For members For hosts For venues Guidebook Support Try it on your phone
  • For members
  • For hosts
  • For venues
  • Guidebook
  • Support
  • Try it on your phone

Privacy policy

Last updated 11 October 2026. Operated by Wanderist LLC, a Massachusetts limited liability company.

This describes what the Wanderist app and this website collect, why, and who else sees it. It is written to be read rather than to be technically unfalsifiable, so where something is a deliberate choice we say what the choice was.

The short version

  • We never see your card details. Payments go through Stripe's own checkout.
  • We never see your identity documents. Verification is run by Stripe; we store only whether it passed.
  • If you claim a venue, the business document you send to prove it is seen only by our team, and deleted 30 days after we decide. See Venue claims.
  • We never read your phone's contacts. "Emergency contacts" means friends you picked inside the app.
  • Your live location is shared only with contacts you chose, only while you are checked in to an Outing.
  • We do not sell your personal information. Advertisers pick interests and a distance; they never receive a list of people.
  • This website sets no cookies and runs no analytics or trackers. The app does use advertising identifiers — see Advertising. The App Preview in your phone's browser uses one Google reCAPTCHA cookie to keep automated abuse out, and no advertising identifiers — see The App Preview.

What we collect

What you give us

  • Account: email address and password, or your Apple or Google sign-in.
  • Date of birth, to enforce the 18+ requirement. Stored privately — other members never see it.
  • Profile: display name, photo, bio, and interest tags. You can mark interests as private; private ones are hidden from other people but still used to decide what you're shown.
  • Content: Outings you create, chat messages, photos you add to Outing albums, ratings, and reports you file.
  • Venue claims, if you make one: which venue, your role there, and how you proved you run it. That is either a code we give you, which you add to the venue's website or to its domain's DNS for us to check, or up to three photos or PDFs of a document naming the business at that address — a business licence, a utility bill or a page of the lease — with an optional note. We ask for a document about the business, not about you, so please don't send an ID. Only you and our team can open the files you send. Once a claim is approved, what you add to the venue's listing — a description, a photo, corrections to its website and phone number, and its events calendar — is public, like the rest of the listing.
  • Launch updates, if you ask for them: if you enter your email address to hear about the public beta or the launch, we store that address and where on the site you entered it. This is separate from an account — you can join the list without having one, and joining it does not create one. We use it only to write to you about Wanderist's own progress: the beta, new features, and the launch. We do not sell or share it, and every message we send carries an unsubscribe link. You can also ask us to remove you at any time by writing to support@wanderist.io.

What your device provides

  • Location. An approximate location decides which Outings you're shown and where your own Outings appear. If you turn on safety sharing, a precise location is shared with your chosen emergency contacts while you are checked in to an Outing and at no other time.
  • Notification token, so we can send you push notifications.
  • Photos and camera, only when you pick or take one, and for hosts scanning entry codes at an event.
  • Files, only a document you pick to prove you run a venue.
  • Calendar, write-only, and only when you ask to add an Outing to it.
  • Face ID / Touch ID, if you enable the app lock. The biometric check happens on your device; we receive only a yes or no.

What the system produces

  • Attendance and check-in records, which is what badges like Regular are built from.
  • For hosts: a host score computed from hosting activity, attendance and ratings, which sets your tier.
  • For paid events: purchase records.
  • Whether your identity verification passed, and when.

What we deliberately do not collect

Not collectedWhy it matters
Card numbers and payment detailsPaid events use Stripe's hosted checkout. Card data never enters the app or our servers.
Identity documents and selfiesStripe Identity runs the check and holds the documents. We store the result — verified or not — and nothing else. Proof that you run a venue is a document about the business, not an identity document; see Venue claims.
Your phone's contactsThe app never requests contacts access. Emergency contacts are people you already have as friends in the app.
Health, financial-account or browsing dataNot collected in any form.

Who else sees your information

We use these providers to run the service. Each receives only what its job needs.

  • Google Firebase — sign-in, database, file storage, push notifications and server functions. This is where your account and content are stored.
  • Stripe — payments, host payouts and identity verification, under Stripe's own privacy policy.
  • Google Places — venue search when creating an Outing. Your search text and approximate location are sent to find nearby venues.
  • Google AdMob — advertising in the app. See below.
  • Google Cloud Vision and Web Risk — automatic screening of images before they are shown: Outing cover photos, venue photos, advertisers' images, and album photos someone has reported. Web Risk checks advertisers' links.
  • Google Vertex AI — an automatic check of text written for everyone to see before it appears: a venue's description, and an interest tag before it is offered to other members as a suggestion. It receives the text, and for a description the venue's name, but not who wrote it.
  • Apple — Sign in with Apple, and push delivery on iPhone.
  • Google Play services — push delivery and app integrity checks on Android.
  • Google reCAPTCHA Enterprise — checking that the App Preview is being used from a real browser. See The App Preview.
  • Google Maps — the map view in Explore, in the App Preview.

We do not sell your personal information, and we do not share it with advertisers. An advertiser selects interest tags and a radius; our systems decide who matches. The advertiser receives counts and performance figures, never identities.

We may disclose information if the law requires it, or where we believe it is necessary to prevent serious harm.

Advertising

The app shows ads, including through Google AdMob. AdMob uses device advertising identifiers, which counts as tracking under Apple's definition — which is why iOS asks your permission before it happens. On Android, the advertising ID is controlled in your phone's settings, where you can reset or delete it. Whichever you choose, the app works exactly the same; you'll see less relevant ads. Your interest tags are also used to decide which of our own campaigns to show you.

Paid placements are always labelled Sponsored or Promoted.

The App Preview

The App Preview at app.wanderist.io is Wanderist in your phone's browser. It collects the same information the app does, as described above, and differs in these ways:

  • Browser storage. To keep you signed in, your sign-in session is stored in your browser. A few preferences are stored there too — such as your Explore search area, and which of our own placements you have seen recently, so the same one does not keep coming round. Signing out ends the session; clearing your browser's data for app.wanderist.io removes the rest.
  • One Google cookie. To keep out automated sign-ups and abuse, the App Preview checks it is running in a real browser using Google reCAPTCHA Enterprise. reCAPTCHA sets a cookie and sends Google information about your browser and how the page is used. Google uses it under its own Privacy Policy and Terms.
  • Maps. If you open the map in Explore, the map is loaded from Google Maps, which receives your IP address and the area being shown.
  • No advertising identifiers. The App Preview runs no third-party ad network and no analytics. The only placements in it are our own, labelled Sponsored or Promoted.
  • Location and notifications come from your browser's own permissions, and you can withdraw either in your browser's settings at any time.

The wanderist.io website you are reading now is separate, and still sets no cookies at all.

What other members can see

  • Public: your display name, photo, bio, public interest tags, badges, and the Outings you host.
  • Private, always: your email address, date of birth, private interest tags, block list, and exact location.
  • Venues you run: a venue you have claimed shows what you added and a Verified venue mark. It doesn't show who claimed it, and your claims and the documents you sent stay private.
  • Blocking is silent. The person you block is not told. You disappear from each other's app in both directions.

Where your information is stored

On Google Cloud infrastructure in the United States. If you use the app from elsewhere, your information is transferred to and processed in the US.

How it is protected

Traffic is encrypted in transit, and stored data is encrypted at rest. Database access is deny-by-default — every read and write is checked against server-side rules, and fields that must not be forged (verification status, payment state, host tier, attendee counts) can only be written by our servers, never by an app. Sensitive operations run through server functions that require Apple's App Attest on iPhone or Google Play Integrity on Android, so a modified client cannot invoke them. In the App Preview the same functions require Google reCAPTCHA Enterprise, which makes automated misuse harder but is a weaker check than a phone's — so the server checks that do not depend on it apply there too. You can add a PIN, Face ID or fingerprint lock on the app itself, separate from your phone's.

Chat messages are not end-to-end encrypted. They are encrypted in transit and at rest, but we are able to read them — and we will, when someone reports a message, when we are looking into a safety concern, or where the law requires it. We do not read them otherwise. We are telling you this plainly because the alternative would mean we could not act on a report, and being able to act on reports is part of how we try to keep meeting strangers safe.

No system is perfectly secure, and we won't claim otherwise.

How long we keep it

Your account content is kept while your account exists. When you delete your account, most of it goes immediately — see deleting your account, which sets out exactly what is removed and what is not.

Three categories deliberately outlive the account:

  • Reports about other people. If deleting an account erased the reports made from it, anyone could erase evidence of their own behaviour by closing their account.
  • Transaction records, for as long as tax and financial regulations require.
  • A venue's history. We keep a record of each decision on a venue claim and each change made to a venue's listing — what changed, when, and from which account — so there is always an answer to who changed a business's listing, and why a claim was decided the way it was.

Venue claim proof is deleted 30 days after we decide on the claim, or straight away if you cancel a claim that is still waiting. If you delete your account, your claims and their proof go with it, and a venue you ran goes back to unclaimed. The description and photo you added to it are removed. Corrections to its website and phone number stay, and so does an events calendar you connected, because they are facts about the venue rather than about you.

The launch-updates list is kept separately from accounts and outlives them in the other direction: unsubscribing removes you from the mailing list but leaves your account untouched, and deleting your account does not by itself remove an address you gave us before you had one. Ask us to remove it and we will.

Your choices

  • Location: revoke it in your phone's settings at any time. Discovery is proximity-based, so the feed becomes much less useful without it.
  • Tracking: on iPhone, decline the prompt or change it in iOS Settings; on Android, reset or delete your advertising ID in Settings → Privacy → Ads.
  • Notifications: turn off in your phone's settings; promoted notifications have their own opt-out inside the app.
  • Safety sharing: entirely opt-in, and you choose who.
  • Private interests: mark any interest private so it is not shown on your profile.
  • Access, correction and deletion: most is editable in the app. For anything else, email support@wanderist.io and say what you want. Depending on where you live you may have additional legal rights, and we will honour them.

Children

Wanderist is for adults. We ask for date of birth at sign-up and do not permit accounts for people under 18. If you believe a minor has an account, tell us and we will remove it.

Changes

If this policy changes materially we'll say so in the app before the change takes effect, rather than quietly updating the date at the top.

Contact

support@wanderist.io

Wanderist

  • For members
  • For hosts
  • For venues
  • Guidebook
  • Support

Legal

  • Privacy
  • Terms
  • Delete your account

Follow

Wanderist LLC, a Massachusetts limited liability company · support@wanderist.io

This site sets no cookies and contains no trackers or analytics.