Controller and contact
Guide Pup is operated by XIANMIN CHEN. For privacy questions, access requests, or deletion requests,
email charliehan112@gmail.com. Include enough detail to
identify the request, but do not email camera images, voice recordings, credentials, or medical details.
Data we process
Guide Pup processes sampled camera frames; image-derived environment-scanning data such as scene
classification, obstacles, surface, lighting, walkability, confidence, direction, and hazard level; an
installation-scoped device identifier and session token;
product interactions, request identifiers, latency and performance measurements, provider/model metadata,
guidance result classes, and sanitized errors. A support email may provide the sender's name, email
address, message, and voluntarily supplied troubleshooting details such as device, operating-system, app
build, permission, or failure information. The app does not require a user account and does not collect
financial, health, contacts, or location data in its current shipping path.
Why we process it
Camera frames support scene analysis and spoken guidance. Image-derived environment-scanning data supports
that app functionality and service-quality analytics; it is not used for tracking. Voice input supports
hands-free control. Installation and session identifiers support authorization and rate limiting.
Product-interaction, performance, and diagnostic metadata support reliability, abuse prevention,
troubleshooting, and service-quality analysis. Support contact information and message content are used
to respond to and manage support and privacy requests.
Camera and AI processing
The app samples frames rather than sending continuous video. Its JavaScript camera fallback converts a
frame to base64, attempts immediate deletion of temporary original and processed files with bounded
retries, and retries any in-memory cleanup queue on the next capture or session transition. If cleanup
still fails, the app exposes only a generic warning and pending-file count, never the local path. An
operating-system cache file may remain until a later retry or system cleanup. Frames are sent to the
Guide Pup backend and may be processed by OpenAI for vision analysis. Provider credentials remain
server-side. Guide Pup does not claim that provider copies are deleted immediately.
Voice and Apple Speech
Voice commands are optional and remain limited to a deterministic command set for guidance and settings.
Guide Pup prefers on-device Apple speech recognition when the device and locale support it. When they do
not, audio may be processed by Apple's speech-recognition service. Guide Pup does not collect or retain
raw voice audio. Apple states that third-party Speech
Recognition audio may be sent to Apple. Unless the user has enabled Improve Siri & Dictation, Apple says
the audio is not stored; transcripts and related request data associated with a rotating random identifier
may be retained for up to two years. Guide Pup does not intentionally log raw voice audio or send it to
the OpenAI vision provider.
Cloudflare observability
The Guide Pup backend runs on Cloudflare. Cloudflare may process network information and bounded request,
performance, and diagnostic data as a service provider. Guide Pup explicitly disables Cloudflare platform
invocation logs in development, staging, and production to avoid automatic header and request capture.
Sanitized custom request and quality logs remain enabled and may persist for up to 3 days on Free plans or
7 days on Paid plans. Because Guide Pup's account plan has not yet been verified, this policy
conservatively states custom-log retention of up to 7 days. Custom logs redact raw images, credentials,
authorization values, signed URLs, and installation identifiers. Cloudflare still processes network and
platform data to provide the service.
Retention and local deletion
Camera and speech buffers are handled transiently in the app, and in-app diagnostics keep only a small
in-memory history. The installation identifier and session token are stored with SecureStore, which uses
the iOS Keychain. iOS Keychain values may persist after the app is uninstalled, so Guide Pup does not
promise that uninstall deletes them. Backend session and rate-limit records expire. Cloudflare platform
invocation logs are disabled; sanitized custom request and quality logs may persist for up to 7 days
because the account plan is not yet verified. For Apple Speech Recognition, audio is not stored unless
Improve Siri & Dictation is enabled, while transcripts and related request data associated with a rotating
random identifier may be retained for up to two years. Under OpenAI's default API data controls,
abuse-monitoring logs may retain customer content for up to 30 days unless approved retention controls
apply. Support emails may remain in the support mailbox as needed to answer and manage the request; no
fixed support-retention period is promised. Guide Pup does not promise zero retention.
Your choices and requests
Camera and microphone permissions can be denied or revoked in iOS Settings, though core guidance or voice
control will then be unavailable. Uninstall may remove ordinary app-local data, but it does not reliably
delete the SecureStore/Keychain installation identifier or session token. You can
request deletion by emailing charliehan112@gmail.com.
Because Guide Pup has no account, we may need a request identifier or approximate time to investigate and
may be unable to associate a request with retained service data. You may also request deletion of your
retained support email and message.
No ads, tracking, or sale
Guide Pup does not use collected data for cross-app tracking, third-party advertising, developer
advertising or marketing, or product personalization, and does not sell personal data. If these practices
change, this policy and the App Store privacy answers must be updated before the change ships.
Safety limits
Guide Pup is assistive and may be delayed, incomplete, or wrong. It is not an emergency service, medical
device, mobility aid replacement, or substitute for a cane, guide dog, trained human assistance, traffic
signals, or personal judgment. Stop and seek human or emergency help whenever conditions are uncertain.
Service-provider policies
Learn more from
OpenAI API data controls,
Cloudflare Workers Logs,
Cloudflare's privacy policy, and
Ask Siri, Dictation & Privacy.
Those providers maintain their own terms and controls; links are provided for transparency and do not
replace this policy.