Travelstone

Privacy Policy

Last updated: 30 August 2026

Travelstone ("the app", "we", "us") is a travel-planning app that turns a few inputs — where you want to go, for how long, what kind of trip, and which season — into a day-by-day itinerary you can adjust. This policy explains what we collect, why, who processes it on our behalf, and the choices you have, including how to delete your account and data.

The short version. We collect the email you sign up with and the trip details you enter. We use them only to run the app — to sign you in and to build and store your itineraries. We do not sell your data, we do not use it for advertising, and we do not track you across other apps or websites. The app never takes payments or makes bookings. You can delete your account and all associated data from within the app at any time.

Information we collect

Account information

When you create an account we collect your email address and an authentication credential (a password, managed by our authentication provider — we never store it in readable form). This is used to identify your account and let you sign in.

Trip content you provide

When you plan a trip we collect the inputs you enter and the itineraries generated from them: destinations (cities or countries), travel dates, trip type (for example leisure, backpacking, adventure), season, and budget preference, plus the resulting day-by-day plans and any swaps you make. This content is stored under your account so your trips are there when you return.

Notification token (if you enable notifications)

Itineraries are generated on our servers and can take a few minutes. If you allow notifications, we store a push notification token for your device so we can tell you when a plan is ready. You can revoke this at any time in your device settings; the token is removed when you sign out or delete your account.

What we do not collect

We do not collect payment or financial information (the app never transacts), contacts, precise device location, health data, or advertising identifiers. We do not run third-party advertising or cross-app tracking SDKs.

How we use your information

We use the information above only to provide and operate the app:

We do not use your information for advertising, profiling for marketing, or sale to third parties.

Service providers who process data for us

We rely on a small number of infrastructure providers ("sub-processors") to run the app. They process data only to provide their service to us, under their own privacy and security terms. We do not share your data with anyone for their own independent use.

ProviderRoleWhat it processes
Supabase Authentication and database hosting Your email, account credential, and stored trips.
Fly.io Server that runs itinerary generation Your trip inputs while a plan is being generated.
Anthropic (Claude) Generates the itinerary text Your trip inputs (destination, length, type, season, budget). No email or account identifier is sent.
Google Places Supplies place details and photos Destination and venue lookups. Called from our servers; your identity is not sent.
Expo Delivers push notifications Your device notification token (only if you enable notifications).

Because these providers operate globally, your information may be processed on servers located outside your country. Where that happens, it remains subject to this policy and the providers' safeguards.

Data retention and deletion

We keep your account and trip data for as long as your account exists. You are in control of removing it:

Deletion is immediate and cascades across our database. Anonymous, non-personal reference data that the app caches to run efficiently (for example, public information about places and venues) is not linked to you and is not removed by account deletion.

Security

Connections between the app and our servers are encrypted in transit. Access to your stored data is restricted by row-level security so that your account can only reach its own records. Server-side keys for third-party services are never included in the app and never exposed to your device. No system is perfectly secure, but we take reasonable measures to protect your information.

Children's privacy

Travelstone is not directed to children, and we do not knowingly collect personal information from anyone under the age of 13 (or the minimum age required in your country). If you believe a child has provided us information, contact us and we will delete it.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise the core of these directly in the app (viewing and deleting your trips, and deleting your account), or contact us using the details below and we will respond as required by applicable law. We do not sell personal information.

Changes to this policy

We may update this policy as the app evolves. When we do, we will revise the "Last updated" date above. Significant changes will be reflected here before they take effect.

Contact

If you have questions about this policy or your data, contact us at apps.subhro@gmail.com.