Legal

Privacy Policy

Last updated: September 17, 2026 (v3) · Contact: mail@mytraveller.app

The short version. Traveller helps you plan trips. We collect the information you give us (account, trip details, documents you upload) and a small amount of usage data needed to run the service. We never sell your data. Your vault documents are stored securely and are only accessible to you through the app. You can export or delete your account at any time from Settings.

1. Who we are

Traveller ("we", "us", "our") is operated by Roam Far Ltd, a company registered in England & Wales (company no. 17192610), with its registered office at 2 Withy Park, Bishopston, Swansea, SA3 3EY, United Kingdom. Roam Far Ltd is the data controller for personal data processed through the Traveller mobile and web application, which helps travellers organise destinations, packing lists, tasks, itineraries, documents, and expenses. This policy explains what data we collect, why, and what rights you have.

If you have questions, email mail@mytraveller.app.

2. Information we collect

Account information

  • Email address, password (stored as a salted hash), and optional name and avatar.
  • Sign-in provider (Google or Apple) when you use social sign-in.
  • Verification codes sent to your email or phone during sign-up.

Profile information

  • Travel persona (e.g. backpacker, business, family, luxury, adventure, digital nomad, roadtripper).
  • Optional demographics, passport country, mother tongue, and travel essentials.

Trip data

  • Destinations, origins, dates, baggage choices, and selected activities.
  • Generated packing lists, tasks, itineraries, journal entries, and expense records you create.
  • Friends you add to a trip and the trip status they see (e.g. "invited").

Document Vault

  • Files you upload (passport scans, tickets, insurance, etc.) are stored securely in your account and are only accessible to you through the app.

Device and usage data

  • Language, timezone, device type, app version, and crash/error logs.
  • Anonymous interaction events used to improve reliability and performance.
  • Device push notification token, used to send you trip reminders and alerts you have opted into.

Payments

If you purchase a trip pass or lifetime upgrade, payment is handled by the relevant platform:

  • Web — processed by Stripe. We receive a confirmation token and the plan purchased. We never see or store your card number, CVV, or full bank details.
  • iOS — processed entirely by Apple through the App Store. We use RevenueCat as our in-app purchase management platform; RevenueCat receives your Apple customer ID and entitlement status and passes them to us. Apple handles all payment details and we never see your card information.
  • Android — processed entirely by Google through Google Play. We use RevenueCat in the same way as on iOS. Google handles all payment details and we never see your card information.

Location

We use only the destinations you type into the app. We do not collect background GPS or precise device location.

3. How we use your information

  • Deliver the service: build your trip dashboard, generate packing lists, sync data across devices.
  • Send transactional emails (verification, password reset, trip-related notifications you opted into).
  • Provide customer support and respond to bug reports or feedback you submit.
  • Detect fraud, abuse, and violations of our Terms of Service.
  • Aggregate, anonymous analytics to understand how features are used and to improve the product.

4. User content and prohibited material

Features such as the Travel Journal allow you to upload photos and write personal entries. This content is stored in your account and is private to you. You must not upload, store, or share nudity, sexually explicit material, graphic violence, or any other prohibited content as defined in our Terms & Conditions §11.

We do not proactively scan your private journal content. However, if prohibited content is reported to us or identified through an automated safety signal, we may review it and take action — including removing the content, suspending your account, or permanently terminating your account. Serious violations involving illegal content (such as material that sexualises minors) will be reported to the relevant authorities.

5. AI processing

Several Traveller features use AI, including trip generation, cultural insights, packing suggestions, and on-demand translations. These features send only the prompt data needed for that request (such as destination, dates, persona, and activity choices) to AI model providers via OpenRouter, an AI routing service. The current AI model is Google Gemini. We do not send the contents of your Document Vault, your journal entries, your friends list, or your payment data to AI providers. Providers process the prompt to return a response and may retain it briefly for abuse monitoring under their own policies.

6. How we share your information

We do not sell your personal data. We share it only with service providers strictly needed to operate Traveller:

  • Hosting and database — Supabase, used for storage, authentication, and edge functions.
  • Payments (web) — Stripe for web purchase processing.
  • In-app purchases (iOS / Android) — RevenueCat for purchase management and entitlement tracking; Apple (App Store) and Google (Play Store) as the underlying payment processors.
  • Authentication — Google and Apple, when you choose social sign-in.
  • AI routing — OpenRouter, which forwards prompts to Google Gemini for the AI features described above.
  • AI model — Google (Gemini), via OpenRouter.
  • Reference data — Public APIs (REST Countries, weather and currency providers) that we query without sending your personal information.
  • Legal — Authorities when required by law, valid legal process, or to protect the safety of our users.

7. Data retention

  • We keep your account and trip data for as long as your account is active.
  • When you delete your account, we remove personal data within 30 days from production systems.
  • Encrypted backups may persist for up to 90 days before they are rotated out.
  • Anonymous, aggregated analytics may be kept indefinitely because they cannot identify you.

8. International data transfers

Traveller may store and process data in the European Union and the United States. When data leaves the EEA or the UK, we rely on Standard Contractual Clauses (SCCs) and equivalent safeguards approved by the European Commission and the UK ICO.

9. Your rights — European Economic Area and United Kingdom (GDPR)

If you are in the EEA or UK you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local supervisory authority.

Email mail@mytraveller.app to exercise any of these rights. You can also export or delete your account directly from Settings inside the app, visit our account deletion page, or use our data deletion request form to remove specific data without closing your account.

10. Your rights — California (CCPA / CPRA)

California residents have the right to know what personal information we collect, to request deletion or correction, to opt out of the "sale" or "sharing" of personal information (we do neither), and to non-discrimination for exercising these rights. Submit requests via our data deletion form or email mail@mytraveller.app.

11. Children

Traveller is not directed to children under 13 (or under 16 in the European Union). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete the account.

12. Cookies and analytics

We use essential cookies and local storage to keep you signed in and remember your language preference. We use a minimal set of privacy-preserving analytics to understand product usage. We do not use cross-site advertising trackers. You can clear local storage at any time from your browser or device settings.

13. Security

  • All traffic between your device and our servers is encrypted with TLS 1.2 or higher.
  • Passwords are stored as salted hashes; we never see your plaintext password.
  • Database access is governed by Row Level Security so users can only access their own rows.
  • Document Vault files are stored in a private, access-controlled bucket accessible only to the authenticated account owner.

No system is perfectly secure. If you discover a vulnerability, please report it to mail@mytraveller.app so we can fix it quickly.

14. Changes to this policy

We may update this Privacy Policy as the product evolves. Material changes will be communicated by email or in-app notice before they take effect. The "Last updated" date at the top of this document always reflects the current version.

15. Contact

Questions, requests, or complaints? Email mail@mytraveller.app, or write to us at:

Roam Far Ltd
2 Withy Park, Bishopston
Swansea, SA3 3EY
United Kingdom

Registered in England & Wales, company no. 17192610.