TheWileyfox

Privacy Policy

LegalVersion 1.1

Privacy Policy

Applies to: the Wiley Fox mobile application, thewileyfox.com, our QR-linked products, and all related services (together, the "Services").

Last updated: 4 August 2026

Last updated: 4 August 2026 Version: 1.1 Applies to: the Wiley Fox mobile application, thewileyfox.com, our QR-linked products, and all related services (together, the "Services").

1. Who we are and how to reach us

Wiley Fox is operated by Wiley Fox Mapping Limited ("Wiley Fox", "we", "us", "our"), a company registered in England and Wales.

Company number

17172765

Registered office

[19 Hereford Close, Hook,United Kingdom]

ICO registration number

[ ZC143718 ]

Privacy contact

privacy@thewileyfox.com

General contact

admin@thewileyfox.com

EU representative (Art. 27 UK/EU GDPR)

[Barry Wilson]

We are the data controller for the personal data described in this policy, including data about Protected Persons (see section 7).

If you are unhappy with how we handle your data you can complain to us first at privacy@thewileyfox.com. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113) or to your local supervisory authority.

2. The short version

We think you should be able to understand what we do with your data without a law degree. In summary:

We collect the minimum we need. Especially for children's data and health data.

Nothing sensitive is shared without your explicit, specific consent. You choose what goes on a QR tag. You choose whether a photo can be broadcast. You can change your mind at any time.

We never sell your personal data for money, to anyone, ever. The free tier does show ads, and to do that we share a resettable advertising identifier with our ad partner — which some US state laws treat as "sharing". You can turn it off. Section 13 explains it plainly, and we never advertise to under-18s using their data.

Safety information in the app is provided for information only. It comes largely from third-party public sources and from other users. We do not verify it and we do not guarantee it. Please read section 9 carefully.

Wiley Fox is not an emergency service. In an emergency, always contact the local emergency services first.

The full detail follows. Where a section particularly matters — children, health data, SOS — we have flagged it.

3. Who can use Wiley Fox

You must be at least 16 years old to hold your own Wiley Fox account.

In limited circumstances, a person aged 13 to 15 may hold a linked account, but only where:

a parent or legal guardian has created a Family Group and provided verifiable consent; and

local law in the user's country permits it; and

the account is restricted to reduced functionality (no public community broadcasting, no independent SOS sharing outside the Family Group).

We do not knowingly create accounts for anyone under 13, anywhere in the world. This includes users in the United States, where the Children's Online Privacy Protection Act (COPPA) applies.

Children of any age may be included as a Protected Person on a guardian's account — for example, a child linked to a QR tag or wristband. A Protected Person does not hold an account, does not agree to our terms, and their data is managed entirely by their guardian. See section 7.

If we learn that we hold data for an account holder under the permitted age, we will delete that account and its data without undue delay. If you believe a child's data is held incorrectly, contact privacy@thewileyfox.com and we will act within 72 hours.

4. What we collect

4.1 Information you give us

Category

Examples

Why we need it

Account data

Name, email address, password (hashed), phone number, country, date of birth or age band

To create and secure your account, verify age eligibility

Profile data

Display name, profile photo, language, notification preferences

To personalise the Services

Family Group data

Names and relationships of Family Group members, linked Protected Persons

To operate Family Groups, SOS alerting and QR tag reunification

Protected Person data

A child's or dependant's first name, age, photograph, distinguishing details, emergency contacts

To help reunite a lost person with their guardian

Health and medical data

Allergies, conditions, medications, blood type, emergency contacts, care instructions

Only if you choose to add it to a medical QR profile

User-generated content

Safety pins, area reports, reviews, photographs, comments, messages sent through the app

To operate the community safety features

Purchase data

Delivery address, order history, subscription tier

To fulfil merchandise orders and manage subscriptions

Support data

Correspondence with us, reports of misuse, appeals

To provide support and enforce our terms

4.2 Information we collect automatically

Category

Examples

Location data

Precise GPS location (only with your permission and only while relevant features are in use); approximate location derived from IP address

Device and technical data

Device model, operating system, app version, device identifiers, crash logs, IP address, time zone

Usage data

Screens viewed, features used, searches, session length, referring links

QR scan data

Time, approximate location and device type of each scan of one of your QR tags; the scanner's message to you if they choose to send one

Cookies and similar technologies

See section 13

4.3 Information from third parties

Public crime and safety data — including data.police.uk (UK Home Office), national statistics agencies, and other public sources catalogued in our data register.

Payment providers — confirmation of payment status. We do not receive or store your full card number.

Affiliate and booking partners — confirmation that a booking was made through our link, for commission reconciliation. We do not receive your full booking details.

App stores — subscription status and receipt validation.

Fraud and abuse prevention providers — signals used to detect misuse of the Services.

4.4 Data we deliberately do not collect

We do not collect your precise location in the background when you are not using a location-dependent feature. We do not collect contacts from your phone unless you explicitly invite someone. We do not collect biometric data, and we do not run facial recognition or face matching on any photograph.

We never use any of the following for advertising, in any circumstances: your precise or historical location, your health or medical data, Protected Person data, Child Alert content, the contents of your QR tags, SOS data, or anything you have marked private. See section 13 for what advertising on the free tier does involve.

4.5 Photographs — metadata is removed

Photographs normally carry hidden metadata, including the exact GPS coordinates and time the picture was taken. We strip all location and device metadata from every image on upload, before it is stored or shown to anyone. A photograph you upload will not reveal where it was taken unless you separately choose to attach a location.

What we do

Legal basis

Create and operate your account

Contract (Art. 6(1)(b))

Fulfil merchandise orders and subscriptions

Contract (Art. 6(1)(b))

Display crime, safety and mapping information

Legitimate interests — providing the core service (Art. 6(1)(f))

Process precise location for maps, routing and SOS

Consent (Art. 6(1)(a)), given via your device permission

Store and share health / medical data on a medical QR profile

Explicit consent (Art. 6(1)(a) and Art. 9(2)(a))

Share health data where you are physically or legally incapable of consenting

Vital interests (Art. 6(1)(d) and Art. 9(2)(c))

Store and share a child's photograph or details for reunification

Explicit consent of the guardian (Art. 6(1)(a) and, where the data is special category, Art. 9(2)(a)); vital interests where the child is at immediate risk

Broadcast a lost-person or lost-item alert to the community

Explicit consent (Art. 6(1)(a)) — you opt in each time

Send SOS alerts to your Family Group

Contract and vital interests

Security, fraud prevention, abuse detection, enforcing our terms

Legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))

Analytics and product improvement

Consent where required, otherwise legitimate interests

Show and measure advertising on the free tier

Consent (Art. 6(1)(a)). Never applied to under-18 accounts — see section 13

Marketing emails

Consent, or soft opt-in for existing customers. Unsubscribe at any time

Responding to law enforcement or court orders

Legal obligation (Art. 6(1)(c))

Where we rely on consent, you can withdraw it at any time in the app under Settings → Privacy, or by emailing privacy@thewileyfox.com. Withdrawing consent does not affect processing carried out before you withdrew it, and may mean a feature stops working.

Where we rely on legitimate interests, we have carried out a balancing assessment. You can request a summary of it, and you have the right to object (see section 14).

6. QR-linked products: lost items, lost children, and medical wristbands

This section describes the most sensitive data we handle. Please read it in full.

6.1 How QR tags work

You can attach a Wiley Fox QR tag — a sticker, keyring, luggage tag, clothing label or wristband — to an item, a child, or yourself. When someone scans it, they see a web page containing only the information you have chosen to publish for that tag, and nothing else.

You control, per tag:

what information is displayed;

whether a photograph is displayed;

whether the finder can send you a message;

whether the finder can see any medical information;

whether the tag is active at all.

You can change or deactivate any tag at any time, instantly, from the app. Deactivating a tag takes effect immediately — a subsequent scan will show only a "this tag is not active" message.

6.2 Lost item tags

A scan of an item tag shows only what you have set — typically a first name and a contact route. We recommend not publishing your home address. When someone scans your tag, we record the time, the approximate location and the device type of the scan, and we notify you. The scanner's own precise location is only shared with you if they actively choose to share it.

6.3 Child tags — additional protections

Where a tag is linked to a Protected Person under 18, additional safeguards apply:

Only a person with parental responsibility or legal guardianship may create the tag. You must confirm this when you register the child, and you warrant to us that it is true.

A child's photograph is never displayed by default. Displaying a photograph requires a separate, explicit, recorded opt-in by the guardian.

A child's medical information is never displayed by default. It requires a separate explicit opt-in, and can be restricted to "on request only", where the scanner must ask and you must approve in the moment.

We never publish a child's surname, home address, school, or date of birth on a scan page.

The scanner is shown a notice reminding them that they are viewing a child's data, that misuse is a criminal offence in many jurisdictions, and that they should contact the local police or emergency services if the child is at risk.

All scans of a child tag are logged and shown to the guardian.

Location metadata is stripped from every photograph on upload (section 4.5), so a child's picture can never reveal where it was taken.

Scan pages cannot be found, guessed or crawled. Every tag has a long, randomly generated address that cannot be worked out from another tag's. Scan pages carry noindex instructions so search engines do not list them, and we rate-limit and monitor attempts to try addresses at scale.

6.4 Child Alerts and community lost-person broadcasts

If a child or dependant is lost, a guardian may choose to raise a Child Alert — a pin on the map, plus a notification to other Wiley Fox users in the surrounding area.

A guardian raising a Child Alert for their own child is the only circumstance in which an image of a child may appear anywhere on Wiley Fox. Our Terms prohibit every other posting of a child's image, and we screen every uploaded image. See Terms clause 5.7.

This is opt-in, every single time. Consent given at sign-up is not sufficient on its own; the guardian must confirm the broadcast at the moment it is sent, and confirm what is included.

The guardian chooses whether the photograph is included, and can raise an alert without one.

The photograph is never displayed automatically. A user must actively tap through a warning notice before it is revealed. The notice explains that the image shows a missing child, that it may be used only to help find them, and that any other use may be a criminal offence.

Every reveal is logged — who viewed it and when — and the log is available to the guardian and to the police.

The photograph is removed from the Services the instant the guardian cancels the alert, and automatically on expiry.

The alert contains the minimum necessary: a description, an approximate area, a time, and a route to contact you or the police. It does not contain your home address or the child's full identifying details.

The guardian can cancel the broadcast at any time, and we will withdraw it from the app. We cannot recall copies that other users have already saved, screenshotted or shared outside the app. Please consider this before broadcasting a photograph.

We will automatically expire a broadcast after [24] hours unless renewed.

Broadcasting to the community is never a substitute for contacting the police. The app will prompt you to contact the emergency services first.

6.5 Medical wristbands and medical QR profiles

Health data is special category data under UK and EU GDPR and we treat it accordingly.

A medical profile is created only by you (or, for a Protected Person, by their guardian), and only with explicit consent recorded at the point of entry.

You decide exactly which fields are visible on a scan. Nothing you have not selected is ever shown. There is no hidden data behind a medical scan page.

Medical information is displayed to a scanner only in the context of assisting you. The scan page carries a notice that the data is provided for emergency assistance only and that any other use may be unlawful.

We log every scan of a medical tag and make the log visible to you.

Where you are unconscious or otherwise incapable of consenting, we may rely on vital interests to display the information you previously chose to publish.

Wiley Fox is not a medical device, a medical service, or a substitute for professional medical care. We do not verify, interpret or update medical information. It is your responsibility to keep it accurate.

6.6 SOS alerts

If you trigger an SOS:

Your alert and your location are sent to your Family Group by default.

You may additionally choose to share the alert with nearby Wiley Fox users in the local community. Where local community sharing is enabled by default in your settings, you can turn it off at any time before or during an alert, and we will tell you clearly at set-up that it is on.

Only the information necessary to get help to you is shared: an approximate or precise location (your choice), a first name, and any emergency information you have chosen to include. Your address, full identity, account details and unrelated medical data are not shared.

SOS alerts and their location trails are retained for [90] days and then deleted, unless you ask us to keep a record or we are required to retain it.

Wiley Fox is not an emergency service. An SOS alert does not contact the police, ambulance, coastguard, mountain rescue or any other emergency service. It depends on a working internet connection, a charged device, and other people choosing to respond. It may fail. Always contact the local emergency services first — 999 in the UK, 112 across the EU and much of the world, 911 in the US.

7. Family Groups, guardians and Protected Persons

A Family Group Administrator (usually a parent or guardian) can add other members and Protected Persons.

When you add a Protected Person, you are giving us their personal data. You confirm that you have the legal authority to do so and, where the person is capable of understanding, that you have explained it to them in a way they can understand.

Where a child is aged 13 or over, we encourage guardians to involve them in decisions about their own data, and we will present child-facing explanations in age-appropriate language.

Members of a Family Group can see the location and status information that the Group's settings permit. Each member aged 16+ can review and object to what is shared about them.

A Protected Person, or someone acting for them, can ask us to remove their data at any time by contacting privacy@thewileyfox.com, even if the guardian objects. We will assess the request in the person's best interests.

In relation to Protected Person data, the guardian decides what is published and to whom. We remain the controller for that data, because we design and determine how the tag, scan page and alert systems work, and we process it for our own purposes of safety, security, abuse prevention and legal compliance. We say this openly rather than describe ourselves as a mere processor, because it means the responsibility for protecting a child's data sits with us and not only with the parent.

Safeguarding

If we become aware of credible evidence that the Services are being used to harm, stalk, groom or endanger a child or vulnerable adult, we may suspend the account and disclose relevant information to the police or a relevant safeguarding authority without notifying the account holder. We consider this necessary in the vital interests of the person at risk and in our legitimate interest in preventing serious harm.

Image screening and child sexual abuse material

Every image uploaded to Wiley Fox is automatically screened before it is published, to detect child sexual abuse material and images of children posted in breach of our Terms. Screening is automated; a human reviews only where the system flags something or a user reports it.

Where we identify child sexual abuse material, or content that appears to constitute grooming or child sexual exploitation, we will — without notifying the account holder, and without waiting for a report — remove it, permanently ban the accounts involved, preserve the material and the associated account, device, location and log data as evidence, and report it to the police, to the Internet Watch Foundation, and to the National Center for Missing & Exploited Children where there is a US connection. We will cooperate fully with any investigation.

We rely on substantial public interest — preventing or detecting unlawful acts (UK GDPR Art. 9(2)(g) and Schedule 1 Part 2 of the Data Protection Act 2018), legal obligation, and the vital interests of children at risk. This processing is not subject to your right to erasure or objection, and we will not confirm or discuss a report with the person who is the subject of it.

Our duties under the Online Safety Act 2023

Wiley Fox is a user-to-user service. We carry out and keep under review an illegal content risk assessment and a children's risk assessment, operate the reporting and complaints routes described in our Terms, and keep records of our safety decisions, as required by the Act and by Ofcom.

8. Contact, blocking and misuse

When someone scans your tag, they may be able to send you a message. To protect you:

Your email address and phone number are never revealed to a scanner. Messages are relayed through Wiley Fox.

You can block any user or scanner permanently, at any time, with one action. A blocked person cannot contact you again through the Services, including via a different tag.

We retain a limited record of blocked interactions for safety and abuse-prevention purposes, even after you block.

You can report a scanner or user. We investigate reports and may suspend or ban accounts, and where appropriate report matters to the police.
Using a Wiley Fox QR tag or the community features to track, harass, stalk, intimidate or defraud another person is strictly prohibited, is grounds for immediate permanent ban, and may be a criminal offence.

9. Mapping, crime data and community safety information

This section explains an important limitation. Please read it.

Wiley Fox displays crime statistics, safety ratings, area information, routes and user-submitted reports.

This information is provided for general information only. It is not advice, a recommendation, an assurance, or a prediction.

We do not generate the underlying crime data. It comes from third-party public sources such as data.police.uk and equivalent national bodies. It is often incomplete, delayed by weeks or months, inconsistently categorised between regions, and reflects only reported crime.

We do not fact-check user-submitted pins, reports, photographs or reviews. They are the opinions and observations of individual users. They may be inaccurate, out of date, biased or malicious.

A safety rating is a calculated indicator, not a guarantee. An area rated as safer is not safe. Serious harm can and does occur in areas with low recorded crime.

We do not recommend, endorse or vouch for any place, route, region or country. If you choose to travel somewhere, or take a particular route, you do so entirely at your own risk and on your own judgement.

Always check official sources — for UK travellers, the FCDO travel advice at gov.uk/foreign-travel-advice; and equivalent government advice in your own country — and use your own judgement.

The full legal position on this is set out in our Terms & Conditions.

10. Who we share your data with

We share personal data only as described here. We do not sell personal data, and we do not share it with third parties for their own marketing.

Recipient

What they receive

Why

Other users

Only what you publish or broadcast: tag content, community pins, SOS alerts you have chosen to share

To operate the community features

Hosting and infrastructure (e.g. Supabase, Netlify, cloud storage)

Data at rest and in transit

To run the Services

Payment processors (e.g. Stripe, Apple, Google)

Payment and subscription data. We never see your full card number

To take payment

Merchandise fulfilment / print-on-demand partners

Name, delivery address, order contents

To make and ship your order

Email and notification providersEmail address, device push token

Analytics and crash reporting

Pseudonymised usage and diagnostic data

To fix bugs and improve the product

Advertising partner (free tier only)

A resettable advertising identifier, approximate region, app context. Never location history, health, children's or Protected Person data

To show and measure ads on the free tier. Not used for under-18 accounts — see section 13

Affiliate and booking partners (e.g. Booking.com)

A referral identifier only. We do not pass your name or contact details

To attribute a booking and reconcile commission

Mapping and tile providers

Requests for map tiles, which contain approximate location

To render maps

Professional advisers (lawyers, accountants, auditors)

As necessary, under duty of confidentiality

Legal and financial compliance

Police, emergency services, safeguarding authorities

Relevant information

Vital interests, safeguarding, legal obligation

A buyer of our business

Data may transfer as part of a merger, acquisition or asset sale

Business continuity. We will notify you

All processors are bound by written contracts requiring them to act only on our instructions, to keep data secure, and to delete or return it at the end of the engagement.

A current, named list of our sub-processors is published at thewileyfox.com/legal/subprocessors and updated when it changes.

Third-party bookings

If you follow a link to book accommodation, an attraction or an activity, you leave Wiley Fox and enter into a contract with that provider, under their terms and their privacy policy. We are not a party to that contract and we do not control their data practices. We earn a commission on some bookings; this never increases the price you pay and never affects the safety information we show you.

11. International transfers

Wiley Fox is available worldwide, so your data may be transferred to and processed in countries outside the UK and the European Economic Area, including the United States.

Where we transfer personal data out of the UK or EEA, we rely on one of the following safeguards:

UK adequacy regulations or an EU adequacy decision for the destination country;

the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses;

the EU Standard Contractual Clauses (2021/914);

certification under the UK–US Data Bridge / EU–US Data Privacy Framework, where the recipient is certified.

We carry out a transfer risk assessment before making a restricted transfer, and apply additional technical measures — including encryption in transit and at rest — where the assessment requires it. You can request a copy of the relevant safeguard by emailing privacy@thewileyfox.com.

12. How long we keep data

Data

Retention

Account data

For as long as your account is active, then [30] days after deletion

Protected Person data

Until removed by the guardian, or the account is deleted, then [30] days

Medical profile data

Until you delete it or close your account, then deleted immediately from live systems and within [30] days from backups

QR scan logs

[12] months

SOS alerts and location trails

[90] days

Community broadcasts and Child Alerts

Expired after [24] hours; record retained [90] days

Child Alert image reveal logs

[12] months, or longer where the police ask us to preserve them

Advertising identifier and ad interaction data

[13] months, or until you opt out or subscribe to Premium

Material reported as child sexual abuse, and associated evidence

Preserved as directed by law enforcement; not deleted on request

User-generated content (pins, reviews)

Until you delete it, or the account is deleted. Anonymised aggregate safety signals may be retained

Purchase and transaction records

6 years from the end of the relevant tax year (UK statutory requirement)

Support correspondence

[3] years

Abuse, ban and safeguarding records

[6] years, or longer where necessary to protect others

Marketing consent records

[6] years after withdrawal, as evidence of consent

Backups

Rolling [35] day cycle, after which deleted data is permanently unrecoverable

When we no longer need data we delete it or irreversibly anonymise it.

13. Cookies, similar technologies and advertising

13.1 Cookies and storage

Our website and app use:

Strictly necessary cookies and storage — for login, security and basic function. These do not require consent.

Functional storage — remembering your preferences.

Analytics — understanding how the Services are used.

Advertising identifiers and storage on the free tier — see 13.2.

On first visit we ask for your consent to non-essential cookies via a banner, and you can change your choice at any time at thewileyfox.com/legal/cookies or in Settings → Privacy. We honour Global Privacy Control (GPC) signals where your browser sends one.

13.2 Advertising on the free tier

Wiley Fox has a free tier and a paid tier. The free tier is supported by advertising. Premium is completely ad-free.

To show ads on the free tier we share a resettable advertising identifier (your device's IDFA on iOS or Advertising ID on Android), your approximate country or region, and basic app-context signals with our advertising partner. We do this so that advertising can be measured and, if you allow it, made more relevant.

What we never share with advertisers, under any circumstances:

your precise or historical location;

your health or medical data, or anything on a medical QR profile;

any Protected Person's data, photograph or details;

any Child Alert, SOS alert, or the content of either;

the contents of your QR tags, your Family Group, or your private messages;

your name, email address or phone number.

Your controls:

On iOS we ask for App Tracking Transparency permission. If you decline, you still get the app in full — you simply see non-personalised ads instead.

On Android and the web you can opt out at Settings → Privacy → Advertising, or reset your advertising ID in your device settings.

Subscribing to Premium removes advertising entirely.

Declining or opting out never reduces your access to any safety feature.

Legal basis: consent (Art. 6(1)(a)), given through the ATT prompt, the cookie banner or the in-app control. You can withdraw it at any time.

13.3 Children and advertising

We do not run personalised or behavioural advertising to anyone we know or believe to be under 18.

Accounts held by 13–15 year-olds within a Family Group are set to contextual advertising only, permanently. This cannot be switched on, by them or by anyone else.

We do not profile children, build advertising audiences from them, or pass any child's identifier to an advertising partner.

We do not use nudge techniques to encourage any user, and particularly any child, to weaken their privacy settings.

This reflects our commitment to the ICO's Age Appropriate Design Code (Children's Code).

14. Your rights

Under UK and EU GDPR you have the right to:

Right

What it means

Access

Get a copy of the personal data we hold about you

Rectification

Have inaccurate data corrected

Erasure

Have your data deleted ("right to be forgotten")

Restriction

Have us pause processing while a dispute is resolved

Portability

Receive your data in a machine-readable format, or have it sent to another provider

Object

Object to processing based on legitimate interests, and to direct marketing (which we will always stop)

Withdraw consent

At any time, for anything based on consent

Not be subject to solely automated decisions

We do not make decisions with legal or similarly significant effects about you by automated means

How to exercise them: in the app under Settings → Privacy → My Data (which offers self-service export and deletion), or by emailing privacy@thewileyfox.com.

We respond within one month. We may extend by two further months for complex requests, and will tell you if we do. There is no charge unless a request is manifestly unfounded or excessive.

If you are in the United States

Depending on your state (including California, Colorado, Connecticut, Virginia, Utah, Texas and others), you may also have the right to know what personal information we collect, to delete it, to correct it, to opt out of "sale" or "sharing" and of targeted advertising, to limit use of sensitive personal information, and not to be discriminated against for exercising these rights.

We do not sell personal information for money. However, on the free tier we share a resettable advertising identifier with our advertising partner so that ads can be shown and measured. Under the CCPA/CPRA this is treated as "sharing" for cross-context behavioural advertising, and we disclose it as such rather than rely on a technicality.

You can opt out at Settings → Privacy → Advertising, by declining the App Tracking Transparency prompt on iOS, via our "Do Not Sell or Share My Personal Information" link, or by sending a Global Privacy Control signal, which we honour automatically.

We never share sensitive personal information — health data, precise geolocation, or children's data — for advertising or for any cross-context behavioural purpose. This limits our use of sensitive personal information to what CCPA permits without a separate right to limit.

We do not share the personal information of any user under 18 for advertising, and we do not knowingly sell or share the personal information of anyone under 16. Premium subscribers see no advertising at all.

To exercise your rights, email privacy@thewileyfox.com or use the in-app controls. You may use an authorised agent. We will verify your identity before acting.

If you are elsewhere

We apply the standards in this policy globally as our baseline, and comply with additional local requirements where they apply — including Canada (PIPEDA), Australia (Privacy Act), Brazil (LGPD) and others.

15. How we protect your data

Encryption in transit (TLS 1.2+) and at rest (AES-256).

Medical and Protected Person data is stored with additional access restrictions and field-level protection.

Row-level security so a user's data is only ever accessible to that user and their authorised Family Group.

Access control — staff access is role-based, minimal, logged, and reviewed. Very few people can access production data, and never medical data without a logged, justified reason.

Multi-factor authentication available on all accounts and required for staff.

Regular security testing, dependency scanning and patching.

Breach response — if a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where the risk is high, notify you without undue delay.

No system is perfectly secure. Please use a strong, unique password and enable multi-factor authentication.

16. Changes to this policy

We will update this policy from time to time. If we make a material change — for example a new category of data, a new purpose, or a new class of recipient — we will:

give you at least 30 days' notice by email and in-app before it takes effect; and

where the change relies on consent, ask for your consent afresh rather than assuming it.

Previous versions are archived at thewileyfox.com/legal/archive.

17. Contact

Privacy queries, data subject requests and complaints: privacy@thewileyfox.com

Wiley Fox Mapping Limited, [19 Hereford close, Hook, United Kingdom]

Information Commissioner's Office — ico.org.uk · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Wiley Fox helps you travel with more confidence. It cannot make you safe. Please use it alongside your own judgement, official advice, and the emergency services.
© 2026 TheWileyfox. All rights reserved.