What vacayi collects, why, and what it never does.
Last updated: 10 September 2026 Effective: on first publication at https://vacayi.app/privacy
vacayi is operated by Vacayi LLC, a limited liability company formed in the Commonwealth of Massachusetts, United States.
For anything in this policy, or to exercise any right described in it, contact support@vacayi.app.
For users in the EEA or UK, Vacayi LLC is the controller of the information described here.
Everything below is collected because a feature needs it. Nothing here is collected "just in case".
| What | Why | Where it comes from |
|---|---|---|
| Email address and password | To sign you in and recover your account | You, at sign-up |
| Display name | To greet you, and to show collaborators who you are | You |
| Optional @handle, and whether you are discoverable | So a friend can find you to share a trip. Off by default | You |
| Your device's time zone | So a "your trip starts tomorrow" notification arrives at a sensible hour where you are, not where the trip is | Your device, on launch |
This is the part that makes a guide personal, and the part we treat most carefully.
| What | Why |
|---|---|
| A first name or nickname for each traveller | So the guide can speak about them ("a quieter afternoon for Ana") |
| An age range — for example toddler (18–24 months) or 65+ | To pace the days: nap windows, walking distances, how far apart stops can be |
| Interests | To pick things they will actually enjoy |
| Mobility needs | To route around stairs and long walks |
| Free-text notes you choose to add | Anything else you want the guide to know |
| Pets: name, species, size | To find places that will let them in |
We ask for an age RANGE, never a date of birth or an exact age. The guide only ever needs to know which band someone falls into, so that is all we store. The AI is never told a number either — it receives the band.
A word about the free-text boxes. Notes are yours to fill and we do not police them, which means health details can end up there even though the structured fields deliberately keep them at the level of the whole party. Write what the guide genuinely needs, and leave out what it does not.
Your trip carries a single list of the whole party's dietary requirements, allergies and accessibility needs — not one per person. We deliberately do not record which traveller an allergy belongs to.
This information exists so a guide does not send you somewhere you cannot eat or cannot get into. It is used to shape restaurant choices and to add reminders to your packing list.
In some places, including the EEA and the UK, this counts as health-related information and gets extra protection.
These fields are optional — every one of them can be left empty, and vacayi works without them; you simply get a guide that knows less about you. You can remove them at any time by clearing the fields, and the next guide you make will not use them.
Destination, starting point, dates, arrival and departure times, lodging, budget, occasion, and any notes you write. Plus the guides we generate for you, which are stored so you can open them again and download them for offline use.
You can attach booking screenshots to a trip so the AI can read your confirmed flights and hotels.
Please read this one. A booking confirmation usually contains other people's information — a travelling companion's name, a flight number, an address. When you upload it, that information is sent to our AI providers along with everything else. Only upload what you are comfortable sharing, and consider covering anything that is not yours.
We keep them for as long as the trip exists, not just until the guide is built. That is deliberate: rebuilding a guide reads your confirmations again, so the flights and hotels you attached stay in the new one instead of being lost. They are deleted when you delete the trip, and when you delete your account.
When you ask the in-guide assistant a question or request a change, we store the request and the reply so the conversation is still there when you come back, and so a request survives closing the app.
We read these. Not routinely and not for advertising — but when someone reports that a guide got something wrong, that message is how we find and fix it. Please do not put anything in a chat message that you would not want a person at vacayi to read.
Credits and subscriptions are bought through Apple's or Google's payment systems. We never see or receive your card details. We receive a confirmation that a purchase happened, an identifier for it, and which product it was, so we can add the credits to your account.
We keep a record of credits added and spent. Some of this is financial record-keeping we are required to retain even after you delete your account — see section 8.
If you turn them on, we store a push token for your device so we can tell you your guide is ready. Preferences are per-category and you can switch any of them off.
Optional, and it never leaves your phone. The guide map has a "Where am I?" button. If you use it, your device's location is drawn on the map on your device. It is not sent to us, not stored, and not shared. Decline the permission and everything else still works.
Photos stay on your phone unless you share them. vacayi can look at when and where your photos were taken to place them in your own guide — that happens on your device, and nothing is uploaded.
If you choose to share a photo to a trip, that photo is stored on our servers so the other people on that trip can see it. What we store: a reduced-size copy of the photo, a small thumbnail, which stop and day of the trip it belongs to, and who shared it. We remove the photo's hidden location data (GPS) before it is stored — we re-encode the image, which drops it — so the trip placement is the only location-shaped fact we keep.
Who can see it: only the people on that trip — the owner and the collaborators they invited. Shared photos are never public and are never used for anything except showing them to the trip's members.
How it leaves: you can delete a photo you shared at any time, and it is removed for everyone. The trip's owner can remove any photo on their trip. If a photo should not be there, anyone on the trip can report it from the photo itself: it is hidden for them at once, and it is removed for everyone automatically — immediately if a second person reports it, and otherwise within 24 hours unless the trip's owner reviews it and keeps it. If you leave a trip or are removed from it, the photos you shared are removed with you. Deleting a trip deletes its photos; deleting your account deletes every photo you ever shared.
If you report a photo, we record that you were one of the people who reported it. We have to, in order to count reports and to stop the same person reporting twice — but we keep it somewhere nobody can read, including the person who shared the photo and including the trip's owner. It is deliberately not possible for someone to find out who reported them.
Your progress through a guide. Ticking a stop, a packing item, a quest or a booking is stored so it is still ticked on your other devices and, on a shared trip, so the people you are travelling with can see what is done. We also count these in aggregate — what fraction of a guide's stops get ticked — to judge whether guides are actually useful. That counting is about guides, not about people.
Your idea list. Places and ideas you save for "one day", with whatever note, tags and destination you add. If you save one by sharing a link from TikTok, Instagram, YouTube or Facebook, we store that link, and the post's caption is sent to our AI provider once so it can work out which place you meant. We do not follow you on those platforms and we receive nothing else from them.
If you share a trip, the people on it produce a shared record together, and we store it: comments, checklist items, reactions, and an activity feed of what changed and who changed it. Each of those carries who wrote it, because a shared list nobody is accountable for is not much use.
We also store, for you alone: which trips you have starred, when you last looked at a trip, and whether you have muted its notifications.
Live presence. While you have a shared trip open, the other people on it can see that you are there — and, so that two people do not unknowingly edit the same thing, that you are typing or editing. This is sent live to the other people on that trip and is not stored: it disappears when you close the trip, and a few minutes of silence turns it into "active a few minutes ago". Only people you have shared the trip with ever see it.
If you send a support message or report a mistake in a guide, we store what you wrote, the address you want a reply at, and a small technical snapshot taken at that moment: your app version, platform and operating system, your language and region, whether you were offline, and your credit balance. It is there so the first reply can be an answer rather than five questions.
If you rate a guide or tell us what went wrong with it, we store that too — it is the main way we find out that something is broken.
Two of these are worth naming because they are copies of things you might expect to exist only once:
We also keep a cached translation of a guide when a collaborator reads it in another language, the short "crafting" messages shown while a guide is being built, and records of each build for cost and reliability. All of it is deleted with the trip or the account.
Stated plainly because these are the things people most often assume:
Some links in your guide go to booking sites that pay us a commission (see the Terms). Tapping one passes through our own redirect, so we should be exact about what that does.
What we record: a counter row, and nothing that is about you. It says a booking link of a certain type was tapped, for a certain destination, in a certain language — "a hotel link for Lisbon, in English". It carries no account, no trip, no name, no IP address and no device identifier, and there is nothing in it that could be traced back to you or joined to anything else we hold. We keep it to learn which parts of a guide are useful, which is the only question it can answer.
What happens next is the booking site's, not ours. Once you leave, the booking network typically sets a cookie on their site so that a booking made later can be credited to us. That processing is theirs and is governed by their privacy policy, not this one. We do not receive your name, your email, your payment details, or what you booked — a commission report tells us that a booking happened, never who made it.
What the link itself carries, which is the part most people would want to know. So that a hotel search opens on the right rooms rather than on a stranger's default of two adults, a hotel link passes the booking site how many adults and how many children are travelling, your dates, and the hotel's own name and coordinates. It carries no names, no ages, nothing about allergies, mobility or diet, and nothing identifying you or your account. Other kinds of link (a car, a tour, a transfer) carry the place and the dates and no party details at all.
You can simply not tap them. Nothing about a guide depends on it, and no part of the app behaves differently either way.
We use a small number of service providers. Each gets only what its job requires.
| Provider | What it receives | What for |
|---|---|---|
| Supabase | Account, crew, trips, guides, images | Database, sign-in and file storage |
| Anthropic (Claude) | Trip details, crew, party-level dietary and accessibility needs, your assistant messages, uploaded images | Writing your guide and answering your questions |
| Google (Gemini, Maps Platform) | Trip details and crew for planning; place names and coordinates for grounding; uploaded images | Planning the itinerary, verifying that places are real, maps, weather |
| Railway | Everything the guide builder touches | Runs the guide-building worker |
| Expo | Your push token and the notification text | Delivering notifications |
| RevenueCat | Your user id and purchase events | Confirming purchases so credits arrive |
| Apple / Google | Payment details, which we never see | Taking the payment |
The rest of what we call gets a destination, a coordinate or a date, and nothing about you — no name, no account, no crew, nothing from section 2.2 or 2.3. We name them anyway, because "some third-party APIs" is not a disclosure:
| Service | What it receives |
|---|---|
| Google (Places, Routes, Weather, Time Zone, Elevation) | Place names and coordinates |
| Ticketmaster (Discovery) | A coordinate and your trip's dates, to find what is on |
| Viator | A destination, to find tours |
| Unsplash | The destination's name, for the photo on your trip card |
| ExchangeRate-API | A currency code, to show prices in your own money |
| OpenStreetMap, MapTiler, Geoapify | Coordinates, for the map drawing |
| OpenHolidaysAPI, Nager.Date | A country and dates, for public holidays |
| TikTok, YouTube, Meta | Only a link you chose to share with us, to read its caption |
We also read the public websites of places in your guide — a hotel's own page, a restaurant's own page — so the guide can tell you things their listing does not, such as which of a resort's restaurants are included. We only ever read pages that are public, we only quote them word for word, and those sites receive a request from our server with nothing about you in it.
When you tap a booking link we pass you to one of these, with the information described in section 3: Stay22, Travelpayouts (and through it partners such as Aviasales, Localrent, Kiwitaxi, Welcome Pickups, Klook, Tiqets and Yesim), Viator, and Impact for event tickets. What each does once you arrive is governed by their own privacy policy, not this one.
Beyond all of these, we share information only where the law requires it, or to protect someone's safety.
When you share a trip, the person you share it with can see the trip, the guide, the map, the shared checklist, the comments and reactions, the activity feed of what changed, any photos shared to that trip, and — while you both have it open — that you are there and are typing or editing. That includes the party-level dietary and accessibility needs written into the guide, because those shape the recommendations.
Anything you do on a shared trip is attributed to you by name: a comment, a ticked item, an edit to the guide. That is the point of sharing one, but it is worth saying plainly.
They cannot see your crew list, anyone's age range, your other trips, or your account details. Sharing is per-trip and you can revoke it at any time.
The app shows you this before you share.
Our database is hosted in Canada. Our AI providers process in the United States.
If you are in the EEA or UK, that means your information is transferred outside your region. Where required we rely on the European Commission's adequacy decision for Canada and on Standard Contractual Clauses with our US providers.
vacayi's guides are written by AI. Three things follow that we would rather say than have you discover:
vacayi is for adults. You must be 18 or over to hold an account, and we do not knowingly let children create one. We do not ask for a date of birth, so this is a condition of use rather than something we verify.
We do let you describe children who are travelling with you, because a guide that does not know there is a toddler is a guide that will exhaust you. For those children we store a first name or nickname and an age range — nothing more precise, and nothing that identifies them beyond your own account.
If you believe a child has created an account, contact support@vacayi.app and we will remove it.
| What | How long |
|---|---|
| Account, crew, trips and guides | Until you delete them, or delete your account |
| Uploaded booking images | With the trip — a rebuild reads them again (see 2.5). Deleted with the trip, and with your account |
| Photos shared to a trip | Until you delete the photo, leave the trip, or the trip or your account is deleted. A reported photo goes within 24 hours unless the owner keeps it |
| Assistant conversations | With the trip, until you delete it |
| Comments, checklist items, reactions, the activity feed | With the trip. See section 9a for what happens to ones you left on someone else's trip |
| Progress, stars, read state, mute | With the trip |
| Your idea list | Until you delete an entry, or delete your account |
| Undo snapshots — automatic repairs | 30 days |
| Undo snapshots — changes a person made, and earlier versions of a guide | With the trip |
| Live presence (that you are here, typing, editing) | Never stored. It exists only while the trip is open and expires within minutes |
| Cached translations, crafting messages, build records | With the trip |
| Support messages and guide feedback | Until you delete your account |
| Push tokens | Until you turn notifications off, sign out, or the device stops accepting them |
| Credit balance, charges and generation records | Deleted with your account |
| Store purchase notifications | Kept with your user ID removed — they record a transaction Apple, Google or RevenueCat also hold, and cannot be linked back to you |
Wherever you are, you can:
If you are in the EEA or UK you also have the right to object to processing, to restrict it, to withdraw consent at any time, and to complain to your data protection authority.
If you are in California you have the right to know, delete, correct, and to opt out of sale or sharing — we do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any right. Because we do not sell or share personal information, there is nothing for a Global Privacy Control signal to switch off; we honour it by never having started.
To exercise anything here, use the app or email support@vacayi.app. We respond within 30 days.
You can delete your account and everything in it at any time, and you do not need the app installed to ask.
In the app — Settings → Delete my account. It takes effect immediately.
Without the app — email support@vacayi.app from the address your account uses, with the subject Delete my account. We will confirm and complete it within 30 days, and usually the same week. If you can no longer send mail from that address, write from any address and we will verify another way before deleting anything.
Very little, and none of it names you. Your credit balance, every charge against it, and the records of each guide being built are all deleted with your account. There are two exceptions, and both keep the text while removing you from it.
What you wrote on someone else's trip stays on their trip, with your name taken off. A comment, a checklist item you added or ticked, and the line in the activity feed recording a change you made all survive — as anonymous entries, permanently unlinked from you. We do it this way because the alternative is worse for the people you travelled with: deleting your account would silently tear items out of a shared list they are still using. If you want something you wrote removed as well as anonymised, delete it before you delete your account, or ask us and we will.
The log of purchase notifications sent to us by Apple, Google or RevenueCat. We keep those, with your user ID removed, because they record a transaction those companies also hold and it is how a payment dispute gets resolved months later. Once your account is gone they cannot be connected back to you.
Aggregate counts that never identified anyone — how many guides were built in a month — also remain. Nothing kept can be used to identify or contact you, and none of it can rebuild an account.
Deleting your account forfeits any unused credits, and they cannot be restored or transferred afterwards. If you have a Pro subscription, cancel it in your device's App Store or Google Play settings — deleting your vacayi account does not cancel a store subscription, and we cannot cancel it for you.
Access to your data is enforced at the database level, so one account cannot read another's even if the app is modified. Guides are kept in private storage and served through expiring links. Payment card details never reach us.
No system is perfectly secure, and we will not claim otherwise. If a breach affects you, we will tell you and the relevant authority as the law requires — in the EEA and UK that means notifying the supervisory authority within 72 hours of becoming aware of it, and telling you directly without undue delay where the risk to you is high.
If we change this policy materially we will tell you in the app before the change takes effect. The date at the top always shows the current version.
Vacayi LLC support@vacayi.app
Last updated 10 September 2026 · vacayi · Vacayi LLC