Privacy Policy
Deutsche Fassung lesenThe short version. Travelog is built local-first: your trips live on your device, not on a server of ours, and there is no account. The app contains no ads, no tracking, no analytics SDKs and no crash reporting. Data leaves your device only when you use a feature that needs a counterpart – maps, place search, AI with your own key, Wikipedia, exchange rates, warnings, the encrypted mailbox for planning together, and the backup in your iCloud. Each of these is listed below. On the website we store only what you enter into the waiting list yourself.
This is a translation for your convenience; in case of doubt the German version applies.
1. Who is responsible
Raffael Jambor1220 Vienna, Austria
Email: support@paloaltea.app
There is no data protection officer; one is not required for an operation of this size.
2. The principle: your data stays with you
Travelog stores everything you enter – trips, itinerary items, tickets, packing lists, expenses, journal entries, recordings – in a database on your device. We run no server holding this data and we have no access to it. That also means we can neither view it, hand it over nor restore it. What you delete is deleted; what you back up, you back up into your own cloud.
Some features need a counterpart on the network. The following sections state, for each of them, what is transmitted, to whom, for what purpose and on which legal basis. All of these features are optional or degrade gracefully without a network: the app works in airplane mode.
3. The Travelog app
3.1 What stays on the device
All content you create lives exclusively on your device and is processed there: trips with days, places and times; imported tickets, boarding passes and documents including their barcodes; packing lists; expenses and budgets; journal entries; references to photos in your library (the app stores identifiers, not copies); GPS recordings you start yourself; and the API key for the AI, which lives in the system keychain. You delete this data via the app's trash or, completely, by deleting the app.
3.2 Backup in your iCloud
If iCloud is enabled on your iPhone, the app places a backup of its data in a private area of your iCloud that belongs to your Apple ID. It is created when the app goes to the background, at most once a day and only if something changed; the last five snapshots are kept. The provider is Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland); iCloud's privacy terms apply. We have no access to this backup. You can also export it as a file and keep or pass it on yourself. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR); the backup can be switched off in the settings. An Android version will place its backup in your Google Drive storage accordingly; this policy will be amended then.
3.3 Maps
The app shows maps using tiles from OpenStreetMap. When a map is displayed, the numbers of the visible tiles – roughly, the map section –, your IP address and an identifier of the app are transmitted to the OpenStreetMap Foundation (St John's Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom). Loaded tiles are cached on the device so the map remains visible offline. Some editions of the app may additionally offer a topographic map style from Tracestrack (tracestrack.com); the same applies there. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) – you opened the map.
3.4 Place search
When you search for a place, or the app determines the place for a coordinate, it queries a geocoding service: Nominatim by the OpenStreetMap Foundation (address above) or Photon by komoot GmbH (Friedrich-Ebert-Straße 8, 14467 Potsdam, Germany). Transmitted are the search term you type or the coordinate of a place in your plan, plus your IP address and the app's identifier. Responses are cached on the device. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
3.5 AI features with your own key
The app's AI features – trip suggestions, suggestions for days and packing lists, information on entry requirements, tipping and local specialities – run on Claude by Anthropic, PBC (548 Market St, San Francisco, CA 94104, USA). They are available only if you store your own Anthropic API key in the app. The key lives in your device's keychain; we do not see it, and no request passes through us.
What is transmitted depends on the feature and is whatever the answer needs: the destination, the dates and your preferences; the items of your itinerary; for entry information your nationality and destination country; for tipping and local specialities the place. No tickets, no expenses, no photos. This transmission is governed by the contract between you and Anthropic, including its privacy terms; by storing the key and with each individual action you decide whether a request is made. A monthly limit in the settings caps what the app requests on your bill.
Outlook. In future, Travelog might route AI requests through a relay service of its own so the AI can be used without a personal key. That service would then see the content of your request. It is not in operation; this policy will be amended before it is.
3.6 Wikipedia and Wikimedia Commons
For places and itinerary items the app can fetch Wikipedia articles and freely licensed images. To do so it asks Wikipedia in your language and Wikimedia Commons (Wikimedia Foundation, Inc., 1 Montgomery Street, Suite 1600, San Francisco, CA 94104, USA) for the name of the place or item; transmitted are that name, the language, your IP address and an identifier of the app that points to this website. Whether the app loads such content on its own is controlled by a switch in the settings; saved articles live on the device. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
3.7 Preview of shared links
When you share a link from your browser or a maps app into Travelog, the app fetches that page once to read its title, description and a preview image. The site's operator sees your IP address and the app's identifier – just as if you had opened the page in your browser. This happens only for links you add yourself.
3.8 Exchange rates
To convert expenses, the app fetches European Central Bank reference rates through the service frankfurter.app. Only the two currencies, the date and your IP address are transmitted. Rates are stored on the device; without a network the app uses the last known rate and shows its date.
3.9 Travel warnings
At app start, for ongoing and soon-starting trips, two public lists are downloaded: the event list of the Global Disaster Alert and Coordination System (GDACS, run by the European Commission's Joint Research Centre and the United Nations, gdacs.org) and the travel and safety advice of the German Federal Foreign Office (open data interface, auswaertiges-amt.de). In both cases the app downloads the complete list and compares it on the device with the places of your trip; nothing about your trip is transmitted. The providers see only your IP address. Your location is never queried for this.
3.10 Planning together
You can share a trip with others. The devices then sync directly with each other, and everything that leaves the device in the process is end-to-end encrypted: only those holding the invitation to the trip can read the contents – not us, and no service in between. The invitation contains the key; you decide whom you give it to. Names that fellow travellers choose travel inside the encrypted data.
There are two ways to sync. The first is a file you pass on via AirDrop, the share sheet or any other route; no service of ours is involved. The second is the mailbox, which you can switch on per trip so devices sync even when they are not online at the same time. The mailbox is a storage relay we operate at Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA – processor under Art. 28 GDPR on the basis of Cloudflare's data processing addendum). It sees no contents, no names, and not which devices belong together. What it does see, because every relay does: the encrypted data packets, a channel identifier derived from the trip key that cannot be attributed to you, the size class and time of each packet, and your IP address during transfer. The packets are held in storage with EU jurisdiction and are deleted automatically after 30 days; the service keeps no access logs. The request itself is processed at the Cloudflare location closest to you. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); the mailbox has to be switched on explicitly per trip.
3.11 Purchases
You buy Pro as a subscription or a one-time purchase through Apple's App Store (Apple Distribution International Ltd., Ireland) or, later, through Google Play. Purchase and payment run entirely through your Apple or Google account; we receive no payment or account data. The app verifies the purchase receipt on the device. The privacy terms of the respective store apply.
3.12 Feedback and support
"Send feedback" in the settings opens your mail app with a prepared message containing the app version, your operating system version and your language – no trip data. Whether you send it is up to you. Mail to support@paloaltea.app is delivered via Cloudflare's email forwarding to a mailbox at Apple (iCloud Mail), where it is read and answered. We process your address and the content to handle your request (Art. 6(1)(b) and (f) GDPR) and delete the message once the matter is settled, at the latest twelve months afterwards.
3.13 Asking for a rating
After a few completed trips the app may use the system's rating feature (StoreKit) to ask whether you would like to rate it in the store. Whether the dialog appears is decided by the system; the request goes to Apple, and we learn nothing of it.
3.14 Links into other apps and websites
In some places the app opens, on your tap, another app or website: Apple Maps or Google Maps for directions, Flightradar24 or the railway for the status of a connection, Apple Music for a song, the official pages of the Federal Foreign Office. From then on the respective provider's privacy policy applies.
3.15 Permissions
The app asks for permissions only when you use the related feature, and explains beforehand what for. Location: only for the GPS recording you start yourself; the track stays on the device and is never uploaded. Photos: for cover pictures, receipts and the photo map; the app stores references, not copies, and reads location and time only of the photos you pick or that fall within the trip dates. Camera: to scan an invitation as a QR code. Notifications: for reminders the app schedules on the device itself – there is no push server. All permissions are optional and can be revoked in the system settings at any time.
3.16 What there is none of
No analytics or statistics services, no crash reporting, no advertising identifiers, no fingerprinting, no sharing with third parties for their own purposes. Should the app ever get crash reporting, it will be only with your explicit consent in the app, off by default – and this policy will be amended beforehand.
3.17 Beta via TestFlight
During the beta the app is distributed via Apple's TestFlight. Under the TestFlight terms Apple collects crash reports and usage statistics from test devices and makes crash reports available to us, together with the feedback you send through TestFlight yourself – including screenshots you choose to attach. Crash reports contain the device model, system version, app version and the technical trace of the crash, no trip contents. We use them to fix bugs (Art. 6(1)(f) GDPR) and delete them at the latest twelve months after the beta ends.
4. The website paloaltea.app
4.1 Visiting the pages
The website is served by Cloudflare (address above; processor under Art. 28 GDPR). To deliver a page, Cloudflare necessarily processes your IP address, the time, the requested address and your browser's identifier. We keep no access logs ourselves; the service's logging is switched off. Cloudflare briefly retains its own logs for the secure operation of its network under its own terms. The pages set no cookies, embed nothing from third-party servers – no fonts, no scripts, no images – and contain no analytics tools. Legal basis: legitimate interest in a working, secure website (Art. 6(1)(f) GDPR).
4.2 The beta waiting list
When you join the waiting list on the start page, we store your email address, your language (German or English), the time and the version of the consent text you agreed to. Your IP address is not stored; it is only counted for a moment to slow down automated mass entries. The data is held in a database at Cloudflare located in Western Europe. We are notified of each new entry by email; that message contains the address and is delivered via Cloudflare to the same mailbox described in section 3.12.
We use the address for exactly one purpose: to invite you to the beta and to tell you when it begins or when something essential about it changes. No newsletter, no advertising, no sharing. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time – with an email to support@paloaltea.app – and we delete the entry. Otherwise we delete the list once the beta has ended, at the latest twelve months afterwards. The beta itself runs on TestFlight; if you accept the invitation, Apple's terms apply to it (section 3.17).
4.3 Contact by email
Section 3.12 applies to mail you send us.
5. Recipients and third countries
The following parties receive data, each only to the extent described above and only when you use the related feature:
| Recipient | For | Based in |
|---|---|---|
| Apple | iCloud backup, purchases, TestFlight, ratings | Ireland / USA |
| Cloudflare, Inc. | Website, waiting list, mailbox, email forwarding | USA, storage in the EU |
| OpenStreetMap Foundation | Map tiles, place search (Nominatim) | United Kingdom |
| komoot GmbH | Place search (Photon) | Germany |
| Anthropic, PBC | AI features – with your key, under your contract | USA |
| Wikimedia Foundation, Inc. | Wikipedia articles, images | USA |
| frankfurter.app | Exchange rates | Germany |
| GDACS (European Commission / UN), Federal Foreign Office | Travel warnings (public lists) | EU / Germany |
For recipients outside the European Economic Area we base the transfer on the European Commission's adequacy decision for the United Kingdom, on the EU-US Data Privacy Framework where the provider is certified under it (to our knowledge this applies to Apple and Cloudflare), otherwise on the European Commission's standard contractual clauses or on the transfer being necessary for the feature you requested (Art. 49(1)(b) GDPR). For the AI features you decide about the transfer to Anthropic yourself by storing your key and invoking the feature.
6. Your rights
You have the right to access the data we process about you, to rectification, erasure and restriction of processing, to data portability, and to object to processing based on legitimate interest. You can withdraw consent at any time with effect for the future. Write to support@paloaltea.app.
For the contents of the app: we do not have them. Access, rectification and erasure you exercise yourself – in the app, in your iCloud and, for shared trips, towards your fellow travellers.
If you believe we process your data unlawfully, you can complain to a data protection supervisory authority. The authority responsible for us is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
7. Children
The waiting list and support are intended for persons aged 14 and over. The app itself creates no data with us; the store's age rules apply to purchases.
8. Changes
If a feature is added that sends data out, this policy is amended beforehand. The date above shows the current version; we announce essential changes in the app.