Przejdź do treści
StreetHunt Powiadom o premierze

StreetHunt

Privacy Policy

Aktualizacja: 23 sierpnia 2026

Version 2.0 · effective: 23 August 2026

Applies to: the StreetHunt iPhone app and the streethunt.app website


The short version

Question Answer
Do I need an account? No. StreetHunt has no accounts and no sign-in.
Where are my cards stored? Only in your iPhone’s storage. We cannot access them.
What leaves my phone? The photo of the car — it goes to Anthropic so their AI can identify the car. As with any internet connection, Anthropic’s server also sees the phone’s IP address and the app version. Nothing beyond that.
Do you send my location? No. The catch location is saved on your phone only, for your own map.
Do you track me? No. No analytics, no ads, no trackers, no data sales.
Who runs this? A father and his son. It is a private hobby project, not a company. The app is free.
How do I delete everything? Settings ⚙️ → Privacy and AI → Delete all my data. Or uninstall the app.

The rest of this document says the same thing in more detail, because GDPR and the App Store require it.


1. Who is responsible for your data (the controller)

The data controller under the GDPR is:

Krzysztof Krajewski

private individual, Poland

email: kontakt@streethunt.app

StreetHunt is a private hobby project built by a father together with his son. There is no company, no business entity, and no commercial operation behind it. The app is free — no purchases, no subscriptions, no advertising.

We have not appointed a Data Protection Officer; we are not required to, given the minimal scale of processing and the absence of any user monitoring.


2. Car photos — the only data that leaves your phone

This is the core of the app and the most important part of this policy.

What happens, step by step

  1. You take a photo of a car with the camera, or pick one from your library.
  2. The app redraws the image from scratch (longest side max. 1280 px) and writes a new JPEG, explicitly deleting the EXIF/GPS/IPTC fields, then verifies the finished bytes: if anything identifying survived, nothing is sent. The date, camera model, serial number and any embedded GPS coordinates are therefore gone. Anthropic receives a bare image.
  3. The prepared image is sent over an encrypted HTTPS connection to the Anthropic API (api.anthropic.com), to the Claude model.
  4. The only other thing in the request is a short text instruction: „identify this car and fill in the card.” Nothing about you.
  5. The model returns the car’s details (make, model, year range, power, top speed, rarity, a fun fact). Your card is built from that.
  6. The photo is stored with the card on your phone.

What we do NOT send with the photo

  • ❌ GPS coordinates or place names
  • ❌ your name, email, or phone number (we do not have them at all)
  • ❌ a device identifier, IDFA, or any number that could identify you
  • ❌ your collection, points, or achievements

What Anthropic sees anyway

We will not call the request „anonymous”, because that would not be true. The request contains no name, email, phone number or device identifier — but, as with every internet connection, the server on the other end sees:

  • the IP address the request came from (under EU law this is personal data — CJEU, Breyer, C-582/14; it gives an approximate area and, with the ISP’s help, the subscriber),
  • the app name and version — we deliberately send a minimal StreetHunt/<version> identifier instead of the default one, which would reveal the phone model and iOS version.

There is no way around this when using someone else’s API. There is only an honest way to write it down — and to keep everything else to a minimum, which we do.

Something we should say plainly

You take these photos in the street. A licence plate or a passer-by may end up in the frame by accident. Please photograph the car itself and try to keep people and plates out of shot. We never see or collect these photos — but the image does pass through Anthropic’s servers, so it is better kept clean.

What Anthropic does with it

Anthropic PBC (USA) acts here as our data processor — it processes the photo solely to answer our request. Under Anthropic’s commercial terms for the API:

  • API inputs and outputs are not used to train models;
  • inputs and outputs are deleted from Anthropic’s servers within 30 days of receipt;
  • there is one exception and it needs saying plainly: if Anthropic’s automated trust and safety systems flag a request as a possible policy violation, Anthropic may retain the inputs and outputs for up to 2 years, and the classification scores for up to 7 years. No human report is needed — an automated classifier decides, so it can also happen to an ordinary car photo that is misclassified. Anthropic may likewise retain data where the law requires it.

Current Anthropic terms: anthropic.com/legal/commercial-terms and privacy.claude.com. We checked these for version 2.0 of this policy in August 2026; if Anthropic changes the periods, we will change this document and ask for consent again inside the app.

The „Market prices 🌍” feature

This feature is OFF by default. You switch it on deliberately — with a separate toggle on the consent screen, or later in Settings ⚙️ → Privacy and AI. It is not part of the scanning consent: you can agree to car recognition and decline web search.

When it is on, after identifying the car the model performs up to 3 web searches on Anthropic’s servers, looking for current classified ads for that model so it can quote a real price instead of an estimate.

Who is on the other end of that search: Anthropic’s search tool is served by Brave Search — a sub-processor listed on Anthropic’s subprocessor list. The chain is therefore us → Anthropic → Brave Search.

What reaches it: a text query about the car (e.g. „Porsche 911 992 price Otomoto”). The photo does not go there — the search tool only accepts text, so this is a property of the interface rather than a promise. The model composes the query from the make and model it recognised.


3. Location — it stays with you

StreetHunt asks for „While Using the App” location access (never background). It serves exactly one purpose: the pin on your own spot map.

How it works precisely:

  • Camera photos — the app takes the phone’s current position, but only if it is fresher than 5 minutes. An older fix is discarded (no pin is better than a wrong pin).
  • Library photos — the app reads the coordinates stored in the image file (EXIF GPS), if present, so an older photo lands on the map where it was actually taken.
  • The place name (e.g. „Mokotów, Warsaw”) is produced by a request to Apple’s geocoding service, built into iOS. The coordinates are momentarily sent to Apple to get a district name back. This is a standard iPhone system service, governed by Apple’s privacy policy.
  • Coordinates and place name are stored in the card’s database on your phone.

Location is never sent to Anthropic or to us. We have no server it could reach.

If you decline location access, the app works normally — cards simply get no pin. You can withdraw consent at any time: iOS Settings → StreetHunt → Location.


4. What is stored on your phone

Everything below lives in your iPhone’s storage (a SwiftData database plus app preferences). We cannot access it, we make no backups of it, and we send it nowhere.

Cards in your collection:

car photo · make and model · year range/generation · value in PLN · top speed · 0–100 acceleration · horsepower · production numbers · rarity · body type · fun fact · recognition confidence · capture date and time · GPS coordinates and place name (if available)

Offline queue:

photos waiting for an internet connection, together with location and timestamp — removed automatically once recognition succeeds.

Settings and game progress:

unlocked achievements and their dates · completed weekly missions and bonus points · selected card frame · the „engine sound”, „market prices”, „city on the social image” and „accept cards from files” toggles · optionally, an Anthropic API key you pasted yourself

The AI consent record (accountability, Art. 7(1) GDPR):

whether consent is given · the date it was given · the version number of the text it was given for · whether it came from a user aged 16+ or from the parent of a user under 16 · the age band as a single flag: „16 or older” or „under 16”. We store no date of birth and no age — we never ask for them.

If you use iCloud Backup or an encrypted Finder backup, this data will be included in your backup, like any other app’s data. That is your Apple account’s backup; we have no access to it.


5. What StreetHunt does NOT do

  • no accounts, no sign-in — we collect no email, password, phone number, or name;
  • no analytics — no Google Analytics, Firebase, Amplitude, Mixpanel, or anything similar;
  • no advertising and no ad networks;
  • no tracking in the App Store sense (App Tracking Transparency) — the app never asks for tracking permission, because it does not track;
  • no third-party SDKs — the app uses only Apple’s system frameworks;
  • no third-party crash reporting (you may separately enable sharing diagnostics with Apple in iOS — that is a system setting, not ours);
  • we never sell or share data for marketing. Ever.

6. Trading cards with a friend (.hunt files)

You can send a card to a friend as a .hunt file — via AirDrop, Messenger, whatever. The file never passes through any server of ours; it is a direct phone-to-phone transfer performed by iOS.

The .hunt file deliberately contains no GPS coordinates and no place name — your friend gets the car card but learns nothing about where you live or travel. Even if a file from another app version carried a location, StreetHunt discards it on import.

The file does contain the car photo. Keep that in mind when passing a card on — whoever receives it will see that photo. The photo is re-encoded by the app before it is sent, so it carries no metadata: no GPS coordinates, no date, no phone model.

Cards arriving from other people

A .hunt file can be sent by anyone within AirDrop range, including a stranger. The app therefore treats such a file as untrusted content:

  • it shows no message from the sender — the file format has no field for sender text, and the screen heading is fixed;
  • it strips web addresses, e-mails, @handles and phone numbers from the card fields, and truncates overly long text;
  • it re-encodes the photo and rejects oversized files;
  • it limits incoming cards to 12 per day;
  • the receiving screen always offers three buttons: Add, Reject and Report abuse. Reporting discards the card and pauses incoming cards for 24 hours; you can also write to kontakt@streethunt.app.

Accepting cards from other people can be switched off entirely in the app: Settings ⚙️ → Cards from other players.

Card image for social media

A card can also be turned into an image and posted, e.g. on Snapchat. By default that image contains no location information at all. In Settings ⚙️ → Privacy and AI you can deliberately enable showing the city name only (e.g. „Warsaw”). A street or district name never appears on the image, regardless of settings. The finished image is saved without any metadata identifying the phone, camera, date or place.

The image and the .hunt file do carry an AI-generated content marker — see section 7a below. That is the only metadata we deliberately add.


7. Legal bases (GDPR Article 6)

What we process Why Legal basis
Car photo sent to Anthropic Identifying the car and building the card Art. 6(1)(a) GDPR in conjunction with Art. 8 GDPR — explicit consent given on the consent screen; for users under 16 the consent is given by a parent or guardian. It can be withdrawn at any time in Settings ⚙️ → Privacy and AI → AI recognition consent; withdrawal does not affect the lawfulness of processing carried out before it.
Location attached to a card The pin on your own spot map Art. 6(1)(a) GDPR — your consent, given through the iOS location permission; withdrawable at any time
Photos and card data on your phone Your collection and gameplay The data stays solely on your device and is inaccessible to us; the app stores it at your instruction
Web-search queries for „Market prices” A real market price instead of an estimate Art. 6(1)(a) GDPR — a separate consent, given by switching on a toggle that is off by default (and can be switched off again in Settings)

We do not profile anyone and we make no automated decisions producing legal effects (Art. 22 GDPR). The AI guesses what car it is looking at, and nothing more.


7a. Marking AI-generated content (EU AI Act, Article 50)

A StreetHunt card is not a database lookup. The make, model, year range, power, top speed, acceleration, rarity, production numbers, valuation and fun fact are produced by a language model from your photo. It can be wrong, and regularly is. Therefore:

  • Before you start — the scanner screen states plainly that an AI system is doing the work (Art. 50(1)).
  • On every screen showing such data — the card, the scan result, the statistics, the Index, the Duel and the points breakdown carry a visible note: „Data generated by AI — may contain errors” (Art. 50(4)). The note scales with the iOS text-size setting and is read out by VoiceOver (Art. 50(5)).
  • Outside the app — the card image and the .hunt file carry a machine-readable marker (Art. 50(2)):
  • image: the IPTC/XMP DigitalSourceType field set to compositeWithTrainedAlgorithmicMedia from the standard IPTC vocabulary — „human-captured media combined with model-generated content”, which is exactly what a card is (your photo plus AI data), together with a plain-text note in the IPTC fields;
  • .hunt file: the aiGenerated, aiProvider and aiNotice fields inside the file.

We do not embed a pixel watermark: for artwork of this size and purpose, IPTC metadata is the approach recommended by the European Commission’s Article 50 guidelines, and a watermark would degrade the image for no real gain.


8. Children and teenagers — read this with a parent

StreetHunt is built for teenage car spotters. We say so openly, because it changes the rules.

How the age gate works

On the consent screen — before anything is sent anywhere — the app asks one question: „16 or older” or „under 16”. One tap, no form.

  • We do not ask for a date of birth or an age and we do not store them. All that stays on the phone is a flag for which side of sixteen the user is on.
  • 16 or older — the decision is the user’s, as before.
  • Under 16 — the „I agree” button is not available to the child. A parent screen appears instead: a short task confirming an adult is holding the phone (multiplying two two-digit numbers), and only then a „Parent: I agree” button. The app records that the consent came from a parent, together with the date and the version number of the consent text.
  • The child can always choose „Not now — I’ll play without the scanner” and go straight back to the game. The collection, map, missions, achievements, duels and card trading all work with no consent and no parent. We block only the AI scanner, because it is the only feature that sends anything outside the phone.
  • The code checks this twice: with the „under 16” flag and no „consent from parent” record, sending a photo is blocked even if someone bypassed the screen itself.

Let us be honest about what this is not: it is not age verification, and it is not identity verification. A teenager determined to lie will lie, and will do the multiplication on a calculator. Real verification would require an ID document or a face scan — collecting far more data from a child than the entire rest of the app put together — and we decided the cure would be worse than the disease. Art. 8(2) GDPR asks for „reasonable efforts, taking into consideration available technology”, and this is our answer: an honest question, a real path for the parent, no benefit whatsoever from lying (the app is free, with no accounts, no chat, no ads and no purchases), and full playability without consent.

For a parent or guardian

  • In Poland, a child under 16 cannot give valid consent to data processing in online services on their own — a parent’s or guardian’s consent is required (Art. 8 GDPR). In other EU countries the threshold may be lower, down to 13.
  • If your child is under 16, install the app together with them and read this document with them. You give the AI-scanner consent yourself, on the screen described above — and you can switch it off at any time in Settings ⚙️ → Privacy and AI.
  • Enable location consciously. The app works without it. If you do not want your child’s phone recording the places they have been, simply decline location access in iOS.
  • Note the card-sharing features (.hunt files and „image for social”). A card contains a photo your child took. It is worth talking about who they send such photos to.
  • The app has no chat, no community, and no connection to strangers. There are no ads and no purchases.

What we deliberately do not do with minors

  • we do not ask for a name, surname, date of birth, address, email, or phone number;
  • we do not build user profiles and do not target advertising;
  • we do not use behavioural analytics;
  • we do not pass data to data brokers.

If you nonetheless believe the app processed your child’s data in a way you do not accept, write to kontakt@streethunt.app. We will respond and explain what we can do (in practice almost all the data sits on the phone and you can erase it yourself, immediately).


9. Retention periods

Data How long
Cards, photos, locations, achievements on the phone As long as you want. Delete a card in the Index, or everything by uninstalling the app.
Photos in the offline queue Until recognition succeeds; the entry is then deleted automatically.
The photo on Anthropic’s side Rule: up to 30 days from sending, then automatic deletion. Exception: if Anthropic’s automated trust and safety systems flag the request, inputs and outputs for up to 2 years and the classification scores for up to 7 years. Longer where the law requires it.
The AI consent record on the phone (date, version, who gave it, age flag) Until consent is withdrawn, or until „Delete all my data” / uninstalling the app.
Data on our side None. We have no server and no database for anything to land in.

Uninstalling the app removes all of its data from the phone (except any iCloud backup, which you control).


10. Transfers outside the European Economic Area

One flow leaves the EEA: the request to Anthropic PBC, based in the USA. It consists of:

  • the car photo, stripped of metadata,
  • a short text instruction,
  • the phone’s IP address and the app name and version — visible to Anthropic’s server as with any internet connection,
  • with „Market prices” enabled, additionally a text query about the car, which Anthropic passes to its sub-processor Brave Search (Brave Software, Inc., USA).

There are therefore two recipients: Anthropic PBC (processor) and Brave Search (sub-processor, only when search is enabled and only for the text query).

The transfer relies on the Data Processing Addendum agreed with Anthropic, incorporating the Standard Contractual Clauses (SCCs) approved by the European Commission, together with Anthropic’s commitments on deletion and on not training models on API data.

To be straightforward: Anthropic and Brave are US companies and are therefore subject to US law (including the CLOUD Act). There is no way around that if you want to use this AI model. That is why we keep the transferred data to an absolute minimum, and why web search is off by default.

The geocoding request (coordinates → city and district name) is handled by Apple as part of iOS.


11. Your rights (GDPR Articles 15–21)

You have the right to access your data, to rectification, erasure, restriction of processing, data portability, to object to processing, and to withdraw consent at any time.

In practice, with an app built this way, it is simple:

  • Access and portability — you can see all your data inside the app. Every card can be exported as a .hunt file (readable JSON) or as an image.
  • Withdrawing AI consent — Settings ⚙️ → Privacy and AI → AI recognition consent → switch it off. One tap, no questions, no confirmation dialog. From that moment the scanner sends nothing; photos waiting in the offline queue stay on the phone and are not sent. Withdrawal does not affect the lawfulness of processing before it. You can switch consent back on the same way — the full consent text is shown again.
  • Deleting a single card — long-press it in the Index and delete.
  • Deleting everything — Settings ⚙️ → Privacy and AI → Delete all my data. This removes: all cards together with their photos, the entire offline scan queue, achievements and their dates, completed missions and bonus points, the selected frame, the AI consent record including the age flag, and the „Market prices” toggle. Two things deliberately remain: the API key you pasted yourself (it is your secret, not our data — clear the field in Settings to remove it) and the safety settings for the incoming-cards channel, so that „delete my data” cannot be used to lift a block set after an abuse report. The operation cannot be undone. You can also simply uninstall the app.
  • Withdrawing location consent — iOS Settings → StreetHunt → Location → Never.
  • Disabling web-search queries (Brave Search) — Settings ⚙️ → Privacy and AI → „Market prices” toggle. It is off by default.
  • Switching off cards from other people — Settings ⚙️ → Cards from other players.

To exercise any right against us: kontakt@streethunt.app. We reply within one month at the latest.

You also have the right to lodge a complaint with a supervisory authority. In Poland:

President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.


12. Security

  • All communication with the Anthropic API uses HTTPS/TLS.
  • App data lives in the iOS app sandbox and is protected by the iPhone’s system encryption (Data Protection) — while the phone is locked with a passcode, it is encrypted.
  • We run no server, so there is no database for anyone to breach.
  • We are a two-person family project, not a security team. We do not promise infallibility — we promise to collect as little as possible, so there is little to lose.

13. What we plan next

We want to add user accounts and collection sync across devices (a backup for when you change phones). At that point we will store data on a server — planned to be located in the European Union — which will mean:

  • providing some identifier (email or phone number),
  • storing cards and photos in the cloud under your account,
  • the ability to delete your account together with all its data from inside the app.

For clarity: deleting all data from inside the app and parental consent for users under 16 already work today (sections 8 and 11) — those are not plans.

None of the above works today, and none of it will be switched on quietly. Before accounts launch we will publish a new version of this policy and announce the change inside the app. Until then StreetHunt remains an app with no account and no cloud.


14. Changes to this policy

If the way the app works changes, we will update this document and raise the version number and date at the top. The current version always lives at https://streethunt.app/privacy. We will additionally announce significant changes (such as the launch of accounts) inside the app.


15. Contact

Questions, concerns, deletion requests, notes from parents:

kontakt@streethunt.app

We reply in Polish and in English.


<!–

NOTATKA REDAKCYJNA — USUŃ PRZED PUBLIKACJĄ

(w aplikacji NIE jest widoczna: kopia offline w bundlu powstaje z tego pliku

skryptem tools/make_bundled_policy.py, który ucina wszystko od tego znacznika)

BLOKERY — bez nich tego dokumentu NIE WOLNO publikować:

  1. DATA. W nagłówkach (PL i EN) stoi 23 sierpnia 2026 — data napisania wersji 2.0.

Jeśli publikacja przesunie się w czasie, popraw obie daty i przegeneruj kopię

offline w bundlu: python3 tools/make_bundled_policy.py

  1. DPA Anthropic. Sekcja 10 (PL i EN) twierdzi, że transfer do USA opiera się na

Data Processing Addendum ze standardowymi klauzulami umownymi. To zdanie jest

prawdziwe DOPIERO po zaakceptowaniu DPA w console.anthropic.com

(Settings → Legal / Data Processing Addendum). Zapisz datę akceptacji.

Dopóki DPA nie jest zaakceptowane, publikacja tego dokumentu = nieprawdziwe

oświadczenie o zabezpieczeniach transferu. To gorsze niż brak zdania.

  1. kontakt@streethunt.app — alias MUSI odbierać pocztę, zanim polityka pójdzie na

stronę i zanim link trafi do App Store Connect (art. 12 ust. 3 RODO).

Skrzynka prywatna może być celem przekierowania; w dokumencie zostaje adres

domenowy.

  1. Certyfikat TLS na streethunt.app + www. TLD .app jest na liście HSTS preload,

więc przy złym certyfikacie Safari NIE pokaże opcji „odwiedź mimo to” —

recenzent Apple zobaczy twardy błąd. Aplikacja ma awaryjną kopię offline

(Ustawienia → „Polityka prywatności (kopia w aplikacji)”), ale link z App Store

Connect prowadzi na stronę i musi działać.

WERSJONOWANIE:

  1. Ta polityka to WERSJA 2.0 i odpowiada wersji 2 treści zgody w aplikacji

(AIConsent.currentVersion). Zmieniasz którekolwiek z poniższych zdań?

Podnieś jedno i drugie:

  • retencja u Anthropic (sekcja 2 i 9),
  • co widzi Anthropic poza zdjęciem (sekcja 2 i 10),
  • Brave Search (sekcja 2, 7a i 10),
  • domyślny stan „Cen rynkowych” (sekcja 2, 7 i 11),
  • bramka wieku (sekcja 8).
  1. Adresy URL: /polityka-prywatnosci (PL) i /privacy (EN) — albo jedna strona

dwujęzyczna. Kod aplikacji linkuje do /polityka-prywatnosci (Core/Consent.swift

→ HuntLinks.privacyPolicy). Jeśli zmienisz adres na stronie, popraw TAM.

  1. Zdania o braku kont i braku chmury są prawdziwe TYLKO dla obecnej wersji

aplikacji. Przy uruchamianiu backendu trzeba wydać wersję 3.0 tej polityki.

–>