Privacy Policy

Last updated: July 2026

WanderFree is built around one rule: collect as little as possible, and keep almost all of it on your own device. This page explains exactly what that means for the app's four features — alertness monitoring, dashcam recording, SOS notify, and the live status page a Dash Alert can send.

Permissions WanderFree asks for

iOS will prompt you for each of these the first time it's actually needed — not all at once on launch. WanderFree doesn't function without them, since they're what the core safety features are built on:

Alertness monitoring and TrueDepth (face) data

What is collected: on a TrueDepth-equipped device (iPhones and iPads with Face ID), WanderFree uses ARKit's face-tracking APIs to read eye-closure (blink/openness) and head-position data from your face while you drive, in order to detect signs of drowsiness in real time. On devices without a TrueDepth camera, this same detection runs instead on a plain camera frame analyzed by Apple's on-device Vision framework — no TrueDepth data is involved on those devices at all.

Purpose: this data exists for exactly one purpose — real-time drowsy-driving detection while a monitored drive is active — and for nothing else. It is never used for authentication, advertising, analytics, personalization, or any purpose beyond that immediate safety check.

Storage and retention: this data is never written to disk, never persisted in any database, and never stored anywhere — on-device or otherwise. It exists only transiently in memory for the fraction of a second it takes to evaluate the current frame, and is discarded immediately after. Nothing about your face is retained once a drive ends; there is nothing to delete, because nothing was ever stored in the first place.

Sharing and transmission: no camera frame, face-tracking data, or derived alertness score is ever uploaded anywhere, transmitted off your device, sent to any server (including WanderFree's own infrastructure), shared with any third party, or used to train any model. All of this analysis happens entirely on-device.

Dashcam footage and your own iCloud

When you trigger a Dash Alert, front and/or back camera footage is recorded locally to your device — that copy is never uploaded anywhere on the free plan. On WanderFree Pro, footage also syncs automatically to your own iCloud Drive (visible in the Files app, under iCloud Drive → WanderFree), so you can browse, open, or share it from outside the app too — WanderFree does not operate its own servers to store this footage, and nobody at WanderFree can access it. Deleting a trip (or using the manual "Delete Clips Older Than…" tool in Settings) deletes both the local files and this iCloud Drive copy, if one exists. Footage saved on your device itself is never deleted automatically, on any plan — only the iCloud Drive copy is pruned automatically, after a duration you choose (24 hours to Keep Forever, Pro only), and you can pin ("Keep") any individual clip to exempt it from that cloud cleanup.

Emergency contacts

The emergency contacts you add are stored locally on your device. They're only ever used to pre-fill the recipients of a message you choose to send through Apple's own Messages app — WanderFree does not transmit your contact list anywhere itself.

SOS incidents and the live status page

Switching a Dash Alert to SOS mode creates a small record containing your first name (if you've set one in Settings), an approximate location and speed, a timestamp, and — once it finishes uploading — a short video clip. Unlike your regular dashcam footage above, this record and its clip are stored in WanderFree's own shared CloudKit space, not your personal iCloud storage — that's what lets the person you notify view it instantly from a plain link, without needing an Apple ID or the app themselves. It's protected by a single safeguard instead: its web address contains a 128-bit random ID that cannot realistically be guessed. Nobody can browse, search, or list these records — only someone who has the exact link (because you sent it to them) can view one.

What we don't do

Children's privacy

WanderFree is intended for licensed drivers and is not directed at children. We do not knowingly collect information from children.

Changes to this policy

If this policy changes in a way that affects what data is collected or how it's used, we'll update the date above and, where practical, note the change here.

Questions

Reach out any time via the contact page.