Legal
Privacy policy
Last updated: 1 October 2026
The short version
- Compass Afar stores what you type into it so the app can work: your account, your school, your address, your budget, and so on.
- Your data is never sold. There are no ads and no analytics or tracking scripts.
- The medical details on your Emergency Card are optional and are shown only to you. The copy kept on your phone for offline use is encrypted.
- Chat messages and the documents you run through the housing tools are sent to Anthropic to get an answer. They are not saved on the Compass Afar server.
- To get your data, fix it or delete it, email lukaritchley@compassafar.com.
1. Who runs Compass Afar
Compass Afar is built and run by Luka Ritchley, a student in Madrid. Luka is the “data controller”, which means the person responsible for your data under the EU’s General Data Protection Regulation (GDPR). In this policy, “I” and “me” mean Luka, and “the app” means Compass Afar at app.compassafar.com.
Contact: lukaritchley@compassafar.com.
2. Who it’s for
Compass Afar is for university students aged 18 or over who are studying in Madrid. It is not meant for anyone under 18. If you think someone under 18 has made an account, email me and I will delete it.
3. What is collected, and why
The app collects only what you give it. Almost every field is optional, and the app says which ones are. You can browse as a guest without an account; a guest has no profile on the server.
- Account
- Your email address and name. Used to sign you in, verify your email and tell your account apart from others. Your password is handled by Firebase Authentication (a Google service). The Compass Afar server never sees or stores it. If you sign in with Google, Firebase receives your basic Google profile (name and email).
- School and campus
- The university and campus you pick. Used to plan routes to your campus, show your school’s community feed and events, and give the chat assistant the right campus.
- Arrival date
- The day you land in Madrid. Used to work out whether you are pre-arrival, in arrival week or settled, so the app can lead with what is useful at that point.
- Home address
- The address you save, and its map coordinates. Used to plan routes from your door, find everyday places near you, and show the nearest hospital on your Emergency Card.
- Budget
- Your budget amount, how you split it across categories, each budget period, and any notes you add. Used to show what you planned and what is left.
- Calendar
- Entries you add: title, date, and optionally a cost, a category and a location. Used for your calendar and to count costs against your budget.
- Interests
- The interests you tick from a fixed list. Used to tailor event suggestions and the chat assistant’s suggestions.
- Contact details
- An optional phone number and contact email. Shown only to people whose friend request you have accepted, or who accepted yours. Nobody else sees them.
- Emergency Card
- Optional: your home country, an emergency contact’s name and phone number, your blood type, allergies and medical conditions. Used only to show your own Emergency Card to you. This is health data. It is never shown to other users, never sent to the chat assistant, and never written to logs. If you add an emergency contact, please make sure they are happy for you to store their number.
- Community
- Posts you write, friend requests you send or answer, and reports you make about posts. Used to run the community feed and keep it safe. See “What other people can see” below.
- Saved items and activity
- Listings, events and neighbourhoods you save; which neighbourhoods you have opened; badges you have earned. Used to show your saved list and award badges.
- Chat messages
- What you type to the in-app assistant, and the last few turns of the conversation. Sent to Anthropic to generate the reply (see section 6). The Compass Afar server does not store your messages or the replies. It stores only a count of how many messages you sent today, to enforce the daily limit. The conversation lives in the open page and is gone when you close or reload it.
- Housing tools
- Text you paste into Scam Check, and the lease you upload or paste into Lease Explainer. Sent to Anthropic to be analysed, then discarded. The file and its text are not saved. If you tap “Save summary”, only the plain-English summary is stored, and you can delete it in Settings. A daily usage count is kept to enforce limits.
- Rent you report
- If you answer “What do you pay?”: your neighbourhood, monthly rent, room type, number of flatmates, and whether bills and a private bathroom are included. Used to show average room prices per neighbourhood to other students. The report is stored without your name or account ID. A separate private record, which only you can read, links you to your own report so you can edit it. Averages are shown only once a neighbourhood has at least five reports.
What the app does not collect
- No advertising or analytics data. The app has no ad network and no analytics or tracking scripts.
- No live location. The app does not read your phone’s GPS; it uses the address you type.
- No payment details. The app is free and takes no payments.
- The app’s own code does not log your IP address or what you type. The hosting provider may keep standard technical logs of requests (such as IP address and time) for security.
4. What is kept on your device
The app uses your browser’s storage for things it needs in order to work. None of it is used for advertising or tracking.
- Your sign-in session, kept by Firebase Authentication so you stay logged in.
- An encrypted copy of your Emergency Card, so it still opens with no signal. The copy is encrypted with a key that your browser creates and keeps on this device. The key cannot be exported, and neither the copy nor the key is sent anywhere.
- Your choice for the switch “Keep medical details available offline on this device” on the Emergency Card. It is on by default. If you switch it off, the offline copy holds only 112, your embassy and the nearest hospital; your medical details and emergency contact are then shown only while you are online.
- If you browse as a guest, the school you picked.
- Small preferences and housekeeping values, such as a view toggle or an action to finish after you sign in.
Logging out wipes this storage on that device, including the Emergency Card copy and its key. The only thing that stays is the offline switch if you turned it off, so that the next sign-in on that device does not start keeping medical details again.
If your browser cannot encrypt, no copy of the card is kept on the device at all.
5. What other people can see
- Community posts are visible to signed-in students at your school. A post appears in the cross-school General feed only if you choose that for the post. Posts show your school or campus. They do not show your name, email or account ID.
- Friends see the phone number and contact email you chose to share, and nothing else. A friend request on its own reveals only your school. If either of you ends the friendship, the contact details stop being shown.
- Reports you make about a post are never shown to the author or to other users.
- Rent averages are visible to anyone using the app, including guests. Individual reports are not.
- I can access the database to run the service, fix problems and review reported posts.
6. Other companies that receive data
The app uses a small number of outside services. Here is each one and exactly what it receives.
- Firebase Authentication and Firestore (Google)
- Firebase Authentication handles sign-in, so Google receives your email, your password (stored by Google in hashed form) or your Google sign-in, and technical details such as your IP address. A small profile is also kept in Google’s Firestore database: your name, email, phone number, home address and arrival date. The rent reports described above are stored in Firestore too.
- Anthropic (the Claude API)
- Receives your chat messages and the recent turns of the conversation, together with your school and the interests you picked. Receives the text you paste into Scam Check and the lease you give to Lease Explainer. It is not sent your name, email, phone number or home address, unless you type them into a message or they appear in a document you upload.
- MapTiler
- Supplies the map images. Your browser requests them directly from MapTiler, so MapTiler sees your IP address and which part of the map you are looking at.
- Nominatim (OpenStreetMap)
- Turns an address into map coordinates. When you save a home address or a calendar location, the Compass Afar server sends that address text to Nominatim. The request comes from the server, not from your device, and carries nothing that identifies you.
- Overpass API (OpenStreetMap)
- Supplies nearby places such as supermarkets and gyms. The server asks about a grid square of roughly one kilometre around your home, never your exact address.
- TheSportsDB
- Supplies upcoming football and basketball fixtures. The server downloads them on a schedule. TheSportsDB receives nothing about you.
- Google Fonts
- This website (compassafar.com) loads its typefaces from Google Fonts, so Google sees your IP address when the fonts load. The app does not: it serves its own font files, and nothing is requested from Google Fonts.
- Google Maps Places
- If address suggestions are switched on, what you type in the address box is sent from your browser to Google to fetch suggestions.
Public transport timetables, rent statistics and housing listings are downloaded from their publishers by the server. Those requests contain nothing about you.
I do not sell your data, share it with advertisers, or give it to anyone else, unless the law requires it.
7. Legal basis
Under the GDPR, every use of personal data needs a legal basis. These are the ones Compass Afar relies on.
- To provide the service you signed up for (contract): your account, school, address, budget, calendar, saved items and community features.
- Your consent: the health details on your Emergency Card, your optional contact details, sharing a post to the General feed, and reporting your rent. You can withdraw consent at any time by clearing the field or emailing me.
- Legitimate interests: keeping the service secure, enforcing daily usage limits, and handling reports about posts.
8. Where data is stored
Most of your data is stored in a database on the Compass Afar server. Your sign-in details, the small profile and the rent reports are stored by Google (Firebase). Chat messages and housing-tool documents are processed by Anthropic in the United States.
Some of these companies process data outside the European Economic Area. Where they do, the transfer relies on the safeguards those companies provide, such as the EU–US Data Privacy Framework or standard contractual clauses.
9. How long it is kept
- Your account and everything in it are kept for as long as you have an account.
- When you ask for deletion, your data is deleted within 30 days. Copies in backups are removed as those backups are replaced.
- Chat messages and housing-tool documents are not stored on the Compass Afar server at all. Anthropic may keep them for a limited time under its own policies.
- Daily usage counts hold only a number per day.
- Rent reports stay in the dataset in anonymous form unless you ask for yours to be removed.
10. Your rights
If you are in the EU or the UK, you have the right to:
- Access the data held about you.
- Correct anything that is wrong. Most of it you can edit yourself in Settings.
- Delete your data.
- Export your data in a common file format.
- Restrict or object to a particular use of your data.
- Withdraw consent for anything based on consent.
- Complain to a data protection authority. In Spain that is the Agencia Española de Protección de Datos (aepd.es).
To use any of these rights, email lukaritchley@compassafar.com from the address on your account. I will reply within 30 days. It is free.
11. How to delete your data
You can remove some things yourself in the app: community posts, calendar entries, saved items, saved lease summaries, friends, and any optional profile field (clear it and save).
To delete your whole account, email lukaritchley@compassafar.com from the address on your account with the subject “Delete my account”. I will delete your account, your profile and everything linked to it, including your sign-in at Firebase, and confirm when it is done.
12. This website
This website (compassafar.com) is a set of static pages. It sets no cookies, runs no scripts and has no analytics. It is hosted on Cloudflare, which processes technical request data such as your IP address in order to deliver the pages. Typefaces are loaded from Google Fonts.
13. Changes to this policy
If the app starts collecting something new or using a new outside service, this page will be updated first and the date at the top will change. For a significant change, the app will tell you.