Privacy Policy
Last updated: August 24, 2026
Privacy Policy — Journeo
Effective date: July 21, 2026 Last updated: August 24, 2026 Website: https://journeo.ai Privacy Policy URL: https://journeo.ai/en/privacy Contact: hello@journeo.ai
1. Who we are
This Privacy Policy is published by Journeo ("Journeo", "we", "us", or "our").
Journeo is an AI-assisted, map-centered travel planning application available for iOS and Android, and related services at https://journeo.ai (collectively, the "Service").
This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, how long we keep it, and the choices you have. It applies to Journeo mobile applications, our APIs, and our website.
If you do not agree to this Policy, please do not use the Service.
2. Scope and roles
We act as the data controller for personal data processed to provide Journeo accounts, trips, preferences, and related features.
Certain processing is performed by processors acting according to our instructions (such as hosting, authentication, analytics, crash reporting, maps, and AI model providers). These processors are described in Section 6.1.
The purpose of this Policy is to meet disclosure expectations for:
- Apple App Store (Privacy Policy URL and App Privacy nutrition labels)
- Google Play (Privacy Policy URL and Data safety form)
- Applicable privacy laws, including EU/UK GDPR and Türkiye's KVKK, where applicable
3. Personal data we collect
We collect only what is necessary to operate Journeo. Depending on how you use the Service, this may include:
3.1 Account and profile information
- Email address (your password is stored only in hashed form; we never see your plain-text password)
- Username (unique, used to find and add friends)
- Display / full name
- Profile photo (avatar)
- Timezone
- Preferred language / locale
- Account identifiers generated by our systems
3.2 Trips and content you create
- Trip titles, destinations (city/country), dates, cover images, and trip status
- Travel preferences (style, pace, diet, budget tier, interests, accessibility settings)
- Itinerary days and stops (places you add, notes, order, booking-related links)
- Packing lists, flights you add, and trip expenses
- Friendships / trip memberships and roles (owner, editor, viewer)
- Planner chat messages and prompts you send to create or refine itineraries
- Affiliate click events when you open partner booking links we generate
3.3 Location data
With your permission, while using the app, we may collect approximate and/or precise device location for the following purposes:
- Displaying your location on the map
- Tailoring travel planning to your current location
- Supporting features such as city detection for voice planning
- Live location sharing with travel companions — only when you initiate a time-limited live sharing session for a trip (e.g., 1 / 4 / 8 hours or until the end of the day). While this session is active and the app is in the foreground, your approximate/precise coordinates are visible to other members of that trip. Sharing stops when you turn it off, when the session expires, or when the app moves to the background. We do not request "always" / background location permission for this feature, and we do not share your live location with non-members or for advertising purposes.
We design location usage around when-in-use access and balanced accuracy. We do not continuously track your location in the background for advertising purposes. Continuous high-accuracy tracking is not used except in narrowly scoped navigation-style use cases when enabled, and is revoked once that mode ends.
You can deny or revoke location permissions in your device settings. Some map and planning features may function with reduced accuracy or without location.
Your location data is not sent to our analytics providers. Analytics events may only contain place names such as your trip's destination city (Section 3.7); your coordinates are never included.
3.4 Microphone and speech
With your permission, we may access the microphone and device/system speech recognition so you can plan trips by voice. Audio is used solely to convert speech to text for planning purposes; we do not sell audio recordings for advertising purposes.
3.5 Camera and photo library
With your permission, we may access the camera or photo library so you can set a profile picture. The photos you select may be uploaded to our storage and associated with your account.
3.6 Notifications
If you enable notifications, we store device push tokens (e.g., FCM tokens) and notification preference settings to deliver trip-related and product notifications. You can change notification permissions via device settings and, where available, in-app preferences.
3.7 Device, diagnostics, and usage data
- App version, device type / operating system, language, and similar technical signals required to operate the Service
- Crash and performance diagnostics (e.g., via Sentry), which may include device metadata and stack traces
- IP address and request metadata processed by our servers and hosting providers for security, rate limiting, and abuse prevention
- Local offline copies of trip data stored on your device (SQLite / Drift) so the app can work offline
#### 3.7.1 Product analytics (only with your consent)
We use two providers for product analytics: Firebase Analytics (Google) and Mixpanel. The same events are sent to both providers.
Analytics collection does not begin without your explicit consent. You are prompted when you first open the app; no data is sent to either provider until you grant permission. You can withdraw consent at any time from Profile → Privacy and Analytics; once withdrawn, collection stops on that device.
When consent is granted, the following may be collected:
- Feature usage events — e.g., sign up completed (`sign_up_completed`), onboarding completed, trip created, AI plan generated/failed, paywall viewed, purchase initiated/completed, booking link clicked, account deleted
- Limited context attached to these events — e.g., destination city name, trip duration in days, platform (iOS/Android), sign-up method (email/Google/Apple), product ID. We do not send the text of your travel content, notes, or planner chat messages.
- Automatic session events — The Mixpanel SDK also collects standard events such as app session start/end, first open, and app updates.
- Your account identifier — When you sign in, your system-generated account identifier (UUID) is sent to analytics providers so that events can be attributed to the same user. Your name, email address, or profile picture are not sent to analytics providers, and we do not build a user profile on your behalf within these providers. When you log out, this association is reset.
Mixpanel data is processed and stored on servers located in the European Union (EU).
We do not use analytics providers to serve advertisements or track you across apps and websites.
3.8 Payments and entitlements (when enabled)
If you purchase a subscription or in-app unlock, payments are processed by Apple, Google, and/or RevenueCat. We receive the entitlement / subscription status required to unlock features; we do not receive your full payment card number.
3.9 Third-party sign-in information (when selected)
If you sign in with Google or Apple, we receive limited account information shared by these providers (typically an identifier and email/name, depending on your provider settings) to create or link your Journeo account.
3.10 Information we do not sell
We do not sell your personal data. We do not rent your contact list or travel content to data brokers.
4. How we use personal data
We use personal data for the following purposes:
- Provide the Service — create accounts, verify your identity, store and sync trips, display maps and itineraries, enable collaboration with trip members and friends
- Generate AI itineraries and related content — send relevant trip and preference context to our backend, which calls AI model providers to generate structured travel plans; verify places against place databases / geocoders; generate specific city cover / icon images under controlled, cached pipelines
- Personalize — apply your preferences, locale, timezone, and travel settings
- Communicate — send transactional messages and (with consent) push notifications
- Enhance reliability and security — diagnostics, debugging, fraud / abuse prevention, rate limits
- Measure product usage — aggregate or event-level analytics to understand which features work well. This occurs only if you have granted analytics consent (Section 3.7.1)
- Affiliate attribution — record when an affiliate booking link is opened so partners can attribute referrals; this supports our business model
- Comply with the law — respond to legal requests; enforce Terms; protect rights and safety
- Fulfill your requests — data export, account deletion, preference updates
Legal bases (where GDPR/KVKK applies): contract performance; consent (e.g., optional permissions such as location, microphone, camera, notifications, and product analytics); legitimate interests (security, fraud prevention, crash diagnostics — balanced with your rights); and legal obligations.
The legal basis for product analytics is your explicit consent, and withdrawing your consent does not affect the lawfulness of processing carried out prior to withdrawal.
5. AI processing
Journeo utilizes artificial intelligence to assist in generating and refining travel itineraries, and in limited cases, for city images used as trip covers or icons.
- AI requests are made from our servers, not directly from your device with exposed model API keys.
- Inputs may include destinations, dates, preferences, and planner conversation content provided by you.
- Outputs may include recommended places and schedules. Some places may be marked unverified if they cannot be validated against place data.
- AI providers process prompts/responses as necessary to return results. We configure providers under our agreements and do not use AI outputs to create advertising profiles about you.
- City cover / icon generation follows a generate-once, cache, and reuse model per city key, so the same city image can be shared among users. This is not a likeness of you and is not connected to any sale of your identity.
- Your planner chats and AI prompts are not sent to analytics providers.
AI recommendations may contain inaccuracies. Always verify critical travel details independently.
6. How we share data
We share personal data only as described below:
6.1 Service providers (processors)
| Category | Example Providers | Purpose |
|---|---|---|
| Backend / Database / Authentication | Supabase (Postgres, Auth, Storage) | Accounts, travel data, synchronization, avatars, certain images |
| Hosting | Google Cloud Run (and related Google Cloud infrastructure) | API hosting |
| Audio file storage / CDN | Cloudflare R2 | Cache for audio files generated for stop voiceovers |
| Maps | Mapbox | Maps, styles, geocoding fallbacks, offline map tools |
| Places | Google Places API (server-side) | Place verification / resolution (cache-first) |
| AI models | Google Gemini | Itinerary generation |
| Image generation (limited) | fal.ai | City cover images (server-side, cached) |
| Free / public image sources | Wikipedia / Wikimedia | POI or destination images |
| Weather | Open-Meteo | Weather forecasts for travel dates (API-keyless weather data) |
| Analytics (only with consent) | Firebase Analytics (Google) | Product analytics |
| Analytics (only with consent) | Mixpanel — processed in EU data region | Product analytics, funnel, and retention analysis |
| Crash / Observability | Sentry | Crash and error monitoring |
| Push notifications | Firebase Cloud Messaging | Push delivery |
| Payments (when enabled) | Apple / Google / RevenueCat | In-app purchases and subscription status |
| Affiliate partners | Booking, Kiwi, Skyscanner, Viator (and similar) | When you click a booking/travel partner link |
Providers receive only what is necessary for their specific function. Analytics providers receive only the events and context specified in Section 3.7.1.
6.2 Other users you choose to interact with
If you add friends, accept requests, or share a trip, other members can view your shared profile details (such as username/name/avatar) and trip content according to their membership roles.
If you enable live location sharing on a trip (Section 3.3), your travel companions can see your location only during that active session.
6.2.1 Safety reports and blocks
You can block another user and report malicious or inappropriate behavior directly within the app. Blocking prevents further friend requests and associated social interactions from that user on your end. Reports are reviewed by Journeo and may include the reported user's account ID, your account ID, the selected reason, and optional details you provide; used solely for safety and abuse prevention.
6.3 Legal and safety
We may disclose information where required by law or legal processes, or to protect Journeo, our users, or the public from harm, fraud, or security threats.
6.4 Business transfers
In the event that we are involved in a merger, acquisition, financing, or asset sale, personal data may be transferred as part of that transaction under appropriate safeguards.
6.5 No sale of personal information
We do not sell personal information as that term is commonly understood under U.S. state privacy laws. We also do not share personal information for cross-app/cross-site advertising tracking ("tracking" as defined by Apple) for commercial purposes. If this changes, we will update this Policy and obtain all required consents (including App Tracking Transparency where applicable).
7. On-device storage and offline use
To support offline-first usage, trip and related data may be stored locally on your device. Local storage remains on your device until you clear app data, uninstall the app, or synchronize deletions after an account is deleted. Please protect your device with a passcode / biometrics, as with any app containing personal content.
Your analytics consent preference is also stored locally on your device and applies per device; it is requested separately across multiple devices.
8. International transfers
We and our providers may process data in Türkiye, the European Economic Area, the United Kingdom, the United States, and other countries. Where necessary, we implement appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.
We have configured Mixpanel analytics data to be processed in the EU data region.
9. Data retention
We retain personal data only as long as needed for the purposes described in this Policy, including:
- Account data — for as long as your account remains active
- Trip and collaboration data — for as long as necessary to provide the Service to you and other trip members
- Caches (e.g., AI plan cache, places cache, weather cache, city images, voiceover audio files) — according to product TTLs/operational needs; some caches are global and not linked to a single user ID
- Affiliate / security logs — kept for a limited duration for attribution, abuse prevention, and compliance
- Diagnostics / analytics — according to the retention settings of those tools
When you delete your account (Section 11), we delete or anonymize personal data we control that is no longer needed, subject to limited exceptions (legal holds, shared trip continuity described below, rolling backups, and data required to be kept by law).
Shared trips: If you own a trip that has other members and you delete your account, ownership may be transferred to another member to prevent data loss for that trip. Therefore, content required for that shared trip may remain accessible to remaining members even after your account is deleted. Trips with no other members are removed from your account.
Analytics data: When you delete your account, you may request deletion of records from analytics providers (Section 11). Because the identifier we send to analytics providers is your account UUID, those records can be matched to your deletion request.
10. Security
We use industry-standard measures appropriate to the sensitivity of the data, including:
- Encryption in transit (HTTPS/TLS)
- Access controls and authentication
- Secure storage of session tokens on-device (iOS Keychain / Android Keystore)
- Server-side authorization checks for trip membership (to mitigate unauthorized access)
- Least-privilege service credentials on the backend
- Abuse monitoring and rate limiting on sensitive endpoints
No method of transmission or storage is 100% secure. Please use a strong, unique password and keep your device updated.
11. Your rights and choices
Depending on your jurisdiction, you may have the following rights:
- Access personal data we hold about you
- Correct inaccurate data
- Delete your account and associated personal data
- Export a copy of your data (data portability)
- Withdraw consent where processing is based on consent
- Object to or restrict certain processing
- Lodge a complaint with a supervisory authority (e.g., your local DPA or Türkiye's KVKK Authority)
In-app controls
- Export my data — Available in Account settings (JSON export via API)
- Delete account — Available in Account settings; deletion is permanent and cannot be undone
- Privacy and Analytics — Available in Profile; you can toggle product analytics consent at any time. When disabled, data transmission to both analytics providers ceases on that device
- Privacy Policy — Linked in Account settings and at https://journeo.ai/en/privacy
- Permissions — Location, microphone, camera, photos, and notifications can be managed via iOS/Android system settings
Contact for privacy requests
Send an email to hello@journeo.ai with the subject line "Privacy Request". We may need to verify that the request originates from the account owner.
We aim to respond within the timeframes required by applicable law (generally within 30 days where GDPR applies, subject to permitted extensions).
12. Children's privacy
Journeo is not directed to children under 13 (or the higher age required in your country, such as 16 in certain EU member states). We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us; we will take necessary steps to delete the account.
13. Third-party links and partner services
The Service may contain links to third-party websites or booking partners. Their privacy practices are governed by their respective policies. When you click an affiliate/partner link, the partner may receive information required to attribute the referral (and may place cookies or similar technologies on their site).
14. App Store and Play Store disclosures
This Policy serves as the public disclosure for our applications. Separately:
- Apple App Store Connect requires an App Privacy questionnaire ("nutrition labels")
- Google Play Console requires a Data Safety Form
These store forms must remain consistent with this Policy; both Firebase Analytics and Mixpanel must be declared as third parties collecting "Usage / Analytics Data". If our practices change, we will update both this Policy and the store disclosures.
15. Changes to this Policy
We may update this Privacy Policy from time to time. We will publish the updated version at https://journeo.ai/en/privacy and revise the "Last updated" date. Material changes may also be communicated in-app or via email where appropriate. Continued use of the Service after the effective date of an update constitutes acceptance of the revised Policy to the extent permitted by law.
16. Contact
Privacy inquiries/requests and support: hello@journeo.ai Legal entity: Journeo Website: https://journeo.ai
*This document is provided for App Store/Google Play release readiness based on Journeo's product design. It does not constitute legal advice. Please have counsel licensed in your jurisdiction review prior to launch.*