Privacy Policy

Effective date: 21 July 2026

Version: 1.0

Who we are: Sidekick Labs Pte. Ltd. (UEN 202405798H), 160 Robinson Road, #14-04, Singapore Business Federation Centre, Singapore 068914 (“Sidekick”, “we”). For EU/UK GDPR purposes we are the controller; under Singapore’s PDPA we are the organisation responsible for your personal data.

Contact / Data Protection Officer: Ryan Chew, Chief Executive Officer — dpo@sidekicklabs.co

This policy covers the Sidekick companion app, the AI concierge, your use of Sidekick smart glasses at participating venues, and our website at sidekicklabs.co. If you are here because you filled in a form on our website and want to know what happens to your details, go straight to §11 — the rest of this policy is about the app and the glasses. It is written for visitors from anywhere; jurisdiction-specific rights are in §9.

1. What we collect

  • Account — What: Your name and email via Google Sign-In (the only sign-in method), your date of birth (to confirm you are 18 or older — see §8), plus a display name and preferences — Source: You, at signup

  • Bookings & uploads — What: Tickets, booking confirmations you provide (used to start your experience) — Source: You

  • Photos & diary content — What: Photos and content in your travel diary — Source: You / the Glasses

  • Location (venue-level) — What: With your permission, the App uses your device’s location in the background to detect when you enter or leave an experience zone at a participating venue (geofencing). This is event-based: we record zone entries and exits for experiences you have joined — not a continuous trail of where you go — and we do not track your location outside venue experiences — Source: App / Glasses

  • Concierge conversations — What: Your questions and the Concierge’s answers; images captured when you ask about what you’re looking at — Source: You / the Glasses

  • Camera imagery — What: The Glasses camera captures your surroundings during an experience, which may incidentally include other people. We do not perform facial recognition and do not create biometric identifiers. Photos you take are stored on the Glasses, then transferred to your account. Images you send the Concierge are stored with your chat until you delete them or your account; AI processing of images is transient (not retained by the AI pipeline beyond answering you) — Source: Glasses

  • Voice — What: Voice messages you choose to record in chat (up to 60 seconds). That’s it — live audio streaming is not active in the current release, and the Glasses have no microphone recording permission. We do not transcribe your audio on our servers. If a voice or live-translation feature launches, this policy will be updated before it goes live — Source: App

  • Device & usage — What: Device type, app version, and crash and error reports via Sentry (processed in the United States — see §5). We do not use advertising or third-party analytics trackers — Source: App

2. What we use it for

  • Provide the experience (pairing, enrollment via geofence/time/booking, concierge answers, travel diary) — Data: Account, bookings, location, conversations, imagery — GDPR legal basis: Contract (Art 6(1)(b))

  • Safety, security, fraud prevention — Data: Account, device — GDPR legal basis: Legitimate interests (f)

  • Support and service communications — Data: Account — GDPR legal basis: Contract (b)

  • Service diagnostics (crash and error reports, app performance) — Data: Device & usage — GDPR legal basis: Legitimate interests (f)

  • Legal compliance — Data: As required — GDPR legal basis: Legal obligation (c)

We do not use your photos, conversations, voice messages, or diary content to train AI models, and we do not use your content for advertising. If we ever want to use de-identified data to improve the Service beyond basic diagnostics, we will update this policy and ask for your consent first.

We collect and enroll you in experiences only through actions you take (booking in-app, uploading a ticket, entering a venue zone after joining an experience) or disclosed partner integrations — never through silent back-channel enrollment.

3. The AI concierge

The Concierge is an AI system (you are told this in the App). Your conversations and query images are processed by our third-party AI provider — currently Google (Gemini, processed on Google Cloud in Singapore) — plus Sidekick’s own models on our infrastructure. Our providers process your data under contractual restrictions and only to provide the service to us; we will update this policy before adding providers or making stronger retention commitments. AI responses to you are cached briefly (up to 24 hours) to improve speed.

4. Who we share it with

  • Venues you visit receive aggregate, anonymised experience analytics only (for example visit counts, zone engagement, and content performance). Venues do not receive your personal data — not your identity, your conversations, or your photos.

  • Service providers (hosting, AI providers, support tooling) processing on our instructions under contract.

  • App stores / OS providers as part of distribution.

  • Authorities where legally required.

  • No sale of personal data. We do not sell your personal data, and do not “share” it for cross-context behavioural advertising (CCPA sense).

5. International transfers

We are based in Singapore, and our systems are hosted there: our application servers, databases, and file storage run with our cloud providers in Singapore, and AI processing runs on Google Cloud in Singapore. One flow leaves Singapore: crash/error reports go to Sentry in the United States, under Sentry’s data processing addendum, which incorporates the EU Standard Contractual Clauses; Sentry also participates in the EU-U.S. Data Privacy Framework.

  • PDPA: we transfer personal data overseas only with protection comparable to the PDPA, using legally enforceable obligations (e.g. contracts) with recipients.

  • GDPR (EU/UK visitors): transfers out of the EEA/UK rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum/IDTA) incorporated in our processors’ data processing agreements.

  • Mainland China: the Service is not currently offered in mainland China (see §9).

  • Our website: form submissions are stored by Framer in the United States under Standard Contractual Clauses — see §11.

6. Retention

  • Account deletion: you can delete your account in the App (and request a copy of your data first). Deletion takes effect immediately for access; your data is permanently erased after a 30-day grace period (in case you change your mind), except where law requires longer.

  • Concierge conversations: deleted within ~24 hours after a conversation expires; short-lived working data within 7 days.

  • Chat images and voice messages: kept until you delete them or your account.

  • AI response caches: up to 24 hours.

  • Crash reports and audit logs: routine automated cleanup.

  • Device-level operational telemetry (technical events and venue-zone records keyed to shared venue hardware, not to your personal account): retained for operating and maintaining the venue devices; it is not linked back to you after your account is deleted.

7. Security

We protect your data with encryption in transit (TLS), encryption at rest on our managed databases and file storage, and access controls that limit staff access to what their role requires. No system is perfectly secure; we notify you and regulators of data breaches where required by law.

8. Children

You must be 18 or older to create an account, and 18 or older to join the early-access waitlist on our website (§11). We ask for your date of birth at signup and do not knowingly create accounts for anyone under 18. If you allow a minor in your care to use the Service under your supervision — for example, wearing the Glasses during your visit — you are responsible for their use, and data collected during that use is processed as part of your account (see the Terms of Service). If you believe a child has created an account or provided us personal data directly, contact us at support@sidekicklabs.co and we will delete it.

9. Your rights

How to exercise any right: email support@sidekicklabs.co. We respond within the timelines required by your jurisdiction. (During our initial venue pilot, requests are handled manually by our team — same rights, human process.)

  • Singapore (PDPA): access and correction; withdraw consent (we’ll explain the consequences); complain to the PDPC.

  • EU/UK (GDPR): access, rectification, erasure, restriction, portability, objection (incl. to legitimate-interests processing); withdraw consent at any time; complain to your supervisory authority or the ICO.

  • California (CCPA/CPRA): know/access, delete, correct, opt-out of sale/sharing (we do not sell or share — §4), limit use of sensitive PI, non-discrimination. Requests via the email above.

  • Mainland China (PIPL): the Service is not currently offered in mainland China. If that changes, we will meet PIPL’s cross-border and consent requirements and update this policy before launch there.

  • Automated decisions: the Concierge recommends and personalises but does not make decisions with legal or similarly significant effects about you.

10. People around you (bystanders)

The Glasses camera may incidentally capture people near you during an experience. We minimise this by design: no facial recognition, no biometric identification of anyone; a hardware-enforced privacy light that is on whenever the camera is active and cannot be switched off by software; venue signage; and no-capture zones enforced by venue rules. Incidental captures exist only within the capturing visitor’s own photos and diary content and follow the same retention rules as that content (§6). If you appear in another visitor’s capture and want it addressed, contact us at support@sidekicklabs.co and we will act on it.

11. Our website

This section covers sidekicklabs.co only. It is separate from the app and the glasses — if you have only visited our website, this is the only section that applies to you.

Early-access waitlist

  • Your name and email — Why: To tell you when early access opens, and to send you product news — Legal basis: Consent

  • Your age range and how often you travel — Why: To understand who is interested, so we build and communicate for the right people — Legal basis: Consent

You must be 18 or older to join the waitlist. We do not knowingly collect details from anyone under 18 through our website.

You can leave at any time. Every email we send has an unsubscribe link, or write to support@sidekicklabs.co and we will remove you. Unsubscribing removes you from the waitlist entirely — we do not keep a suppressed copy beyond what is needed to honour your request.

We keep waitlist details until you unsubscribe or ask us to delete them, or until the waitlist has clearly served its purpose and we close it.

Venue and partner enquiries

If you contact us about running a pilot at your venue, we collect your name, email, venue and role, plus whatever you write in your message. We use it to reply and to discuss a possible partnership. Our basis is our legitimate interest in responding to business enquiries, and taking steps at your request before entering a contract. Most of this is business contact information given to us in a business capacity.

We keep enquiries for as long as the conversation is live, and for a reasonable period afterwards in case you come back to us.

Who else handles website data

  • Framer, our website platform, hosts the site and stores form submissions. Framer stores this data on servers in the United States, under its data processing terms which incorporate the EU Standard Contractual Clauses.

  • Our email provider, so enquiries and waitlist emails reach us and you.

  • Nobody else. We do not sell website data, do not share it with venues, and do not use it for advertising.

Cookies and analytics

Our website does not use tracking or advertising cookies. We use our website platform’s built-in analytics to see how many people visit and which pages they read. It is cookie-free, it does not create a persistent identifier for you, and it does not tell us who you are.

What we do not do on the website

We do not use your website details to build a profile for advertising, and we do not pass them to advertising networks. Website details are kept separate from your app account unless you later sign up and use the same email.

Your rights (§9), our security measures (§7) and our contact details all apply to website data in the same way.

12. Changes

We will post updates here and notify you in the App of material changes before they take effect. Each version carries its effective date.

Sidekick

Sidekick Labs · Singapore · © 2026