Nowhere in Particular

Privacy Policy

Your precise location never leaves your device. The app asks you once, on first run, whether to share your finds — and what it shares carries no name and no account, only a cohort code that changes every month.


The short version

There is no account, no sign-up, and no Clapham Digital server. We cannot see who you are, where you are, or where you have been, because none of that is ever sent to us.

The app needs your location to do the one thing it does — work out the direction and distance from you to a place. That calculation happens on your phone. The result is a compass heading. Nothing about your position is transmitted anywhere.

Location

Used on your device. Never transmitted. The app reads your GPS position to compute the bearing and range to your destination, and to recognize when you have arrived. That is the entire purpose and the entire use.

Your coordinates are not logged to a server, not attached to anything shared, and not retained by us in any form. Denying location permission will stop the game working, because a bearing from an unknown position is not a thing that exists.

What stays on your phone

All of the following is stored locally and never leaves the device:

  • Your drive and attempt history
  • Which places you have found, and how you did
  • Any photos you take in the app
  • Your settings, including your home location

Delete the app and this goes with it.

Sharing — we ask you once, up front

The app has an optional shared layer that lets you see how other players have got on at a place — whether anyone has found it, whether it turned out to be a dud. The app asks you about it once, on first run, before it has published anything at all. Two answers, given equal weight on the screen: share your finds, or not this time. Neither is pre-selected and neither is styled to be the one you press.

Nothing is published before you have answered, and nothing is published ever if you answer no. You can change your mind either way, whenever you like, in the log — and records from drives you took while sharing was off are discarded, not held back and released later.

When it is on, a completed attempt publishes exactly this and nothing else:

  • which marker it was
  • how the attempt ended — found, arrived, not found, or reported as a dud
  • if a dud, which kind
  • a coarse efficiency figure and a count of hints used
  • the day
  • a broad region and cohort, used to group results

There is no name, no account, no advertising identifier, and no coordinate in that record. An in-progress run is never published, because a run in flight is a person who is currently somewhere.

The one identifier it does carry is the cohort, and it is worth being exact about what that is. Only a single feature needs identity at all — counting distinct drivers, so the map reads as populated rather than merely busy. So the cohort is a random value generated on your install and re-hashed every month. Within a month the driver count is honest. Across months, the records cannot be assembled into one person’s travel history, because the value they share has already changed. The residual, stated rather than waved away: inside a single month, someone with access to the store could group one install’s records and infer a rough area of operation. That is the price of the driver count, it is bounded to 31 days, and it is the only identity the record has.

The cohort is what the App Store privacy label calls a Device ID, declared as collected and not linked to your identity. We say so here because the two descriptions should agree, and because “Device ID” sounds heavier than what it is: a random number made on your install, not your phone’s serial, not an advertising ID, and not your Apple account.

Where shared records go

The shared layer uses Apple CloudKit's public database. We do not run a server; Apple does, and their handling is governed by Apple's privacy policy. As with any CloudKit public database, Apple associates a saved record with a per-app identifier for the account that wrote it. That identifier is not visible to us and is not your Apple ID.

Two things worth knowing before you say yes. Records on a public database are readable by the app's other users, which is the point of the feature. And switching sharing back off stops all future publishing but does not retract records already written.

We should be straight about what that second one means, because it is the one place where a privacy feature and a privacy right pull against each other. A record carries no name and no account, and the one identifier it does carry — the month’s cohort code — is a random value with no link to a person, so we cannot look up “your” records. That is not an oversight we are apologizing for; it is the same property that makes the record harmless in the first place, and we would have to collect more about you, not less, to be able to honour a lookup.

What we can do, and will: tell us the place and the day and we will delete every record matching that description. We cannot verify which of them was yours, and we are not going to ask you to prove it — deleting a few extra anonymous rows costs nobody anything.

What we don't do

  • No accounts or sign-ups
  • No advertising and no ad identifiers
  • No third-party analytics or tracking SDKs in the app
  • No selling or sharing of data with anyone
  • No crash reporting that carries personal data

Children

The app is not directed at children under 13 and collects no personal information from anyone, of any age.

Changes and contact

If the data practices above ever change, this page changes with them and the date below is updated. This policy covers Nowhere in Particular specifically; other Clapham Digital apps are covered by the general policy.

Questions, or a removal request: [email protected].

Last updated: August 2026


The marker data is public too.

The open corpus → About the app →