Privacy Policy (Aviso de Privacidad Integral)
This comprehensive privacy notice (Aviso de Privacidad Integral) is issued in compliance with Mexico’s current Ley Federal de Protección de Datos Personales en Posesión de los Particulares (the “LFPDPPP”, published in the Official Gazette of the Federation on March 20, 2025) and its applicable implementing provisions, and explains how personal data is processed when you use the Traveluns mobile app and the website traveluns.com (together, the “Service”). It is additionally written to satisfy the EU/UK General Data Protection Regulation (GDPR), the Swiss FADP, the California Consumer Privacy Act (CCPA/CPRA) and Japan’s APPI, as well as the privacy-disclosure requirements of the Apple App Store and Google Play. The Service is not directed at, or offered in, South Korea, Russia or mainland China. The Spanish version governs; the English, German and French versions are courtesy translations.
1. Identity and Address of the Controller (Responsable)
The party responsible for the processing of your personal data (the “Controller” or “Operator”) is:
Kevin Meda Rodriguez, an individual (persona física) of Mexican nationality
Address: Paseo de los Fresnos 182, Col. Paseos de Taxqueña, C.P. 04250, Alcaldía Coyoacán, Ciudad de México, Mexico
Email: contact@traveluns.com
Kevin Meda Rodriguez is the sole person responsible for the treatment of personal data collected through the Service. We have not appointed a Data Protection Officer (not required at our current scale). Direct all privacy inquiries to the email above.
2. What Data We Process, Why & on What Legal Basis
| Category | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Account | Email, username, first/last name, date of birth, home country/city, password (stored only as a salted hash), avatar photo, preferred language/currency/units | Create and operate your account; verify you are 18+; personalize content | Art. 6(1)(b) contract; age check: Art. 6(1)(c) legal obligation |
| Technical device data | Device model, operating system and version, app version, device or installation identifiers used by integrated SDKs, IP address, user-agent | Operate the app, diagnose errors, security and abuse prevention | Art. 6(1)(b)/(f) |
| Trips & planning | Destinations, dates, itineraries, notes, reservations, tracked flights, preferences you enter as part of a trip (e.g. interests or dietary requirements for that trip), trip members | Provide the planning features you use | Art. 6(1)(b) contract |
| Files & receipts | Files you upload (tickets, confirmations, receipts, photos) | Store and display them in your trips; malware scanning | Art. 6(1)(b); scanning: Art. 6(1)(f) legitimate interest (security) |
| Travel memories & photos | Photos and clips you add to your travel log, including the capture time and location embedded in a photo’s metadata (EXIF), which we read and store to place it on your journey map and timeline. The copy shown to you and others is stripped of that metadata. Photos and videos that can become visible to others are also checked by an automated content-safety review | Build your travel log, journey map and recap features; keep the Service free of prohibited content | Art. 6(1)(b); safety review: Art. 6(1)(f) legitimate interest |
| Imported reservation emails | If you forward a booking confirmation to our import address (or link an email address for that purpose): the email, its attachments (PDFs, screenshots) and the reservation details extracted from it, including passenger names it contains | Turn the confirmation into a reservation in your trip. Extraction is performed by the AI provider named in Section 6; the original email is kept for 90 days so you can re-run or correct an import, then deleted | Art. 6(1)(b) contract |
| Secure vault | End-to-end encrypted files and metadata | Encrypted storage. Zero-knowledge: we store only ciphertext and cannot read it | Art. 6(1)(b) |
| Expenses | Expense amounts, splits, group members, receipt images | Expense-splitting features | Art. 6(1)(b) |
| AI features | Your chat messages to the travel assistant, trip parameters, and content needed to generate itineraries/tips/translations | Generate AI content you request (processed by the AI providers in Section 6) | Art. 6(1)(b) |
| Device location | Precise or approximate device location (only if you grant the OS permission), processed via Google Maps/Google Places services and the app’s map components | Solely for the app’s core functionality: showing your position on maps, suggesting your departure city, and showing nearby places and content. Precise location is not stored on our servers and is never sold to third parties. When you tap a travel-deal, discount or tour link we record the interaction with an approximate location, rounded to roughly 1 km, to measure relevance | Art. 6(1)(a) consent (revocable in OS settings) |
| Social profile & sharing | Your public profile elements (username, display name, avatar, badges, subscription tier), your follower/friend connections, your visibility settings, the countries/stats/photos/trips you choose to share, and your optional profile card | Operate the social features described in Section 17, according to the audience settings you control | Art. 6(1)(b) contract |
| Install attribution | Only with your analytics consent: a store-provided install token (Apple Search Ads) or install referrer (Google Play) and the campaign click identifier from the ad or link that brought you here | Measure which of our own campaigns lead to installs. We buy no third-party advertising inside the app and build no advertising profile of you | Art. 6(1)(a) consent |
| Security & audit logs | IP address, device/user-agent, timestamps for logins and security-relevant changes (email/username changes), terms acceptances | Security, abuse and fraud prevention, rate limiting, legal evidence of consent | Art. 6(1)(f) legitimate interest; Art. 6(1)(c) |
| Passport country | The country whose passport you say you travel on, if you ask us for entry requirements | Work out the visa and entry rules that apply to you for a destination | Consent (you choose to ask) |
| Subscription status | App-store transaction identifiers and entitlement status (no card data — payments are handled by Apple or Google) | Activate and verify First Class | Art. 6(1)(b) |
| Notifications | Push token (if you enable push), notification preferences | Send the notifications you opted into (e.g. flight alerts) | Art. 6(1)(a)/(b) |
| Emails | Email address, delivery events for transactional mail (verification codes, password reset, account activity); product news and offers according to your email settings | Operate the account; optional product news and offers | Art. 6(1)(b); product news and offers to existing account holders: Art. 6(1)(f) legitimate interest, read with the ePrivacy Directive Art. 13(2) exception, with an opt-out in every message |
| Support & feedback | Messages you send us, feedback text | Respond to you; improve the Service | Art. 6(1)(b)/(f) |
For LFPDPPP purposes, the processing described rests on the consent you give by accepting this notice and, where applicable, on the exceptions provided by the LFPDPPP itself (data necessary for the existence, maintenance and performance of the legal relationship between you and the Controller). The categories above correspond to the privacy declarations published on the app’s store listings in the Apple App Store (“App Privacy” / privacy nutrition labels) and Google Play (“Data safety”).
We do not use your data for automated decision-making with legal or similarly significant effects, and we do not process special categories of data on purpose (do not upload health or similar sensitive data outside the encrypted vault).
3. What We Deliberately Do Not Do
- We do not sell personal data, we do not “share” it for cross-context behavioral advertising within the meaning of the CCPA/CPRA, and your location data is never sold to third parties.
- The app shows no advertising and contains no advertising SDK. Apart from Sentry (crash diagnostics, Section 6) and PostHog (opt-in analytics and session replay, Sections 4 and 6), we run no third-party analytics or tracking SDKs inside the mobile app, and both can be switched off.
- We do not store your precise GPS coordinates on our servers (deal, discount and tour link taps record only an approximate location rounded to roughly 1 km — Section 2; photo EXIF locations are part of the content you choose to upload — Section 2).
- We do not read your encrypted vault — technically impossible without your passphrase.
4. Purposes of Processing
Primary purposes (necessary for the legal relationship that gives rise to the processing):
- creating, authenticating, operating and maintaining your account, including verifying you are an adult;
- providing the Service features you use (trip planning, itineraries, reservations, expenses, files, vault, flight tracking, weather, AI content you request);
- managing your First Class subscription and verifying your entitlements;
- operating the referral program, including granting and safeguarding referral credits (Section 13 describes the anti-fraud ledger);
- sending indispensable transactional communications (verification codes, password resets, security and account notices) and the notifications you enable;
- securing the Service, preventing fraud and abuse, and preserving evidence of consent;
- complying with applicable legal obligations.
Secondary purposes (not necessary for the legal relationship):
- sending our own product news and promotional communications about the Service. They are off unless you turn them on — in the app’s opt-in prompt or under Settings → Notifications — go only to people who already hold an account, concern only our own similar products, and never carry third-party advertising. We rely on our legitimate interest in telling our own users about our own service (Art. 6(1)(f), read with the ePrivacy Directive Art. 13(2) exception for existing customers); you can refuse at the moment we collect your address and in every message we send;
- measuring which of our own advertising campaigns lead to installs (install attribution, Section 2) — only with your analytics consent;
- internal, first-party analytics to improve the product, collected at two levels. Anonymous measurement runs for everyone: counts of which screens and features are opened and whether an action succeeded. Nothing is stored on your device for it. So that a day’s devices can be counted rather than double-counted, our server derives a short-lived key from the technical details your request already carries (network address, app version, device family); that key is computed with a secret that is replaced every 24 hours and then destroyed, so it cannot connect one day’s activity to the next and cannot be traced back to you or to any account. The network address itself is used to compute the key and discarded — it is never stored. Identified analytics — the same events tied to a durable identifier and, once you sign in, to your account — runs only if you switch it on, and you can switch it off again at any time in Settings (app) or at traveluns.com/privacy-settings (web). Switching it off also deletes the identified events already collected for you. Identified analytics is processed for us by PostHog (Section 6) and may include session replay: some or all of consenting users’ sessions are recorded as a screen-interaction sequence. What may remain readable: the app’s own fixed interface (such as buttons, menus, headings, the onboarding pages and the plans and prices on the upgrade screen), catalog content we publish for everyone (such as city guides), simple non-identifying numbers the app shows beside them (such as how many trips you have) and — only if you agreed to this version of this notice — the trip you are planning: its destinations, dates, itinerary items and the options you pick in the trip form, and our own stock photos of destinations. Masked before anything leaves your device: everything you type, other people and their names or pictures, your own photos, messages, notes, spending, bookings and documents, your home city, and anything about dietary needs, accessibility or special occasions. Recording is suspended entirely on sensitive screens (sign-in, sign-up, verification codes, profile, account deletion, the document vault, the AI guide chat and expenses) and while the app is in the background. Replays exist so we can see where the app confuses people, are visible only to the Operator, and are deleted when you withdraw consent or delete your account. We never use either level for advertising, and we never sell or share it. Some information you volunteer separately, such as an account-deletion reason, is also used for product analysis.
- aggregated trip insights: to improve suggestions for everyone, we study city-wide trends across trips — for example, which places and activities are most often added in a given city. This works only on counts pooled across many travellers, with no names, accounts, notes, messages or other identifiers; results are never used to profile, target or make decisions about you, and they are never sold or shared. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in improving the Service. You can object at any time by writing to contact@traveluns.com, and your trips will then be left out of these counts;
You may refuse processing for secondary purposes at any time and without affecting the Service, by any of these routes: the unsubscribe link in the footer of any such email, which needs no password and takes effect immediately; the page at traveluns.com/unsubscribe; the notification settings in the app (Account → Notifications), where each category can be switched off separately for email and for push; or an email to contact@traveluns.com with the subject “Limitación de finalidades secundarias” (limitation of secondary purposes). Opting out is as easy as not opting out, it is recorded with the date, and it never affects the transactional messages your account needs — verification codes, password resets and security notices always reach you.
5. Sensitive Personal Data
We do not collect or request sensitive personal data within the meaning of the LFPDPPP (racial or ethnic origin, health status, religious beliefs, union membership, political opinions, sexual preference, among others). Please do not include such information in free-text fields; if you need to store documents containing delicate information, use the zero-knowledge encrypted vault.
6. Processors & Recipients
We use the following service providers (processors within the meaning of the LFPDPPP and GDPR or, in some cases, independent controllers) to run the Service:
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Google Cloud (Google Ireland/LLC) | Hosting: servers, database, file storage, task queues (region europe-west1, Belgium) | All server-side data | EU (hosting); Google LLC US support |
| Google (Gemini / Vertex AI) | AI content generation (itineraries, chat, tips, translations, deals), extraction of forwarded reservation emails, and automated content-safety review of photos and videos that can become visible to others | Chat messages, trip parameters, content to translate, forwarded reservation emails and their attachments, uploaded photos/video frames submitted for safety review | Global (Google infrastructure; see Section 7) |
| OpenAI, xAI | Further AI providers for text-generation tasks. Neither is a primary: every request goes to Google first. OpenAI is the first fallback when Google fails, and xAI (Grok) is the last-resort fallback after OpenAI | The same text prompts (no account identifiers sent; never your emails, photos or videos) | US |
| Langfuse (Langfuse GmbH) | Technical logging of AI requests (quality & cost monitoring); prompts/responses are recorded | AI inputs/outputs, pseudonymous identifiers | EU |
| Google Maps / Google Places / Distance Matrix | Place search, details, photos, travel times, map features | Search terms, place queries, queried coordinates | US/global |
| Mapbox | Maps and routing | Map tile requests, route coordinates | US |
| Open-Meteo | Weather forecasts | Destination coordinates (no personal identifiers) | EU |
| AeroDataBox (via MagicAPI) | Flight status for flights you track | Flight numbers, dates | US/EU |
| MailerSend | Transactional and (opt-in) product emails | Email address, name, delivery events | EU/US |
| Firebase Cloud Messaging (Google) | Push notifications (if enabled) | Push token, notification payloads | US/global |
| Apple / Google Play | App distribution, in-app subscription billing | Purchase/transaction data (they are independent controllers). When you ask the store for a refund, the store may ask us about the purchase; we answer with delivery status and how much of the paid period had elapsed — never your content — to help it decide | US/global |
| PostHog (PostHog, Inc. — EU cloud) | Identified product analytics and session replay, only for users who opt in (Section 4) | Usage events with a pseudonymous identifier or your account id, allowlisted properties, masked session replays; IP addresses are not stored | EU |
| Sentry (Functional Software, Inc.) | Crash and error diagnostics for the app and website | Device/OS data, app version, stack traces and technical state at the time of an error (no chat or trip content is intentionally included; email addresses are redacted and IP addresses are not stored in the clear) | EU/US |
| Operational alerting (Telegram, Slack, GitHub) | Notifying the Operator of service errors and incidents | Technical error data only: request identifiers, counts, hashed or pseudonymous references — no names, emails or content | US/global |
| Cloudflare | Content delivery (images, website) | IP address, requested URLs | Global |
| VirusTotal (Google) / self-hosted ClamAV | Malware scanning of uploads | File hashes / file content of uploads (not vault files) | US / EU |
| exchangerate-api.com | Currency rates | None (generic rate queries) | US |
| Upstash (Upstash, Inc.) | Redis cache and queues: short-lived sessions, rate limits, one-time verification codes (always hashed) and temporary job data | Pseudonymous identifiers, the email address a pending sign-in or verification belongs to, IP addresses used for rate limiting, and hashed codes. These entries are short-lived and expire in minutes | EU |
| Sign in with Apple (Apple), Google Sign-In (Google) | Provider sign-in, when you choose that button | The provider’s user identifier, your email (or Apple’s private relay address) and your name if the provider sends it. Each is an independent controller of the account you hold with them | US/global |
| Pixabay, Pexels | Catalogue destination photography | None: generic image queries by city or place, carrying nothing of yours | EU/US |
When you open a booking partner’s site or app through a link in the Service (e.g. Expedia, Trip.com, Check24, GetYourGuide, Viator, Klook, Tiqets, Civitatis), that partner processes your data as an independent controller under its own privacy policy. Outbound links may carry an affiliate identifier so the partner can attribute the referral; we do not receive your booking details from partners.
7. International Transfers
Our servers and databases are in the European Union (Belgium). Some providers above process data in the United States or globally; in particular, AI requests are processed in the United States in several cases: Google’s Gemini models may be served from Google data centers outside the EU wherever capacity is available, and OpenAI and xAI are US providers. The transfers to processors described in this notice are necessary to operate the Service and are made as permitted under the LFPDPPP; by providing your data and accepting this notice you consent to those transfers. Where data leaves the EU/UK/Switzerland, we rely on European Commission adequacy decisions (including the EU–US Data Privacy Framework for certified providers) and/or Standard Contractual Clauses with supplementary measures. The Controller, based in Mexico, accesses the systems for administration; the LFPDPPP and our contractual safeguards apply to that access.
8. Google Maps and Google Places
The Service’s map, place-search and geographic features use Google Maps and Google Places services. By using these features you are additionally bound by the Google Maps/Google Earth Additional Terms of Service and the Google Privacy Policy. Google may receive the place queries and coordinates needed to answer your searches; Google acts under its own terms. Google Maps, Google Places and other Google marks are the property of Google LLC.
9. Links and Redirections to Third-Party Sites
The Service contains links that redirect you to external third-party websites and platforms that are entirely outside the Controller’s control. When you leave the Service through such a link, this privacy notice ceases to apply: the processing of your data is governed exclusively by the privacy notice or policy of the external site concerned. We recommend reading the privacy policies of every third-party site you visit. The Controller assumes no responsibility for the privacy practices of such third parties.
10. ARCO Rights (Mexico)
You or your legal representative may at any time exercise the rights of Access, Rectification, Cancellation and Objection (ARCO rights) provided by the LFPDPPP. Procedure:
- Send a request by email to contact@traveluns.com with the subject “Solicitud ARCO”.
- Under the LFPDPPP the request must contain: (a) your full name and a means of communicating the response to you (email); (b) a copy of a document proving your identity (INE/IFE, passport) or, where applicable, the legal representation of the person acting on your behalf; (c) a clear and precise description of the personal data concerned and of the right you wish to exercise; and (d) any element that helps locate the data (e.g. the email you registered with).
- Deadlines: we will communicate our determination within a maximum of 20 business days from receipt of the request; if granted, it will be carried out within the following 15 business days. These periods may be extended once for an equal period where justified.
- Exercising ARCO rights is free of charge; only justified shipping costs or the cost of reproduction in copies or other formats may be charged.
- If the response does not satisfy you or you do not receive it in time, you may initiate a rights-protection procedure before Mexico’s Secretaría Anticorrupción y Buen Gobierno — the data-protection guarantor authority that replaced INAI as of March 2025 — via www.gob.mx/buengobierno, within the following 15 business days.
11. Rights in Other Jurisdictions
EU/UK/Switzerland (GDPR/FADP): you have the right of access, rectification, erasure, restriction, data portability, and objection (including to legitimate-interest processing), and the right to withdraw consent at any time with future effect. You may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): you have the rights to know, delete, correct, opt out, and to non-discrimination. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information beyond what is necessary to provide the Service (we do not collect precise geolocation as defined by the CPRA — stored locations are rounded to roughly 1 km), and we do not knowingly share the personal information of consumers under 16.
Japan (APPI): you have equivalent rights of access, correction, deletion, and objection/revocation under your local law.
How to exercise: most rights are self-service in the app (edit profile; Account → Delete Account; a machine-readable copy of everything we hold on you under Settings → Your data → Request my data, delivered within minutes as a ZIP archive holding data.json — the complete machine-readable copy — and a plain-language README that names every section it contains and how many records each one holds; available for 7 days). For anything else email contact@traveluns.com; we will verify your identity and respond within the statutory deadline (one month under GDPR, extendable as permitted).
12. Revocation of Consent and Limitation of Use or Disclosure
You may revoke the consent you have given for the processing of your personal data, and limit the use or disclosure of that data, by emailing contact@traveluns.com with the subject “Revocación de consentimiento” (revocation of consent) or “Limitación de uso” (limitation of use), following the same procedure and deadlines as Section 10. Note that revocation has no retroactive effect and that, where the processing is necessary to provide the Service, revocation may mean we can no longer provide it to you (in which case you may delete your account as described in Section 13). The location permission can be revoked at any time directly in your operating-system settings, with no request needed.
13. Data Retention and Deleting Your Account
How to delete your account: in the app, go to Account → Delete Account, confirm with your password and the verification code emailed to you — or, if you signed in with Apple or Google and have no password, with a fresh sign-in at that provider — and the request is executed immediately. Alternatively, you may request deletion by emailing contact@traveluns.com (we will verify your identity). This path satisfies the account-deletion requirement of the Apple App Store and Google Play guidelines.
- What is irreversibly anonymized: deleting your account permanently and irreversibly scrubs your personally-identifying information — name, email address, profile photo, date of birth, and home city/state — which can never be recovered, by us or anyone else. Your password is invalidated and your access is revoked immediately. Your email address is freed for reuse (for example, to create a new, unrelated account) as soon as deletion completes.
- What is fully erased, not just anonymized: your AI travel-assistant conversation history (including the copy held by our AI-tracing provider), the contents of your encrypted document vault and its key material, your travel memories, photos, clips and logbook, your notes, uploaded files and imported reservation emails, reservations only you could see, your linked email addresses, identity-change audit logs, and your devices’ push-notification registrations. Stored files are deleted within minutes of the request completing.
- What happens to trips you own: during deletion we list every trip you are the only owner of and that other people are on, and ask you to choose. Each one is either transferred to a member you name, who becomes its owner and keeps it working for everyone, or — if you name nobody — permanently deleted for every person on it, along with its itinerary, reservations and files. Trips only you could see are deleted with the rest of your private data. A trip that already has a second owner simply carries on without you, and is not raised.
- What is kept, re-attributed to “Deleted User”: content inside trips that survive you — activities, notes, bookings and files you added to a trip you transferred or were a member of — is retained under an anonymized placeholder identity that can no longer be linked back to you, so those trips keep working for the people still on them and we retain aggregate, non-identifying product analytics. Expense reports shared with at least one other registered user are kept for them, detached from any deleted trip, with your name replaced by the placeholder; a report whose only other names are guests you typed in yourself is deleted with the trip.
- Other survivors: (a) your stated deletion reason, kept without your email address, for product analytics; (b) records of your terms/privacy acceptances and email-consent choices, reduced to your anonymized account id, the document version and the time, plus — for terms/privacy acceptances only — an irreversible keyed hash (HMAC) of the email address you signed up with, so that, should a legal claim ever arise, we can show that this address accepted a given version; kept as legal evidence and erased five years after your account is deleted, or sooner once no longer needed; (c) purchase and subscription records, as tax and refund handling require; (d) one anonymous statistical summary of your trips — destination, month, length, party type, budget band, pace, style, the interests and transport options chosen, how many people the trip was shared with, and a count of stops by category — that contains no name, email, identifier, date finer than a month or free text, and therefore cannot identify you; and (e) short-lived encrypted backups, rotated within 7 days — a backup is never used to bring deleted data back into service, and if one is ever restored, every deletion made after it is re-applied from a ledger that holds only anonymized account ids.
- An anti-fraud ledger of irreversible fingerprints: to stop one person collecting a referral welcome bonus over and over by deleting an account and signing up again, we keep a keyed hash (HMAC) of your sign-up email address, of your Apple or Google sign-in identifier, and of your device identifier. This ledger holds only those hashes — no name, no address, no identifier in the clear, and no link to your account, your trips or any profile. It cannot be read back to recover the original values, and it cannot be used to identify you or to build a picture of you; all it can answer is whether some fingerprint of a given kind has created an account before. Entries are deleted 24 months after they were last seen. The copy of that email hash that is attached to your account is erased when you delete it. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in preventing fraud; retention against erasure is permitted by Art. 17(3). You may still create a new account with the same email address (see above); what the ledger prevents is claiming the same promotional credit twice.
- Deactivation (as opposed to deletion) keeps your own data unchanged so you can return — your private trips, travel log and badges are all still there when you log back in. It is not, however, a quieter version of staying: deactivating removes you from every trip and expense report you share with other people and hides you from search, profiles and member lists, so it asks the same question about trips you solely own and share, with the same two outcomes as above. Trips you leave are not restored if you come back. You can request full deletion at any time instead.
- Standing retention periods while your account exists: raw analytics events are deleted after 180 days (aggregated counts are kept longer without identifiers); AI request logs at our tracing provider (Langfuse) are deleted after 90 days; forwarded reservation emails after 90 days; data exports after 7 days; the anti-fraud ledger entries 24 months after last seen; administrative audit logs (records of changes made to accounts by the Operator or by you, kept for security and accountability) for as long as the account context requires. Email delivery logs and server logs are retained for short technical periods.
- Why anonymization satisfies your right to erasure: once data has been irreversibly stripped of everything that could identify you, it is no longer “personal data” under GDPR (Art. 4(1); Recital 26) — anonymizing it is a recognized way of satisfying the right to erasure (Art. 17) once genuine re-identification is impossible. The same principle underlies the Apple/Google account-deletion requirements: what they require is that you can no longer be identified or contacted through the Service, not that every database record referencing your former account be physically removed.
14. Security
Measures include: TLS for all transport (with certificate pinning in the app), bcrypt password hashing, encrypted storage, EU residency for stored data (Section 7), strict access controls, rate limiting and brute-force lockout, malware scanning of uploads via an isolated quarantine pipeline, append-only audit logs, and a zero-knowledge encrypted vault (AES-256-GCM, argon2id key derivation on your device). No internet service is 100% secure; keep your password unique and confidential.
15. Children
The Service is for adults (18+). Before anything is generated — including as a guest, without an account — you must confirm that you are at least 18, and we record when you did. Where a date of birth is given at signup, the signup flow rejects dates under 18. We do not knowingly process children’s data. If you believe a minor has an account or a guest session, contact us and we will delete it.
16. Using Traveluns Without an Account (Guest Sessions)
You can plan one trip without creating an account. When you tick the age and terms confirmation on the New Trip screen, we create a temporary guest profile — not an account — so that the itinerary can be generated. What this involves:
- A device identifier generated on your device and held in its secure keychain. We store only a keyed hash (HMAC) of it, never the identifier itself. It exists to enforce one free trip per device and to limit abuse, and it persists if you reinstall the app. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in protecting a costly free feature from abuse.
- The trip details you enter, and the messages you send if you use the AI Guide. These go to the AI providers listed in Section 6 to build your itinerary, on the same terms as for account holders. Legal basis: Art. 6(1)(b) GDPR — providing the service you asked for.
- A keyed hash of the IP address the guest session was created from, kept to investigate abuse. We do not store the address itself.
As a guest we do not ask for your name, email address or date of birth. You confirm that you are 18 or older (Section 15); no birth date is collected at that point.
Retention. Guest data is deleted automatically 30 days after the guest session is created — the temporary profile, the trip it generated and the device ledger entry. To delete it sooner, open Account → Delete my trip and data in the app, or write to contact@traveluns.com. Deleting also frees the device to plan a new trip.
If you create an account from a guest session, the trip carries over and the temporary profile becomes your account. The 30-day guest deletion then no longer applies and Section 13 governs instead.
17. Social Features, Profiles & Sharing with Other Users
Traveluns includes optional social features. There is no public feed: nothing you create is visible to the general internet, and every audience below is limited to signed-in Traveluns users.
- Your audience controls. Three settings — Profile (flags, world map, stats, travel dates, badges), Photos (galleries, covers, full-size avatar) and Trips (trips and diaries) — each set to Private, Friends, Followers or Everyone. “Everyone” means any signed-in user, including people who find you in search. You can change each setting at any time in the app.
- Defaults. Unless you change them, your Profile group is visible to your approved followers, and your Photos and Trips groups to your friends (mutual connections). You appear in people search by default; switch “discoverable” off to be found only through links you share. People you travel with on a shared trip can see your Profile group like a friend would.
- Followers and friends come only from connections you approve: someone follows you when you accept their request or they use an invitation link you shared; until you approve, they see only your name and photo.
- What members of a shared trip see about each other: username, display name, avatar, subscription tier, badges, and each member’s access level on that trip — plus everything added to the shared trip itself (itinerary, notes, files, expenses, polls, according to per-member access settings). The trip’s owner can also see the email address you joined with, which is needed to manage invitations.
- Invitations. When you invite someone by email, we store that address to deliver and track the invitation. When you join through a link, the trip owner sees your name and photo before approving you.
- Profile card. If you create a shareable profile card (showing, at your choice, your name or username, avatar, tier, flags, visited states or passport stamps with years), the card image is stored on our servers and shown to the audience your Profile setting allows. You can change or remove it at any time.
- Referral program. When you share a referral code and someone redeems it, each of you sees only what the product shows (e.g. that a reward was earned) — the other person’s account details are not shared. Anti-fraud processing for referrals is described in Section 13.
- Blocking and reporting. You can block any user (they can no longer see your content or interact with you) and report users or content to us for review.
18. Cookies, Analytics & the Website
The mobile app shows no advertising and contains no advertising SDK. It does not use cookies or third-party trackers; our product analytics are first-party (Section 4), assisted by the opt-in providers in Section 6, and can be switched off.
The website traveluns.com (including the web version of the app) shows no ads and sets no advertising or tracking cookies. It does use your browser’s local storage for your signed-in session and for your privacy choices. A first-party analytics identifier is written there only after you switch identified analytics on; until then, and again if you switch it back off, no analytics identifier and no session record is stored on your device at all. It also loads a crash and error reporter (Sentry, Section 6) and makes requests to the map and image providers in Section 6, which receive your IP address when serving content. Product analytics and crash diagnostics have separate switches at traveluns.com/privacy-settings, and the app has the same two under Settings. Product analytics is off until you turn it on; crash diagnostics is on by default and can be turned off. If you are signed in, your analytics choice is stored against your account as well, so it applies on every device and survives a reinstall. If you arrive at the website through one of our campaign links, the campaign tags carried by the link (utm parameters or a click identifier) are kept only for your current visit and discarded — unless you enable identified analytics, in which case they may be stored to attribute your sign-up to the campaign. We use no third-party advertising or cross-site tracking network on the website. If that changes, we will add a consent banner first.
What we store on your device, and the map. The keys we may write are your signed-in session, your privacy choices (pmt24_analytics_consent, pmt24_diagnostics_enabled), a first-party analytics identifier (pmt24_anon_id, only after you turn identified analytics on) and, briefly, up to three codes carried across a sign-up: pmt24_pending_invite_code, pmt24_pending_follow_code and pmt24_pending_referral_code. They are removed as soon as they are used, and when you delete or deactivate your account on that device. Separately, the mapping library we use (Mapbox, Section 6) sends its own usage telemetry — map interaction events tied to an identifier Mapbox generates, not to your account. The versions we ship offer no switch to turn that off, so we name it here rather than leave it unsaid.
19. Changes to This Notice
We will update this notice as the Service evolves. The version and effective date appear at the top; any change will be published on this page (traveluns.com/privacy) and material changes will be announced in the app, where you will be asked to confirm the new version. Records of the version you accepted are kept.
20. Contact
contact@traveluns.com — Kevin Meda Rodriguez, Alcaldía Coyoacán, Ciudad de México, Mexico (the Controller’s full address appears in Section 1 and is additionally provided on request for ARCO purposes and official notifications).