Legal

Security

Last updated July 20, 2026

We take the security of your account and data seriously. This page summarizes the practices that keep Guidepole safe to use, and how to reach us if you find a vulnerability.

Authentication

Guidepole has no passwords to steal. You sign in with a one-time code sent to your email or phone, or with Sign in with Apple or Google. We never store, transmit, or handle passwords — which eliminates entire categories of attack, from credential stuffing to password-database breaches.

Sessions use short-lived tokens that rotate. Signing out — or deleting your account — invalidates them.

Encryption

In transit. All traffic between the app or website and our servers is encrypted over HTTPS/TLS, and our website enforces HTTPS.

Storage and backups. Your data is stored on reputable managed cloud infrastructure in the United States, and we take regular encrypted backups kept separately from the primary database so we can recover from a failure.

Payments

Subscriptions are billed through Apple or our payment processor. We never see, store, or transmit your full payment card number — the app store and processor handle payment details directly.

Access & data isolation

Every request is scoped to the signed-in account, so one user cannot reach another user’s data. Administrative endpoints require staff-level authentication and are separated from the public API. Staff access to production data is limited to what is required to operate the service.

Location & data minimization

We collect only what the map and assistant need to work. Precise location is used only while you are actively using the app and only with your permission, and you can revoke it at any time in your device settings.

Abuse & rate limiting

Our API is rate-limited to protect the service and the upstream data providers we rely on, and responses are cached so normal use never amplifies load on external systems. We monitor for anomalous activity and errors.

Infrastructure

Guidepole runs on managed cloud infrastructure. TLS certificates are renewed automatically, so encrypted connections are never at risk of lapsing, and we keep our platform and dependencies patched.

Your controls

You can revoke location permission at any time in your device settings, and you can permanently delete your account and all associated data from within the app.

Deleting your account is irreversible and removes your data on our systems.

Responsible disclosure

If you believe you have found a security vulnerability, please email [email protected] with the details and steps to reproduce. We take all reports seriously and aim to respond within a few business days. Please do not access or modify other users’ data, and give us a reasonable chance to confirm and fix the issue before any public disclosure. We appreciate coordinated disclosure.