Guide Pup Privacy

Effective August 2, 2026

Guide Pup Privacy Policy

Guide Pup provides assistive scene guidance using sampled camera frames, optional voice commands, and bounded service diagnostics. This policy explains what leaves the device, why it is processed, and the limits of current retention controls.

Controller and contact

Guide Pup is operated by XIANMIN CHEN. For privacy questions, access requests, or deletion requests, email charliehan112@gmail.com. Include enough detail to identify the request, but do not email camera images, voice recordings, credentials, or medical details.

Data we process

Guide Pup processes sampled camera frames; image-derived environment-scanning data such as scene classification, obstacles, surface, lighting, walkability, confidence, direction, and hazard level; an installation-scoped device identifier and session token; product interactions, request identifiers, latency and performance measurements, provider/model metadata, guidance result classes, and sanitized errors. A support email may provide the sender's name, email address, message, and voluntarily supplied troubleshooting details such as device, operating-system, app build, permission, or failure information. The app does not require a user account and does not collect financial, health, contacts, or location data in its current shipping path.

Why we process it

Camera frames support scene analysis and spoken guidance. Image-derived environment-scanning data supports that app functionality and service-quality analytics; it is not used for tracking. Voice input supports hands-free control. Installation and session identifiers support authorization and rate limiting. Product-interaction, performance, and diagnostic metadata support reliability, abuse prevention, troubleshooting, and service-quality analysis. Support contact information and message content are used to respond to and manage support and privacy requests.

Camera and AI processing

The app samples frames rather than sending continuous video. Its JavaScript camera fallback converts a frame to base64, attempts immediate deletion of temporary original and processed files with bounded retries, and retries any in-memory cleanup queue on the next capture or session transition. If cleanup still fails, the app exposes only a generic warning and pending-file count, never the local path. An operating-system cache file may remain until a later retry or system cleanup. Frames are sent to the Guide Pup backend and may be processed by OpenAI for vision analysis. Provider credentials remain server-side. Guide Pup does not claim that provider copies are deleted immediately.

Voice and Apple Speech

Voice commands are optional and remain limited to a deterministic command set for guidance and settings. Guide Pup prefers on-device Apple speech recognition when the device and locale support it. When they do not, audio may be processed by Apple's speech-recognition service. Guide Pup does not collect or retain raw voice audio. Apple states that third-party Speech Recognition audio may be sent to Apple. Unless the user has enabled Improve Siri & Dictation, Apple says the audio is not stored; transcripts and related request data associated with a rotating random identifier may be retained for up to two years. Guide Pup does not intentionally log raw voice audio or send it to the OpenAI vision provider.

Cloudflare observability

The Guide Pup backend runs on Cloudflare. Cloudflare may process network information and bounded request, performance, and diagnostic data as a service provider. Guide Pup explicitly disables Cloudflare platform invocation logs in development, staging, and production to avoid automatic header and request capture. Sanitized custom request and quality logs remain enabled and may persist for up to 3 days on Free plans or 7 days on Paid plans. Because Guide Pup's account plan has not yet been verified, this policy conservatively states custom-log retention of up to 7 days. Custom logs redact raw images, credentials, authorization values, signed URLs, and installation identifiers. Cloudflare still processes network and platform data to provide the service.

Retention and local deletion

Camera and speech buffers are handled transiently in the app, and in-app diagnostics keep only a small in-memory history. The installation identifier and session token are stored with SecureStore, which uses the iOS Keychain. iOS Keychain values may persist after the app is uninstalled, so Guide Pup does not promise that uninstall deletes them. Backend session and rate-limit records expire. Cloudflare platform invocation logs are disabled; sanitized custom request and quality logs may persist for up to 7 days because the account plan is not yet verified. For Apple Speech Recognition, audio is not stored unless Improve Siri & Dictation is enabled, while transcripts and related request data associated with a rotating random identifier may be retained for up to two years. Under OpenAI's default API data controls, abuse-monitoring logs may retain customer content for up to 30 days unless approved retention controls apply. Support emails may remain in the support mailbox as needed to answer and manage the request; no fixed support-retention period is promised. Guide Pup does not promise zero retention.

Your choices and requests

Camera and microphone permissions can be denied or revoked in iOS Settings, though core guidance or voice control will then be unavailable. Uninstall may remove ordinary app-local data, but it does not reliably delete the SecureStore/Keychain installation identifier or session token. You can request deletion by emailing charliehan112@gmail.com. Because Guide Pup has no account, we may need a request identifier or approximate time to investigate and may be unable to associate a request with retained service data. You may also request deletion of your retained support email and message.

No ads, tracking, or sale

Guide Pup does not use collected data for cross-app tracking, third-party advertising, developer advertising or marketing, or product personalization, and does not sell personal data. If these practices change, this policy and the App Store privacy answers must be updated before the change ships.

Safety limits

Guide Pup is assistive and may be delayed, incomplete, or wrong. It is not an emergency service, medical device, mobility aid replacement, or substitute for a cane, guide dog, trained human assistance, traffic signals, or personal judgment. Stop and seek human or emergency help whenever conditions are uncertain.