Last updated 12 September 2026

Privacy

Phoo helps you find toilets without creating an account or a movement history. This page explains the data used by the app and website, including maps, contributions and website analytics.

The short version

  • No account. There is nothing to sign into and no profile to build.
  • Location is requested only while the app is open, and your coordinates are never sent to a server to rank results.
  • No movement history is created, kept or derived.
  • No advertising, no trackers, no data sold or shared for marketing.
  • The app does not track how you use it. This website records page views without identifying visitors, and you can turn those analytics off below.
  • One random device identifier exists, used solely to rate-limit contributions. It is described below.

Location

Phoo asks for "While Using the App" location access only when it would improve the feature on screen. There is no background or "Always" permission, so a movement history cannot accumulate.

Walking distance and the nearby ordering are computed on the device, from the directory the app has already downloaded. Your position is not transmitted for that. When you select or open a specific toilet, the app asks Apple's maps framework for the street address nearest that toilet's pin, and for one walking estimate to that one destination. Both lookups describe the toilet's published position, not yours, and are handled by iOS under Apple's own privacy terms.

Declining location is a supported way to use the app, not a degraded one: you can search and move the map instead, and the app resolves which city you are looking at from the map rather than from you.

What our servers receive

The directory is served as a per-city snapshot: one public file, identical for everyone in that city. Requesting it tells our infrastructure that a device asked for that city's file at that time from an IP address, as any HTTP request does. It carries no user identifier or search terms, and we do not use it to build a profile.

The backend runs on Supabase in the EU (Ireland). Its logs exist for operating and securing the service and are kept for a short period.

Contributions

Confirming a detail, reporting a problem or suggesting a missing toilet sends exactly what the form shows: which listing, what kind of report, the proposed values, and an optional note. No account is created.

Those requests include a random identifier generated on first use and stored on the device. It is not derived from your hardware or shared with anyone; its only purpose is rate limiting and preventing abusive activity. Deleting the app discards it. It cannot be used to look up a person, because there is no person on file.

We keep contributor data to the minimum necessary and for a limited time. Reports are evaluated against other visitors' reports rather than published as free text, so nothing you send appears publicly as a review.

What is stored on your device

  • The last city's directory snapshot, in the system caches directory, so its listings can be read without a network. The system may evict it at any time and the app simply refetches.
  • A flag recording whether you opted into location.
  • The random contribution identifier described above.

This website

phoo.app consists of static files. There is no advertising pixel, no cookie set by us, and no third-party font or embed. Nothing on the page loads a script belonging to another company: the analytics described here use a short script of our own, and you can read all of it in the page source.

When you open a page, the site sends a page-view analytics event containing the page path, referring site, browser language and any campaign tag. It goes to TelemetryDeck, based in Augsburg, which processes it for us. We send no cookies or other identifiers. TelemetryDeck derives a visitor number from the request address and browser information, combined with a value that changes daily. Your number changes daily, so today’s visit is not connected to tomorrow’s.

One thing is removed before anything leaves. The access card stores its settings in the address bar, and one setting can describe why you need a toilet. Before data is sent, the address is rebuilt from the path alone, so that setting never travels. Neither does anything typed into the tools here.

The browser tools — the phrasebook and the access card — run entirely on your device. The language you pick and any name you type stay in the page.

Two things are kept in your browser, both in local storage on your device, and we never see either: whether you chose light or dark, and whether you turned analytics off. If your browser sends Global Privacy Control or Do Not Track, analytics stay off and the switch below has no effect.

This preference is saved in this browser, on this device. Clearing site data removes it. Analytics are on by default in a different browser.

Your rights

Under the GDPR you have rights of access, correction, deletion, restriction, objection and portability. Because Phoo holds no account or identifiable profile, there is usually no profile to retrieve. That is intentional by design.

If you have sent a contribution and want it removed, write to us with enough detail to find it and we will delete it. For anything else about this policy, the same address reaches a person.

Children

Phoo is not directed at children and collects nothing that would identify one. The app is usable by anyone without an account or a sign-up.

Changes

If this policy changes in a way that affects what the app or this site does with data, the date at the top changes and the change is described on this page rather than applied quietly.

Not on the App Store yet

Bring Phoo along

Get the App Store link when Phoo launches, then occasional news about new cities and useful additions.

We use Kit to send these emails. Unsubscribe at any time.

Need help signing up? Email hello@phoo.app.