Privacy Policy
Last updated 11 August 2026 · Applies to the Waylight website and waitlist, the Waylight web app, the Waylight mobile app, and the Waylight API.
Waylight helps you plan walking and cycling routes that account for real, measured conditions — lighting, surface, shade, traffic — rather than just distance and time. This page explains what personal data we collect to do that, why, and what control you have over it.
1. What we collect
| Data | When | Why |
|---|---|---|
| Email address | You create an account | Sign-in (magic link / password), account recovery, service emails |
| Display name | You create an account or set one | Shown to you in the app; shown to other users only if you enable presence-sharing (see below) |
| Saved places (home, work, starred), and recent searches | You save or search a place while signed in | Personalize routing and let you return to places quickly across devices |
| Onboarding answers (e.g. preferences you choose during setup) | You complete onboarding | Personalize default route preferences |
| Current location (GPS coordinates) | Every time you request a route or ask the assistant something | Compute a route from where you actually are; see §3 |
| Sign-in metadata (approximate timing, not IP-logged by us beyond standard hosting logs) | Every sign-in | Security alerting for account owners; see §6 |
We do not collect payment information (Waylight has no paid tier at this time), government ID, or biometric data.
Correcting a previous version of this notice: saved places and recent searches for a signed-in account are stored on our servers (in our database), not only on your device, so that they follow you across devices. If you never create an account, nothing you save can leave your device, because there is nowhere signed-out data is sent.
2. Waitlist and referrals
Before Waylight launches you can join a waitlist at waylightapp.site. This is separate from having an account, and everything in it is optional except your email address and your consent.
| Data | When | Why |
|---|---|---|
| Email address (stored in full, not hashed) | You join the waitlist | Send the confirmation email, and tell you when Waylight launches |
| Where you walk (a city or place you type) | Optional, during signup | Decide which cities to build support for first |
| What matters to you (shade, light, quiet, step-free, populated, flat) | Optional, during signup | Understand which needs to prioritise |
| Phone platform and preferred app language | Optional, during signup | Decide what to build and translate first |
| Your referral code, and the code of whoever invited you | Automatically, at signup | Count how many people you brought, and apply the referral reward |
| Approximate country, plus hashes of your IP address and browser string | At signup | Abuse prevention and proof-of-consent (the IP itself is never stored) |
Double opt-in. Joining sends you a confirmation email. Until you click the link in it, your entry counts for nothing — you are not on the list, and you do not count as anyone's referral. Unconfirmed entries are deleted automatically after 30 days.
Referral links. Your referral link contains an opaque random code and nothing else — it reveals no name, no email address and no other detail about you to the people you send it to, or to us about them beyond what they choose to enter themselves. Only confirmed signups are counted. Referral rewards are described in our Terms.
Legal basis. Consent (GDPR Art. 6(1)(a)), given by ticking the box at signup and again by confirming your address. You can withdraw it at any time.
Leaving. Every email we send carries a one-click removal link. Using it permanently deletes your waitlist entry — the whole row, including your email address. It is not a "do not contact" flag with your data kept behind it. You can also email privacy@waylight.app and we will do the same thing by hand.
3. Location data
Waylight is a location app; location is core to what it does. Specifically:
- Route requests. Your current coordinates are sent with each route-planning request so the server can compute a real route from your position. This request is processed to return a result and is not stored as a standing location history.
- The AI assistant. When you type a free-text request ("somewhere calm, I have 40 minutes"), your current coordinates are included in that request — see §4 for what that involves.
- Presence sharing (opt-in, off by default). If you turn this on, your live coordinates are published so other signed-in nearby users can see you're out walking/cycling. This is independent of whether you're signed in — signing in does not turn it on by itself, and you can turn it off at any time in Settings. Published presence expires automatically (currently after about 12 minutes of inactivity) and is not retained as history.
4. AI-assisted route planning
When you type a free-text request instead of using structured filters, that text plus your current coordinates are sent to our server, which forwards them to Infomaniak AI Services ("Euria") — a Swiss-hosted platform running open Mistral-family language models — solely to convert your sentence into a structured route intent (e.g. destination, preferences, time budget). The AI's only job is that translation; the actual route, distances, comfort scores and explanations you see are computed by Waylight's own routing and scoring engine from real map and city data, not generated by the AI.
This is genuinely optional: every feature Waylight offers is also reachable through structured filters and buttons that never touch an AI model. If you never use the free-text assistant, this section doesn't apply to you.
We do not use your requests to train our own models. For how Infomaniak processes API requests on their infrastructure, see Infomaniak's privacy policy. Switzerland has an EU adequacy decision, meaning the EU has determined it offers a comparable level of data protection — no additional transfer safeguards are required to send data there.
5. Cookies and local storage
Strictly necessary. Waylight uses one essential cookie, wl_session, to keep you signed in (HttpOnly, Secure, 45-day expiry). It is required for the service to work when you're signed in, is never used for advertising or cross-site tracking, and needs no consent under EU ePrivacy rules. We also keep non-sensitive preferences (like theme) and, during waitlist signup, your unsubmitted answers in your browser's local storage — that data never leaves your device.
Measurement that always runs, and sets no cookie. Every visit to our website is counted in aggregate so we can see how many people arrive, roughly where from, on what kind of device, and which parts of the page they reach. This runs whether or not you accept anything below, because it cannot identify you: no cookie is set or read, no visitor ID is created or stored, your IP address is used only to look up an approximate country and city and is then discarded without being stored — not even as a hash — and your browser string is reduced to "mobile", "tablet" or "desktop" before anything is written down. The tools are Vercel Web Analytics and Vercel Speed Insights, plus our own server-side event log.
Optional analytics, only if you accept. If you accept in the banner, we additionally load PostHog, which does set cookies (named ph_*) and does build a per-person picture: which elements you click, how far you scroll, and a replay of your session as a reconstruction of the page — with all text you type masked, including the email field. This is genuinely optional. Choose Reject and PostHog is never downloaded at all, not merely disabled, and everything on the site keeps working. You can change your mind any time via the link in the footer; we will ask again if this policy materially changes.
6. Who we share data with
We use a small number of infrastructure providers to run Waylight. Each processes only what's needed for its function, under its own terms:
| Provider | Purpose | What it sees |
|---|---|---|
| Supabase | Account database and authentication | Email, display name, saved places, recents, onboarding answers |
| Vercel | Hosting, edge network, serverless functions | Standard request/hosting logs for every request to waylightapp.site |
| Infomaniak AI Services (Euria) | Free-text route request parsing (opt-in by usage — see §4) | Your typed text and current coordinates, per request |
| Resend | Transactional email (magic links, security alerts, waitlist confirmation and launch announcements) | Your email address, when an email needs to be sent |
| PostHog | Product analytics, heatmaps and session replay — only after you accept (see §5) | Pages viewed, clicks, scrolling, and a masked replay of your session. EU region; requests are routed through waylightapp.site rather than direct to PostHog |
| Vercel Web Analytics & Speed Insights | Aggregate visit counts and page-performance measurement (always on, cookieless) | Page path, approximate country, device class, page-load timings — never an identifier |
| OpenStreetMap Nominatim & Photon (Komoot) | Turning place names into coordinates and back | The place name or coordinates you search |
| FOSSGIS OSRM | Turn-by-turn route geometry | Origin/destination coordinates for a route |
| CARTO | Base map tiles | Map viewport coordinates (standard for any map tile request) |
| Open-Meteo | Weather and elevation data | Coordinates along a route |
| Cloudflare Turnstile | Bot protection on some forms, when enabled | Standard bot-verification signals; see Cloudflare's own privacy policy |
We do not sell personal data, and we do not share it with advertisers.
7. International transfers
Depending on each provider's own infrastructure, processing may occur inside or outside the EU/EEA. Switzerland (Infomaniak) has an EU adequacy decision. Where a provider processes data outside the EEA without an adequacy decision, we rely on that provider's own standard contractual clauses or equivalent safeguards — see the individual providers' privacy policies linked above.
8. How long we keep data
- Account data (email, saved places, recents, onboarding) is kept for as long as your account exists.
- Session cookies expire automatically after 45 days.
- Presence data expires automatically after roughly 12 minutes and is not retained as history.
- Route-planning requests (including AI-assisted ones) are processed to return a result and are not retained as a standing log tied to your identity.
- Unconfirmed waitlist entries are deleted automatically 30 days after signup. If you never click the confirmation link, your address disappears on its own.
- Confirmed waitlist entries are kept until Waylight launches plus 12 months, or until you use the removal link in any email we send — whichever comes first.
You can delete your account and all associated data at any time from Settings → Account → Delete account, or by emailing privacy@waylight.app. Deletion is immediate and permanent.
9. Your rights
If the GDPR applies to you, you have the right to: access the data we hold about you; correct it; delete it (see §8); export it in a portable format; restrict or object to certain processing; and withdraw consent for anything based on consent (like presence sharing) at any time. To exercise any of these, email privacy@waylight.app — we'll respond within one month. You also have the right to complain to your local data protection authority.
10. Security
Traffic to Waylight is encrypted in transit (HTTPS/TLS). Session cookies are HttpOnly and Secure. Passwords, where used, are hashed by Supabase Auth and never visible to us in plain text. Email security@waylight.app to report a vulnerability — see §7 of our Terms of Service for our disclosure policy.
11. Children
Waylight is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.
12. Map and street data (OpenStreetMap)
Waylight's routes and comfort scores are built from © OpenStreetMap contributors data, licensed under the Open Database License (ODbL), plus municipal open-data sources credited in-app where used. This data describes streets and public infrastructure, not people, and is separate from the personal data described above. See our LICENSE for the ODbL derivative-database notice.
13. Changes to this policy
We'll update the date and version badge at the top of this page whenever this policy changes, and — for material changes affecting how we use your data — notify signed-in users in-app. The version stamp (e.g. LEG-2026-08-11) is recorded against your account when you accept our terms, so we always know which version you agreed to.
14. Contact
Privacy questions or requests: privacy@waylight.app
Security reports: security@waylight.app