Legal
How analytics work
How analytics work
When you sign in to Viewpoint you’ll see a one-time prompt asking whether you’d like to share anonymous usage data. This page explains exactly what that means — what gets collected, what is never collected, where the data goes, and how to change your mind.
The web app, too. The same opt-in applies on the Viewpoint web app (web.getviewpoint.app). It’s off by default there as well — turn it on under Settings → Privacy → Share usage analytics. As on the phone, your browser never contacts the analytics provider directly; events go through a Viewpoint server.
Guests send nothing. If you use Viewpoint without signing in, no analytics events ever leave your device — there’s no account to attach them to. Analytics only come into play once you have an account, and only then if you opt in.
Default is off. If you tap Not now, no analytics events leave your device. Your subscription, your spots, your maps, your photos, your watches, your shoot plans — all of it works identically with analytics off. Saying yes only helps us prioritise what to build next; saying no doesn’t degrade what you get.
Arrived from the cookie banner on getviewpoint.app? That banner is about the website, not the app — a separate surface with its own separate choice. See The marketing website below.
What is collected (when you’ve opted in)
- Screens you visit — Gallery, Explore, Settings, Capture, Spot detail, etc. So we can see which surfaces actually get used and which sit unused.
- Buttons and gestures you tap — drop pin, capture, swipe between spots, drag-to-reorder a map, long-press the map. Helps us know which affordances work in the wild and which we should redesign.
- Counts of artifacts — how many spots you’ve created, how many maps, how many shoot plans. The counts, never the content.
- Which platform you’re on (iOS or Android), your OS version, and your app version — so we can prioritise bug fixes for the OS versions that have the most users. Your language setting is not sent.
- An anonymous identifier — a random UUID generated by the server when you signed up. It’s the same identifier our backend uses internally for your account, but it isn’t linkable to your real name, email, or any other identity outside Viewpoint.
What is never collected
- Your photos. Both the image bytes and the EXIF metadata stay on your device + your own private cloud row. They are never sent to our analytics pipeline.
- Your spot locations or GPS coordinates. Not the coordinates of spots you create, not the centres of regions you watch, not the bounds of maps you build. We don’t know where you’ve been.
- Your notes, titles, or any free-text you’ve written. Spot names, map descriptions, parking notes, hazard notes, private notes — none of it is sent.
- Your email, sign-in name, or any other directly identifying information. Sign in with Apple’s private relay email, your Google sign-in name, an email/password you registered — none of these leave your device for analytics purposes.
- The contents of any watch, condition event, or shoot plan.
Where the data goes
Events go from your phone (or the web app) to a Viewpoint server, which forwards them to Mixpanel — a third-party product-analytics platform.
Mixpanel derives a rough country and city from the network request — granular enough to tell us “a third of users are in Germany” but no finer. We never see your individual location through this channel; only the country / city granularity Mixpanel reports, aggregated across all users.
Mixpanel’s own data-handling practices are published at https://mixpanel.com/legal/privacy-policy/. Viewpoint sends no personal data beyond the anonymous identifier described above.
Changing your mind
- Open Settings → Privacy → Share usage analytics at any time and toggle it on or off. The change takes effect immediately — the next event your phone would have sent is the first one suppressed (or, if you’re toggling on, the first one sent).
- Mixpanel keeps your historical events under the same anonymous identifier. If you’d like that erased, the cleanest path is to delete your Viewpoint account (Settings → Account → Delete account). Our deletion pipeline calls Mixpanel’s GDPR-erasure endpoint to remove the linkage on their side as well.
Why we ask
Analytics are the only signal that tells us which features actually solve a problem versus which ones sit in the menu unused. Saying yes here directly shapes what gets built next — it’s the attention budget behind every roadmap decision.
We’ve kept the data inventory deliberately narrow (no photos, no GPS, no content, no identifiable info) precisely because the goal isn’t to know who you are — only how people in general use the app.
The marketing website (getviewpoint.app)
Everything above is about the app. The public website — the marketing pages, the Field Guide, the calculators and these legal pages — is a separate surface, with its own separate choice: the cookie banner on your first visit.
Nothing is stored unless you accept. Decline, or simply ignore the banner, and no analytics or advertising cookies are written and no identifiers are kept in your browser. Every page works identically either way.
If you accept, two things switch on:
- Mixpanel — the same product-analytics platform the app uses, here recording which pages you read, which links you click, and how far you get through a Field Guide article. Page path, language, page title, referrer. No account is involved: the website has no sign-in.
- Google Ads — measures whether the ads we run actually bring people to the site, so we can stop paying for the ones that don’t. That is the whole of it: ad personalisation stays switched off even when you accept, so your visit is never used to build a remarketing list or to follow you around the web with our ads. We don’t run ads on this site either — there are no third-party ad slots on any page. Google’s own data-handling practices are published at https://policies.google.com/privacy.
The Google tag is present on every page from the moment it loads, but it starts denied (Google Consent Mode v2): before you accept it stores nothing on your device, the ad identifiers in its requests are redacted, and all it can report is a cookieless signal that a visit happened. Accepting is what lifts that.
Withdrawing consent: clear cookies and site data for getviewpoint.app in your browser. The banner returns on your next visit and you can choose again.
This choice is independent of the in-app toggle above — accepting on the website does not opt your account into app analytics, and opting in inside the app does not accept anything on the website.
Related
- Privacy policy — the overall data-handling commitments Viewpoint operates under.
- The in-app version of this page lives in Settings → How analytics work (tap “Learn more” on the first-launch consent prompt to read the same content there).
Changelog
- 2026-09-09 — Documented the marketing website (getviewpoint.app) as a separate surface: its cookie banner, the Mixpanel and Google Ads tags accepting can enable, and the Consent Mode v2 denied-by-default behaviour of the Google tag. Ad personalisation is never granted there, so the site builds no remarketing audiences.
- 2026-06-25 — The web app (web.getviewpoint.app) now shares the same analytics: opt-in, off by default, toggled under Settings → Privacy. Same server-side proxy to Mixpanel, same narrow data inventory.
- 2026-06-04 — Clarified that guests (not signed in) send no analytics at all; analytics apply only once you have an account, and only if you opt in.
- 2026-05-29 — Initial publication. Captures the data inventory + opt-in behaviour shipped with the v0.1.x onboarding-consent prompt.