Privacy Policy
Last updated 2 August 2026 · Applies to the Waylight web app, the Waylight mobile app, and the Waylight API.
Waylight helps you plan walking and cycling routes that account for real, measured conditions — lighting, surface, shade, traffic — rather than just distance and time. This page explains what personal data we collect to do that, why, and what control you have over it.
1. What we collect
| Data | When | Why |
|---|---|---|
| Email address | You create an account | Sign-in (magic link / password), account recovery, service emails |
| Display name | You create an account or set one | Shown to you in the app; shown to other users only if you enable presence-sharing (see below) |
| Saved places (home, work, starred), and recent searches | You save or search a place while signed in | Personalize routing and let you return to places quickly across devices |
| Onboarding answers (e.g. preferences you choose during setup) | You complete onboarding | Personalize default route preferences |
| Current location (GPS coordinates) | Every time you request a route or ask the assistant something | Compute a route from where you actually are; see §2 |
| Sign-in metadata (approximate timing, not IP-logged by us beyond standard hosting logs) | Every sign-in | Security alerting for account owners; see §5 |
We do not collect payment information (Waylight has no paid tier at this time), government ID, or biometric data.
Correcting a previous version of this notice: saved places and recent searches for a signed-in account are stored on our servers (in our database), not only on your device, so that they follow you across devices. If you never create an account, nothing you save can leave your device, because there is nowhere signed-out data is sent.
2. Location data
Waylight is a location app; location is core to what it does. Specifically:
- Route requests. Your current coordinates are sent with each route-planning request so the server can compute a real route from your position. This request is processed to return a result and is not stored as a standing location history.
- The AI assistant. When you type a free-text request ("somewhere calm, I have 40 minutes"), your current coordinates are included in that request — see §3 for what that involves.
- Presence sharing (opt-in, off by default). If you turn this on, your live coordinates are published so other signed-in nearby users can see you're out walking/cycling. This is independent of whether you're signed in — signing in does not turn it on by itself, and you can turn it off at any time in Settings. Published presence expires automatically (currently after about 12 minutes of inactivity) and is not retained as history.
3. AI-assisted route planning
When you type a free-text request instead of using structured filters, that text plus your current coordinates are sent to our server, which forwards them to Infomaniak AI Services ("Euria") — a Swiss-hosted platform running open Mistral-family language models — solely to convert your sentence into a structured route intent (e.g. destination, preferences, time budget). The AI's only job is that translation; the actual route, distances, comfort scores and explanations you see are computed by Waylight's own routing and scoring engine from real map and city data, not generated by the AI.
This is genuinely optional: every feature Waylight offers is also reachable through structured filters and buttons that never touch an AI model. If you never use the free-text assistant, this section doesn't apply to you.
We do not use your requests to train our own models. For how Infomaniak processes API requests on their infrastructure, see Infomaniak's privacy policy. Switzerland has an EU adequacy decision, meaning the EU has determined it offers a comparable level of data protection — no additional transfer safeguards are required to send data there.
4. Cookies and local storage
Waylight uses a single essential cookie, wl_session, to keep you signed in (HttpOnly, Secure, 45-day expiry). It is strictly necessary for the service to function when you're signed in and is not used for advertising, analytics, or cross-site tracking — so it does not require a consent banner under EU ePrivacy rules. We also store some non-sensitive preferences (like theme) in your browser's local storage, which never leaves your device.
5. Who we share data with
We use a small number of infrastructure providers to run Waylight. Each processes only what's needed for its function, under its own terms:
| Provider | Purpose | What it sees |
|---|---|---|
| Supabase | Account database and authentication | Email, display name, saved places, recents, onboarding answers |
| Vercel | Hosting, edge network, serverless functions | Standard request/hosting logs for every request to waylightapp.site |
| Infomaniak AI Services (Euria) | Free-text route request parsing (opt-in by usage — see §3) | Your typed text and current coordinates, per request |
| Resend | Transactional email (magic links, security alerts) | Your email address, when an email needs to be sent |
| OpenStreetMap Nominatim & Photon (Komoot) | Turning place names into coordinates and back | The place name or coordinates you search |
| FOSSGIS OSRM | Turn-by-turn route geometry | Origin/destination coordinates for a route |
| CARTO | Base map tiles | Map viewport coordinates (standard for any map tile request) |
| Open-Meteo | Weather and elevation data | Coordinates along a route |
| Cloudflare Turnstile | Bot protection on some forms, when enabled | Standard bot-verification signals; see Cloudflare's own privacy policy |
We do not sell personal data, and we do not share it with advertisers.
6. International transfers
Depending on each provider's own infrastructure, processing may occur inside or outside the EU/EEA. Switzerland (Infomaniak) has an EU adequacy decision. Where a provider processes data outside the EEA without an adequacy decision, we rely on that provider's own standard contractual clauses or equivalent safeguards — see the individual providers' privacy policies linked above.
7. How long we keep data
- Account data (email, saved places, recents, onboarding) is kept for as long as your account exists.
- Session cookies expire automatically after 45 days.
- Presence data expires automatically after roughly 12 minutes and is not retained as history.
- Route-planning requests (including AI-assisted ones) are processed to return a result and are not retained as a standing log tied to your identity.
You can delete your account and all associated data at any time from Settings → Account → Delete account, or by emailing privacy@waylight.app. Deletion is immediate and permanent.
8. Your rights
If the GDPR applies to you, you have the right to: access the data we hold about you; correct it; delete it (see §7); export it in a portable format; restrict or object to certain processing; and withdraw consent for anything based on consent (like presence sharing) at any time. To exercise any of these, email privacy@waylight.app — we'll respond within one month. You also have the right to complain to your local data protection authority.
9. Security
Traffic to Waylight is encrypted in transit (HTTPS/TLS). Session cookies are HttpOnly and Secure. Passwords, where used, are hashed by Supabase Auth and never visible to us in plain text. Email security@waylight.app to report a vulnerability — see §6 of our Terms of Service for our disclosure policy.
10. Children
Waylight is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.
11. Map and street data (OpenStreetMap)
Waylight's routes and comfort scores are built from © OpenStreetMap contributors data, licensed under the Open Database License (ODbL), plus municipal open-data sources credited in-app where used. This data describes streets and public infrastructure, not people, and is separate from the personal data described above. See our LICENSE for the ODbL derivative-database notice.
12. Changes to this policy
We'll update the date and version badge at the top of this page whenever this policy changes, and — for material changes affecting how we use your data — notify signed-in users in-app. The version stamp (e.g. LEG-2026-08-02) is recorded against your account when you accept our terms, so we always know which version you agreed to.
13. Contact
Privacy questions or requests: privacy@waylight.app
Security reports: security@waylight.app