TravelMate Privacy Policy
Last updated: 20 June 2026 Effective date: 20 June 2026
This Privacy Policy explains what personal data we collect, why, and what your rights are. It is incorporated by reference into the TravelMate Terms of Service.
We take your privacy seriously. TravelMate is offline-first: your trips, itineraries, schedules, and downloaded maps live on your device and work without an internet connection. We don't run a profile warehouse. We don't sell data. We don't show ads. We don't track you across apps or sites.
1. Data Controller
The data controller for personal data processed by TravelMate is:
Ilia Vlasov, operating as "w4app" (sole trader), domiciled in Finland. Contact: privacy@w4app.com (or support@w4app.com)
We plan to transfer the Service to w4app Oy in 2026 (expected Q3 2026). When that happens we will notify you and reissue this Policy under the new controller's name without reducing your protection — see Section 14.
We do not currently have a designated Data Protection Officer (DPO), as appointment is not mandatory under GDPR Art. 37 for an entity of our size and scope. We monitor this threshold; if our processing activities meet the DPO appointment criteria, we will appoint and disclose one.
2. What Data We Collect
Plain summary: location (only while you use a guide or discovery feature), your purchase/subscription status, crash diagnostics, a device token for notifications you turn on, and the trip text you type when you ask the AI for help. That's it. No contacts, no health data, no photos from your library, no advertising identifiers.
2.1 Location Data
TravelMate uses your device location to power nearby discovery, proactive suggestions, and the walking audio guide.
- Precise location (GPS) — used only inside an explicit, opt-in, foreground walking-guide session that you start. When you end the session, the app reverts to a coarse, low-power mode. On iOS, location authorization is requested as "While Using the App" (When In Use) only.
- Coarse / approximate location — a budgeted, kilometer-accuracy mode (significant-location-change and region/geofence monitoring) used while you explore, to surface nearby places and time-anchored nudges. This is optional and granted via the system location prompt.
How location is handled:
- Location is used to generate suggestions and guide narration for you. It is not linked to your identity and is never used for tracking, advertising, or profiling.
- Precise location is session-scoped and foreground-only. [VERIFY — LOCATION-SCOPE OPEN ITEM: the current store declarations (iOS "When In Use"; Android
ACCESS_BACKGROUND_LOCATIONnot declared) state there is no background-continuous location collection. If a background-nudge capability is ever shipped, this section, the Apple/Google data declarations, and the OS permission prompts must all be updated together before that feature goes live.] - We do not maintain a server-side location history of your movements. Precise location used by a guide session is processed to produce the guidance you requested and is not retained as a tracked trail.
2.2 Account and Subscription Data
- w4app account identifier (used to reconcile your Pro entitlement across w4app products)
- Subscription / purchase status and entitlement state (from Apple or Google via RevenueCat), including the active product (
travelmate.pro.monthly/travelmate.pro.annual) - Push-notification device token (for delivery of notifications via Apple Push Notification service (APNs) on iOS or Firebase Cloud Messaging (FCM) on Android)
2.3 Trip Content You Provide to AI Features
When you ask TravelMate to build an itinerary, narrate an audio guide, or answer a question about a place, the trip text, queries, and preferences you provide (e.g. a destination, dates, interests, or a question) are sent to our AI processor to generate the response (see Section 4). Where the app transcribes your voice into text (for a spoken query), the audio is sent transiently for transcription and is not retained on our servers after processing.
This content contains the text you choose to enter or speak. It does not include identifiers (no name, email, or account ID) at the AI-prompt layer.
2.4 Diagnostic Data
Crash and performance diagnostics, collected at the platform / billing-SDK level and via our error-monitoring tool (Sentry), to keep the app stable:
- Technical crash stack traces, device model, OS version, performance metrics
- PII-scrubbed: breadcrumbs and reports do not include your trip text or your precise location
Hosting provider and region: [VERIFY — confirm production hosting provider and data-center region of the shared w4app backend / LLM proxy before publication. If outside the EEA, add transfer safeguards in Section 4/5.]
2.5 Payment Data
We do not collect or store payment card data. Apple (App Store) and Google (Google Play) process all payments via in-app purchase. We receive only subscription/entitlement status via Apple/Google and RevenueCat.
2.6 What We Do NOT Collect
We do not collect: contacts, health & fitness data, messages or calendar, your photo library (the imagery you see is Wikimedia Commons media rendered by the app, never your own photos), browsing or search history, advertising or device identifiers (no IDFA, no Android Advertising ID), or any "sensitive" special-category data. We do not use App Tracking Transparency (ATT) because the app does not track.
3. How We Use Your Data
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Location (precise, session-scoped) | Power the walking audio guide and proactive guidance you start | Art. 6(1)(b) contract / Art. 6(1)(a) consent (device permission) |
| Location (coarse) | Nearby discovery and proactive nudges | Art. 6(1)(b) contract / Art. 6(1)(a) consent (device permission) |
| Trip text / queries / voice | Generate itineraries, audio narration, and place answers via AI | Art. 6(1)(b) contract |
| Account / entitlement data | Authenticate, reconcile Pro entitlement, support | Art. 6(1)(b) contract |
| Push device token | Deliver notifications you have enabled | Art. 6(1)(b) contract / Art. 6(1)(a) consent |
| Diagnostics (crash/performance) | Keep the Service stable, fix bugs | Art. 6(1)(f) legitimate interest |
| Payment / subscription status | Operate the subscription | Art. 6(1)(b) contract + Art. 6(1)(c) legal obligation |
We do not use your data for:
- Selling to third parties or data brokers
- Advertising or ad targeting
- Cross-app or cross-site tracking
- Training AI models (we invoke "no-training" provisions with our AI processor where available)
- Profiling for decisions with legal or similarly significant effects (no automated decision-making under Art. 22)
4. Who We Share Data With (Sub-processors)
We engage carefully selected sub-processors. They process personal data only on our instructions and only as needed to operate the Service. The table below reflects the sub-processors used in production as of the last-updated date.
| Sub-processor | Purpose | Data processed | Location | Safeguards |
|---|---|---|---|---|
| Apple Inc. | iOS app distribution, In-App Purchase, Apple Push Notification service | Account/entitlement identifiers, subscription status, push device token | Ireland (EU) / Worldwide | EU-US Data Privacy Framework |
| Google LLC | Android app distribution (Google Play), Google Play Billing, Firebase Cloud Messaging (push) | Account/entitlement identifiers, subscription status, push device token | United States / Worldwide | EU-US Data Privacy Framework + SCCs |
| OpenAI, L.L.C. | AI processing — itinerary narrative (GPT-5.5), audio guide (text-to-speech), voice transcription (Whisper) — reached via the shared w4app LLM proxy | Trip text / queries / preferences you provide; transiently, voice audio for transcription (no persistent identifiers) | United States | SCCs (2021 module 2) + API "no-training" / zero-retention provisions where available |
| RevenueCat, Inc. | Subscription / entitlement management across stores | Account identifier, subscription/entitlement state | United States | EU-US Data Privacy Framework + SCCs |
| Functional Software, Inc. (Sentry) | Crash / error monitoring | PII-scrubbed technical diagnostics (no trip text, no precise location) | United States | SCCs (2021 module 2) |
Map, place, and imagery data (NOT third-party data sharing)
TravelMate's place and map data come from self-hosted OpenStreetMap services (Overpass + Valhalla) operated by us, GPT-5.5 model knowledge, and Wikimedia Commons imagery. We use no Google Places, Google Maps, Foursquare, Yelp, Mapbox, or any other paid third-party place / imagery / map-tile vendor. No third-party place vendor receives your data. When the app fetches a public map tile or a Wikimedia image, it retrieves public content; it does not send your personal data to a place vendor for that purpose.
How the w4app LLM proxy works
The trip text you provide is sent to a shared w4app LLM proxy operated by us. The proxy injects the API key server-side (the key is never on your device) and forwards your request to OpenAI (api.openai.com). The proxy does not attach your name, email, or account ID to the AI prompt. We do not retain your prompts and responses on our servers beyond ephemeral processing.
We do not share data with sub-processors not listed above without prior notice and, where required, your consent.
5. International Data Transfers
Where personal data is transferred outside the EEA (e.g., to our AI processor, billing processor, or error-monitoring processor in the US), we rely on:
- The EU Standard Contractual Clauses (2021 module 2) with each processor
- The EU-US Data Privacy Framework where the processor is self-certified
- Additional technical measures: no identifiers attached at the AI-prompt layer; PII-scrubbing of diagnostics
You can request copies of the safeguards in place by emailing privacy@w4app.com.
6. How Long We Keep Data
| Data | Retention |
|---|---|
| On-device trips, itineraries, schedules, downloaded maps | Until you delete them or uninstall the app (stored on your device) |
| Account / entitlement data | Until account closure + 30 days |
| Subscription / billing records | 7 years (legal obligation — accounting/tax) |
| AI prompt / response content | Not retained on our servers beyond ephemeral processing |
| Location used in a guide session | Not retained as a tracked trail; processed to produce the requested guidance only |
| Diagnostic / crash data | [VERIFY — confirm Sentry retention window; default 90 days] |
| Support communications | 24 months |
When you delete your account (via the in-app account screen or the support route), server-side account deletion runs over the shared w4app identity stack. On-device data is removed when you delete it or uninstall the app. Subscription/billing records are retained for legal compliance, accessible only on legitimate request.
7. Your Rights (GDPR Articles 12–22)
If we process your personal data, you have the following rights:
| Right | What it means | How to exercise |
|---|---|---|
| Access (Art. 15) | Get a copy of your data | privacy@w4app.com |
| Rectification (Art. 16) | Correct inaccurate data | In-app for most fields, OR email |
| Erasure (Art. 17) | Have your data deleted | In-app account screen → Delete account, OR https://w4app.com/travelmate/support |
| Restriction (Art. 18) | Limit how we process your data | |
| Portability (Art. 20) | Get your data in a portable format | |
| Objection (Art. 21) | Object to certain processing | |
| Withdraw consent (Art. 7(3)) | Withdraw consent where consent is the basis (e.g., disable location in system settings) | Device settings, or by email |
| Lodge a complaint | Complain to a supervisory authority | Finnish DPA (Tietosuojavaltuutettu): https://tietosuoja.fi/en |
We respond within 30 days (extendable by 60 days for complex requests, with notice). We do not charge for these requests except where they are manifestly unfounded or excessive.
8. Children
The Service is a general-audience travel utility (age rating 4+ / PEGI 3) and is not directed at children. [VERIFY — Founder to set the minimum age: default here is "not intended for users under 16." Finland's GDPR-K digital-consent age is 13; the Terms of Service set the contracting age. Align this section with the Terms once decided.] We do not knowingly collect data from children below the applicable age threshold without verifiable parental consent. If you believe a child has provided us data, contact privacy@w4app.com and we will delete it promptly.
9. Security
We implement technical and organizational measures appropriate to the risk:
- On-device storage for trips, itineraries, schedules, and downloaded maps (offline-first)
- TLS / HTTPS for all network communications (standard OS-provided encryption)
- Server-side key injection via the w4app LLM proxy — no API keys on your device
- PII-scrubbed diagnostics — no trip text or precise location in crash breadcrumbs
- Access controls for administrative systems
- Incident response plan with 72-hour breach notification to the supervisory authority per Art. 33
Despite our efforts, no system is fully secure. In the event of a data breach affecting your personal data, we will notify you and the supervisory authority as required by law.
10. Automated Decision-Making and Profiling
The Service uses AI to generate travel suggestions, itineraries, and narration personalized to your stated preferences and location. We do not make decisions with legal or similarly significant effects about you using automated means under Art. 22 GDPR.
You can always:
- Override or ignore AI suggestions (every AI place suggestion is labeled "verify on site")
- Disable location features in device settings
- Request human review of any suggestion — email privacy@w4app.com
11. Cookies and Tracking
The mobile app does not use cookies in the web sense and does not track you.
Our marketing website (w4app.com, https://w4app.com/travelmate) may use:
- Essential cookies (session, language preference)
- Analytics cookies (only with consent — see cookie banner)
We do not use advertising cookies, cross-site tracking, the IDFA, or the Android Advertising ID. We declare our Apple Privacy Manifest accordingly and do not declare the AD_ID permission on Android.
12. Store Privacy Disclosures (Apple App Privacy + Google Play Data safety)
This Privacy Policy is the canonical source. The Apple App Privacy survey (App Store Connect) and the Google Play Data safety form must be kept in exact sync with it and with the sub-processor table in Section 4.
Apple App Privacy — declared:
- Data Linked to You: Purchases (purchase history / subscription state)
- Data Not Linked to You: Precise Location, Coarse Location, Diagnostics (crash/performance)
- Data Used to Track You: None
Google Play Data safety — declared:
- Collected (none shared with third parties, none for tracking): Precise Location, Approximate Location, Financial info › Purchase history, App performance › Crash logs / Diagnostics
- Data encrypted in transit: Yes
- Data deletion path: Yes (in-app account screen + https://w4app.com/travelmate/support)
- Advertising ID requested: No
[VERIFY before submission: that the App Store Connect App Privacy survey and Play Console Data safety form match this Section and Section 4 exactly, including the AI/error-monitoring processors. Note for reviewers: the store nutrition labels disclose declared-data only; this hosted policy is the full GDPR Art. 13/14 disclosure and is the document referenced by the mandatory Privacy Policy URL field in both stores.]
13. Changes to This Policy
We may update this Privacy Policy. For material changes, we will notify you in-app and (if you have provided an email) by email at least 30 days before the change takes effect, and make the prior version available on request. Continued use after the effective date constitutes acceptance.
14. Change of Controller
The data controller is currently the toiminimi listed in Section 1. We plan to transfer the Service to w4app Oy in 2026 (expected Q3 2026). When this transfer occurs:
- You will be notified at least 30 days in advance via in-app message
- All your data and consent records will transfer to the new controller
- This Privacy Policy will be reissued under the new controller's name
- Your rights and the level of protection will not be reduced
The legal basis for the transfer is GDPR Art. 6(1)(b) and (f) — necessity for the contract and the legitimate interest of corporate reorganization that does not adversely affect you.
15. Contact
- General privacy questions: privacy@w4app.com
- Subject access / data export / deletion requests: privacy@w4app.com or https://w4app.com/travelmate/support
- Complaints: Finnish Data Protection Ombudsman, https://tietosuoja.fi/en (or your local EU DPA)
Hosted at: https://w4app.com/travelmate/privacy (the URL referenced in App Store Connect and Google Play Console).
Document control
- v1.0 (2026-06-20) — Published. Founder sign-off granted and licensed-attorney review waived for v1 by founder directive (ESC-044, extended to all w4app products 2026-06-20; licensed FI attorney + GDPR-specialist review deferred to Aug 2026 per ESC-024). Data controller is the natural person Ilia Vlasov operating as "w4app" (sole trader); transfer to w4app Oy planned Q3 2026 (Section 14). Drafted by Legal agent (Spark cycle 551) for DB task #545 (TM-LEGAL-01), grounded in the verified TravelMate data surface (travelmate-ios
app-privacy.json, travelmate-androiddata-safety.json,travelmate-product-scope.md); house style mirrored from the HealthMate / CareerMate Privacy v1 templates. TravelMate collects no health or special-category data; precise location is foreground/session-scoped only (no background-continuous collection). Founder-decision items (SCC execution with US sub-processors, hosting-region confirm, children's minimum-age threshold, App Store/Play declaration cross-check) tracked in the document front-matterreview_requiredlist.