01
Who we are and what this covers
Pathfinder is operated by Decentre Studio Limited, the controller of the personal information described here. Decentre Studio Limited is registered in England and Wales. Company number 16201479.
This policy applies to the Pathfinder Android app with package
io.decentre.pathfinder, including the Pathfinder API and account services that
the app uses. Screens expressly labelled as design previews or synthetic data do not create
live path, date or map records merely because you view them.
Privacy questions and rights requests can be sent to jessejr@decentre.io. Our website is www.decentre.io.
02
Information the current app handles
Account, sign-in and policy records
Google sign-in through Firebase Authentication provides a Firebase user identifier and email address. Pathfinder receives an identity token to establish an authenticated, student-bound session; it does not receive your Google password or request access to Gmail, Google Calendar or Google Drive. Firestore stores the accepted policy version, acceptance time, email and app surface for the signed-in user.
Student profile and planning information
The Pathfinder backend can hold the student profile information you provide or correct, such as education stage, qualifications, subjects and predicted grades, route and subject interests, constraints and preferences, open questions and active tasks, confirmed or disliked choices, comparison preferences, and origin, destination or other user-entered location information. These records support a student-scoped profile and planning view.
Conversations and durable history
When you use Ask Pathfinder, we process your messages, Pathfinder's responses, message and thread references, timestamps, and the bounded profile or source context needed to answer. Text conversation history is stored durably on the Pathfinder backend so an admitted account can load earlier turns. Relevant, minimised prompt context and the model response are also processed by the configured AI route.
Saved items, Pins and choices
We store items you deliberately save as Pins, the account-bound reference and display information needed to show them, and pin or unpin events. An unpin request removes that saved reference; it does not delete the underlying public source. Choices and preferences that form part of your profile remain separate from Pins.
App, API and security activity
We process session identifiers, request identifiers, route names, times, response status, policy state, bounded operational diagnostics, and security or abuse-prevention events. These operational and security logs help us authenticate requests, prevent cross-account access, diagnose failures and keep an accountability record. Mobile diagnostics use bounded error codes and request references rather than retaining raw response bodies.
On-device state and diagnostics
Firebase's Android SDK keeps the credential state needed to remain signed in. Pathfinder product queries and drafts are memory-only in the current app and are cleared when the account owner changes; inactive query data becomes eligible for removal after five minutes while the process is running. The app does not use analytics. It does not use advertising SDKs or the Android Advertising ID. It does not use Crashlytics or Sentry and does not add a separate crash or session-replay collector. Google Play or the Android platform may process platform diagnostics under your Google and device settings, independently of a Pathfinder SDK.
03
Google Maps, interactions and location
When the provider renderer is enabled for the Android release, Pathfinder uses the Google Maps SDK to render a map and markers. Loading or interacting with that map causes requests to Google. Google may process information such as IP address, device and app information, requested map area, and interactions needed to render and secure Google Maps, under the Google Privacy Policy. We do not claim that Google Maps traffic is anonymous or zero retention.
Exact or approximate device location
Pathfinder does not request Android precise-location or approximate-location permission, does not show the user's live location, and does not collect GPS or network-derived device location for the Pathfinder account. Google may still derive general location from an IP address as described in Google's own policy.
Coarsened location
A country, region, city, travel radius or bounded area that you provide as a preference can be stored in your student profile or included in a conversation. This is not obtained from the Android location permission.
User-entered location
If you type a location into a profile field or message, we process it as part of that profile or conversation. Avoid entering an exact home address unless it is genuinely necessary for your request.
Map camera and marker interactions
The current screen keeps the selected marker and camera position as local presentation state. Decentre does not add those interactions to your student profile. Coordinates shown for public or synthetic map markers are not your device location.
04
Why we use this information
- To authenticate you and provide the student-scoped Pathfinder service under our contract with you.
- To maintain your profile, conversations, Pins and current planning choices.
- To generate a response when you deliberately submit a message to Ask Pathfinder.
- To keep the service secure, reliable and correctly separated between accounts, based on our legitimate interests.
- To record policy acceptance and respond to data-rights or legal requests.
We do not sell personal information. Pathfinder does not use advertising or the Android Advertising ID, and we do not use Pathfinder information to track your activity across other apps or websites. We do not make a solely automated decision that has a legal or similarly significant effect on you.
05
Where information is processed and who receives it
Access is limited to authorised Decentre personnel and service providers needed to run Pathfinder. We do share data with processors; those services are not described as anonymous.
Google / Firebase
Firebase Authentication handles Google sign-in and authentication identifiers. Firestore holds the bounded policy-acceptance record. Google Cloud hosts the Pathfinder API, operational services, logs and Cloud SQL records. See Firebase privacy and security and the Google Cloud Privacy Notice.
Google Maps
When enabled for the release, the Android Maps SDK provides the base map and processes map requests and interactions as described above. Pathfinder does not send the Firebase bearer token or Pathfinder session header to Google Maps.
OpenRouter and the selected model provider
When you send an Ask Pathfinder message, the backend can route minimised prompt context through OpenRouter to the selected model provider to generate a response. Both the routing layer and selected provider may process those bytes. Their retention and location depend on the configured route and provider; see the OpenRouter privacy policy. Pathfinder does not promise that every provider route is anonymous or zero retention.
These services may process information in the United Kingdom, European Economic Area and United States. Where personal information is transferred outside the UK, we use an applicable adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard. We may also disclose information when required by law or to protect users and the service.
06
How long we keep information
We follow the current Pathfinder retention schedule below. A verified deletion request can shorten these periods where no legal, security or accountability exception applies.
- Account identity
- For the duration of the Pathfinder account and up to 12 months after account closure.
- Student profile, choices and Pins
- For the duration of the account and up to 12 months after account closure.
- Conversation history
- Rolling six-month window.
- Session, operational and security logs
- Up to 12 months.
- Policy acceptance, consent and deletion accountability
- Up to three years.
- On-device Pathfinder product cache
- Memory-only; cleared on account replacement or process end, with inactive queries eligible for removal after five minutes while running.
- Google Maps and platform records
- Controlled by Google under its own service, account and device retention settings.
Backup copies may remain until the normal backup cycle expires. If a backup is restored, the deletion record is used to re-apply eligible deletion. We may retain a limited record where it is needed for security, fraud prevention, legal obligations, policy acceptance or to prove that a rights request was completed.
07
Your data-protection rights
Depending on the circumstances, UK data-protection law lets you ask us to access, correct, restrict, object to, export or delete your personal information, and to withdraw consent where consent is the basis for processing. Withdrawing consent does not affect processing that was lawful before withdrawal.
Email jessejr@decentre.io. We will verify the request against the signed-in account and the server-bound student record before disclosing or changing data. We aim to acknowledge requests within five working days and complete a verified request within one calendar month where possible. We will explain if a lawful exception or a complex request requires a different outcome or timeframe.
08
Account deletion
The current app does not currently provide an in-app account-deletion control. Signing out, uninstalling Pathfinder or removing a Pin does not delete the Pathfinder account or its other backend records.
Use our stable public Pathfinder account-deletion request page. After identity verification, the operator reviews Firebase Auth, Firestore policy acceptance, profile, conversation, Pin, planning, audit and backup store groups and records what was deleted, retained or deferred. Eligible deletion is completed within one calendar month where possible; retained security, legal or accountability records and backup expiry are explained in the outcome.
09
Security and young people
Pathfinder uses HTTPS, Firebase authentication, server-bound account and student identity, scoped data projections and redacted operational diagnostics. No internet service is completely secure, but we limit access and use technical and organisational controls proportionate to the service.
The current release is for people aged 16 or over. If you are under 16, do not create a Pathfinder account or submit personal information. We apply data-minimisation and higher privacy defaults to users aged 16 or 17.
10
Changes, contact and complaints
We may update this policy when the app or its processing changes. The current version and its last-updated date will remain on this page. Material changes will be communicated where required.
Decentre Studio LimitedCompany number 16201479
England and Wales
jessejr@decentre.io
You can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We would appreciate the opportunity to address your concern first.