Traulo Privacy Policy
Effective · version 12 · Previous versions
What changed in version 12
Updated for the Plans tab. New §2.13 explains planning together: who can join a plan, what members see of each other, and the plan's activity and undo history. New §2.14 explains AI trip planning: what we send to Anthropic, what we never send, and why you should not type health or other sensitive details into a request. New §2.15 explains community places: counts of how many published guides stop at a place, never who. New §2.12 explains booking a hotel in the app: the booking holder's and guests' details go to our booking partner Nuitée (LiteAPI) and the hotel and are not stored on our servers; the card never reaches us; the hotel and Nuitée are responsible for their own part. §2.3 covers private plans, walks and the live trip view (your location stays on your device). §5 adds Nuitée, the hotel and OpenStreetMap; §7 adds retention for bookings (10 years, accounting) and plan history. §2.1: profiles of accounts created from this version's effective date are public by default.
This Privacy Policy explains how we collect, use, share and protect your personal data when you use the Traulo mobile application and the website at www.traulo.com (together, the "Service").
We follow the European General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Slovenian Personal Data Protection Act (ZVOP-2), the Slovenian Electronic Communications Act (ZEKom-2) and the Slovenian Consumer Protection Act (ZVPot-1).
1. Who we are
The data controller responsible for your personal data is:
Računalniške storitve REK, Mihael Rek s.p. Ulica heroja Jevtiča 5, 2000 Maribor, Slovenia Matična številka: 7412037000 Davčna številka: 89184882 Privacy contact: [email protected] Postal contact: the address above
We act as the controller under GDPR Article 4(7) for personal data processed through the Service. We have not appointed a Data Protection Officer; under GDPR Article 37 a DPO is not required for our scale and processing activities. You can reach our privacy contact directly at the email or postal address above.
2. What we collect
We collect only the personal data we need to deliver the Service, comply with our legal obligations, and protect the Service against abuse. We never sell your personal data and we never share it for third-party advertising.
2.1 Identity and account data
When you create an account or sign in, we collect:
- Your email address
- A user-chosen handle (username) and optional display name
- An identifier from your chosen sign-in provider — the opaque Apple user identifier (Sign in with Apple), or your Google account ID and the email/name claims you choose to share (Google Sign-In)
- Passkey credentials (WebAuthn public key, credential ID) for two-factor authentication, if you enroll one
- An optional avatar image that you upload
- An optional phone number in E.164 format, if you add it in your profile — stored alongside a one-way SHA-256 hash to allow contact matching (see §2.7). Clearing the field in Settings removes both. We never use your phone number for marketing or SMS notifications.
Profile visibility. Profiles of accounts created on or after the effective date of this policy are public by default (keeping a profile private needs a paid subscription); profiles of accounts created before that date are private by default. If you choose to make your profile Public in Settings → Account → Profile visibility, your handle, display name and avatar become visible to all Traulo users and to any unauthenticated visitor of www.traulo.com/@<handle>. Your vlog count, follower count and following count are also shown on that public profile page. You can revert to private at any time; doing so immediately hides your profile page from non-followers.
Public profiles, public vlogs and published trip guides are also discoverable through in-app search and through the discovery and search features on www.traulo.com — including by visitors who are not signed in — and may be indexed by external search engines. Only content you have made public is exposed this way; private profiles, private vlogs and unpublished plans are not.
2.2 Device data
When the app connects to our backend, we collect:
- A device identifier generated locally on first launch
- The Apple Push Notification Service token that allows us to deliver push notifications you have asked for — for example when someone follows you or comments, when you are invited to a plan or someone joins it, when a plan you share changes, when an idea, cost or settlement is added to it, and when a stay is booked for it. These notifications can include the plan's title, a member's name and an amount. Reminders about your own trip (when to leave, check-in, a free-cancellation deadline ending tomorrow) are scheduled on your device and are not sent through our servers.
- Your device's platform (iOS), app version, build number and locale (e.g.,
sl_SI) - The IP address of API requests and a short User-Agent string (kept in session records to detect token theft and to revoke compromised sessions)
2.3 Content and media data
Traulo generates short vertical vlogs from media you choose. To do this we process, on your device:
- Photos and videos you select from your camera roll
- The technical metadata of those assets — creation timestamp, duration, resolution, frame rate, video codec, perceptual hashes (for deduplication), aesthetic scores (computed locally with Apple's Vision framework), and any EXIF location the camera embedded
- GPS waypoints (latitude, longitude, altitude, speed) sampled from location-tagged assets and used to compose the vlog's route
- Reverse-geocoded city and country names derived from those coordinates
When you save a vlog to the cloud (every account can save publicly shared vlogs within the free 1 GB allowance; paid plans can also save private vlogs, with more room), the following data is uploaded to our backend:
- The rendered vlog video file (MP4) and thumbnail image
- A composition snapshot in JSON form — the title, mood, music selection, captions, asset references, GPS waypoints, peak altitude and reverse-geocoded city/country
- The size of the file and our internal storage key
If you do not save a vlog to the cloud, none of this is uploaded — it stays on your device.
Trip plans and guides. Traulo can turn a trip into a structured trip plan or guide — a day-by-day itinerary with places and stops (their names and coordinates), a route, written notes and tips, and photos you attach to individual stops. A guide may also include GPS route tracks you import (for example from a .gpx file — a sequence of latitude/longitude/elevation points and the timestamps recorded with them) together with the type of activity (such as a hike or a bike ride). We store this so we can show and let you edit your plan. When you publish a guide it becomes public content that others can view and save (see §2.1 here and §8.8 of the Terms); a plan you keep private stays in your account and is not shown to other users, except the members you invite (§2.13).
Private trip plans. A private plan can also hold your trip dates and nights, the number of travellers, your home (the place you set in Settings, or one the app works out on your device from where your photos of the last months were taken — you can change or clear it), notes and checklists, costs and how they are split, ideas and votes, bookings, and photos you add. If you start a plan from a published guide, the plan records which guide it came from. When you delete a plan you can restore it for 30 days; after that it is erased.
Walks and trails. To show walks, trails and huts near your plan, our servers look up map data for the area from OpenStreetMap through the Overpass service, and your device fetches terrain-height tiles and, for some views, trail data directly (see §5). These requests contain an area of the map — not your name or account — but a request made from your device carries your device's IP address, as any web request does.
The live trip view. If you allow location access while using the app, the live trip view reads your phone's position to show where you are on today's route and what comes next. Your position stays on your device: it is not sent to our servers, not stored by us and not shown to other members. We never ask for "Always" location access and do not use your location in the background.
2.4 Usage and behaviour data
To improve the auto-selection algorithm and protect against abuse we record, server-side:
- Feed and viewing activity — for each public vlog or guide shown to you in a feed we record, against your account, how many times it was shown to you, how long you watched it, whether you watched it to the end, and whether you opened it. We use this in two ways: to shape what your own feed shows you next (so you are not shown the same post over and over, and so posts closer to what you actually watch rank higher), and — in aggregate across all viewers, not as your individual record — to score how well a post holds attention, which feeds the Explore rankings and the weekly Editor's-choice selection described in §2.8 and §4. We store one row per viewer per post, not one per event, and delete it after 90 days.
- Auto-select telemetry events — anonymised at the algorithmic level (per-asset decisions, asset actions, composition completions and abandonments). Stored in monthly partitions and deleted after 30 days; aggregated rollups are retained for up to 2 years.
- Abuse signals — rate-limit breaches, schema rejections, deduplication storms, oversize batches. Used to detect and block automated abuse.
- AI quota ledger — a per-month count of AI editorial requests you have made, with a request identifier (no content).
- AI call log — for each AI editorial request: model used, token counts, cost, latency, error code (if any). The request body itself is not retained.
If you turn on telemetry opt-out in Settings, we no longer record auto-select telemetry for you. Feed and viewing activity is not covered by that switch — it is what makes a ranked feed work at all — but it is never shown to other users, never used for advertising or for tracking you across other apps and websites, and is deleted on the 90-day cycle above. Abuse signals and AI call logs are kept under our legitimate interest in operating the Service safely.
2.5 Diagnostics
We use Firebase Crashlytics and Apple's MetricKit to collect crash logs and performance diagnostics. These include:
- Crash stack traces and the application state at the moment of the crash
- Performance metrics (launch time, hangs, energy, disk space)
- Your user identifier (so we can correlate crashes with the affected account and reach you if there is an account-level problem)
2.6 Billing data
We use RevenueCat (and, for App Store purchases, Apple) to manage subscriptions and one-time in-app purchases. We receive, depending on the product:
- Your subscription status (active / trial / grace / expired / canceled / refunded), the plan you are on, the billing period and the anniversary day — for auto-renewing subscriptions (Traveler / Daily Vlogger)
- A record of one-time purchases — product ID, purchase date and the AI-vlog quota credited to your account — for consumable AI vlog packs (10 / 20 / 100)
- A non-financial purchase or subscription identifier issued by RevenueCat or Apple
Apple is the merchant of record for App Store purchases. We never see your payment card or bank account details.
2.7 Contacts (optional)
When you tap "Find friends from your contacts" in the Search tab, Traulo asks iOS for permission to read your address book. If you grant it:
- We compute a one-way SHA-256 hash of each contact's email address and phone number on your device.
- We send only the hashes to our servers. We discard them after the lookup completes.
- We never store your contacts, their names, their phone numbers, or their email addresses on our servers.
- If a contact's own Traulo account email or phone matches one of those hashes, we show them to you so you can follow them.
You can revoke contacts access at any time in iOS Settings → Privacy & Security → Contacts → Traulo. If you deny or revoke access, the feature is simply unavailable — no other functionality is affected.
2.8 Social graph and interactions
When you use the social features of the Service, we collect and store the following data:
- Follow relationships. When you follow another user, or when another user follows you, we record the follow relationship, the user identifiers involved, and the timestamp. Your follower count and following count are displayed on your public profile if it is public. The identities of your individual followers and followees are not currently shown to other users — only aggregate counts are.
- Hearts (likes). When you heart a vlog, we record the interaction linked to your account, the vlog identifier, and a timestamp. The vlog's total heart count is visible to the creator and, on public vlogs, to all viewers. We do not currently display which specific accounts hearted a vlog to third parties.
- Block relationships. When you block a user, we record the block so that it can be enforced consistently across the Service. Block relationships are not visible to the blocked user or to third parties.
- Comments. When you post a comment on a vlog, we store the comment text, your account identifier, the identifier of the vlog, and a timestamp. A comment on a public vlog is visible to anyone who can see that vlog. You can delete your own comments, and the creator of a vlog can delete comments on their vlog or turn comments off; deleting a comment removes it from the Service (subject to backup rotation). We may notify a creator that you commented on their vlog.
- Companion tags and trip groups. When you tag another user as a companion on a trip — or another user tags you — we record the tag and the identifiers of the participants, the trip and trip-group identifier, each participant's own point-of-view (POV) vlog reference, and timestamps, so the participants' POV vlogs of the same trip can be presented together. This means another user can associate your account with a trip by tagging you, and you can do the same to them. Each participant controls their own POV vlog and its visibility, may decline or remove a tag, and may leave the trip group; doing so removes their participation and POV vlog from the shared trip. Companion stat cards generated from this data (for example, "You & @handle") may include the other participant's handle, display name, avatar and aggregate trip statistics.
- Saved guides (bookmarks). When you save another user's published trip guide, we record that you saved it, the guide identifier and a timestamp, so you can find it again and so the creator can see an aggregate count of how many people saved their guide. We do not show creators the identities of individual savers.
- Guide lineage (remixes) and place credits. When you create a trip guide inspired by another published guide, we record the link between the two guides ("inspired by") and may display that attribution publicly, so the original creator is credited. The same link is recorded when you take a single place from the community index into a plan of your own — including a private plan — and it points at the guide that published that place first. The link is an identifier for a guide, not for the person who copied it: the credited creator is not told who added their place, and a private plan stays private.
- Public rankings ("Top travellers"). Explore shows a public ranking of travellers, ordered on aggregate statistics derived from your own public vlogs — the number of distinct countries and distinct places you have posted from, and how many of your vlogs qualify. Only accounts whose profile is public are eligible; if your profile is private you are never listed, and switching it back to private removes you. If you would rather not appear while keeping a public profile, write to
[email protected]and we will exclude your account from the ranking. - Editor's choice. Once a week the Service selects a small set of already-published public guides to feature in Explore, on the globe and in the feed. Selection is automated and is described in §4. If a guide of yours is selected we display it — with your handle, display name and avatar — to other users, notify you, and generate a short one-line blurb for it.
Social graph data is used solely to operate the social features of the Service and to protect users from harassment. We do not sell, license or share it with third parties for advertising, profiling or any purpose other than operating the Service.
2.9 What we do NOT collect
To be specific: we do not collect health or fitness data, browsing history outside our app, search history, sensitive personal data within the meaning of GDPR Article 9, or financial information beyond purchase history (which, if you book a stay through the app, includes that booking — see §2.12; we never see your card number) and the trip costs you and your plan's members choose to record in a plan (§2.13). We do not access your contacts without your explicit permission (see §2.7 for how contact matching works when you opt in). We do not use your data for tracking across apps or websites (see §2.10 for how third-party booking links work when you choose to tap one, and §2.11 for the website analytics you can accept or decline — which measures our own site only, with advertising features switched off).
2.10 Booking suggestions and affiliate links
Inside trip guides we may show booking suggestions — such as stays, flights, activities, airport transfers or eSIM data plans — from third-party travel partners. To produce them we send a partner, or our affiliate-link provider, only the non-personal inputs needed for the lookup: a guide's destination place names and coordinates and, for flights, the major airports nearest your home region. We do not send your name, email, account identifier or device identifier to these partners.
When a suggestion is an affiliate link and you tap it, you are redirected out of Traulo to the partner's own website or app. From that point the partner is the controller of any data you give it, and its own privacy policy and cookies apply. So that the click can be attributed for our commission, our affiliate provider receives an attribution code that identifies the guide and its creator — not you. We also keep an internal, append-only log of these clicks (the guide, the creator and the partner's domain, with a timestamp) to calculate earnings; that log contains nothing that identifies the person who clicked.
We do not sell your personal data and we do not share your identity with these partners for advertising. Tapping a booking suggestion is always optional. The processors and partners involved are listed in §5.
2.11 The website: cookies and analytics
This section applies to www.traulo.com — the website where you can browse Traulo, sign in, and view your own vlogs, guides and travel map. The iOS app does not use cookies; everything below is about the site.
Cookies we set to make the site work. These are set because the site cannot do what you asked without them. Under the ePrivacy rules they are strictly necessary or the direct result of a choice you made, so they do not require your consent.
| Cookie | What it is for | How long it lasts |
|---|---|---|
__Host-tr_session | Keeps you signed in. Contains your session token. | 30 days |
tr_lang | Remembers the language you chose. | 1 year |
tr_map_style | Remembers your map style. | 1 year |
__Host-tr_welcome | Marks that you have finished the welcome steps, so we do not show them again. | 30 days |
tr_consent | Records your answer to the analytics question below — including a No, so that we do not keep asking. | 6 months |
We also keep a few small values in your browser's own storage. These are not cookies and are never sent to our servers with your requests: traulo.device, a random identifier for this browser so that a passkey registered here is recognised at your next sign-in; av_home / av_region, the departure point and region you last chose when viewing travel suggestions in a guide; and, if you book a stay on the website, the booking holder's details you typed (traulo.holder…), so a page reload does not lose them. Clearing your browser's site data removes all of them.
To suggest a departure point when you first view travel suggestions, the website may ask an IP-location service (ipapi.co or ipwho.is) for the approximate region of your IP address; this request is made by your browser. Satellite map imagery on the website is loaded from Esri, and map requests carry your IP address and the area viewed.
Analytics, only if you say yes. We use Google Analytics to understand how the website is used — which pages people open, on what kind of device, and roughly where in the world they are.
Nothing analytics-related loads until you accept it. When you first visit, we ask. Until you answer, and permanently if you answer No, no analytics script is loaded, no analytics cookie is set, and no data reaches Google. Declining costs you nothing: signing in, your language, your map style and every feature of the site work exactly the same either way.
If you accept, Google Analytics sets its own cookies to recognise a returning browser and count visits. We configure it with advertising features switched off — no ad personalisation, no ad targeting, no advertising identifiers — and with IP anonymisation on. We do not use it to follow you onto other websites, and we do not combine it with your Traulo account.
Changing your mind. Clear your browser's cookies for www.traulo.com and we will ask again on your next visit. You may also use Google's own opt-out browser add-on. Withdrawing consent is as easy as giving it.
Legal basis: your consent (GDPR Article 6(1)(a); ZEKom-2 Article 157). This is the only place in Traulo where consent is the legal basis, which is why it is the only place we ask.
Sign-in providers. If you choose Continue with Google or Continue with Apple, that provider's script loads at the moment you open the sign-in panel — not before, and not at all if you never try to sign in. From that point the provider's own privacy policy also applies to the sign-in exchange. We receive only what §2.1 describes.
2.12 Booking a stay through Traulo
Inside your own trip plan you can book a hotel room without leaving the app. This is different from the affiliate links in §2.10: the booking is made through our booking partner Nuitée Ltd (LiteAPI), an Irish company, and Traulo keeps a record of it so the stay shows in your plan. Here is exactly what happens with your data.
Who is responsible for what. We are the controller for what Traulo does: presenting the offer, collecting the booking details and passing them on, and keeping the booking in your plan. Nuitée takes your payment as the merchant and places the booking, and the hotel hosts you; each of them processes your details for its own part — including its own legal obligations, such as payment, fraud-prevention, tax and guest-registration rules — as an independent controller under its own privacy policy.
What you give us to make the booking. The booking holder's first name, last name and email address, an optional phone number, the names (and, if you add them, emails) of the other guests, and the ages of any children travelling. They pass through our servers to Nuitée, which passes them to the hotel so that the room is held in your name. We do not store the holder's or guests' names or contact details on our servers. The app keeps the holder's details on your device so the next booking is faster, and you can clear them there at any time; on the website they are kept in your browser's storage (§2.11). Reservation records on our side carry no guest names — only a pseudonymous guest reference issued by Nuitée.
The stay itself. We store the hotel, the dates, the number of guests, the room and board type, the price and currency, the cancellation terms you were shown, Nuitée's booking reference and the hotel's confirmation number, the trip plan the booking belongs to and — when you booked from a published guide — that guide and its creator. This is what lets your plan show the booking, lets you cancel it in the app, and lets us pay the guide's creator their share (§8.10 of the Terms describes the creator's share). The creator never sees who booked — only that a booking happened and the amount they earned. If the plan is shared (§2.13), its other members see the booking in the plan — the hotel, the dates and the price — and who made it, but not the holder's or guests' contact details.
Payment. The card is entered on a secure page at www.traulo.com that embeds Nuitée's PCI-compliant payment form; the card details travel from your browser to Nuitée's payment provider (Stripe) and never reach our servers. We receive only whether the payment succeeded and the amount. Neither we nor the hotel see your card number.
Booking tags. So that the booking can be matched to your plan and to the guide it came from, we attach to it pseudonymous identifiers — your account identifier, the plan and the guide — as booking tags at Nuitée. These identify records in our system; they contain no name or email.
Reconciliation. Once a day we ask Nuitée for the status of bookings made through Traulo (confirmed, cancelled, refunded) so that your plan and the creator's earnings stay correct. Nuitée also notifies us of changes as they happen; we keep those status notifications with the booking record and do not keep guest names or contact details from them.
Help with a booking. If you write to us about a booking, we use your message, the booking record and what you tell us to sort it out with Nuitée and, through it, with the hotel; we share with them only what the problem needs. We keep the correspondence as long as the booking record (§7).
Cancelling. You can cancel a booking from the plan at any time; the refund is decided by the cancellation terms you were shown before paying and is made by the payment provider. We never cancel a booking for you. A free-cancellation deadline reminder is an on-device notification that you can switch off.
The legal basis is the contract you enter when you book (Art. 6(1)(b)); keeping the booking and payment records afterwards is a legal obligation under Slovenian accounting and tax rules (Art. 6(1)(c)); see §3 and §7.
2.13 Planning together
You can invite people to a private plan you own (Terms §4.9).
Invitations. You can add a person directly or share an invite link. The link contains a random code; anyone who opens it before it expires (30 days) or is revoked sees the plan's title, dates and length, the role on offer, and your handle and display name, and can join. We record each member, their role (view, suggest or edit), who invited them and when they joined, left or were removed.
What members see of each other. Members see each other's handle, display name, avatar and profile colour — never each other's email address — and everything added to the plan: notes (with their author), ideas and votes, photos (with who added them), costs, how they are split and who has settled, any payment link a member chooses to add (for example a revolut.me link), and bookings made for the plan without the guests' contact details (§2.12).
Activity and undo. Every change to a shared plan is recorded — who made it, when, and what changed — so members can see recent activity and undo a change. This history is deleted after 90 days.
Notifications. Members are notified of invitations, new members, changes, new ideas and costs, settlements and bookings (§2.2).
When you leave or are removed, you lose access to the plan and are no longer notified. What you added stays in the plan for its other members and is shown as coming from a former member.
The legal basis is the contract (Art. 6(1)(b)): showing a shared plan to the people you invited is the service you asked for.
2.14 AI trip planning
When you ask Traulo to draft a trip plan or to improve one, our server sends Anthropic (Claude) what the request needs, and nothing that identifies you:
- For a draft: the destinations, dates, number of nights, pace and trip types you choose, and the free text you type (up to 800 characters); your home — its name and location — so the plan can start and end there; and, when you do not name a destination, the names of up to 40 places you have already been to, taken from your own vlogs and plans (including private ones), so the suggestions are new to you. We also send places from the community index (§2.15) and titles of published guides as candidates.
- To improve a plan: its title, summary and notes, its days and nights, and for each stop its name, category, time, description and links, plus the name of your home. For a private plan no photos are sent; when you improve a guide you are preparing to publish, small previews of the photos you attached to its stops may be sent so the suggestions can describe them.
- Never sent: your name, email, account identifier, the members of the plan, or anything from other members' accounts.
Do not type health, religious, political or other sensitive details — or other people's personal details — into a request; the text goes to Anthropic as written. Anthropic processes requests as our processor under its commercial terms, does not use them to train its models, and keeps them only for a limited period for safety and abuse monitoring. Place names that come back are matched to map positions by a geocoding service that receives only the place names (§5).
Each request uses AI credits from your plan's monthly allowance and is logged as described in §2.4 (the model, token counts and cost — not the request text). The legal basis is the contract (Art. 6(1)(b)). A drafted plan is a suggestion you review and edit; see §4.
2.15 Community places
When you plan a trip, Traulo can show that a place is popular with travellers — for example "12 travellers went here" — and list the published guides that stop there. Once a night we count, for each place, the published guides and the public, available vlogs that include it. Private plans, private vlogs and unpublished guides are never counted. Tapping a place can show the published guides behind the count with their authors' handle, display name and avatar — only for authors whose profile is public and who have not blocked you. The counts contain nothing about who viewed or planned a place.
The legal basis is our legitimate interest in helping travellers find good places from content its authors chose to publish (Art. 6(1)(f)). If you do not want a guide or vlog to count, unpublish it or make it private.
3. Why we process your data and on what legal basis
| Purpose | Data categories | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and manage your account | Identity, Device | Art. 6(1)(b) — contract performance |
| Generate vlogs (on-device + cloud render) | Content, GPS, Identity | Art. 6(1)(b) — contract performance |
| AI-assisted editorial suggestions | Limited Content metadata, GPS timeline | Art. 6(1)(b) — contract performance |
| Music suggestions (music catalogue lookup) | Mood / activity / location keywords | Art. 6(1)(b) — contract performance |
| Billing and entitlements (subscriptions + one-time purchases) | Billing, Identity | Art. 6(1)(b) — contract performance |
| Security, abuse prevention and audit logging | Device, IP, Abuse signals | Art. 6(1)(f) — legitimate interests |
| Crash diagnostics and performance monitoring | Diagnostics | Art. 6(1)(f) — legitimate interests |
| Auto-select algorithm improvement | Auto-select telemetry | Art. 6(1)(f) — legitimate interests (with opt-out) |
| Contact matching ("Find friends") | On-device SHA-256 hashes of contact emails and phones — not stored server-side | Art. 6(1)(a) — your consent (revocable in iOS Settings → Privacy & Security → Contacts → Traulo) |
| Public profile display | Handle, display name, avatar, vlog count, follower and following count (public profiles only) | Art. 6(1)(b) — contract performance |
| Social interactions (follow, heart, block) | Follow and block relationships; heart interactions; all with timestamps | Art. 6(1)(b) — contract performance |
| Comments on vlogs | Comment text, author identity, vlog identifier, timestamps | Art. 6(1)(b) — contract performance |
| Companion tagging, POV vlogs and trip groups | Participant identifiers, trip / trip-group membership, POV vlog references, timestamps | Art. 6(1)(b) — contract performance |
| Create, store and publish trip plans and guides | Content, GPS, attached photos | Art. 6(1)(b) — contract performance |
| Saving guides, guide lineage (remixes) and place credits | Save records, guide identifiers, "inspired-by" links, timestamps | Art. 6(1)(b) — contract performance |
| Discovery and search of public content | Public profile, vlog and guide data | Art. 6(1)(b) / Art. 6(1)(f) — contract + legitimate interests |
| Booking suggestions and affiliate attribution | Destination place names / coordinates, home-region airports (no identity); click-attribution log | Art. 6(1)(f) — legitimate interests (offering relevant travel options and funding the Service) |
| Booking a stay through the app (§2.12) | Booking holder and guest details (transmitted to the booking partner, not stored by us); the stay, its price and terms; the plan and guide it belongs to; pseudonymous booking tags | Art. 6(1)(b) — contract performance |
| Planning together (§2.13) | Members, roles, invitations and invite links; everything members add to a shared plan; the plan's activity and undo history | Art. 6(1)(b) — contract performance |
| AI trip planning (§2.14) | The request text you type, destinations, dates, nights, home name and location, places you have been to, plan content | Art. 6(1)(b) — contract performance |
| Walks, trails, maps, weather and place look-ups | Map areas, plan locations and dates, place names (no identity; your IP address where your device makes the request) | Art. 6(1)(b) — contract performance |
| Community places (§2.15) | Counts from published guides and public vlogs; public authors' handle, display name, avatar | Art. 6(1)(f) — legitimate interests (helping travellers find places from content its authors published) |
| Helping with a booking | Your message, the booking record | Art. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interests (resolving disputes) |
| Keeping booking and earnings records | The stay, amounts, references and confirmation numbers; creator earnings | Art. 6(1)(c) — legal obligation (accounting and tax); Art. 6(1)(f) — legitimate interests (paying creators, resolving disputes) |
| Content moderation and safety | Cloud-stored vlog files accessed by authorised staff in strictly limited circumstances (see §5) | Art. 6(1)(f) — legitimate interests (safety, legal compliance) |
| Use of precise location | GPS, EXIF location; your current position in the live trip view (on the device only) | Art. 6(1)(a) — your consent (revocable in iOS Settings → Privacy) |
| Sending push notifications you asked for | Device token, content | Art. 6(1)(a) — your consent (revocable in iOS Settings → Notifications) |
| Compliance with legal obligations | All categories as required | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interests, we have weighed them against your fundamental rights and freedoms. You can object to that processing at any time (see Section 8).
4. Automated decision-making
Traulo uses artificial intelligence (Anthropic's Claude model, via our backend) to suggest an editorial composition for your vlog — which clips to feature, in what order, and with what tone. These suggestions are not solely automated decisions within the meaning of GDPR Article 22(1): you can always preview, edit, override or discard them before exporting your vlog. They produce no legal or similarly significant effect on you. We do not profile you for credit, employment or other consequential purposes.
We also use the same AI to draft and enrich trip-guide text — titles, descriptions and tips — and to draft and improve trip plans (§2.14). A drafted or improved plan is likewise a non-binding suggestion you can edit, accept or discard; it decides nothing about you and produces no legal or similarly significant effect.
We also rank content automatically. Your feed is ordered by an algorithm using the feed and viewing activity in §2.4, who you follow, where you have travelled, and how each post performs with viewers generally. Explore rankings and the weekly Editor's-choice selection run on aggregate signals across all viewers: a deterministic score built from how completely a post is watched, how often it is re-watched, its hearts, saves and comments over the previous seven days, whether it carries a title and description, its length, and whether a trip guide is attached — with per-creator, per-country and per-region diversity limits applied afterwards. Once a set is chosen we ask Claude to write a one-line blurb for each featured guide, from that guide's title, description and country only. An administrator can override or remove any selection by hand.
None of this is a solely automated decision within the meaning of GDPR Article 22(1). It decides the order in which public content is displayed — not whether you may use the Service, what you are charged, or what you are entitled to — and produces no legal or similarly significant effect on you. Being featured is editorial: it is not a benefit you are entitled to and carries no payment.
In line with EU AI Act Article 50 (transparency obligation for AI systems generating content), this Privacy Policy is the place where we tell you that AI is used to suggest editorial choices for your own vlogs and guides, to draft and improve trip plans, and to write the one-line blurb shown with an Editor's-choice pick.
5. Who we share your data with
We share personal data with the processors listed below, who act on our instructions under data-processing terms that meet GDPR Article 28, and — where the table says so — with independent recipients that decide for themselves how they handle what they receive. We never sell your data.
| Recipient | Role | Data shared | Location |
|---|---|---|---|
| Anthropic, PBC | AI editorial and trip-guide suggestions, AI trip planning, and Editor's-choice blurbs (Claude API) | For a vlog: small, downscaled preview images of the photos and clips you selected, and a summary of your trip — asset count, drone ratio, reverse-geocoded place names, GPS timeline (lat/lon/altitude/speed), drone clip summaries. For trip plans and guides: what §2.14 lists — including the text you type, your home's name and location, and, for a guide you are preparing to publish, small previews of its stop photos (never for a private plan). For an Editor's-choice blurb: the title, description, country and post identifier of a guide you have already published publicly. No full-size photos, no videos, no email, no account identifier. | United States |
| RevenueCat, Inc. | Subscription and one-time purchase state management | A pseudonymous user ID, your plan and status (for subscriptions), purchase records (for one-time AI vlog packs), and relevant timestamps | United States |
| Cloudflare, Inc. (R2) | Object storage of cloud-saved vlogs and avatars | The vlog video, the thumbnail, your avatar | EU + United States |
| Google LLC (Firebase Crashlytics) | Crash reporting and performance diagnostics | Crash stack traces, MetricKit payloads, user ID | United States |
| Apple Inc. | App distribution, Sign in with Apple, App Store payments, push notifications | What Apple needs to deliver each function | United States and EU |
| Google LLC (Sign-In) | OAuth authentication if you choose Google | OAuth ID token, your email and name claims | United States |
| Google LLC (Analytics) | Website usage measurement on www.traulo.com, only with your consent | Pages viewed, approximate location derived from a truncated IP, browser and device type. Advertising features disabled. Not linked to your Traulo account. | United States |
| Jamendo SA | Music catalog search | Anonymous mood / activity / location keywords. No PII. | Luxembourg (EU) |
| Travelpayouts (Go Travel Un Limited) | Affiliate-link generation and click attribution for booking suggestions | A pseudonymous attribution code identifying the guide and its creator (not the clicking user); destination keywords. No clicking-user identity. | Cyprus (EU) and United States |
| Travel-inventory partners (incl. LiteAPI for stays, Aviasales for flights) | Supplying the accommodation and flight options and prices shown in guides | Destination place names and coordinates; home-region airports. No PII. | EU and United States |
| Nuitée Ltd (LiteAPI) — as our booking partner when you book a stay in the app (§2.12) | Placing the booking with the hotel, holding it in your name, taking the payment through its PCI-compliant payment provider, and reporting the booking's status back to us | Booking holder's name, email and optional phone; guests' names and emails; the stay (hotel, dates, room, price); pseudonymous booking tags (your account, plan and guide identifiers). Card details go from your browser to Nuitée's payment provider (Stripe) and never to us. The hotel receives the holder and guest details it needs to host you. | Ireland (EU); Stripe in Ireland and the United States |
| The hotel you book (independent controller) | Hosting you | The holder's and guests' names and contact details, children's ages and the stay, received from Nuitée | Wherever the hotel is; see §6 |
| Mapbox, Inc. | Map tiles, 3D terrain and tour-video rendering for trip-guide maps | Map-tile and styling requests, including the map area being viewed (approximate location) and your IP address | United States |
| Map, place and weather services (independent providers) | Answering look-ups that plans, walks and maps need | From our servers: map areas to the OpenStreetMap Overpass service (FOSSGIS e.V., Germany, and overpass.kumi.systems); place names and search text to the Photon geocoder (komoot, Germany) and to Apple's Maps Server API; place names to Wikipedia and Wikimedia Commons (Wikimedia Foundation) for place summaries and photos — none with your identity. From your device or browser: the plan's area and dates to Open-Meteo (weather); map areas to OpenStreetMap Overpass, to Amazon Web Services terrain tiles (walk heights), to Mapbox and to Esri (satellite imagery on the website); and, on the website, your IP address to ipapi.co or ipwho.is (§2.11) — each of these sees your IP address | EU (Germany, Austria) and United States |
| Traulo authorised staff | Content moderation, technical support at user request, legal compliance | Cloud-stored vlog video files and thumbnails — accessed only in the strictly limited circumstances described below | Slovenia (EU) |
Staff access to private content. Your cloud-saved vlogs are encrypted at rest and are not browsed by staff in the ordinary course of business. An authorised administrator may access the content of a specific vlog only in the following three circumstances: (a) investigating a credible report of illegal or harmful content submitted through the in-app reporting flow or by a competent authority; (b) responding to a valid legal order or binding request from a law-enforcement or judicial authority; or (c) diagnosing a technical fault at your express written request to
[email protected]. Every access is recorded in an audit log — which staff member, which vlog, the timestamp, and the reason. You may request a copy of the audit log relating to your own content at any time by writing to[email protected].
We may also disclose personal data (a) to comply with a legally binding request from a competent authority, (b) to protect our or others' rights, property or safety, (c) in connection with a corporate transaction (merger, acquisition or sale of assets), in which case the recipient will be bound by privacy commitments at least as protective as these.
Booking partners you are redirected to. When you tap a booking suggestion you may be sent to an independent travel provider — for example Booking.com, Agoda, Klook, Tiqets or Airalo. Once you leave Traulo these providers are not our processors: they act as independent controllers under their own privacy policies. We do not pass identifying information about you to them; any data they hold about you results from your own interaction with their website or app.
6. International transfers
Some of our processors are based outside the European Economic Area, primarily in the United States. When we send personal data there we rely on the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) under GDPR Chapter V, supplemented by additional safeguards where appropriate. You can ask us for a copy of these clauses by writing to [email protected].
For the United States specifically, we additionally rely on the EU–US Data Privacy Framework where the recipient is certified.
When you book a stay at a hotel outside the European Economic Area, your booking details must go to that hotel for it to host you. That transfer is necessary for the contract you asked for, and we rely on GDPR Article 49(1)(b). The hotel then handles your details under the law where it is.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account, profile, billing | For the life of your account, then 30 days soft-delete grace, then permanent erasure |
| Cloud-saved vlogs and avatars | Until you delete them, or until your account is permanently erased |
| Publicly shared vlogs within your free 1 GB allowance | Kept for as long as they remain publicly shared on your account, whether or not you have ever held a paid plan. If you remove one from the cloud (download & make private) or delete it, our copy is deleted per the deletion rows below |
| Cloud-saved vlogs above your allowance after a paid plan ends | When a subscription lapses, is cancelled and expires, or is downgraded, we keep your public vlogs, newest first, up to the free 1 GB (which applies to public vlogs only). Everything else — the excess and all private vlogs — is soft-deleted (hidden, recoverable) and permanently erased 30 days later, after warnings at the start of that window and again 7 days and 1 day before erasure, unless you resubscribe within it (Terms §8.7) |
| Comments | Until you or the vlog's creator delete them, or your account is permanently erased |
| Companion tags, POV references and trip-group membership | Until a participant removes the tag or leaves the trip group, or the account is permanently erased |
| Trip plans and guides, and photos attached to them | Until you delete them or your account is permanently erased; a published guide is kept after your account or subscription changes (Terms §8.8) until you delete the guide |
| Saved-guide (bookmark) records, guide-lineage links and place credits | Until you remove the save or the link, or your account is permanently erased |
| Affiliate click log | Up to 24 months for earnings and accounting; contains no clicking-user identity and may be retained in aggregated, de-identified form beyond account deletion |
| Hotel bookings made in the app (the stay, amounts, references, confirmation number, plan and guide identifiers) and creator earnings | 10 years from the booking, as Slovenian accounting and tax rules require; after your account is erased the record keeps only the pseudonymous references |
| Booking holder and guest details | Not stored on our servers. Held by the booking partner and the hotel under their own policies; kept on your device until you clear them |
| Private trip plans (including costs, ideas, notes and photos members added) | Until the owner deletes the plan (restorable for 30 days, then erased) or the owner's account is permanently erased |
| Plan membership and invitations | Membership: while the plan exists (a member who left or was removed is kept as "former member" so the plan's history reads correctly). Invite links: expire after 30 days or when revoked |
| Shared-plan activity and undo history | 90 days (monthly partitions are dropped) |
| Correspondence about a booking | As long as the booking record |
| Sessions and refresh tokens | 30 days, or until revoked |
| Auto-select telemetry events | 30 days (monthly partitions are dropped) |
| Auto-select aggregate rollups | Up to 2 years (no per-user data) |
| Feed and viewing activity (one row per viewer per post) | 90 days |
| AI call logs | 12 months for cost and abuse analysis, then aggregated |
| Abuse signals | 24 months |
| Crash diagnostics (Firebase) | Per Firebase's retention — typically 90 days for crashes, 30 days for performance |
| Acceptance records (legal documents) | For the lifetime of your account, plus 6 years after deletion (Slovenian limitation period for civil claims) |
| Backups | Encrypted off-site backups, rotated within 30 days |
When you delete your account we erase or anonymise your personal data within 30 days unless we are legally required to keep it longer (for example, billing records under Slovenian tax law).
Private cloud backup is a paid feature. If a paid plan lapses, is cancelled and then expires, or is downgraded, we keep your public vlogs up to the free 1 GB as described in the table above and in Terms §8.7; the rest — public vlogs above that allowance and all private vlogs — are soft-deleted (hidden from your feed but recoverable) and permanently erased 30 days later. Resubscribing within those 30 days restores them. Vlogs saved on your device are never affected, and you can download your cloud vlogs to your device at any time before the 30 days elapse.
8. Your rights
Under the GDPR you have the rights to:
- Access the personal data we hold about you (Art. 15) — in-app at Settings → Account → Export my data, or by emailing
[email protected]. The in-app export does not yet include your trip plans, plan memberships and bookings; ask us at[email protected]and we will send them to you within the time below - Rectify inaccurate or incomplete data (Art. 16) — most fields are editable in Settings → Account; for the rest, email us
- Erase your data, the "right to be forgotten" (Art. 17) — in-app at Settings → Account → Delete my account, or by email
- Restrict processing while a dispute is being resolved (Art. 18)
- Receive a portable copy in a structured, machine-readable format (Art. 20) — same export as above
- Object to processing based on legitimate interests, including profiling (Art. 21)
- Withdraw consent at any time, where processing is based on your consent (Art. 7(3)) — without affecting lawfulness of processing before withdrawal
- Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects (Art. 22) — see Section 4
- Lodge a complaint with a supervisory authority (Art. 77)
To exercise any right, write to [email protected]. We will respond within one month of receiving your request (extendable by two further months for complex requests, in which case we will tell you why). Most requests are free; we may charge a reasonable fee or refuse to act on manifestly unfounded or excessive requests as permitted by GDPR Article 12(5).
If you believe we have not handled your data correctly, you can complain to the Slovenian supervisory authority:
Informacijski pooblaščenec RS Dunajska cesta 22, 1000 Ljubljana, Slovenia Phone: +386 (0)1 230 9730 Web: https://www.ip-rs.si
You may also contact the supervisory authority of your EU country of residence.
9. How to delete your account
You can delete your account at any time:
- In the app: Settings → Account → Delete my account. We will ask you to confirm.
- By email: write to
[email protected]from the address on your account.
After confirmation, your account enters a 30-day grace period during which you can sign back in to recover it. After 30 days we permanently erase or anonymise your personal data. That includes the private plans you own — so before you delete your account, tell the members of any shared plan you own, because they will lose it — and your membership of other people's plans, where what you added stays shown as coming from a former member. Booking records are kept for the accounting period in §7 with only pseudonymous references; deleting your account does not cancel a booking — cancel it first if you no longer need it. Some data may be retained beyond that window when we are legally required to keep it (for example, billing records under Slovenian tax law) — those records are kept only for the legally required period and only for the legally required purpose.
10. Children
Traulo is not directed at users under 15 years of age, which is the digital-consent age in Slovenia under ZVOP-2 (implementing GDPR Art. 8). We do not knowingly collect personal data from anyone under 15. If you believe a child under 15 has provided us with personal data, please contact us at [email protected] and we will delete it.
For users under the age of 18 (the age of majority in Slovenia), parental authorisation may also be required for in-app purchases under the Slovenian Civil Code (OZ).
11. Security
We protect your personal data using:
- Encryption in transit — HTTPS / TLS 1.2 or higher for all client–server traffic
- Encryption at rest — Postgres data encryption and Cloudflare R2 object encryption
- Authentication — Sign in with Apple, Google Sign-In, or passkey-based two-factor authentication for high-risk actions
- Access control — admin access requires passkeys, an IP allow-list, and full audit logging
- Operational hardening — least-privilege roles, dependency scanning, and regular review of our security posture
No system is perfectly secure. We continually work to improve our defences and to detect, contain and notify in the event of an incident.
12. Data breach notification
If we become aware of a personal data breach within the meaning of GDPR Article 4(12), we will:
- Notify the Slovenian Information Commissioner (Informacijski pooblaščenec RS) within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to your rights and freedoms (GDPR Art. 33).
- Notify affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34), describing the nature of the breach, the likely consequences and the measures taken or proposed.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we publish the new version on www.traulo.com/privacy together with the new effective date and an archive of all previous versions.
For material changes — for example, a new processor receiving sensitive data, a new processing purpose, or a change to your rights — we will ask you to review and accept the updated Policy in the app before you can continue using Traulo. For non-material changes (typo fixes, clarifications) we publish the new version without asking for re-acceptance, but you can always read the current text and the change log on the website.
We keep a permanent record of which version of this Policy you accepted and when, so we can demonstrate compliance.
14. Contact
For any privacy question or to exercise any of your rights:
- Email:
[email protected] - Post: Računalniške storitve REK, Mihael Rek s.p., Ulica heroja Jevtiča 5, 2000 Maribor, Slovenia
For complaints you cannot resolve with us, please contact the Informacijski pooblaščenec RS as described in Section 8.
This Privacy Policy is also available in Slovenian at https://www.traulo.com/privacy?locale=sl. In case of any discrepancy between the English and Slovenian versions, the Slovenian version prevails for users domiciled in Slovenia.