🌍 TravelLog

Privacy Policy

Effective date: September 25, 2026 Β· Last updated: October 8, 2026

This policy explains what TravelLog collects, why, who it is shared with, and the choices you have. TravelLog is a personal trip logger with optional shared trips, optional (off-by-default) location suggestions during a trip, and an AI trip planner. It covers the TravelLog app on iPhone, iPad and Android and our website (travellogapp.web.app, which hosts these pages and shared-trip links). It is also our notice at collection: the categories we collect, why, and how long we keep them are set out below (Sections 2, 6 and 10).

Questions about this policy or your data? Contact us at armgardtj@outlook.com.

1. Who we are

TravelLog ("we," "us," "the app") is operated by an independent individual developer based in New York, United States. The app is available on iOS and Android and uses Google Firebase as its backend.

Controller. The controller of your personal data (the person responsible for deciding how it is used) is John Armgardt, who operates TravelLog. Contact for all privacy matters, including exercising your rights: armgardtj@outlook.com. He is also the person in charge of the protection of personal information (privacy officer) for the purposes of Canadian law, including Quebec's Law 25, and of other laws that ask for one.

Where TravelLog is offered. The app is offered in the United States and many other countries, including Canada, Australia, New Zealand, South Africa and Brazil. It is not offered in the EU/EEA, the United Kingdom or Switzerland.

2. What we collect and why

We collect only what the app needs to do what you asked it to do. Much of your data never leaves your phone (see Section 4).

Data you create

Location

Importing your Google Timeline

If you choose to import a Google Maps Timeline export, the file you pick is read on your device and never uploaded to us. To turn its points into named places, the coordinates of each stop are sent to Google (the device geocoder and the Google Places API). Everything imported stays as a suggestion until you accept it. Places Google identifies as health-related places or places of worship are discarded, as described above; you can still add any of them yourself.

Photos

Identifiers and technical data

Where the data comes from

Automatic content filter

Comments, public trip links and text returned by the AI features are checked by an automatic word filter for clearly objectionable content (for example slurs, threats or explicit sexual content). Matching content is removed or not published without a person reviewing it first. If you think something was removed by mistake, email armgardtj@outlook.com and a person will review it. We do not make any other decisions about you based solely on automated processing, and we do not profile you.

3. Who else receives data (third parties)

To make features work, some data is sent to the services below. Each receives only what that feature needs, and only to carry out the feature you asked for.

ServiceWhenWhat it receives
Google Places / MapsPlace search, place details, map views, naming the stops you visited, and Google Timeline import The place name or area you're searching for, the coordinates of the place being viewed, and the coordinates of a stop the app detected during a trip (or read from a Timeline file) so it can be given a name. Places requests go through our own server function, which holds the API key and does not log coordinates; Google receives the request from our server.
Google Sign-In / Sign in with AppleSigning in with Google or AppleYour sign-in credentials with that provider; we receive your name, email address, and a provider user ID
AeroDataBox & FlighteraFlight lookups The flight number and date you enter
OpenStreetMap contributors & OSRM (routing)Travel times between stopsCoordinates of places on your trip
OpenFreeMap (vector map tiles)Any map view The area of the map you are looking at, and your IP address
Esri / ArcGIS Online (satellite imagery)Satellite map view, which is the default The area of the map you are looking at, and your IP address
Apple (MapKit, iPhone and iPad only)Maps, place lookups and naming the stops you visited The coordinates and place names shown on the map, the text you type into place search, and the coordinates of a stop the app detected during a trip
Anthropic (Claude)The AI features listed in "Service providers and AI processing" below (Pro / only when you use them) The trip details, prompt, booking text, or forwarded email you provide, and β€” for receipt scanning or importing a booking from a screenshot β€” the image you choose to scan, so the AI can build, improve, or read it
Google AdMobAds (free tier only) Your device advertising ID, your IP address, and the coarse (city-level) location derived from it. If you turn on "Do not sell or share my personal information" (Settings β†’ Privacy), every ad request tells Google to apply restricted data processing, so your data is not used to personalise ads; you still see ads on the free plan
Google Firebase (Auth, Firestore, Storage, Cloud Functions, Cloud Messaging, Crashlytics) and Google Cloud Logging Backend, sync, photo storage, notifications, diagnostics, and the server logs our backend writes while handling your requests Your account data, synced trip content, uploaded photos, push token, crash reports, and log entries that can include your account identifier and the id of a trip or comment

We do not sell your personal data for money. Showing personalised ads through Google AdMob may count as "sharing" personal information for cross-context behavioural advertising under California and some other US state laws; you can opt out at any time in Settings β†’ Privacy β†’ "Do not sell or share my personal information" (see Section 10). Data sent to Anthropic is used to serve your request and is not used by us to build advertising profiles. Each provider processes data under its own privacy terms. We require every third party that receives your data to provide the same or equal protection of your data as described in this policy.

Service providers and AI processing

The following features send content you provide to Anthropic (the maker of Claude), which processes it on our behalf, as our service provider, solely to fulfil that request. Nothing is sent unless you use the feature:

Anthropic's API terms state that data submitted through the API is not used to train its models. Anthropic keeps API inputs and outputs only for a limited period set out in its terms, for abuse and safety monitoring, and longer only where a request is flagged under its usage policies or the law requires it; we do not store the raw prompts server-side beyond the result written back to your trip. See Anthropic's commercial terms and privacy center.

Other disclosures

We do not disclose personal information to third parties for their own direct marketing. (California residents may ask about this under California Civil Code Β§1798.83; the answer is that there is nothing to report.)

4. Where your data lives

On your device only (never uploaded): the raw location points recorded during a trip (Android only, and only until they are deleted β€” see Section 6), the "did you visit here?" suggestions you haven't accepted, and your home location. None of these are in your account, in any backup or in Export all my trips. The coordinates of an individual detected stop are sent to a geocoder and to Google Places to name it; the trail itself is not.

Synced to your account (Firebase): your trips, itinerary, expenses, and profile β€” so you get them back when you sign in on another device. Personal entries, and entries created from a suggestion you accepted, stay visible only to you, even on a shared trip. If you use Auto-log (or tap "Mark visited") on a planned entry of a shared trip, the people on that trip see it marked visited with the times you were there. Your wishlist and its notes are private to you.

Shared only when you choose: only trips you explicitly share are visible to the people you add, and only the base itinerary. Nothing is public unless you create a public link yourself. A public link carries the trip's name, dates and itinerary, your display name and the names of anyone you listed as a companion. For a companion who has joined the trip with their own TravelLog account, it also carries their @handle and account ID, so people viewing it in the app can open their public profile; never their email or anything else from their account. A shared view (public link or friends) never carries anything tracking observed: an entry whose times came from tracking shows its planned time if one was recorded and otherwise no time, and "visited"/"completed" status is never published. It never includes coordinates or street addresses. Public links created from this version of the app never include booking confirmation numbers or map coordinates; if you published a link before September 2026, revoke and re-create it under Settings β†’ Privacy & Data β†’ Manage public links to remove those fields.

5. How we protect your data

All traffic between the app and our backend, and between our backend and the services listed above, uses HTTPS/TLS. Your cloud data is stored in Google Firebase and is encrypted at rest by Google. Access is enforced by server-side security rules: your profile's private data, your wishlist, your backups and your personal trip entries are readable only by your own signed-in account, and a shared trip is readable only by the people you invited. Photos are stored under unguessable URLs that only you and the people you share a trip with receive. Our third-party API keys are held in Google Secret Manager and never ship inside the app.

No system is perfectly secure, and we cannot guarantee that data will never be accessed without permission. If a security breach affects your personal information, we will notify you and the relevant authorities as the law requires.

6. Retention

We keep nothing else about you once the periods above end.

7. Deleting your account and data

You can delete your account at any time in the app: Settings β†’ Privacy & Data β†’ Delete my account. This runs a server-side cascade that permanently deletes:

Shared trips you own are deleted for everyone on them. Trips saved only on your device are not part of the cloud deletion. On both Android and iPhone/iPad the app erases its local copy from that phone when you delete your account, along with your location data and saved home place. Use Settings β†’ Privacy & Data β†’ Export all my trips first if you want to keep them. Abuse reports and purchase records may be retained as described on the deletion page. This cannot be undone.

A record of any purchase you made is kept so the same subscription cannot be redeemed on two accounts at once. It holds a one-way fingerprint of the store's purchase identifier, the product, the platform, the dates it was recorded and released, and the ID of the deleted account β€” never your name, email or payment details. When you delete your account, the record is released from it, so if you sign up again you can restore the same subscription on your new account. Deleting your account does not cancel a subscription: cancel it in the App Store or Google Play if you no longer want to be billed.

If you cannot access the app, you can request deletion by emailing armgardtj@outlook.com from the email associated with your account. See our account deletion page for details.

8. Your choices

9. Age requirement

TravelLog is intended for adults. You must be at least 18 years old to create an account, as set out in our Terms, and the app is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us data, contact armgardtj@outlook.com and we will delete it.

10. Your rights, legal bases and international transfers

Your rights

Depending on where you live, you may have the right to:

How to exercise them. Many rights can be used directly in the app: Settings β†’ Privacy & Data (export your trips, delete your account), Settings β†’ Privacy ("Do not sell or share my personal information"), and editing your profile and trips. For anything else, email armgardtj@outlook.com, or use the account deletion page.

Verification. To protect your data, we verify requests before acting on them β€” normally by asking you to send the request from the email address on your account, or to confirm it in the signed-in app. We use what you give us for verification only for that purpose. If we cannot verify you, we will tell you why.

Authorised agents. Where your law allows, someone you authorise may make a request for you. We may ask for your signed permission and to verify your identity directly with you, unless the agent holds a valid power of attorney.

Response time. We respond within the time your law requires β€” generally within 30 days, or 45 days under most US state laws. Where the law allows an extension, we will tell you within the original period and explain why.

Appeals (US states). If we decline to act on your request, you can appeal by replying to our decision or emailing armgardtj@outlook.com with "Appeal" in the subject. We will respond in writing within the time your state's law requires (at most 60 days) and explain our decision. If you disagree with the outcome, you can contact your state attorney general.

California and other US states

This table describes the personal information we have collected in the past 12 months, in the categories California law uses. Sources are described in Section 2 ("Where the data comes from"); retention is in Section 6.

CategoryWhat we collectWhyDisclosed for a business purpose to"Shared" for targeted ads?
IdentifiersName / display name, @handle, email, account ID, sign-in provider ID, push token, IP address, Crashlytics installation ID, device advertising ID (free tier)Your account, sync, sharing, notifications, security, diagnostics, ads on the free tierGoogle (Firebase, Cloud, AdMob), Apple (sign-in), other users you choose (display name, @handle, avatar)Yes β€” advertising ID and IP address, to Google AdMob, free tier only, unless you opt out
Customer records (Cal. Civ. Code Β§1798.80)Name and email Your accountGoogle (Firebase)No
Commercial informationPro subscription status and purchase recordUnlocking Pro; stopping one subscription being redeemed on two accountsGoogle (Firebase)No
Internet or other electronic network activityCrash reports, device model and OS version, server logs, AI usage counters; ad interactions collected by AdMob (free tier)Fixing bugs, security, AI fair-use limits, ads on the free tierGoogle (Firebase Crashlytics, Cloud Logging, AdMob) Yes β€” ad and device activity to Google AdMob, free tier only, unless you opt out
GeolocationPrecise location, only for trips you choose to track; coarse (city-level) location that AdMob derives from your IP address The trip features listed in Section 2; ads on the free tier (coarse location only)Google Places and your device's geocoder (a detected stop's coordinates), Google (Firebase, for places you accept), people on a shared trip, Google AdMob (coarse only)Coarse location only, to Google AdMob, unless you opt out. Precise location: never
Audio, electronic or visual informationPhotos and receipt images you attachShowing them on your trips; reading receipts and booking screenshots when you askGoogle (Firebase Storage), Anthropic (images you scan), people on a shared tripNo
Other information you give usTrips, itineraries, notes, expenses, wishlist, comments, profile details, and what you send to the AI features Providing the app and the features you useGoogle (Firebase), Anthropic (AI features you use), map and routing providers (place names and coordinates), flight-data providers (flight number and date), people you share with No
Sensitive personal informationPrecise geolocation (above) β€” nothing elseOnly to provide the features you asked forAs for precise location aboveNo

We do not collect protected-classification characteristics, biometric information, professional or employment information, or education information, and we do not create inferences or profiles about you.

Selling and sharing. We do not sell personal information and have not sold it in the past 12 months. On the free plan, Google AdMob may use your advertising ID and IP-based coarse location to show personalised ads, which California and some other US state laws may treat as "sharing" for cross-context behavioural advertising (or "targeted advertising"). You can opt out at any time in Settings β†’ Privacy β†’ "Do not sell or share my personal information": when it is on, every ad request tells Google to apply restricted data processing, so your data is not used to personalise ads (you still see ads on the free plan, and Pro removes them). Where Google shows a US state privacy message, you can also change your choice under "Privacy choices" in the same section. We do not knowingly sell or share the personal information of anyone under 16 (and the app is for adults only β€” Section 9).

Sensitive personal information. Precise geolocation is "sensitive personal information" under the CPRA and similar state laws. We collect it only when you turn tracking on for a trip, and use it only to provide the features you asked for (the list in Section 2). We do not sell it, do not share it for cross-context behavioural advertising, and do not use it to infer characteristics about you. Because we use sensitive personal information only for these permitted purposes, the right to limit its use does not apply, and we do not offer a separate "Limit the use of my sensitive personal information" link.

Consumer health data (for example under Washington's My Health My Data Act, Nevada SB 370 or Connecticut law): TravelLog does not collect consumer health data. Location is never used to identify health-related visits; places Google identifies as health-related are discarded and never suggested or stored, as described in Section 2.

Religious beliefs: location is never used to infer your religion; places Google identifies as places of worship are discarded from automatic suggestions and never suggested or stored, as described in Section 2. You can still add any place yourself.

Canada (including Quebec)

We collect and use your personal information only for the purposes described in this policy, with your consent. Using the app with an account is consent to the processing needed to provide it; for optional uses (per-trip location tracking, notifications, personalised ads) we ask separately, and you can withdraw consent at any time as described in Section 8. Location tracking is off by default. You have the right to access and correct your personal information and to withdraw consent; contact our privacy officer (Section 1). Your data is stored and processed outside Canada, mainly in the United States (see "International transfers" below), where it may be accessible to courts and authorities under local law. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, to the Commission d'accès à l'information (or to your provincial privacy commissioner where one applies).

Australia and New Zealand

Your personal information is disclosed to and stored by overseas recipients β€” our providers in the United States and other countries where they operate (Section 3). You can ask to access or correct your information at any time. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner or New Zealand's Office of the Privacy Commissioner.

South Africa

You can ask to access or correct your personal information, and object to its processing. If you are not satisfied with our response, you can complain to the Information Regulator (inforegulator.org.za).

Brazil

Under the LGPD you have the rights listed above, including confirmation that we process your data, access, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about who we share it with and about the consequences of not giving consent, and withdrawal of consent. You can also complain to the Autoridade Nacional de ProteΓ§Γ£o de Dados (ANPD). The legal bases we rely on are below.

Legal bases

Where the law requires a legal basis for processing (for example Brazil's LGPD), we rely on the following:

PurposeLegal basis
Trip location tracking and everything it powers (suggestions, Auto-log, distance, flight-delay notes, place-search bias) Consent, given per trip. You can withdraw it at any time for one trip (switch it to Off) or for the whole app (revoke location permission). Withdrawing does not affect processing that happened before.
Your account, trips, sync, sharing with people you choose, photos, AI features you use, notifications you enable, Pro purchases Performance of our contract with you β€” providing the app you signed up for.
Security, fraud and abuse prevention, moderation, crash reports and diagnostics, AI fair-use limits Legitimate interests in keeping the app safe, working and affordable to run.
Ads on the free tier (Google AdMob) Your consent where the law requires it, collected through Google's consent message and changeable under "Privacy choices" or "Ad privacy choices" in Settings; otherwise our legitimate interests in funding the free tier, subject to your right to opt out of personalised ads.
Keeping purchase records and responding to lawful requests Legal obligation where applicable, otherwise legitimate interests.

International transfers

TravelLog is operated from the United States, and your data is stored in the United States. Our providers β€” including Google (Firebase, Places, AdMob) and Anthropic β€” process data in the United States and other countries. Wherever you live, your data is therefore transferred to and processed in countries whose data-protection laws may differ from yours. We send each provider only what the feature you use needs (Section 3). If you used TravelLog in the EU/EEA, UK or Switzerland before it was withdrawn there, transfers from those places rely on the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where the provider is certified, and otherwise on Standard Contractual Clauses in the provider's data processing terms; you can also complain to your local data protection authority.

Anywhere else

If you live somewhere not listed above, you have the rights your local law gives you, which you can exercise as described in this section, and you can complain to your local data protection authority.

11. Changes to this policy

We may update this policy. Every change is reflected by a new "Last updated" date at the top of this page. If a change would let us use data we have already collected in a materially different way, we will ask for your consent first where the law requires it.

12. Contact

Questions or requests: armgardtj@outlook.com.

TravelLog Β· Privacy Policy Β· Effective September 25, 2026 Β· Last updated October 8, 2026