Privacy Policy
This policy explains what Roamly collects about you, why, who it is shared with, how long it is kept, and what you can do about it. It is written to be read, not skimmed: if a sentence is unclear, write to us and we will fix it.
1. Who is responsible
The data controller is [to be completed: operatorName], [to be completed: operatorAddress], registration number [to be completed: operatorRegistration] (“we”, “us”). For anything in this policy, write to [to be completed: contactEmail]. We have not appointed a data protection officer; the same address reaches the person who handles privacy.
2. What Roamly is
Roamly is a travel app. Creators publish posts about places, and readers follow them, save what they like, message them, and can buy access to paid content or an itinerary built from a creator’s recommendations. Some of what you do is public by design (a creator’s posts), some is visible to a defined group (members-only content), and some is private (your saves, your messages). Section 5 says which is which.
3. What we collect
3.1 Your account
- E-mail address and password. The password is stored only as a cryptographic hash; we cannot read it.
- Display name, username, language, currency, and — if you add them — a bio, an avatar, a cover photo, your country (shown as “Based in”) and the interests you pick during onboarding.
- Terms acceptance: the version of the Terms of Use you accepted and when.
- Notification settings: which notifications you want, and quiet hours.
3.2 If you are a creator
- Your headline, creator type, countries visited, the prices you set, your verification status and the dates you applied and were approved.
- Your earnings and payout records (section 3.6).
3.3 What you post and do
- Posts: text, photos and videos, tagged places, whether the post is free or paid and who may see it. Photos are re-encoded before upload and their embedded metadata (such as the location a camera may record) is removed. Videos are uploaded as they are; check your camera settings if you do not want a video to carry location metadata.
- Stories: a photo or a video of up to 15 seconds, a caption, an optional place. Stories are visible for 24 hours. We record which stories you viewed so the creator can see their audience and so you do not see the same story as new twice.
- Comments, likes, saves, collections, follows, trips. Likes and follows are visible to other users (section 5).
- Places you tag. Place details (name, address, coordinates, opening hours, rating) come from Google Places and are stored with the post.
3.4 Messages
Messages between a reader and a creator: the text, any post or story you attach, and when it was sent, read or unsent. Messages are stored on our servers and are not end-to-end encrypted. Authorised staff can access message content when needed to investigate a report, a safety concern, a support request or a legal obligation — not routinely, and never for advertising.
3.5 Purchases
When you buy something in the app — a paid post or trip, a membership to a creator, or an itinerary — the purchase is processed by Apple (App Store) or Google (Google Play). They handle your payment details; we never receive your card number. We receive and store: what you bought, the price and currency, the platform, the store’s transaction identifier and the receipt details needed to verify the purchase, the status of the purchase (verified, refunded, revoked), and, for memberships, the subscription’s period and whether it renews.
3.6 Creator earnings and payouts
For creators, we keep a ledger of each sale: gross amount, store fee, our fee, your net amount, the currency and the state of the earning (pending, available, paid, reversed), plus each payout: amount, date, and the reference of the transfer. We do not store bank account numbers in the app; payment details for a transfer are exchanged with you directly when a payout is made.
3.7 Itineraries generated with AI
When you ask for an itinerary, we send an AI provider (Anthropic, see section 6) the information needed to build it: the destination, the creator’s public posts and tagged places about it, and what you told us — number of days, pace, interests and any notes you typed. Your name, e-mail and account identifier are not sent. Anything you write in the notes field is sent as is, so do not put personal details there that you would not want processed by the AI provider. We store your request, the resulting itinerary, and the size and cost of the AI call.
3.8 How you use the app
We record product analytics ourselves, in our own database: which screens and features you use (for example “post opened”, “itinerary purchased”), the platform and app version, and the identifiers of the content involved. For searches we record only the length of what you typed, not the words. There is no third-party analytics or advertising SDK in the app, and no advertising identifier is collected.
3.9 Your device and notifications
To send push notifications we store a push token issued for your device, the device model, the app version and its language. Notifications themselves (for example a message preview of up to 120 characters) pass through the platforms that deliver them (section 6).
3.10 Reports and moderation
If you report content or a person, we keep the report: what you reported, the reason, any details you wrote, and how it was resolved. If action is taken on your account or content, we keep a record of the action, the reason and who took it.
3.11 Bot protection at sign-in
Sign-up and sign-in include a Cloudflare Turnstile check that tells bots from people. Cloudflare processes technical signals from your device and browser view for that purpose and may set a cookie inside the sign-in screen. We receive only a pass/fail token.
3.12 What we do not collect
- Your location. The app never reads your device’s GPS. Places are attached to posts by searching for them, and the search is biased to the destination you are writing about, not to where you are.
- Your contacts, calendar contents or photo library. The photo picker shows you your photos on the device; only the ones you choose are uploaded. If you add an itinerary to your calendar, the app writes the events and checks for duplicates on your device; nothing is uploaded.
- Card numbers, bank details, or an advertising ID.
4. Why we use it, and the legal basis
| Purpose | What is used | Legal basis (GDPR art. 6) |
|---|---|---|
| Providing the service you signed up for: your account, content, feed, follows, messages, purchases, itineraries | Sections 3.1–3.7 | Performance of a contract (art. 6(1)(b)) |
| Paying creators and keeping the books | 3.5, 3.6 | Contract; legal obligation (accounting and tax law) (art. 6(1)(b), (c)) |
| Push notifications | 3.9 | Contract; you can turn each kind off in Settings and the whole thing off in your phone’s settings |
| Keeping the service safe: bot protection, blocking, reports, moderation, enforcing the Terms | 3.10, 3.11 and content | Legitimate interests — ours and other users’ — in a service that is not abused (art. 6(1)(f)); legal obligations to act on illegal content |
| Understanding how the app is used, fixing bugs, deciding what to build | 3.8 | Legitimate interest in improving the product (art. 6(1)(f)). No profiling with legal or similarly significant effects. |
| Marketing e-mails about Roamly | E-mail address | Consent — off by default; the switch is in Settings → Notifications (art. 6(1)(a)) |
| Answering you, handling rights requests, defending claims | Whatever you send us | Legitimate interests; legal obligations |
We do not sell personal data, and we do not use it for third-party advertising.
5. Who sees what
- Public: a creator’s profile, headline, free posts, stories (to followers and members, depending on the creator’s settings), the list of who liked a post, and who follows a creator.
- Members only: a members-only creator’s posts and stories are visible to their members. Non-members see the profile header and the price.
- The creator you buy from can see that you bought or subscribed (your username), so they can serve their members. Creators do not see your payment details.
- Private to you: your saves and private collections, your notification settings, your purchases, your itineraries, your itinerary requests, your reports.
- Between the two of you: messages.
- Staff: authorised staff can see account details, including e-mail addresses, and content — for support, safety and moderation. Staff access is protected by a second sign-in factor and is logged.
6. Who we share it with
We use a small number of service providers (“processors”) that act on our instructions. Some are outside the European Economic Area; where they are, the transfer is covered by the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.
| Provider | What for | What they get | Where |
|---|---|---|---|
| Supabase | Database, sign-in, file storage, real-time updates, server functions, transactional e-mails (verification, password reset) | Everything in section 3 | Hosted in the European Union |
| Expo (Expo.io) | Building and updating the app; the push notification relay | Push tokens, notification titles and previews, app version | United States |
| Apple | App Store purchases; delivering push notifications on iPhone (APNs); Apple Maps for map views on iPhone | Purchase details on their side; notification content; map requests from your device | Global (Apple’s own terms apply) |
| Google Play purchases; delivering push notifications on Android (Firebase Cloud Messaging); Google Maps on Android; Google Places for place search and details | Purchase details on their side; notification content; map and place requests (the search text and the destination it is about — not your location) | Global (Google’s own terms apply) | |
| Cloudflare | Turnstile bot protection at sign-up and sign-in | Technical device and browser signals during the check | Global |
| Anthropic | Generating itineraries | Destination, the creator’s public content, and your itinerary inputs (days, pace, interests, notes); never your identity | United States |
Beyond processors, we disclose personal data only when the law requires it (for example a valid request from an authority), to defend or establish legal claims, or — with notice where possible — if the business is transferred to a new owner who takes on this policy.
7. How long we keep it
- Your account and profile: until you delete the account. Then the profile is anonymised immediately (section 8).
- Posts, comments, collections, saves, likes, follows, trips: until you delete them or the account.
- Stories: shown for 24 hours; the record is removed within 30 days, or immediately when you delete the account. The list of who viewed a story goes with the story.
- Messages: until the sender unsends them. When an account is deleted, the messages it sent remain visible to the other participant, attributed to “Deleted account”; the deleted person’s content is otherwise gone.
- Purchase and payout records: for as long as accounting and tax law requires after the transaction. After you delete the account these records no longer reference you; the store receipt details are removed.
- Itinerary requests and itineraries: until you delete the account.
- Usage events (section 3.8): detached from your account when you delete it and kept only in aggregate form afterwards.
- Reports and moderation records: for as long as needed to act on them and to keep a record of moderation decisions; after deletion they no longer name you as the reporter.
- Push tokens: removed when you sign out or delete the account; tokens that stop working are retired.
- Technical logs held by our providers (server and delivery logs): for a short period set by each provider, typically no more than 90 days.
8. Deleting your account
You can delete your account yourself, in the app: Settings → Delete account. Deletion is immediate and cannot be undone. It removes your content and your personal details, anonymises what the law requires us to keep, and signs you out everywhere. The full list of what is deleted and what is kept, and how to ask for deletion if you cannot sign in, is on the account deletion page.
Deleting the account does not cancel a membership you bought through the App Store or Google Play — only you can, in the store. Cancel first, then delete.
9. Your rights
Under the GDPR you can ask us to:
- access the personal data we hold about you and get a copy;
- correct it — most of it you can edit yourself in Settings;
- delete it — Settings → Delete account, or ask us;
- restrict or object to processing based on our legitimate interests;
- receive the data you gave us in a portable format;
- withdraw consent where processing is based on it (marketing e-mails: the switch in Settings), without affecting what was done before.
Write to [to be completed: contactEmail] from the e-mail address on your account. We may ask you to confirm your identity. We answer within one month; if a request is complex we may take up to two more months and will tell you. Exercising these rights is free unless a request is plainly unfounded or excessive.
If you think we have not respected your rights, you can complain to a supervisory authority. In Romania that is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, Bucharest, www.dataprotection.ro. You can also complain to the authority where you live.
10. Children
Roamly is for people aged 16 or over. We do not knowingly collect data from anyone younger. If you believe a child under 16 has an account, tell us at [to be completed: contactEmail] and we will delete it.
11. Security
Data travels encrypted (TLS). On the server, every table is protected by row-level access rules, so a user can only reach what their account is allowed to see, and paid content is served only to accounts that hold the entitlement. Media that is not public is delivered through short-lived signed links. Staff access requires a second sign-in factor and is recorded. No system is perfectly secure: if a breach affects you, we will notify you and the authority as the law requires.
12. Changes to this policy
When we change this policy in a way that matters, we will tell you in the app or by e-mail before the change takes effect, and update the date at the top. Earlier versions are available on request.
13. Contact
[to be completed: operatorName], [to be completed: operatorAddress] · [to be completed: contactEmail]