passportKITT — Privacy Policy
Last updated: 7 October 2026
passportKITT helps you plan and run a trip. This policy explains what the app stores, where, and who else touches it. Plain language, no surprises.
The short version
- Your trip lives on your device first. A copy syncs to our backend so you can use it on another device or with a travel companion.
- We don't sell data, run ads, or embed third-party trackers.
- Documents in the vault are encrypted on your device before they're uploaded. We can't read them.
- Analytics and crash reporting are optional — turn them off in Settings.
- Photo matching happens entirely on your device. Your photos are never uploaded.
What we store
Account. An email address (if you sign in with one) or an anonymous identifier (if you choose "continue without an account"). A per-device id used only to reason about sync conflicts.
Your details (optional). Your name as on your passport, gender and date of birth, if you add them. They are saved to your account so they follow you across devices, and only you can read them. Your display name is visible to companions on your trips. Passport numbers you type into the app are never sent to us: they stay encrypted on your device. (Booking documents you import or forward can show them; see below.)
Forwarded emails (optional). If you forward a booking confirmation to your trip's import address, we read it to extract the booking and delete the original email straight afterwards. The extracted details, any PDF attachments, and a short excerpt of the email (with the passport and ID numbers we can recognise removed) so you can check what was read, are kept until you accept or dismiss the booking (at most 30 days). The excerpt is deleted as soon as you accept or dismiss. When you accept, you choose whether to keep each PDF with the booking: booking PDFs can show passport numbers, and a kept PDF can be opened by everyone on the trip, view-only companions included. PDFs you don't keep are deleted within a day. Only you and your trip's companions can send to that address.
Imported documents. When you import a booking, text (pasted, from a PDF, or from a forwarded email) has the passport and ID numbers we can recognise removed before it is read. A photo or a scanned PDF is read as it is, so anything printed on it, a passport number included, is sent for reading. Nothing you import this way is stored unless you attach it to a booking.
Medicines (optional). Medicines you add to a packing list stay on your device, encrypted. They leave it only inside a backup file that you make and lock with your own password.
Trip content. Destinations, dates, flights and other travel, accommodation (including any confirmation and room numbers you enter), activities and the itinerary, packing lists, budgets and expenses, and free-text notes. This is whatever you put into the app.
Companions. If you invite someone to a trip, their name and their role on that trip are visible to the others on it.
Vault documents. Files you add to the documents vault (passport, insurance, tickets, and so on). These are encrypted with a key generated on your device and held in the device's secure storage. The encrypted blob and its initialisation vector are all our servers ever see.
Push token. If you allow notifications, an Expo push token for your device, used only to send flight-status alerts for your trips.
Diagnostics (optional). Crash reports and anonymous, aggregated usage events. No trip content, no vault content, no precise location. Off by default on the web; toggleable everywhere in Settings → Privacy.
Closed beta (beta build only). Your email is checked against the tester list, and when you agree to the beta agreement we record its version, the name you typed and the time. A bug report you send includes what you write, the screenshots you add (including one of the screen you were on) and your device and app version, and goes to our crash-reporting service (Sentry).
What we do not do
- No advertising or ad networks.
- No selling or renting of personal data.
- No background or continuous location tracking.
- No reading of your device photo library contents — matching runs locally and only reads the timestamp and, if present, the GPS tag of each photo.
- No access to your email inbox. Booking import works only on text, a PDF or a photo that you explicitly hand to the app, or an email you choose to forward.
Where it's stored
- On your device: a local database is the primary copy, so the app works fully offline.
- Our backend: Supabase, hosted in Sydney, Australia. Row-level security limits every record to you and the companions you've invited.
Who else is involved (subprocessors)
We route third-party API calls through our own backend so these providers don't receive your account identity unless noted.
| Provider | Purpose | What they receive |
|---|---|---|
| Supabase | Hosting, database, authentication, file storage | Everything listed under "What we store" |
| Expo (EAS) | App delivery, push notification relay | Push token, notification payload |
| Mapbox | Maps, locating the airports, stations and ports of your travel, and driving times | Coordinates of the map area, those place names, and the start and end of a ride. The lookups and driving times go through our server; map tiles load directly from your device, so Mapbox also sees its IP address |
| Google Maps Platform | Place details, routes and travel times | The place or coordinates you look up — not your identity |
| Anthropic | Reading a booking you import or forward | The text (recognisable ID numbers removed), or the photo or scanned PDF as it is |
| AeroDataBox (via RapidAPI) | Flight schedule and status | A flight number and date |
| Cloudflare | Receiving forwarded emails for our backend | The forwarded email, passed straight on and not kept |
| Viator | Tours and tickets for places | The name of a place or city |
| LiteAPI (Nuitée) | Hotel search and prices | A city or area, dates and number of guests |
| Pexels, Wikipedia | Pictures and short descriptions of cities and places | The name of a city or place |
| Open-Meteo | Weather forecast | Coordinates of a destination |
| open.er-api.com | Currency exchange rates | A currency code — no personal data |
| Sentry | Crash reporting (optional) | A stack trace and device model — no PII |
| PostHog | Anonymous usage analytics (optional, mobile only) | Screen names and anonymous event counts |
Your choices and rights
- Export: "Share this trip" produces a plain-text copy of your itinerary.
- Delete a trip: removes it from your devices and our backend.
- Delete your account: contact us (below) and we erase your account and its trips. Anonymous accounts are erased when you sign out and wipe local data.
- Analytics: Settings → Privacy → turn off "Anonymous analytics & crash reports".
- Notifications: turn them off in your device settings at any time.
Retention
Trip data is kept until you delete the trip or your account. Cached third-party responses (place details, weather, flight status) expire automatically within days to a month. Optional diagnostics are retained by Sentry and PostHog per their standard policies (about 30–90 days).
Children
passportKITT is not directed at children under 13 and we don't knowingly collect their data.
Changes
If this policy changes materially we'll note it in the app before the change takes effect.
Contact
Questions or a deletion request: privacy@passportkitt.app
(Replace this address with a monitored contact before publishing to a store.)