whimsee

how we care for your data

This is where we explain, plainly, what we do with your data. The short version: we ask for as little as we can, we never sell it, and we never share it for advertising.

Whimsee is run by Whimsee Ltd, company no. 17353256, registered in England and Wales. For any privacy question, or to use any of your rights below, write to us at privacy@whimsee.co.uk.

What we collect, and why

Only what a wander needs, and for each one there is a clear legal basis under UK GDPR. Here is the whole of it:

  • Your email, if you join the waitlist or link it to your account. The waitlist one lets us send you a note when it is your turn, and we keep it with your consent. The account one lets you sign in across devices and keep your glimmers safe, and we hold it to give you the service you asked for (our contract with you). You can withdraw either at any time.
  • A nature name and an emoji you pick. That is your whole identity here, held to run the service for you. We never ask for your real name. For a child profile, a parent sets it up and consents through their own account.
  • A fuzzed sense of where you are, to play the hotter and colder of the wander. We rely on our contract with you to provide that, and we never store your exact position. More on this just below.
  • The glimmers and notes you leave. This is the heart of the thing, held to run the service.
  • Invite and referral codes, if a wanderer shares one with you, part of giving you access to the service.
  • Flags and moderation. If you flag something, a keeper looks and may hold or remove content. We do this in our legitimate interest in keeping whimsee kind, and to meet our legal duty to act on illegal or harmful content.
  • A little analytics (through PostHog, EU cloud), so we can see whether the wander loop actually works. A plain, anonymous count runs for everyone in our legitimate interest, and it stores nothing on your device. Only if you say yes to the banner do we also recognise you across visits, and that part is with your consent. No ad trackers. Never sold. More just below.

We practise data minimisation: we ask for as little as possible, and we never sell your data or share it for advertising.

Your location

Your location powers the wander, but we only ever use a fuzzed warm-zone, an approximate area, never your exact position, and we do not store precise coordinates. Your location is never shown to other people as a point on a map. There is a clear indicator whenever location is in use.

Cookies, and what sits in your browser

We do not use advertising or cross-site tracking cookies, ever. Here is what actually sits in your browser or on your device:

  • An anonymous count (PostHog, EU cloud). By default we keep a plain count of how the wander is going that stores nothing on your device, so it needs no cookie. It reads your address only to work out a rough location and count the visit, in our legitimate interest in knowing whether the product works, and it never builds a profile or follows you across sites.
  • Recognising you across visits (only if you say yes). Say "that's fine" on the banner and we also keep a first-party id, some session info, and a small feature-flag cache, so we can recognise you across visits. Only to see whether the wander works. Never for ads, never across other sites.
  • Staying signed in (Supabase). Your sign-in token is kept in your browser so you do not have to sign in on every visit. This one is strictly necessary.
  • On the app, there are no cookies at all. The analytics queue lives in the app's own on-device storage.

The anonymous count needs no consent, because it touches nothing on your device. The little first-visit banner asks only about the extra layer that recognises you across visits. Say "no thanks" and only the anonymous count remains, alongside the strictly necessary sign-in token. To change your mind later, clear this site's data and the banner will ask again.

Children

The open wander app is for grown-ups, 18 and over. Children come to Whimsee only in two gentle, supervised ways:

  • With a family. A parent or guardian creates and looks after a child profile (a nature name and emoji, no email). The parent's consent, given through their own verified account, is the basis for it. The parent chooses what their child sees, family-safe by default, and okays anything their child wants to make public.
  • At school. A teacher runs a closed trail. Children hold no accounts, and we store no personal data about them. The school is the data controller.

We collect the least we can about children, never profile them, never use nudges, and there is no private messaging anywhere in Whimsee, so no one can privately contact a child. You can read our safeguarding policy too.

For younger wanderers, the short version 🌱

  • Whimsee helps you find little wonders hidden in real places.
  • We use where you are to play hotter and colder, but only roughly, never the exact spot, and we do not keep it.
  • We only know a nature name and an emoji you pick, never your real name.
  • A grown-up looks after your profile, decides what you can see, and checks anything you want to share before others can find it.
  • No one can message you on Whimsee. There is no chat at all.
  • You can ask your grown-up to delete everything whenever you want.
  • If something ever feels not okay, tap flag, and a kind keeper will look.

Who helps us run Whimsee

A small number of trusted services, each under a data-processing agreement, and no one else:

  • Supabase, our database, sign-in and storage (EU region, Stockholm).
  • PostHog, product analytics (EU cloud).
  • Brevo, sending email (EU).
  • Expo, building the app and its updates.
  • Cloudflare, serving the website (its edge network; visitor addresses pass through in transit).

We do not sell data, and we do not use advertising trackers.

Keeping it in safe places

Most of your data stays in the UK and EU. Our database, sign-in and storage are in the EU (Stockholm), our analytics and email-sending are EU-hosted, and our mailboxes are UK-hosted. Two of the services that run our infrastructure, Cloudflare (which serves the website) and Expo (which builds the app), are US companies. Where data passes through them, transfers rely on UK-recognised safeguards: the UK extension to the EU-US Data Privacy Framework and the UK International Data Transfer Agreement, set out in their data-processing terms.

How long we keep it

Only as long as it is needed. Waitlist emails until launch and a short while after, then deleted. Account data while your account exists, and a parent can delete a child's profile and its data at any time. Our analytics are deliberately lean, anonymous on the web and only a nature name on the app, and our policy is to keep them for no longer than 12 months. Our analytics provider may hold raw logs longer, but we do not use anything older, and you can ask us to delete your data at any time.

Your rights

Under UK GDPR you can access, correct, delete, restrict, object to, or port your data, and withdraw consent at any time. To use any of these, write to privacy@whimsee.co.uk and we will respond within one month. You can also complain to the ICO (ico.org.uk, 0303 123 1113), though we would love the chance to put things right first.

Changes

We will post any changes here, and for anything material we will tell you in the app. This is our notice while we finish our formal registration.

Last updated: July 2026.

← back to the wander