Pew · Privacy

Pew privacy notice

How Pew uses location, photos, local app data, mapping and weather services.

Status
Current
Effective
25 September 2026
Last reviewed
25 September 2026
Product status
In development

Scope

This notice applies to the public Release version of Pew for iPhone and iPad. Pew is a local-first exploration journal. It does not require a Netro Labs account and does not contain a Netro Labs analytics, advertising or crash-reporting SDK.

Pew is not a healthcare or emergency service and does not process health data as part of its intended operation.

Data used on the device

Depending on the features a user chooses, Pew can use:

  • while-in-use location to show nearby candidate benches, assess location freshness and accuracy, validate a visit and request a walking route;
  • a photo selected through the iOS or iPadOS system photo picker;
  • optional visit notes, saved places, claim history and Atlas progress; and
  • display name, onboarding state, preferences and comfort settings.

These records are stored inside the app’s local container or local preferences. Pew does not upload a profile, visit history, notes, selected photos or sampled GPS history to Netro Labs. Claim records do not retain the user’s sampled GPS coordinates.

Pew’s internal Experimental Discovery tools are not available in the public Release version.

External services

Pew uses Apple platform services and limited public-data services when the corresponding feature is used:

  • Apple MapKit displays maps. When a user asks for walking directions, Apple processes the route endpoints and ordinary network information needed to return the route.
  • Apple WeatherKit provides weather for the centre of the selected public area, not the device’s precise live location.
  • MET Norway may provide the same area-centre weather information when WeatherKit is unavailable. MET Norway receives that public area coordinate and ordinary network information needed to return the forecast.
  • OpenStreetMap supplies candidate bench geometry in a bounded offline snapshot included with the app. Pew does not send a user’s location or journal data to OpenStreetMap during normal app use.
  • OpenBenches supplies a minimal offline corroboration subset containing public source identifiers, coordinates, dates and links. It excludes inscriptions, uploader identifiers and photographs. Pew does not contact OpenBenches during normal app use.
  • Apple iCloud (CloudKit public database). When you open a bench, Pew may ask Apple’s iCloud for any shared, moderated answers about that bench. The request identifies the bench, not you, and does not need you to be signed in to iCloud. The public Release version does not upload your own bench answers, notes or location to iCloud.
  • Pew plotted-bench manifest. When you open Pew it may download one public file listing benches added since the app was last updated, so new benches can appear without an app update. The request is anonymous: it sends no account, no identifier and no location, and asks for the same file for everybody. Pew works fully without it — if the download fails, or you are offline, the app carries on with the benches it already has. As with any web request, the hosting provider may record the connection in its ordinary server logs.

Pew caches returned weather information locally. Opening an external attribution or source link is an explicit user action and is then handled by the selected browser or system service under its own privacy terms.

Sharing and support

Pew does not sell personal information and does not include a public sharing network.

“Report a problem” prepares a public place name, Pew source identifier and mapped coordinate in the iOS share sheet. Pew does not send the report automatically; the user chooses whether to share it and which destination receives it.

After answering “Is this bench here?”, a user can choose Send my bench notes to Pew in Settings. This prepares a file in the iOS share sheet containing, for each answered bench: the bench’s public name and position, the answer, whether the user was at the bench, the distance from the mapped position, any corrected position where the user was standing, the time, any note and the random identifier described below. Nothing is sent unless the user chooses a destination. If it is sent to Netro Labs (for example by email), Netro Labs receives it together with the sender’s contact details and uses it only to correct and verify bench records.

If shared answers are shown for a bench, a user can flag them for review. A flag is sent to Pew’s container in Apple’s iCloud and contains the bench identifier, the chosen reason, the time and a random identifier created on the device (a full reset of Pew replaces it). It does not contain a name, email address or location. Apple associates the record with an anonymous, app-specific iCloud user identifier; Netro Labs cannot see the user’s Apple Account details. Sending a flag requires the user to be signed in to iCloud; if it cannot be sent, Pew says so. Netro Labs uses flags only to review and, where needed, hide shared answers. Flags stay in Pew’s iCloud container until Netro Labs deletes them; there is currently no automatic deletion period. Because a flag contains no name or contact details, Netro Labs may be unable to match a specific flag to a person who asks about it.

If a user chooses to email support, their email provider and the Netro Labs support mailbox process the address, message, attachments and delivery information needed to receive and answer the request. Users should not include passwords, payment-card details, identity documents or precise location histories in ordinary email.

Permissions

Location

Pew requests location only while the app is in use. A user can deny location and continue browsing, but nearby guidance and physical visit validation may be unavailable. Permission and Precise Location choices can be changed in system Settings.

Photos

Adding a visit photo is optional. The system photo picker lets the user choose a specific item. The selected copy is kept in Pew’s local container until it is deleted through the app’s controls, the app is reset or the app is removed, subject to operating-system backups.

The public Release version does not expose the internal camera-based Experimental Discovery workflow.

Retention and deletion

Local Pew data remains on the device until the user deletes it, resets the app or removes the app, subject to copies retained in operating-system backups. In Settings → Privacy & your data, users can delete visit photos, delete claim history or reset all local Pew data. There is no server-side Pew account to delete.

Netro Labs keeps support correspondence only for as long as needed to respond, support users, maintain necessary records, resolve disputes, protect legal rights or meet legal obligations. The email provider may retain provider-controlled operational information according to its service settings, security requirements and published retention practices.

Your rights and contact

Netro Labs is operated by James Nettey, who acts as controller for support correspondence. Privacy and data-rights enquiries can be sent to support@zedipass.com.

Netro Labs cannot retrieve local-only Pew information because the public Release version does not upload it to Netro Labs. The primary controls for that information are Pew’s delete/reset controls, system permission settings and uninstalling the app.

Depending on where a user lives and the applicable legal basis, they may have rights to request access, correction, deletion, restriction, portability or objection concerning correspondence held by Netro Labs. A user may also complain to the UK Information Commissioner’s Office at ico.org.uk.

Revisions

This permanent URL will be reviewed when Pew changes its location use, photos, datasets, maps, weather services, SDKs, accounts, synchronisation, analytics, advertising, purchases or any other off-device data flow. Material changes will be posted here with updated effective and review dates.