This policy explains what TravelLog collects, why, who it is shared with, and the choices you have. TravelLog is a personal trip logger with optional shared trips, optional (off-by-default) location suggestions during a trip, and an AI trip planner. It covers the TravelLog app on iPhone, iPad and Android and our website (travellogapp.web.app, which hosts these pages and shared-trip links). It is also our notice at collection: the categories we collect, why, and how long we keep them are set out below (Sections 2, 6 and 10).
armgardtj@outlook.com.
TravelLog ("we," "us," "the app") is operated by an independent individual developer based in New York, United States. The app is available on iOS and Android and uses Google Firebase as its backend.
Controller. The controller of your personal data (the person
responsible for deciding how it is used) is John Armgardt, who
operates TravelLog. Contact for all privacy matters, including exercising your rights:
armgardtj@outlook.com. He is also the person in charge of the protection of
personal information (privacy officer) for the purposes of Canadian law, including
Quebec's Law 25, and of other laws that ask for one.
Where TravelLog is offered. The app is offered in the United States and many other countries, including Canada, Australia, New Zealand, South Africa and Brazil. It is not offered in the EU/EEA, the United Kingdom or Switzerland.
We collect only what the app needs to do what you asked it to do. Much of your data never leaves your phone (see Section 4).
If you choose to import a Google Maps Timeline export, the file you pick is read on your device and never uploaded to us. To turn its points into named places, the coordinates of each stop are sent to Google (the device geocoder and the Google Places API). Everything imported stays as a suggestion until you accept it. Places Google identifies as health-related places or places of worship are discarded, as described above; you can still add any of them yourself.
Comments, public trip links and text returned by the AI features are checked by an
automatic word filter for clearly objectionable content (for example slurs, threats or
explicit sexual content). Matching content is removed or not published without a
person reviewing it first. If you think something was removed by mistake, email
armgardtj@outlook.com and a person will review it. We do not make any other
decisions about you based solely on automated processing, and we do not profile you.
To make features work, some data is sent to the services below. Each receives only what that feature needs, and only to carry out the feature you asked for.
| Service | When | What it receives |
|---|---|---|
| Google Places / Maps | Place search, place details, map views, naming the stops you visited, and Google Timeline import | The place name or area you're searching for, the coordinates of the place being viewed, and the coordinates of a stop the app detected during a trip (or read from a Timeline file) so it can be given a name. Places requests go through our own server function, which holds the API key and does not log coordinates; Google receives the request from our server. |
| Google Sign-In / Sign in with Apple | Signing in with Google or Apple | Your sign-in credentials with that provider; we receive your name, email address, and a provider user ID |
| AeroDataBox & Flightera | Flight lookups | The flight number and date you enter |
| OpenStreetMap contributors & OSRM (routing) | Travel times between stops | Coordinates of places on your trip |
| OpenFreeMap (vector map tiles) | Any map view | The area of the map you are looking at, and your IP address |
| Esri / ArcGIS Online (satellite imagery) | Satellite map view, which is the default | The area of the map you are looking at, and your IP address |
| Apple (MapKit, iPhone and iPad only) | Maps, place lookups and naming the stops you visited | The coordinates and place names shown on the map, the text you type into place search, and the coordinates of a stop the app detected during a trip |
| Anthropic (Claude) | The AI features listed in "Service providers and AI processing" below (Pro / only when you use them) | The trip details, prompt, booking text, or forwarded email you provide, and β for receipt scanning or importing a booking from a screenshot β the image you choose to scan, so the AI can build, improve, or read it |
| Google AdMob | Ads (free tier only) | Your device advertising ID, your IP address, and the coarse (city-level) location derived from it. If you turn on "Do not sell or share my personal information" (Settings β Privacy), every ad request tells Google to apply restricted data processing, so your data is not used to personalise ads; you still see ads on the free plan |
| Google Firebase (Auth, Firestore, Storage, Cloud Functions, Cloud Messaging, Crashlytics) and Google Cloud Logging | Backend, sync, photo storage, notifications, diagnostics, and the server logs our backend writes while handling your requests | Your account data, synced trip content, uploaded photos, push token, crash reports, and log entries that can include your account identifier and the id of a trip or comment |
We do not sell your personal data for money. Showing personalised ads through Google AdMob may count as "sharing" personal information for cross-context behavioural advertising under California and some other US state laws; you can opt out at any time in Settings β Privacy β "Do not sell or share my personal information" (see Section 10). Data sent to Anthropic is used to serve your request and is not used by us to build advertising profiles. Each provider processes data under its own privacy terms. We require every third party that receives your data to provide the same or equal protection of your data as described in this policy.
The following features send content you provide to Anthropic (the maker of Claude), which processes it on our behalf, as our service provider, solely to fulfil that request. Nothing is sent unless you use the feature:
Anthropic's API terms state that data submitted through the API is not used to train its models. Anthropic keeps API inputs and outputs only for a limited period set out in its terms, for abuse and safety monitoring, and longer only where a request is flagged under its usage policies or the law requires it; we do not store the raw prompts server-side beyond the result written back to your trip. See Anthropic's commercial terms and privacy center.
We do not disclose personal information to third parties for their own direct marketing. (California residents may ask about this under California Civil Code Β§1798.83; the answer is that there is nothing to report.)
On your device only (never uploaded): the raw location points recorded during a trip (Android only, and only until they are deleted β see Section 6), the "did you visit here?" suggestions you haven't accepted, and your home location. None of these are in your account, in any backup or in Export all my trips. The coordinates of an individual detected stop are sent to a geocoder and to Google Places to name it; the trail itself is not.
Synced to your account (Firebase): your trips, itinerary, expenses, and profile β so you get them back when you sign in on another device. Personal entries, and entries created from a suggestion you accepted, stay visible only to you, even on a shared trip. If you use Auto-log (or tap "Mark visited") on a planned entry of a shared trip, the people on that trip see it marked visited with the times you were there. Your wishlist and its notes are private to you.
Shared only when you choose: only trips you explicitly share are visible to the people you add, and only the base itinerary. Nothing is public unless you create a public link yourself. A public link carries the trip's name, dates and itinerary, your display name and the names of anyone you listed as a companion. For a companion who has joined the trip with their own TravelLog account, it also carries their @handle and account ID, so people viewing it in the app can open their public profile; never their email or anything else from their account. A shared view (public link or friends) never carries anything tracking observed: an entry whose times came from tracking shows its planned time if one was recorded and otherwise no time, and "visited"/"completed" status is never published. It never includes coordinates or street addresses. Public links created from this version of the app never include booking confirmation numbers or map coordinates; if you published a link before September 2026, revoke and re-create it under Settings β Privacy & Data β Manage public links to remove those fields.
All traffic between the app and our backend, and between our backend and the services listed above, uses HTTPS/TLS. Your cloud data is stored in Google Firebase and is encrypted at rest by Google. Access is enforced by server-side security rules: your profile's private data, your wishlist, your backups and your personal trip entries are readable only by your own signed-in account, and a shared trip is readable only by the people you invited. Photos are stored under unguessable URLs that only you and the people you share a trip with receive. Our third-party API keys are held in Google Secret Manager and never ship inside the app.
No system is perfectly secure, and we cannot guarantee that data will never be accessed without permission. If a security breach affects your personal information, we will notify you and the relevant authorities as the law requires.
deleteUserAccount cascade removes your cloud data and your sign-in account
in a single run.We keep nothing else about you once the periods above end.
You can delete your account at any time in the app: Settings β Privacy & Data β Delete my account. This runs a server-side cascade that permanently deletes:
Shared trips you own are deleted for everyone on them. Trips saved only on your device are not part of the cloud deletion. On both Android and iPhone/iPad the app erases its local copy from that phone when you delete your account, along with your location data and saved home place. Use Settings β Privacy & Data β Export all my trips first if you want to keep them. Abuse reports and purchase records may be retained as described on the deletion page. This cannot be undone.
A record of any purchase you made is kept so the same subscription cannot be redeemed on two accounts at once. It holds a one-way fingerprint of the store's purchase identifier, the product, the platform, the dates it was recorded and released, and the ID of the deleted account β never your name, email or payment details. When you delete your account, the record is released from it, so if you sign up again you can restore the same subscription on your new account. Deleting your account does not cancel a subscription: cancel it in the App Store or Google Play if you no longer want to be billed.
If you cannot access the app, you can request deletion by emailing
armgardtj@outlook.com from the email associated with your account. See
our account deletion page for details.
TravelLog is intended for adults. You must be at least 18 years old to create an
account, as set out in our Terms, and the app is not directed
to children. We do not knowingly collect personal information from anyone under 18. If
you believe a minor has provided us data, contact
armgardtj@outlook.com and we will delete it.
Depending on where you live, you may have the right to:
How to exercise them. Many rights can be used directly in the app:
Settings β Privacy & Data (export your trips, delete your account), Settings β
Privacy ("Do not sell or share my personal information"), and editing your profile and
trips. For anything else, email armgardtj@outlook.com, or use the
account deletion page.
Verification. To protect your data, we verify requests before acting on them β normally by asking you to send the request from the email address on your account, or to confirm it in the signed-in app. We use what you give us for verification only for that purpose. If we cannot verify you, we will tell you why.
Authorised agents. Where your law allows, someone you authorise may make a request for you. We may ask for your signed permission and to verify your identity directly with you, unless the agent holds a valid power of attorney.
Response time. We respond within the time your law requires β generally within 30 days, or 45 days under most US state laws. Where the law allows an extension, we will tell you within the original period and explain why.
Appeals (US states). If we decline to act on your request, you can
appeal by replying to our decision or emailing armgardtj@outlook.com with
"Appeal" in the subject. We will respond in writing within the time your state's law
requires (at most 60 days) and explain our decision. If you disagree with the outcome,
you can contact your state attorney general.
This table describes the personal information we have collected in the past 12 months, in the categories California law uses. Sources are described in Section 2 ("Where the data comes from"); retention is in Section 6.
| Category | What we collect | Why | Disclosed for a business purpose to | "Shared" for targeted ads? |
|---|---|---|---|---|
| Identifiers | Name / display name, @handle, email, account ID, sign-in provider ID, push token, IP address, Crashlytics installation ID, device advertising ID (free tier) | Your account, sync, sharing, notifications, security, diagnostics, ads on the free tier | Google (Firebase, Cloud, AdMob), Apple (sign-in), other users you choose (display name, @handle, avatar) | Yes β advertising ID and IP address, to Google AdMob, free tier only, unless you opt out |
| Customer records (Cal. Civ. Code Β§1798.80) | Name and email | Your account | Google (Firebase) | No |
| Commercial information | Pro subscription status and purchase record | Unlocking Pro; stopping one subscription being redeemed on two accounts | Google (Firebase) | No |
| Internet or other electronic network activity | Crash reports, device model and OS version, server logs, AI usage counters; ad interactions collected by AdMob (free tier) | Fixing bugs, security, AI fair-use limits, ads on the free tier | Google (Firebase Crashlytics, Cloud Logging, AdMob) | Yes β ad and device activity to Google AdMob, free tier only, unless you opt out |
| Geolocation | Precise location, only for trips you choose to track; coarse (city-level) location that AdMob derives from your IP address | The trip features listed in Section 2; ads on the free tier (coarse location only) | Google Places and your device's geocoder (a detected stop's coordinates), Google (Firebase, for places you accept), people on a shared trip, Google AdMob (coarse only) | Coarse location only, to Google AdMob, unless you opt out. Precise location: never |
| Audio, electronic or visual information | Photos and receipt images you attach | Showing them on your trips; reading receipts and booking screenshots when you ask | Google (Firebase Storage), Anthropic (images you scan), people on a shared trip | No |
| Other information you give us | Trips, itineraries, notes, expenses, wishlist, comments, profile details, and what you send to the AI features | Providing the app and the features you use | Google (Firebase), Anthropic (AI features you use), map and routing providers (place names and coordinates), flight-data providers (flight number and date), people you share with | No |
| Sensitive personal information | Precise geolocation (above) β nothing else | Only to provide the features you asked for | As for precise location above | No |
We do not collect protected-classification characteristics, biometric information, professional or employment information, or education information, and we do not create inferences or profiles about you.
Selling and sharing. We do not sell personal information and have not sold it in the past 12 months. On the free plan, Google AdMob may use your advertising ID and IP-based coarse location to show personalised ads, which California and some other US state laws may treat as "sharing" for cross-context behavioural advertising (or "targeted advertising"). You can opt out at any time in Settings β Privacy β "Do not sell or share my personal information": when it is on, every ad request tells Google to apply restricted data processing, so your data is not used to personalise ads (you still see ads on the free plan, and Pro removes them). Where Google shows a US state privacy message, you can also change your choice under "Privacy choices" in the same section. We do not knowingly sell or share the personal information of anyone under 16 (and the app is for adults only β Section 9).
Sensitive personal information. Precise geolocation is "sensitive personal information" under the CPRA and similar state laws. We collect it only when you turn tracking on for a trip, and use it only to provide the features you asked for (the list in Section 2). We do not sell it, do not share it for cross-context behavioural advertising, and do not use it to infer characteristics about you. Because we use sensitive personal information only for these permitted purposes, the right to limit its use does not apply, and we do not offer a separate "Limit the use of my sensitive personal information" link.
Consumer health data (for example under Washington's My Health My Data Act, Nevada SB 370 or Connecticut law): TravelLog does not collect consumer health data. Location is never used to identify health-related visits; places Google identifies as health-related are discarded and never suggested or stored, as described in Section 2.
Religious beliefs: location is never used to infer your religion; places Google identifies as places of worship are discarded from automatic suggestions and never suggested or stored, as described in Section 2. You can still add any place yourself.
We collect and use your personal information only for the purposes described in this policy, with your consent. Using the app with an account is consent to the processing needed to provide it; for optional uses (per-trip location tracking, notifications, personalised ads) we ask separately, and you can withdraw consent at any time as described in Section 8. Location tracking is off by default. You have the right to access and correct your personal information and to withdraw consent; contact our privacy officer (Section 1). Your data is stored and processed outside Canada, mainly in the United States (see "International transfers" below), where it may be accessible to courts and authorities under local law. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, to the Commission d'accès à l'information (or to your provincial privacy commissioner where one applies).
Your personal information is disclosed to and stored by overseas recipients β our providers in the United States and other countries where they operate (Section 3). You can ask to access or correct your information at any time. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner or New Zealand's Office of the Privacy Commissioner.
You can ask to access or correct your personal information, and object to its processing. If you are not satisfied with our response, you can complain to the Information Regulator (inforegulator.org.za).
Under the LGPD you have the rights listed above, including confirmation that we process your data, access, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about who we share it with and about the consequences of not giving consent, and withdrawal of consent. You can also complain to the Autoridade Nacional de ProteΓ§Γ£o de Dados (ANPD). The legal bases we rely on are below.
Where the law requires a legal basis for processing (for example Brazil's LGPD), we rely on the following:
| Purpose | Legal basis |
|---|---|
| Trip location tracking and everything it powers (suggestions, Auto-log, distance, flight-delay notes, place-search bias) | Consent, given per trip. You can withdraw it at any time for one trip (switch it to Off) or for the whole app (revoke location permission). Withdrawing does not affect processing that happened before. |
| Your account, trips, sync, sharing with people you choose, photos, AI features you use, notifications you enable, Pro purchases | Performance of our contract with you β providing the app you signed up for. |
| Security, fraud and abuse prevention, moderation, crash reports and diagnostics, AI fair-use limits | Legitimate interests in keeping the app safe, working and affordable to run. |
| Ads on the free tier (Google AdMob) | Your consent where the law requires it, collected through Google's consent message and changeable under "Privacy choices" or "Ad privacy choices" in Settings; otherwise our legitimate interests in funding the free tier, subject to your right to opt out of personalised ads. |
| Keeping purchase records and responding to lawful requests | Legal obligation where applicable, otherwise legitimate interests. |
TravelLog is operated from the United States, and your data is stored in the United States. Our providers β including Google (Firebase, Places, AdMob) and Anthropic β process data in the United States and other countries. Wherever you live, your data is therefore transferred to and processed in countries whose data-protection laws may differ from yours. We send each provider only what the feature you use needs (Section 3). If you used TravelLog in the EU/EEA, UK or Switzerland before it was withdrawn there, transfers from those places rely on the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where the provider is certified, and otherwise on Standard Contractual Clauses in the provider's data processing terms; you can also complain to your local data protection authority.
If you live somewhere not listed above, you have the rights your local law gives you, which you can exercise as described in this section, and you can complain to your local data protection authority.
We may update this policy. Every change is reflected by a new "Last updated" date at the top of this page. If a change would let us use data we have already collected in a materially different way, we will ask for your consent first where the law requires it.
Questions or requests: armgardtj@outlook.com.