Roam Wyld's use of information received from Google APIs (including Gmail) adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Account
Your email address, used only to sign in and identify your data.
Trips & Bookings
Trip names, destinations, travel dates, and booking details (flight numbers, hotel names, confirmation codes, activities) that you enter manually or import via Gmail.
Travel Profile
Your passport nationality and home currency, stored in your profile to personalize entry requirements, visa information, and currency conversion. You may update or remove this at any time in Profile settings.
Insurance Details (optional)
If you add travel insurance to a trip, we store the provider name, policy number, coverage dates, and emergency contact number you enter. This information is stored on your device and on our servers and is never shared with insurance providers or third parties.
Travel Companions (optional)
If you share a trip with another person, we store their display name and email address for the purpose of sending them a trip invitation. By inviting someone, you confirm you have their permission to share their information with Roam Wyld. If they decline the invitation, their email address is deleted from our records.
Once someone accepts an invitation to a shared trip, they can see that trip's bookings marked "Visible to both of us" — including confirmation numbers and costs — and you can see theirs. Either person can mark a booking "Just me" to keep it visible only to themselves. This visibility is limited to people you've explicitly invited and who've accepted; it is never shared more broadly.
If you or your travel partner leave a shared trip, or are removed from one, access to the other person's data is revoked immediately, and any of their booking data already downloaded to your device is deleted from local storage — it isn't retained after access ends.
Gmail (optional)
If you use Gmail Import, Roam Wyld requests read-only access to your Gmail account to find travel confirmation emails. We scan subject lines and senders of up to 300 emails matching travel keywords, then retrieve the body text (up to 1,500 characters) of the top-matching emails to extract booking details. We do not store your Gmail password or credentials. Access can be revoked at any time at myaccount.google.com/permissions.
Usage Analytics
Feature usage events collected via PostHog, linked to an anonymous user identifier. Events may include which features you use and general trip attributes (e.g., number of destinations). We do not collect your name, email, or other identifying information in analytics events.
Error Reports
Crash and error logs collected via Sentry to help us identify and fix bugs. Logs do not include your trip data or personal information.
We apply the safeguards below to all personal data, with particular care for sensitive data — including your passport nationality, travel insurance policy details, trip itineraries, travel companions' contact details, and any Gmail content processed during import.
Encryption in transit
All data exchanged between the app, our backend, and every third-party service is encrypted in transit using HTTPS with TLS 1.2 or higher. This includes every request to our Supabase backend, to Google’s Gmail API, and to Anthropic’s Claude API.
Encryption at rest
Data stored on our Supabase servers is encrypted at rest with AES-256. Data cached on your device is held in the operating system’s app-private storage, which is encrypted by the device.
Credential storage
Your Google OAuth access token is stored only on your device, in the platform secure keystore (Apple Keychain on iOS, Android Keystore on Android) — never on our servers. We never receive or store your Google password. The token is deleted from your device when you disconnect Gmail or delete your account, and you can revoke it at any time at myaccount.google.com/permissions.
Access controls
Every record in our database is protected by row-level security rules that let each account read and write only its own trips, bookings, profile, insurance details, and companion invitations. The backend function that processes Gmail content verifies your signed-in identity before handling any request. Administrative access to production systems is limited to the minimum necessary and protected by strong authentication.
Sensitive data minimization
Gmail message text is processed in memory only for the moments needed to extract booking details and is never written to our database or server logs. We retrieve only the body text (up to 1,500 characters) of emails matching travel keywords — not your full mailbox. Passport data is limited to nationality; we never collect your passport number, name as shown on the document, or photo page.
Vendor safeguards
Our infrastructure and processing providers (Supabase, Anthropic, and the underlying cloud hosting) maintain SOC 2 Type II or equivalent independent security certifications and are bound by data processing agreements that limit use of your data to providing their service to us. Anthropic does not use data submitted through its API to train models and does not retain it after processing.
Ongoing practices
We keep software dependencies patched, review the data each feature collects before every release, and monitor for errors and anomalies. No method of transmission or storage is completely secure; if we become aware of a breach affecting your personal data, we will notify affected users and the relevant authorities as required by law.
Supabase
Database and authentication provider. Your account, trip, booking, insurance, and profile data is stored on Supabase servers in the United States.
Anthropic (Claude)
AI processing for Gmail Import. Email body text (up to 1,500 characters per email) is sent to Anthropic’s API to extract booking confirmation details and is not retained after processing.
Mapbox
Mapping services. Map display interactions may be processed by Mapbox servers.
PostHog
Usage analytics. Events are linked to an anonymous user identifier and stored on PostHog servers in the United States.
Sentry
Crash and error monitoring. Logs are stored on Sentry servers and retained for 90 days.
Apple
If in-app purchases are offered in a future version of Roam Wyld, all billing will be handled by Apple through the App Store. Apple does not share payment information with Roam Wyld.
We do not sell, rent, or trade your personal data to any third party. Data is shared only with the service providers listed above, solely to operate the app.
If you use trip sharing, bookings marked "Visible to both of us" — including confirmation numbers and costs — are visible to trip members you've invited and who've accepted. This is user-to-user sharing within a trip you control, not sharing with a third party.
California residents: Roam Wyld does not sell your personal information as defined by the California Consumer Privacy Act (CCPA). We do not share your personal information with third parties for cross-context behavioral advertising.
| Data type | How long we keep it |
|---|---|
| Account email | Until you delete your account |
| Trips, bookings, insurance details | Until you delete your account |
| Travel profile (passport, currency) | Until you delete your account or update it |
| Travel companion invite emails | Deleted immediately on invite decline; otherwise until you delete the trip or your account |
| Gmail email body text | Not retained — deleted immediately after extraction |
| Analytics events (PostHog) | Per PostHog’s retention policy (verify in PostHog settings) |
| Error logs (Sentry) | 90 days |
You may delete your account and all associated data at any time directly in the app (Profile → Delete Account). Deletion is permanent and immediate — your account, trips, bookings, insurance details, and travel profile are removed from our servers. Anonymized analytics event data cannot be linked back to you and may be retained as part of aggregate statistics.
Roam Wyld is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.
We may update this Privacy Policy. If changes are material, we will notify you within the app or by email to the address associated with your account. Continued use after notification constitutes acceptance.