Gowalk

Privacy

Privacy Policy

What this app collects, why it collects it, and what you can ask us to delete.

Effective date: 21 September 2026

Gowalk provides prepaid travel eSIM plans, purchase and installation tools, usage information, a trip planner and customer support. This policy explains how the Gowalk app and its services handle personal information. For questions or privacy requests, use the Gowalk support form.

Information we use

Account and installation information: an automatically created Firebase account identifier, an installation identifier and public signing key, device model, operating system, app version, language and time zone. These protect access to your plans and authenticate requests.

Purchases and eSIM service: selected plans, prices, payment status, receipts, refunds, eSIM identifiers, provider assignment records, installation status and data usage. We use these to fulfil orders, display your service, process support and refunds, and investigate disputes.

Payments: Stripe processes payment details entered in its payment sheet or supplied by Apple Pay or Google Pay. This may include billing contact and address details required for a transaction. Our backend receives payment references and limited details such as card brand, last four digits, wallet type and billing country or postal code, not your full card number or CVC. Stripe also processes device and interaction information for fraud prevention and service analytics.

Security and transaction evidence: request IP addresses, timestamps, device and request metadata, payment/fulfilment receipts, and relevant in-app actions such as showing installation details or a refund policy. Client-reported actions are distinguished from provider observations. We use recorded facts to investigate abuse and payment disputes; they do not guarantee an outcome.

Optional contact and recovery details: your email and message when you request support, plus any name supplied through our support form. Importing an older Gowalk account sends its email and password to Firebase Authentication to verify ownership. The new backend receives an identity token rather than storing that password.

Planner and Help: trip choices, questions you type, and relevant eSIM status are sent through our backend to OpenRouter and its selected AI provider to generate an answer. Avoid entering sensitive information that the question does not need. We request zero-retention provider routes and disallow provider data collection for training in these requests. We retain request outcome and cost/quota metadata; submitted support messages and reports are retained to resolve them.

Answer reports: when you report a Help or Planner answer, we send the previewed excerpt, answer reference and optional reason to the Gowalk team through our protected backend. We do not include the rest of your conversation or send reports to the AI provider. Reports remain available for developer review without a separate automatic expiry and are removed when you delete your account. Report text is not included in analytics or crash logs.

Analytics and reliability: Firebase Analytics and Crashlytics process app-instance or installation identifiers, screen and feature events, device information, crash reports and diagnostics. Analytics derives approximate location from masked IP addresses. We do not request GPS location. App-authored analytics events use fixed labels, without account IDs, eSIM numbers, payment details, email addresses or typed questions.

Optional notifications: if you enable notifications in Settings, Firebase Cloud Messaging and, on iOS, Apple deliver low-data and expiry reminders using a device registration token. Lock-screen reminders contain generic text; they do not include your eSIM details. You can turn them off in Gowalk or your phone settings. Our backend removes tokens after 60 days without installation activity and delivery-attempt records after 30 days; account deletion removes both. A delivery service accepting a reminder does not prove you received or read it.

The app does not request access to your contacts, photos, camera or microphone. It checks whether WhatsApp is installed locally to determine eligibility for a first-launch rating invitation; it does not read WhatsApp content. We disable advertising identifier collection and personalized advertising in our analytics configuration. We do not sell personal information or use it to track you across other companies' apps and websites for advertising.

Service providers and disclosures

We use Firebase for identity, app integrity, optional notifications, analytics and crash reporting; Stripe and relevant payment networks for payments and fraud prevention; eSIM-Go and its network partners for eSIM fulfilment and service status; OpenRouter and its selected model providers for optional AI features; and hosting/security providers to operate the service. Information necessary for a payment dispute may be supplied to Stripe, banks and card networks. We may also disclose information when legally required or necessary to protect users and the service.

Providers may process information outside your country under their applicable data protection terms. Their independent obligations, including payment and telecommunications recordkeeping, may continue after you close your Gowalk account. Provider privacy information is available from Firebase, Stripe, eSIM-Go and OpenRouter.

Retention and deletion

Account and service information is retained while needed to provide your account and plans. You can export your account information and request deletion in Settings. Closing your account removes access, preferences, assistant request records and support messages, and schedules deletion of the associated Firebase identity and legacy personal records. Provider cleanup is retried if temporarily unavailable; it is separate from immediate local account closure.

Limited purchase records, IP addresses and verifiable dispute evidence are retained with a pseudonymous reference for 400 days after account deletion for refunds and dispute handling, then purged. A pending provider cleanup can delay final removal of its associated deletion record. Pseudonymous evidence is still personal data. Payment and network providers may retain their own records under their policies and legal obligations. Analytics and crash diagnostics follow the applicable provider retention and deletion controls.

To request deletion without reinstalling the app, use the Gowalk support form, select a privacy/account request in your message, and provide an order or account reference if available. Do not send a password, card number or eSIM activation code. We verify ownership before acting so another person cannot close your account using only a receipt reference.

Your choices and rights

Planner, AI Help, support messages, old-account import and saving a payment method are optional. You can manage usage alerts, saved payment preferences and account recovery in Settings. Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, obtain a copy of information, or complain to your data protection authority. Submit these requests through the support form. Some records must be retained as explained above.

Security, age and changes

The app communicates over encrypted HTTPS. Backend access uses identity tokens, app integrity checks and installation signatures. Secret payment and provider credentials stay on the server. No service can guarantee absolute security. Gowalk is intended for adults and is not directed to children. We will update this policy when practices change and show the effective date above.