Privacy Policy — Travelito

Last updated:

Travelito holds travel documents: boarding passes, tickets, hotel bookings, passports, visas, insurance. That is unusually sensitive material, so this policy is specific about what happens to it. Where a third party is involved, it is named.

Travelito is operated by Travelito LLC (“we”, “us”). If you have a question about anything here, write to support@travelito.org.


1. What we collect

1.1 Your account

The email address you sign up with, the name you give, and — if you sign in with an email and a password — a cryptographic hash of that password. We never store the password itself. If you sign in with Apple or Google instead, we receive an identifier for you from them and the email address they release; we do not receive your password. You may add a profile picture; if you do, we store it.

1.2 Documents you add, and what is inside them

When you photograph a document, import a PDF or image, forward a booking email, or connect a mailbox, we store the file and the information read out of it.

Depending on the document, that information can include:

This is the core of the service. Without it there is nothing to show you.

1.3 Connected mailboxes

If you connect Gmail, Outlook, Yahoo Mail or another mailbox over IMAP, we store the access credentials for that mailbox — an OAuth token, or the credentials you supply for IMAP — so we can look for booking confirmations. We store the content of the messages we identify as travel-related, their attachments, and a record of which messages we have already examined so we do not process them twice.

We look for travel bookings. We do not read your mailbox for any other purpose, and we do not send mail from it.

If instead you forward bookings to a personal Travelito address, we store the messages you send there and their attachments.

1.4 Your device

1.5 Measurement

We use Firebase Analytics to see which parts of the app are used, and Firebase Crashlytics to receive crash reports. We use Google’s on-device conversion measurement to understand which advertising brought someone to the app; that measurement happens on your device.

1.6 What we do not collect

We do not collect your location. We do not read your contacts, your photo library beyond the images you pick yourself, your health data, your messages, or your browsing. We take no payment in the app and hold no card details. We do not buy personal data about you from anyone.


2. Who else sees it

We do not sell your data, and we do not share it for advertising. The following parties process it on our behalf, each for one named purpose.

2.1 OpenAI — reading your documents

To read a document we send it to OpenAI (model gpt-4o-mini). A PDF is rendered to page images first; a photograph is sent as you took it. The text of a booking email is sent as text. This means the contents of the document — including any identity document numbers printed on it — are transmitted to OpenAI for the purpose of transcribing them into fields.

OpenAI processes this as our processor. It is used only to read the document, never to build a profile of you, never for advertising, and we do not permit it to be used to train models.

2.2 Mail providers

Google (Gmail), Microsoft (Outlook) and Yahoo receive only what is needed to authorise and maintain the connection you asked for. The access we request is read-only.

2.3 Infrastructure

2.4 Content shown next to a trip

2.5 People you invite

If you share a trip, the people you invite see that trip and everything in it. Nobody else can reach it: there is no public feed, no directory and no way to discover another person’s trips.

2.6 When the law requires it

We may disclose data if we are legally obliged to, and to establish or defend a legal claim. We will tell you unless we are forbidden from doing so.


3. Where it is kept, and for how long

Our servers are operated on Google Cloud. Some of the processors named above — OpenAI and Google among them — are located in the United States, so your data is transferred outside the EEA and the United Kingdom. Those transfers are made under the European Commission’s Standard Contractual Clauses.

We keep your data for as long as your account exists, because the app’s purpose is to keep your documents until you no longer want them. You can delete individual entries and documents at any time, and deleting your account removes everything (see section 5).

Backups are kept for one calendar month and then overwritten. Deleting your account removes your data from the live service immediately; copies still held in a backup disappear when that month's backup is overwritten.


4. Why we are allowed to process it (GDPR)

Identity documents are special category data under some laws. We process them because you have chosen to store them with us, and only to show them back to you.


5. Deleting your data

In the app: Account → Privacy & Security → Delete account.

That deletes your trips, tickets, boarding passes, hotel bookings, visas and other identity documents, uploaded files, expenses, notifications, trip memberships, imported mail, parse records and any stored mailbox credentials. Your account is closed and its email address released.

You can also delete your travel data on its own and keep the account, or delete individual entries and documents one at a time.

If you would rather ask us to do it, write to support@travelito.org and we will act within 30 days.


6. Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our using it, and you can ask for it in a portable form. Write to support@travelito.org.

If you are in the EEA or the UK and you think we have handled your data badly, you may complain to the data protection authority where you live. Ours, in Ukraine, is the Ukrainian Parliament Commissioner for Human Rights.


7. Security

Traffic between the app and our servers is encrypted with TLS. Passwords are stored only as hashes. Access tokens are held in the iOS Keychain on your device. Mailbox credentials are stored encrypted. Access to production systems is limited to the people who need it.

No system is perfect, and we do not claim otherwise. If a breach affects you, we will tell you and the relevant authority as the law requires.


8. Children

Travelito is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, write to support@travelito.org and we will delete it.


9. Changes

If we change this policy we will update the date at the top and, where the change matters, tell you in the app before it takes effect.


10. Contact

Travelito LLC support@travelito.org