Nothing writes to them today. If that feature ever ships it will ask your permission first, and this policy will be updated before it does.
Photos — read this one
When you add a photo to a stop, the app uploads the file your phone gives it and we store it as-is. We do not currently strip the metadata that cameras attach to a picture, which on many phones includes the GPS coordinates where the photo was taken, the time, and the device model.
If you put that photo on a public route, that metadata goes with it. This is the one place where the app can reveal a location, and it is a consequence of us not processing your file rather than anything we want to know. We intend to strip it; until this page says we do, assume we do not. If you would rather not chance it, turn off location tagging in your camera app, or send us a photo you took somewhere you do not mind naming.
Who else sees your data
These are service providers who process data so the app can work. They are not permitted to use it for their own purposes, except Google AdMob acting as an ad network, which is described above.
| Who | What they handle | Why |
|---|---|---|
| Microsoft PlayFab | Your account identifier, optional email, your route-maker score | Sign-in and the leaderboard |
| Microsoft Azure | Everything you make, your check-ins, your photos, server logs | Our servers, database and photo storage |
| Google AdMob | Your device advertising identifier | Ads in the free app |
| Google Places & Routes | Place searches and walking directions | Finding places and timing the walk between stops. These are requested by our server, not by your phone, so Google does not see your device or IP address for them. |
| Apple / Google Play | Subscription billing | Taking payment, if anything is ever on sale |
How long we keep it
Routes, reviews, check-ins and photos are kept while your account exists, because they are what the app is. Server logs are kept for a short operational period and then rotate away. Ask us to delete your account and we delete the account and the content attached to it.
One exception worth stating: a route you published that other people have saved or walked may be kept in an anonymised form, so their history does not develop holes. Your name comes off it.
Your choices
- See what we hold, or delete it. Email mark@stgengineer.com and we will answer within 30 days.
- Stay anonymous. Never link an email, and we have nothing that identifies you beyond a random number.
- Skip the age question. The app works without it.
- Refuse ad tracking. On iOS, decline the prompt. On Android, reset or limit your advertising ID in system settings.
- Take your data. Ask, and we will send you your routes and check-ins in a readable format.
If you are in the UK, EU, or a US state with its own privacy law, you have rights of access, correction, deletion, portability and objection. The email above is how you use them; we do not require a form.
Children
The app is not intended for children under 13 and we do not knowingly create accounts for them. Some routes are designed to be pleasant with a small child along — those are for an adult to walk with them, on the adult’s account. If you believe a child has an account, write to us and we will remove it.
Security
Your session credential is held in the operating system’s secure store rather than ordinary app storage. Traffic between the app and our servers is HTTPS only. Your phone never talks to Google’s or our database directly — everything goes through our server, which is also why no API key that matters ships inside the app.
No system is perfect, and this one is young. If you find a security problem, please tell us at mark@stgengineer.com before you tell anyone else, and we will fix it and credit you if you want that.
A beta caveat
See the City has not launched. During the beta we may reset test data, and features described here may change or disappear. When something changes what we collect, this page gets updated and the date at the top changes with it. If the change is significant, we will say so in the app rather than hoping you re-read a web page.