Privacy Policy
Contents
1. Introduction
Detour is an Android app that helps you save places you come across — in a video, an article, a message or a conversation — and shows you which of those saved places are along a route you are about to drive.
Detour is provided by Ran Werker, referred to in this policy as "we" or "us". This policy applies to everyone who uses the Detour Android app or visits this website, and it describes what the app actually does in the version currently published. Where a feature is planned but not built, it is not described here as if it existed.
The short version
- Detour has no user accounts. You do not sign up, sign in, or give us your name or email to use the app.
- The places you save are stored on your device. Detour does not upload your saved places to us.
- Everything Detour captures happens when you press the Detour button or use the Android share sheet. Nothing runs on a timer and nothing listens or watches in the background.
- A press can capture in four ways, depending on which app you are in: it can record a few seconds of audio, read the page or post in front of you in a browser and a short list of other apps, take one still image of the screen in Instagram, TikTok, YouTube and Facebook when that reading found no place, or read your clipboard. Section 2 says exactly which app leads to which.
- In Instagram, Facebook and TikTok only, a press can also tap the post's own Share control for you to reach Android's share sheet, saving you five taps. It never sends anything to anyone, never posts anything, and types nothing — see 2.5.
- A recording is sent for transcription and then deleted. We keep no copy.
- When you save a place from a link, our backend opens that link and reads the page, so the place can be recognised without you typing anything.
- Text captured this way is sent to a language model to find a place name in it. The place you confirm is saved on your device; the text itself is not stored anywhere.
- Detour shows no ads, contains no advertising identifiers, and we do not sell or rent any data.
- Detour counts how features are used, twice: through Firebase Analytics (Google) and in Detour's own database, so we can ask the numbers a question. Both copies carry no place names, addresses, coordinates, transcripts, page text or destinations — only counts, yes/no flags and a fixed list of technical labels — and both are keyed by a random install identifier generated on your phone, not by anything about you. Firebase Crashlytics receives crash reports. All of it is switched off entirely in development builds.
2. What Detour collects
2.1 Microphone audio
Detour asks for microphone access the first time it needs to record, and it records only as the result of a press of the floating Detour button. There is no always-on listening, no wake word, and no background recording.
- A single capture lasts up to sixty seconds. It usually ends much sooner — when you press again, when the app you were in starts playing sound again, or when the screen goes off — and sixty seconds is the hard ceiling rather than the normal length. It is recorded as 16 kHz mono audio.
- The clip is written to Detour's private cache folder on your device. It is not placed in shared or external storage and no other app can read it.
- The clip is uploaded over an encrypted (HTTPS) connection to Detour's own backend, which forwards it to a speech-to-text provider (see section 5).
- The clip is deleted from your device once it has been transcribed, when the place is saved, when you dismiss the card, and on every failure path. Anything left behind by an interrupted capture is cleared the next time the app starts.
- Detour's backend does not store the audio. It holds the clip in memory only for the length of the request.
One case opens the microphone without you asking for it a second time. In Instagram, TikTok, YouTube and Facebook, a press first reads the caption or title on screen, and if that names no place it then reads the text in a single still image of the screen (both are described in 2.4). Only if neither finds a place, and you have granted microphone permission, does Detour record — because in those apps the place is often said out loud rather than written. If you have not granted microphone permission, the press simply ends with the manual card instead.
2.2 Transcribed text
The transcription provider returns text, which Detour sends — again through its own backend — to a language model that answers a single question: does this text contain a place name, a category and a city?
- The transcript exists in the app's memory for the duration of one capture. It is not written to Detour's database and it is not logged.
- Detour's backend does not store transcripts. Its own log lines record the number of characters and the number of candidates, never the text itself.
- What ends up saved is only the place you confirm, under the name shown on the confirmation card — which you can edit before saving.
2.3 Content you share into Detour
When you use the Android share sheet to send text or a link to Detour, the app receives whatever the sharing app provides — typically the text, a title and a URL — and processes it to work out which place it refers to. Up to about two thousand characters of that text are sent on for recognition.
Android may also tell Detour which app the share came from (its package
name, for example com.google.android.youtube). When it does, that package
name is saved on your device alongside the place, so you can remember where you found it, and
it is sent with the recognition request — a caption from a video app and the
title of a web page are different kinds of text, and saying which one it is helps Detour read
it correctly. It is the name of an app, never of a person, and it is not stored by our backend
or used to build any profile of you.
2.4 What Detour reads from your screen
Detour includes an accessibility service, which you switch on yourself in Android Settings and can switch off at any time. Android restricts it to a fixed list of apps, written into the app and visible to Google Play: outside that list Detour is given nothing at all, not even the name of the app you are in. It reads only at the moment you press the Detour button — never on a timer, never in the background.
In three of those apps the same service also taps for you, to reach the Android share sheet without you doing it by hand. That is described separately and in full in 2.5, because acting inside an app is a different thing from reading it. It never types anything, anywhere.
The list has four parts, and they are used for different things:
- Waze and Google Maps. Detour reads the destination you are navigating to, or the place you currently have open, so a route can be planned without you typing it again. Nothing else on those screens is read.
- Browsers — Chrome, Firefox, Edge, Samsung Internet, Brave, Opera and DuckDuckGo — and the reading apps Reddit, X (Twitter), Pinterest and Medium. Detour reads the address of the page you are on and the visible text of that page, so that pressing the button saves the place you are reading about without you having to copy the link first. In a browser, the address it reads is the same address that browser's own share button would have sent.
- Instagram, TikTok, YouTube, Facebook and Facebook Lite. Detour reads the caption, title or post in front of you. If that names no place, the microphone opens instead — see 2.1.
- Android's own share dialog. Not an app anyone browses: it is the window Android puts up when an app says "share this". It is on the list for one reason — the automation in 2.5 hands over to that window and has to be able to find Detour's own row in it. Nothing on that window is ever read or collected. It sits outside both of the groups above, so the checks that decide whether a screen may be read at all answer no for it, every time.
What the reader deliberately refuses to take, in every app on the list:
- password and other masked fields, and everything inside them;
- anything you can type into, other than a browser's address bar — so a message you are composing, a search box or a form field is not read;
- fields whose names identify a card number, a security code or an account;
- the browser's own furniture — its tab list, its toolbar, the controls around the page.
Detour reads the whole of the post or page you are on, not only the part currently scrolled into view. It used to stop at the edge of the screen, and that made saving a place depend on how far you happened to have scrolled: a caption collapsed behind “… more” keeps the restaurant's name in the half you cannot see, which is usually the half that matters. Reading only the visible part meant that pressing Detour on exactly the video you wanted often found nothing.
This changes how much is read, not what is refused. Everything in the list above is refused wherever it sits on the page — scrolling a password or a card field out of view does not make it readable, because being off screen was never what made those private. What is read is the post, the article or the caption you pressed Detour on. It is still read only at that press, still only in the apps listed above, and still never written down: it is used to work out which place you meant, and then discarded.
No messaging app is on the list. What is read is held in memory for the length of one capture, is never written to Detour's database and is never written to a log. Up to about two thousand characters of it are sent to our backend for place recognition, in the same way shared text is — see section 5 — and if the screen contained a link, the page behind it may be fetched as well (2.7). The only thing that survives the press is the place you choose to save.
One still image of the screen, in Instagram, TikTok, YouTube and Facebook only. A great many places are named in a picture rather than in text — a location sticker on a story, a caption burned into a video, a photograph of a menu or a shopfront — and none of those can be read from the screen's text. So in those four apps, and only there, if the reading described above finds no place at all, Detour asks Android for a single frame of the display and reads the text in it.
- It happens on that one press, and only after the text reading has already found nothing. There is no timer, no background path, and nothing that takes a frame while you are not pressing the button.
- Android hands back the whole display rather than one app's window, because it offers nothing narrower. Anything else visible at that moment — a notification banner, the status bar — is therefore in the frame too.
- A screen the app you are in marks as secure (banking apps, password managers) is refused by Android outright, and Detour receives nothing.
- The frame is shrunk, sent over an encrypted connection to Detour's backend, and forwarded to Google Cloud Vision, which returns the text it can see (see section 5). Only that text goes on to place recognition.
- The image is never written to your device's storage, never logged, and is not stored by our backend or by us. It exists in memory for the length of one request.
- If you would rather this never happened, turning off Detour's accessibility service in Android Settings disables it, along with the rest of the screen reading above.
2.5 What Detour taps on your behalf
Instagram, Facebook and TikTok publish no web address anywhere Detour can read. The only thing in those apps that produces a shareable link is the app's own Share control, and the only route from there back to Detour is Android's share sheet. Doing that by hand is five taps, every time. So in those three apps — and nowhere else — a press of the Detour button can make those taps for you, using the same accessibility service described in 2.4.
This is the one thing Detour does that acts inside another app rather than reading it, so it is set out here in full.
- Three apps. Instagram, Facebook and TikTok — the main builds of each. It does not run in Facebook Lite, in TikTok's regional build, in YouTube, in a browser, in Waze or Google Maps, or in any app that is not on the list in 2.4. There is no general "find anything called Share": an app with no written-out sequence takes exactly the path it took before this feature existed.
- Only when your device language is English. The controls are found by the labels those apps publish, and those labels follow your device's language. Only the English ones have been verified on a real device, so on a device set to any other language the automation does not start at all and the button behaves as it did before.
- Only when reading the screen was not enough. Most presses never reach this. Detour reads the caption first, and where the caption already names a place — which is the common case — nothing is tapped, no sheet opens, and the confirmation card simply appears over the post you are watching. The taps are the fallback for a post whose screen says nothing identifiable.
- Only the taps needed to reach Android's share sheet. The post's own Share control, the entry in that app's sheet that hands over to Android, and then Detour's own row in the Android sheet. That is the whole sequence, and it stops there.
- It never sends anything to anyone. Controls that send a post to a named person or a conversation — "Send to …", "Send message", "Messenger", Instagram's contact chips — are on a refusal list and are never tapped, whatever else is on screen.
- It never posts or publishes anything. Controls that publish to your own audience — "Share now", "Post", "Publish", "Repost", and anything mentioning a story — are on the same refusal list. Detour cannot put anything on your timeline, your feed or your story.
- It never touches passwords or anything you type. It types nothing at all, anywhere. It cannot enter text, and the refusals in 2.4 — masked fields, fields you can type into, fields whose names identify a card, a code or an account — apply unchanged.
- It cannot tap at a screen position. Detour does not hold the Android capability that lets a service synthesise a touch at a coordinate, and does not want it. Every tap is made on a control it has already found and identified by name, which means a control that is not there simply fails rather than being tapped at by position.
- If anything is not exactly as expected, it stops. If the screen does not match, if more than one control could be meant, if you switch apps, if the sequence takes more than a few seconds, or if the accessibility service is not attached — it aborts without tapping further.
- It tidies up after itself, and only when it can prove it is safe to. If it opened a sheet and then could not finish, it closes it. It will only do that when it can confirm the thing it opened is still the thing on screen; if it cannot confirm that, it leaves the screen alone rather than pressing Back on a guess and navigating you out of the post you were watching.
- Nothing on the share sheet is read or collected. Android's share dialog is visible to Detour only so it can find its own row while a press you started is in progress. It is excluded from every group whose contents may be read.
What comes back at the end is an ordinary Android share — the same link and text you would have got by making those five taps yourself — and it is handled exactly like any other share, as described in 2.3.
Turning off Detour's accessibility service in Android Settings switches this off along with the screen reading in 2.4. The button then behaves as it did before: in those three apps a press falls back to the microphone or to a card you can type into.
2.6 Your clipboard
When you press the Detour button in an app Detour cannot read — which is most apps — the press falls back to your clipboard: Detour comes to the front and takes whatever text you last copied, so you can save a link you copied a moment ago. If the clipboard holds nothing usable, an empty card opens for you to type into.
This happens only on that press, never in the background, and Android 12 and later show you a "Detour pasted from your clipboard" notice when it does. The clipboard text is treated exactly like shared text: used for one recognition, never stored, never logged.
2.7 Links, and the pages behind them
A link on its own rarely says which place it is about, so when a capture contains one, Detour's backend opens that link and reads the page. This is worth stating plainly because it is the one thing Detour does that reaches beyond your phone and our own providers.
- The fetch is made by our server, not your device. The website therefore sees a request from our backend; it does not see your IP address, your phone or anything identifying you.
- Only public web addresses are fetched. Addresses on private or internal networks are refused, including after a redirect, and at most three redirects are followed.
- At most 512 KB of the page is downloaded, and at most about 12,000 characters of its text — plus its title, its description, the site's name and any place details the page publishes about itself — are passed to the language model along with your own text.
- Nothing about the page is stored. It exists for the length of one request.
- Only links that arrive with a capture are fetched. Detour does not crawl, does not follow other links on the page, and does not fetch anything you have not shared or had on screen.
2.8 Location
Detour asks for location permission — precise or approximate, both work — and uses it in a deliberately narrow way:
- For a capture, Detour reads the last known location already held by the Android system. It does not switch anything on and does not request a new fix.
- For a route, Detour needs a starting point that is actually current. It uses the last known location if it is less than five minutes old, and otherwise asks Android for one new fix — a single reading, from the network or GPS, after which Detour stops listening. There is no continuous tracking anywhere in the app and no background location.
- Location is read only at the moment you capture a place or ask for a route — never while the app is idle.
- The coordinates are sent with that one request so that a search for "the bakery on the corner" finds results near you rather than on another continent, and so a route can be calculated from where you are. The language model is given them rounded to about ten metres; the maps provider is given them as read.
- Your location is not stored by our backend. On your device, the coordinates you set off from are kept as part of the route record described in 2.10.
- If you decline location permission, capture and routing still work — results are simply less well targeted.
- The current version does not request background location and contains no background location tracking.
2.9 Places you save
A saved place is stored in Detour's database on your device and may contain:
- the name you saved it under (suggested by Detour, editable by you) and any note you add;
- a category (restaurant, café, shop and so on), when one was identified;
- latitude and longitude, a street address, and the place's Google Places identifier — once you confirm a suggested match. These are what make it possible to tell, later, that the place is on your route;
- the package name of the app the content was shared from, when Android supplies it;
- how the place was created (share, voice button, or route screen), the date it was saved, and whether you have marked it as visited.
In the current version, saved places are local to your device only. Detour does not copy them to our servers and they are not visible to us or to anyone else.
Detour switches Android's own backup off for its data. Its database and its settings file are excluded from both the encrypted device backup Google stores in your account and the device-to-device transfer that runs when you set up a new phone. In practice that means your saved places, your route sessions and your settings stay on the device they were created on and do not follow you to a new one — a deliberate trade, because there is no account to reconcile a restored copy against.
2.10 Destinations and routes
When you ask Detour which saved places are on your way, the destination — whether you typed it or Detour read it from Waze or Google Maps — and your current coordinates are sent through our backend to a directions provider, which returns the shape of the route. Detour uses that shape in memory to work out which saved places lie close to it.
Detour keeps a record of each route it plans, on your device. When a route is calculated, a route session is written to Detour's database containing:
- the destination's name, as the directions provider returned it;
- the latitude and longitude you started from, and the latitude and longitude of the destination;
- the encoded shape of the route;
- the date and time it was planned.
This record exists for one purpose: it is the trip that a marked stop belongs to. When you tick a saved place and set off, Detour records that as a confirmed intent — the place, the moment you ticked it — attached to that route session. Nothing in the app reads these records back to you today, and the current version has no screen for viewing or deleting them individually; clearing the app's data or uninstalling removes them, as does deleting the saved place a marked stop belongs to.
Detour also remembers your most recent destination for a short time: its name, its coordinates, when it was saved, and which navigation app it came from. This exists because neither Waze nor Google Maps exposes its destination once turn-by-turn guidance has started, so without it, pressing Detour mid-drive could not tell where you were going. Detour stops using it after about three hours, and the stored value is removed as soon as a newer route replaces it or you end or discard the trip.
Both the route sessions and the remembered destination are local to your device only. Neither is copied to our servers, and we cannot see them.
2.11 App settings
Detour stores a small set of preferences on your device: whether you have completed the introduction, whether the floating button is switched on, where on the screen you last dragged it, whether the screen reader was switched on the last time Detour looked, and which permission prompts you have already been shown. Nothing here identifies you.
2.12 Technical information reaching our backend
Detour's backend runs as serverless functions on Supabase, in a European Union region. Like any internet service, it necessarily receives the technical details of each request — including your device's IP address, the time of the request and its size — and the hosting platform keeps operational logs of that traffic for a limited period for reliability and abuse prevention. Detour's own log lines record only counts and lengths (for example "3 candidates, 62 characters"), never the content of a recording, a transcript, a page, a place name or an address.
Two things are written to a database, and both are worth naming.
The first is an abuse counter. To stop anyone from running up the bill on the paid services behind these endpoints, the backend keeps a counter per caller. The row it keeps holds which endpoint was called, your IP address (for an IPv6 address, only the network part of it), and how much of the allowance is left. It holds no request content — no audio, no text, no place, no coordinates — and rows are deleted about a day after their last use.
The second is the product-usage events described in section 5: the same fixed set of counts and labels that go to Firebase, stored in Detour's own database so we can query them, together with a random install identifier the app generates on first run and the app's version number. The identifier is not derived from your device, your account or any advertising ID; it changes if you clear the app's data or reinstall, and it is the only way two events are known to come from the same installation. No place, address, coordinate, transcript or page text can be expressed in an event — the backend refuses any event or value outside the fixed vocabulary.
The recognition, transcription, place lookup, routing and screen-reading requests carry no account and no login. App versions released after 12 September 2026 send the same install identifier with them, in a request header, so that the abuse-prevention counter can be kept per installation rather than per network address — which is what stops one person's presses being throttled because thousands of other people share their mobile carrier's address. The backend turns the identifier into a one-way hash before it becomes a counter key, stores nothing you said, shared, saved or typed beside it, and sweeps the counters after a day. The providers in section 5 never receive it.
3. What Detour does not collect
- No accounts. There is no registration, no password, no email address, no profile. Nothing in the app asks who you are.
- No advertising identifier and no ad networks.
- No personal content in analytics. Detour uses Firebase Analytics and keeps a second copy of the same events in its own database, but what either can hold is deliberately limited by the way the app is built: the set of events is fixed in the source code, every value is restricted to lowercase letters, digits and underscores, and the backend rejects anything outside that list. A place name, an address, a transcript, a page or a typed destination cannot be expressed in that form, so none of them can be sent. See section 5 for what is sent.
- No personal content in crash reports. Detour uses Firebase Crashlytics. Crash reports carry stack traces and the app's own diagnostic messages, which are limited to identifiers, counts, durations and error types. Where a technical error would otherwise quote the data that caused it — for example a malformed reply containing a place name — the app deliberately records only the type of error, and the detail stays on your device.
- No contacts, photos, files, call logs or SMS.
- No continuous screen reading. The accessibility service described in 2.4 is off until you switch it on, is restricted by Android to a named list of apps, reads only on a press of the button, and refuses passwords, fields you type into, and anything a field's name marks as a card, a code or an account — wherever they sit on the page. It is not a keylogger: it types nothing, anywhere, and it cannot read what you type. It does tap for you in three apps, to reach Android's share sheet and only that far — described in full in 2.5. The one exception to the refusals above is the single still image described in 2.4: Android hands back the whole display rather than one app's window, so those field-by-field rules cannot be applied to it. It is taken in four apps only, only on a press that already found no place, never on a screen marked secure, and it is not stored.
- No background clipboard access. The clipboard is read only on a press of the button, with Detour in the foreground, and Android shows you when it happens.
- No sale or rental of data, and no sharing of your saved places with other users or with businesses.
- No AI training on your data by us. We do not train any model — we have none — and the providers we use do not use API content to train their models by default.
4. How information is used
Detour uses the information described above only to make the app work:
- to turn a few seconds of speech into text, so you can save a place without typing;
- to recognise a place name in that text, in content you shared, in what was on your screen, or on the page behind a link;
- to look up the real address and coordinates of a place you are about to save, so it can be matched to a route later;
- to keep your saved places on your device and show them to you;
- to calculate a route to a destination you enter, and to work out which of your saved places are along it;
- to hand a chosen destination to your navigation app;
- to keep the service working and to protect the backend endpoints against abuse.
Detour does not use your information to profile you, to advertise to you, or to train any AI model of ours. We have no such model.
5. Third-party services
Detour is built to keep provider keys off your phone: the app talks only to Detour's own backend, and the backend talks to the providers. The table below lists every external service the current version can reach and exactly what is sent.
| Service | Used for | What is sent | Policy |
|---|---|---|---|
| Google Firebase (analytics) |
Counting how often features are used, so we can tell what works. Release builds only — switched off entirely in development builds. | Counts (how many suggestions were offered, how many stops were found), yes/no flags (was the suggestion kept, was a location available) and a fixed list of technical labels (which navigation app, which kind of app the button was pressed in, which step failed). Plus an app-instance identifier generated by Google, which is reset if you uninstall or clear the app's data. Never a place name, address, coordinate, transcript, page, note, destination or the name of the app you were in. | firebase.google.com/support/privacy |
| Google Firebase (Crashlytics) |
Receiving crash reports and non-fatal errors so faults can be found and fixed. Release builds only. | Stack traces, device model and Android version, and the app's own diagnostic messages, which are limited to identifiers, counts, durations and error types. One custom value is attached: whether the build has a backend configured at all. | firebase.google.com/support/privacy |
| Supabase (hosting, EU region) |
Runs Detour's backend functions and holds Detour's own usage-event database. Every call below passes through it. | The request itself, plus the usual network metadata such as your IP address, and the random install identifier in a header. Two things are stored: the abuse-prevention counters (keyed by your network address and by a one-way hash of the install identifier, kept for a day) and the usage events, both described in section 2.12. The events carry counts, flags and fixed labels with the install identifier and the app version — never a place, an address, a coordinate or any text you shared. | supabase.com/privacy |
| OpenAI (speech-to-text) |
Converting your recording into text. | The audio clip only. No account, no identifier, no location. | openai.com/policies |
| OpenAI (place recognition) |
Finding a place name, category and city inside the text. | The transcript, the text you shared, or the text read from your screen — up to about two thousand characters; the link, when there is one; the address the page gives for itself; the name of the app it came from; up to about 12,000 characters of the page behind that link; and your coordinates rounded to about ten metres, when location permission was granted. | openai.com/policies |
| The website behind a link (fetched by our backend) |
Reading the page you shared or had on screen, so the place in it can be recognised. | A request from our server for that one address. The site sees our backend, not you: no IP address of yours, no identifier, nothing about your device. See section 2.7. | Each site's own policy |
| Google Places API | Turning a recognised name into a real place with an address and coordinates. | The candidate place name, a city, country, address or neighbourhood when known, and coordinates used to bias the search toward you. | policies.google.com/privacy |
| Google Cloud Vision | Reading the text in a still image of the screen, when a press in Instagram, TikTok, YouTube or Facebook found no place in the screen's text (see 2.4). | One image of the display, taken at that press. It is held for the length of the request and is not stored by us. Only the text found in it goes any further. | policies.google.com/privacy |
| Google Directions API | Calculating the route you asked for. | The destination — typed by you, or read from Waze or Google Maps — and the coordinates you are starting from. | policies.google.com/privacy |
| Google Maps / Waze (on your device) |
Actually navigating, once you choose to go. | Detour opens the app you pick with the destination coordinates. From that point the trip is handled by that app under its own policy. | Google · Waze |
Each provider processes what it receives under its own privacy terms, and each keeps data for its own operational periods, which we do not control. OpenAI states that content sent to its API is not used to train its models by default, and that it keeps a copy for a limited period — currently up to thirty days — for abuse monitoring (platform.openai.com/docs/guides/your-data). Providers may change: the app names none of them internally, so a provider can be replaced without an app update. This policy will be updated if that happens.
Because Detour sends no account and no identifier with these requests, a provider receives a fragment — an audio clip, a sentence, a page, a place name — that is not tied by us to a person.
6. Data retention
| What | Where it lives | How long |
|---|---|---|
| Audio recordings | Your device's private cache, briefly | Deleted as soon as the capture ends — after transcription, after the place is saved, when the card is dismissed, and on every failure path. Leftovers cleared at next app start |
| Transcripts, shared text, screen text, clipboard text, fetched pages | App memory during one capture, and our backend during one request | Discarded when the capture ends. Never written to storage on either side, and never logged |
| Location coordinates | Used in one request | Not retained by our backend. Coordinates that form part of a planned route are kept on your device in the route session below |
| Saved places | Detour's database on your device | Until you delete the place, clear the app's data, or uninstall Detour |
| App settings | Your device | Until you clear the app's data or uninstall |
| Route sessions and marked stops | Detour's database on your device | Kept until you clear the app's data or uninstall Detour. Deleting a saved place also deletes the marked stops that belong to it. The current version deletes them on no other schedule and offers no in-app control for removing them individually |
| Remembered destination | Detour's settings file on your device | Stops being used after about three hours; removed when a newer route replaces it or you end or discard the trip |
| Backend request content | Nowhere — nothing you send is written to a database | Not retained |
| Abuse-prevention counter (endpoint + IP address) |
Supabase database | Deleted about a day after the last request from that address |
| Usage events and install identifier (counts, flags, fixed labels) |
Detour's own Supabase database | Kept while the product is measured. Deleted on request by install identifier (see section 7); the identifier itself is reset when you clear the app's data |
| Backend operational logs | Supabase | Kept for a limited period by the hosting platform under its own retention settings — currently a small number of days |
| Data held by providers | OpenAI, Google | Governed by each provider's own retention terms, linked above. OpenAI currently keeps API content for up to thirty days for abuse monitoring |
7. Deleting your data
Because Detour keeps your places on your device, you are in direct control:
- Delete a single place — remove it from the saved places list in the app. It is deleted from the device immediately, along with any marked stops that referred to it.
- Delete everything — Android Settings → Apps → Detour → Storage → Clear storage. This removes every saved place, every route session and every setting.
- Uninstall — removes all of Detour's local data, including any cached recording.
- Android backup — nothing extra to do. Detour excludes its own data from Android's cloud backup and from device-to-device transfer, so there is no Detour backup in your Google account to delete.
- Switch the reading off — Android Settings → Accessibility → Detour, and the screen reading described in 2.4 stops entirely.
There is no account to delete, because there is no account. We hold no server-side copy of your places. The one thing we do hold is the usage events described in section 2.12, keyed by the app's install identifier. To have them deleted, open Settings in the app, note the identifier shown beside the version number, and write to ranwerker@gmail.com quoting it; clearing the app's data or reinstalling gives the app a new identifier and disconnects it from those rows. If you believe we hold anything else about you, write to the same address and we will look into it and reply.
8. Android permissions
Detour asks for each permission at the moment the feature needs it, not all at once at first launch. Every one of them can be refused, and can be changed later in Android Settings → Apps → Detour → Permissions. Refusing a permission disables the feature that needs it; it does not break the app.
| Permission | Why Detour asks |
|---|---|
| Accessibility service Detour — acts on button press |
Two things, both only when you press the Detour button. It reads the destination shown in Waze or Google Maps, and the page or post in front of you in a browser and a short list of reading and video apps; Android restricts the service to that list, it reads on demand only, and it refuses passwords and fields you type into. In Instagram, Facebook and TikTok it also taps the post's own Share control and then Detour's row in Android's share sheet, so one press does what used to take five — the minimum taps to reach that sheet, never sending to a person and never posting anything, and it types nothing anywhere. It is off until you switch it on in Android Settings. Turning it off means typing your destination by hand and copying a link before pressing. Full detail in section 2.4 and section 2.5. |
MicrophoneRECORD_AUDIO |
To record the audio a press of the Detour button captures — up to a minute, and usually far less. Used only during that capture. |
LocationACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION |
To read your position so place search is biased near you and a route can start from where you are. Both are declared so that answering "Approximate" in Android's dialog still works. Read on demand only; one fresh fix is requested when a route needs a current starting point. |
Display over other appsSYSTEM_ALERT_WINDOW |
To draw the floating Detour button on top of whatever app you are using, so you can save a place without leaving it. |
NotificationsPOST_NOTIFICATIONS |
Android requires a visible notification while the floating button is active, and Detour uses notifications to tell you what happened to a capture. |
Foreground serviceFOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE, FOREGROUND_SERVICE_MICROPHONE |
Keeps the floating button on screen while you have it switched on, and lets a recording continue while you are inside another app. The microphone type is added only while a recording is actually running and dropped again afterwards, so Android's microphone indicator reflects what is really happening. |
VibrationVIBRATE |
Short haptic feedback when a capture starts or finishes. |
Internet and network stateINTERNET, ACCESS_NETWORK_STATE |
To reach Detour's backend for transcription, place recognition, place lookup and routes. |
Two further permissions are granted at install time rather than asked for, because Android does
not treat them as user-facing: WAKE_LOCK, which the analytics SDK uses to finish
sending queued events, and an automatically generated permission that lets the app receive its own
internal broadcasts. Neither reads anything about you. The advertising-identifier permissions that
normally arrive with the analytics SDK are removed from the built app, so it
cannot read an advertising ID even if it tried.
The current version does not request background location. The accessibility service listed above is switched off until you enable it yourself in Android Settings, and Android limits it to the apps named in section 2.4. If a future version widens what it reads, this policy and the app's Google Play listing will be updated before it ships, and the app will tell you inside the app what has changed.
9. Children
Detour is a driving and trip-planning tool intended for general audiences and is not directed to children. It is not designed for, marketed to, or intended to be used by children under 13, and we do not knowingly collect information from them. Since Detour has no accounts and collects no identifying information, we have no way to know a user's age. If you believe a child has provided information to us through Detour, contact ranwerker@gmail.com and we will act on it.
10. Security
We take a small number of concrete measures, and we would rather describe them plainly than promise perfection:
- All traffic between the app, our backend and every provider uses encrypted HTTPS connections.
- No provider API key is contained in the app. Keys are held only by the backend, so unpacking the app reveals no credential.
- Saved places and settings are stored in Detour's private app storage, which Android isolates from other apps. They are not separately encrypted by Detour beyond the encryption Android applies to the device as a whole.
- Recordings are written to private cache storage, never to shared storage, and are deleted after use.
- Our backend stores no request content, so there is no server-side collection of your places, recordings, page text or transcripts to be exposed. The one thing it does store is the abuse-prevention counter in section 2.12, in a table that is not reachable through the public API.
- The backend's endpoints are open — Detour has no accounts, so there is nothing to sign in with — and are protected by rate limits and daily spending ceilings rather than by authentication. We say this rather than implying a login exists.
No method of transmission over the internet and no method of electronic storage is completely secure, and we cannot guarantee absolute security. Anyone with physical access to an unlocked device can see the places saved on it.
11. International users and your rights
Detour is distributed through Google Play and can be installed in many countries. Depending on where you live, data-protection law may give you rights over personal data held about you — typically the right to access it, to correct it, to have it deleted, to object to or restrict its processing, to receive a copy in a portable form, and to complain to a supervisory authority.
In Detour's case those rights are mostly exercised directly on your device, because that is where the data is:
- Access and portability — your saved places are visible in the app on your device; there is no server-side copy to request.
- Correction — edit a saved place's name or note in the app.
- Deletion — see section 7.
- Objection and restriction — refuse or revoke the microphone, location or accessibility permission at any time in Android settings, or stop using the relevant feature.
We do not hold an account, a profile, or any identifier that would let us find "your" data on request, which means that for most requests there is genuinely nothing on our side to produce or erase. The one exception is the short-lived abuse-prevention counter keyed to an IP address described in section 2.12; if you want that removed before it expires, tell us the address and roughly when you used the app. Where the law requires it, the controller of any processing described here is Ran Werker, and requests can be sent to ranwerker@gmail.com. We will respond within the period required by the law that applies to you.
International transfers. Detour's backend runs in a European Union region, and the providers it calls (OpenAI, Google) operate internationally, so a request may be processed on servers outside your country, including in the United States. Each provider maintains its own transfer safeguards, described in the policies linked in section 5.
California. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and we do not use it for cross-context behavioural advertising.
12. Changes to this policy
Detour is under active development, and this policy will change when the app does — for example if a future version adds accounts or backend sync of saved places (a sync of saved places existed briefly in early September 2026 and was removed on 12 September 2026 before this policy was updated; rows it wrote have been deleted). When it changes we will update the effective date at the top of this page, and the current version will always be available at this address. Material changes will be highlighted here. Continuing to use Detour after a change means you accept the updated policy.
6 September 2026. Detour's accessibility service now taps as well as reads: in Instagram, Facebook and TikTok, a press of the button can activate the post's own Share control and then pick Detour from Android's share sheet, so that one press does what previously took five. Earlier versions of this policy said the service could not tap on your behalf, which was true when it was written and is no longer true. The new section 2.5 describes exactly what it taps, what it refuses to tap, and when it refuses to run at all. Android's share dialog was added to the list of windows the service can see, for the sole purpose of finding Detour's own row in it; nothing on that window is read or collected.
13. Contact
Questions about this policy, or about how Detour handles data:
Ran Werker
Email: ranwerker@gmail.com
See also the Terms of Use.