Travelogue

Privacy Policy

What we collect, why, how long we keep it, and your rights

Last updated 17 August 2026

The short version

Travelogue is a diary of your holidays. It is built to work with as little of your information leaving your phone as possible.

By default, everything you write stays on your device and we never see it. If you want your diary to survive a lost phone or move to a new one, you can choose to turn on sync — and then a copy is held on our server so we can give it back to you.

That choice is yours, it is not pre-ticked, and you can change your mind and have the server copy deleted.

We do not sell your information. We do not use it for advertising. We do not build a profile of you.

The rest of this policy is the detail behind those sentences, including the things the law requires us to tell you.

The state of this build

In this build, Travelogue is local-only. Crash reporting is described below because it is planned and you should be able to read what it would mean before you are ever asked to choose — but it is not switched on, and **there is currently no Travelogue server holding your diary**.

THE CHOICE IS REAL EVEN THOUGH THE SERVER IS NOT. When you create an account the app asks whether to keep everything on your device or to back your diary up, with the trade-off on both options, and neither is pre-selected. That answer is recorded and you can change it in Settings at any time. It controls one thing and one thing only: whether a copy of your diary is kept on our server. **Nothing is uploaded either way in this build, because there is nowhere to upload it to yet** — when there is, the answer you already gave is the one that will be honoured, and you will not be opted in by silence. Keeping everything on your device means exactly what it says, including that there is no backup: if you lose the phone, the diary goes with it, so export it now and then.

Three things below are partly true of this build, and here is exactly how far.

NEARBY PLACE SUGGESTIONS ARE REAL AND ARE OFF. If you switch them on in Settings, the app asks your phone for an approximate position and uses it to put the closest places at the top of the list while you are writing about a holiday. It is read only while you have that form open, it is not written down anywhere, and it never leaves your device — there is nowhere for it to go. Switching the setting off, or withdrawing the permission in your phone's own settings, stops it immediately. Journey tracking, which is the other location feature described below, is not built at all.

FLIGHT TRACKING SHOWS SAMPLE DATA. The screen exists for Premium subscribers, but no flight-data provider is contacted and nothing you type into it is sent anywhere. The description below is of the finished feature, and the app says on the card itself that what you are looking at is a stand-in.

Who we are, and how to contact us

Travelogue is run by Travelogue Ltd. We are the data controller for everything described in this policy, which means we are responsible for it and we are who you hold to account.

Travelogue Ltd is being incorporated in England and Wales. Once registration completes, this section will carry the company number and registered office address, and we will tell you in the app that it has changed.

For anything to do with your information — a question, a request, or a complaint — email privacy@thetravelogueapp.com.

We are not required to appoint a Data Protection Officer and have not appointed one. Your email goes to the person who actually builds and runs the app.

The two ways Travelogue can hold your diary

These are genuinely different privacy positions, and you pick one. Neither is pre-selected, and both have a real downside that you should read before choosing.

LOCAL ONLY. Your diary is stored on your device and nowhere else. We hold nothing, so there is nothing for us to lose, hand over or be compelled to produce. The downside is real and permanent: if you lose the phone, break it, or delete the app, your diary is gone and we cannot get it back for you, because we never had it. Export your diary from Settings if you want a copy you control.

SYNCED. A copy of your diary is held on our server. You can sign in on a new phone and find everything where you left it, and losing a device stops being a disaster. The downside is equally real: your holidays, and any photographs in them, sit on a computer you do not own, and you are trusting us to look after them.

You can switch between the two at any time in Settings. Turning sync off deletes what we hold — properly deleted from our systems, not hidden from view — and leaves your diary on your device.

What we collect, and where it comes from

ACCOUNT DETAILS, from you when you sign up: your name, username, email address and date of birth. Optionally your home country, nationality, sex, a short bio and a profile picture or avatar.

Your date of birth is collected for one reason: to check you are old enough to use Travelogue and to apply safer defaults if you are under 18. See "Children and young people" below.

WHAT YOU WRITE, from you as you use the app: reviews of holidays, ratings, dates, the countries and places you attach to them, photographs and documents you add, postcards, bucket-list entries and goals. This is your diary. It is the reason the app exists.

WHO YOU ARE CONNECTED TO, from you and from other users: friend requests you send, and friend requests other people send you.

LOCATION, only if you ask for it, and only approximately: if you turn on nearby-place suggestions, the app asks your phone for a coarse position — about a kilometre, not a precise fix — and uses it to put the places closest to you at the top of the list while you are writing about a holiday. It is off unless you switch it on. It is read only while that form is open, it is never stored, and it is never sent to us or to anyone else. Switching the setting off stops it, and so does withdrawing the permission in your phone's own settings. Journey tracking, when it is built, would be a separate switch and a separate decision.

TECHNICAL INFORMATION, from your device, and only if you are synced or have opted into crash reporting: your app version, device model, operating system version, and the IP address your device connects from. Where you have opted in, this includes diagnostic details of a crash — what the app was doing when it failed.

PURCHASE INFORMATION, from Apple or Google if you buy Premium: confirmation that a valid subscription exists, and when it renews or lapses. We never receive your card number, and we never see your payment details.

We do not ask for, and do not want, special category data — information about your health, race or ethnicity, religion, politics, sex life or sexual orientation. Please bear in mind that a diary can reveal such things without meaning to, and that a review marked Public can be read by anyone.

Information about other people

This section is about people who never signed up to Travelogue, and it exists because a holiday diary is full of other people.

If you are reading this because your name, face or something you did has ended up in someone's Travelogue diary, this is the part that applies to you, and the rights below are yours too.

WHAT WE MAY END UP HOLDING ABOUT SOMEONE WHO IS NOT A USER their image, if they appear in a photograph; their name or a description of them, if a review mentions them; and the fact that they were in a particular place on a particular date, if that is what the entry says.

WHERE IT COMES FROM entirely from the user who wrote the entry. We do not buy information about anybody, we do not collect it from public sources, and we do not go looking for it.

WHY WE HOLD IT because we cannot give someone their diary back without the contents of their diary. Our lawful basis is our legitimate interest in providing a working journal, balanced against the interests of the people written about — which is why entries default to being seen by nobody but their author, why a private entry is never shown to anyone else, and why we do not run face recognition, tag people automatically, or index diary contents to make people findable.

WHAT YOU CAN DO ABOUT IT write to privacy@thetravelogueapp.com. You can ask what we hold, ask us to correct it, ask us to delete it, or object to us holding it at all. We will normally act on a deletion request about an identifiable person without argument. Because entries live inside somebody's personal diary, we will tell you what we have done but will not usually hand over the rest of that person's entry.

WHY WE HAVE NOT WRITTEN TO YOU the law asks us to tell people directly when we hold information about them. We cannot, because we have no way of knowing who is in a photograph or of contacting them — and finding out would mean analysing faces and hunting for contact details, which would be far more intrusive than the problem it solves. Publishing this section is how we tell you instead.

IF YOU ARE THE ONE WRITING please think before you post a photograph in which somebody else is identifiable, and do not post one if they have asked you not to. Our Community Guidelines say the same thing, and we mean it.

Why we use your information, and our legal basis for it

The law requires us to name a lawful basis for each thing we do. These are ours.

TO GIVE YOU THE APP AND YOUR ACCOUNT — showing you your own diary, map, passport and statistics. Basis: performance of our contract with you.

TO SYNC YOUR DIARY, IF YOU TURN SYNC ON — holding a copy so you can get it back on another device. Basis: performance of our contract with you. If sync is off, this processing does not happen at all.

TO SHOW YOUR ENTRIES TO THE PEOPLE YOU CHOSE — publishing a review to friends or publicly, because that is what you asked for when you set its privacy. Basis: performance of our contract with you.

TO CHECK YOU ARE OLD ENOUGH, AND TO PROTECT YOUNGER USERS — verifying your date of birth meets our minimum age and applying safer defaults under 18. Basis: compliance with a legal obligation, and our legitimate interest in running a service that is safe for the people using it.

TO KEEP THE SERVICE WORKING AND SECURE — preventing abuse, limiting how much any one account can send us, and investigating problems. Basis: our legitimate interests in keeping the app available, affordable to run, and not usable as a tool against other people.

TO FIX CRASHES, IF YOU OPT IN — receiving a diagnostic report when the app fails. Basis: your consent. You can withdraw it at any time in Settings, and the app works identically either way.

TO SUGGEST PLACES NEAR YOU, IF YOU OPT IN — reading an approximate device position while you are writing an entry, and ordering the suggested places by how near they are. Basis: your consent, withdrawable at any time in Settings. Nothing is stored and nothing is transmitted, so withdrawing consent leaves nothing behind to delete.

TO LOOK UP A FLIGHT, IF YOU ASK US TO — sending a flight number and date to a flight-data provider through our own server. Basis: performance of our contract with you, for the Premium feature you asked for.

TO SELL AND SUPPORT PREMIUM — confirming a subscription is valid, and keeping the records of it that tax law requires. Basis: performance of our contract with you, and compliance with a legal obligation.

TO ANSWER YOU WHEN YOU GET IN TOUCH. Basis: our legitimate interest in supporting the people who use the app.

Where we rely on legitimate interests, you have the right to object — see "Your rights" below. Where we rely on consent, you can withdraw it at any time without losing anything else, and withdrawing does not undo processing that was lawful before you withdrew.

WHAT WE DO NOT DO WITH IT. We do not send marketing emails, and we do not have a mailing list to be on. The only emails we send are about your own account — a password reset, a receipt, or a reply when you write to us. We do not sell or rent your information, we do not share it with data brokers, and we do not use it to target advertising, here or anywhere else.

Notifications inside the app are a different thing and you control them in Settings, kind by kind. They are switched off at the operating-system level until you ask for them.

Who we share it with

We do not sell your information to anyone, and we do not share it for anyone's advertising.

OTHER PEOPLE USING TRAVELOGUE, but only as far as you decided. Every entry carries a setting: Private (nobody but you), Friends (only people whose connection you accepted), or Public (anyone using Travelogue). You set it when you write, and you can change it afterwards.

HOSTING AND STORAGE PROVIDERS, if you turn sync on. They store the data on our behalf, under a contract that forbids them using it for anything else.

APPLE AND GOOGLE, when you buy Premium, because the purchase happens in their store and they tell us whether it succeeded.

A CRASH REPORTING PROVIDER, only if you opted into crash reporting.

A FLIGHT DATA PROVIDER, only when you look up a flight, and only the flight number and date. The request goes through our own server so the provider does not receive your device's address, and we do not tell them who is asking.

SERVICES THE APP CALLS DIRECTLY, WITHOUT AN ACCOUNT exchange rates from Frankfurter and weather forecasts from Open-Meteo, both fetched when you open a country; a place-name lookup from Open-Meteo while you are typing a place into an entry; and satellite map imagery from NASA's Global Imagery Browse Services when you zoom into the map with satellite turned on. None of them is told who you are. The first two receive only which country you tapped. The place lookup receives the letters typed into the place field and nothing else — no title, no dates, no photographs, no rating, and never the entry itself. It is sent only while that field is being typed into, and never if you pick one of the places already built into the app, which is most of them. The map imagery receives a zoom level and a grid reference — a rectangle of the earth, with nothing to say whether it means anything to you. As with any request from your device, all of them will see the IP address it came from. All are free services requiring no key and no account.

LAW ENFORCEMENT OR A REGULATOR, if we are legally required to hand something over — and only what we are actually required to hand over.

A BUYER, if Travelogue is ever sold or merged. We would tell you before your information moved, and the policy would have to be honoured.

Where your information is held

If you turn sync on, we intend to hold your data in the United Kingdom or the European Economic Area, so that for most of our users it does not leave the area whose laws protect it.

Some of the services we rely on operate internationally, so information may be transferred outside the UK and EEA. Where that happens, we will only do it under one of the protections the law provides: an adequacy decision by the UK government or the European Commission recognising the destination as offering equivalent protection, or the UK International Data Transfer Agreement (or the addendum to the European Commission's Standard Contractual Clauses) where there is no adequacy decision.

You can ask us for a copy of the safeguards that apply to any particular transfer by emailing privacy@thetravelogueapp.com.

While you stay local-only, none of this arises: your diary does not leave your device, so there is no transfer to protect.

How long we keep it

YOUR DIARY, IF YOU ARE SYNCED for as long as your account exists. Delete an entry and it goes immediately. Delete your account, or switch back to local-only, and we remove everything from our live systems straight away and from our backups within 30 days.

YOUR DIARY, IF YOU ARE LOCAL-ONLY entirely up to you, because we never receive it. It stays on your device until you delete it or remove the app.

YOUR LOCATION not at all. A position read for nearby suggestions exists only in the app's memory while you have an entry open, and is gone when you close it. There is no location history in Travelogue, on your device or anywhere else.

CRASH REPORTS 90 days, then deleted. Long enough to spot a pattern across a release; not long enough to become a history of your use.

SERVER AND FLIGHT-PROXY LOGS 30 days, kept to spot abuse and diagnose faults.

SUPPORT EMAILS 2 years from the last message, so we have the context if you write again.

PREMIUM PURCHASE RECORDS 6 years, because UK tax law requires it.

RECORDS WE MAY NEED TO DEFEND A LEGAL CLAIM up to 6 years, which is the ordinary limitation period in England and Wales. We keep the minimum that serves that purpose and nothing else.

Where we cannot delete something immediately — because it sits in a backup — we isolate it so nothing further is done with it, and it goes when the backup rotates.

Your rights

These rights are yours under UK and EU data protection law, and they apply whether or not you have a Travelogue account.

ACCESS — ask what we hold about you and get a copy.

RECTIFICATION — have anything inaccurate corrected. Most of it you can simply edit in the app.

ERASURE — have your information deleted. In the app: delete an entry, delete your account, or switch back to local-only.

RESTRICTION — ask us to hold your information but stop doing anything else with it, while a dispute is sorted out.

OBJECTION — object to processing we base on legitimate interests. We must then stop unless we can show compelling grounds that override your interests.

PORTABILITY — receive your information in a structured, commonly used, machine-readable format, or have it sent to another service. Export in Settings does this now, without asking us and without an account.

WITHDRAWING CONSENT — where we relied on your consent, withdraw it at any time in Settings. It takes effect immediately and does not make earlier processing unlawful.

To exercise any of these, email privacy@thetravelogueapp.com. We will respond within one month. If a request is unusually complex we may take up to two further months, and we will tell you inside the first month if so. We may need to check who you are before acting, so that nobody else can use these rights against you. There is no charge unless a request is clearly unfounded or excessive.

Do you have to give us anything?

Not to use the app. Travelogue works as a local diary with no account at all.

IF YOU WANT AN ACCOUNT, we need a username, an email address and your date of birth. That is a condition of the contract between us: without a username there is nothing to sign in to, without an email there is no way to recover your account, and without a date of birth we cannot tell whether you are old enough. If you will not give them, we cannot create the account, but you can keep using Travelogue locally.

EVERYTHING ELSE IS OPTIONAL — your real name, home country, nationality, sex, bio, profile picture, location access and crash reporting. Declining any of them costs you only the feature that needs it, and never the app.

Automated decisions and profiling

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you.

Travelogue does rank and count things — a leaderboard of popular countries, statistics about your own travel, the order of your friends list. These are arithmetic over what you and your friends have written, they decide nothing about you, and they are not used to judge you, price anything differently, or restrict what you can do.

Children and young people

You must be at least 13 to use Travelogue. We ask for your date of birth when you sign up, and we will not create an account below that age.

We know a typed birthday is not proof of age. It is the standard first step, and we will strengthen it if the way Travelogue is used ever calls for more.

IF YOU ARE UNDER 18, your account *starts* with safer settings: new entries are private rather than public, location features start off, your diary starts set to stay on your device, and your profile is not publicly listed. Every one of those is a starting point, not a rule about you. You can change any of them whenever you like, including straight away — the sign-up screen shows you the same choices as everybody else, with the safer one already picked and a line saying so.

We think that is the right way round. Refusing a sixteen-year-old the ability to back their diary up would not protect them from anything: they would simply lose it along with the phone. What we owe you is that privacy is where you begin and that the trade-off is explained in plain words, not that a decision about your own diary gets made for you.

We design on the basis that under-18s may well be using Travelogue, which is what the Children's Code requires of a service like this. In practice that means privacy is the default rather than something to go and find, we do not use nudges to push anyone into sharing more widely, and there is no advertising or profiling anywhere in the app.

If you believe a child under 13 has an account, email privacy@thetravelogueapp.com and we will delete it and everything in it.

How we look after it

Everything travelling between the app and our server goes over an encrypted connection, and anything we store is encrypted at rest. Access to systems holding user data is limited to the people who need it to run the service.

Photographs are resized on your device before they are ever uploaded. Travelogue is a diary, not a photo backup — your originals stay in your own photo library, where they were.

Who can see an entry is enforced on our server, not only in the app on your phone. That distinction matters: a check that runs only on the reader's device can be bypassed by anyone prepared to talk to the server directly, and would mean a private entry was private only by good manners.

If there is ever a breach that puts you at risk, we will tell the Information Commissioner's Office within 72 hours and tell you without undue delay.

No system is perfectly secure, and we will not claim otherwise. Staying local-only remains the strongest privacy position available in Travelogue, and it is always there.

Changes to this policy

We will update this policy when what we do changes. The date at the top tells you when it last did.

If a change materially affects you — anything new leaving your device, a new recipient, or a new purpose — we will tell you in the app before it takes effect, not afterwards. Where the change needs your consent, we will ask, and carrying on using the app will not be treated as an answer.

Complaints

If you are unhappy with how we have handled your information, email privacy@thetravelogueapp.com and we will look into it properly.

You can also complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not have to come to us first, though it is usually quicker.

If you are in the EEA, you can complain to the supervisory authority in your own country instead.

If this doesn't match what the app does, tell us

This policy was written to describe accurately what Travelogue actually does, rather than borrowed from wording that describes somebody else's product. It has been reviewed by a solicitor.

That is not the same as it being right forever. If you spot something here that does not match what the app does, that is a bug in one or the other and we want to know: privacy@thetravelogueapp.com.