Privacy Policy
Last updated: July 10, 2026
Wayfaro is a trip-planning app for iOS, with this website as its companion. This policy explains what data we handle when you use Wayfaro, why we handle it, and the choices you have. The short version: there are no accounts, we never see your name or email, there is no advertising, and we never sell your data. We use one privacy-focused analytics tool (PostHog) to understand how the app is used and to catch crashes — nothing is ever sold or used for ads.
What we collect
Wayfaro has no user accounts. When you first open the app, a random anonymous user ID is created for your device (via Supabase anonymous sign-in). We never ask for your name, email address, phone number, or password.
- Trip preferences you enter during onboarding: destination, travel dates, who you're traveling with, travel style, budget level, and any special needs you describe in your own words.
- The itineraries Wayfaro generates for you.
- Purchase records for trip credits: the App Store transaction identifier and receipt, linked to your anonymous user ID. We never see your card number or billing address — payment is handled entirely by Apple.
- Basic technical data needed to operate the service, such as server request logs.
- If you email us, your email address and the contents of your message.
- Product analytics and error reports: which screens you visit, how far you get through onboarding, which features you use, your device model, OS and app version, and crash/error reports. These are linked to your user ID, not your name.
How we use your data
- To generate and deliver your personalized itinerary.
- To grant, reserve, and refund the trip credits you purchase.
- To operate, secure, and debug the service.
- To respond when you contact us.
- To understand how the app is used — for example where people abandon onboarding — so we can improve it, and to detect and fix crashes and errors.
That's it. We don't use your data for advertising, we don't build marketing profiles, and we never sell or share your personal data with data brokers. There are no advertising or ad-tracking SDKs in the app; the only third-party analytics service we use is PostHog, described below.
Who processes your data
To build an itinerary we rely on a small number of service providers. Your trip preferences are shared with them only to the extent needed, and never together with your name or contact details — we don't have them.
Supabase
Database, anonymous authentication, and storage. Cloud Postgres hosted in the EU/US.
Anonymous user ID, trip preferences, itineraries, credit balance
Apple (App Store)
Processes all in-app payments.
Your payment details (Apple never shares your card number with us)
RevenueCat
Validates purchase receipts and keeps your credit balance in sync.
App Store transaction IDs linked to your anonymous user ID
PostHog
Product analytics and error tracking (hosted in the US). Shows us how the app is used in aggregate and reports crashes and errors so we can fix them.
Usage events (screens viewed, onboarding progress, purchases), device model and OS version, error reports — linked to your user ID
OpenRouter
Provides the AI language model that drafts your itinerary.
Trip preferences and planning context (no identifying data)
Google Places
Looks up venues, addresses, and coordinates (server-side).
Destination and venue search queries
Firecrawl
Web search and page retrieval for live events and research (server-side).
Destination and activity search queries
OSRM
Calculates routes between itinerary stops (server-side).
Venue coordinates
Photon (komoot)
Powers destination autocomplete, called directly from your device.
The text you type into the destination search
Railway
Hosts our backend servers.
Data passing through our backend, including request logs
None of these providers is permitted to use your data for its own advertising.
Data retention
Your trip preferences and itineraries are kept for as long as your anonymous user ID exists, so the app can keep showing your trips. Purchase records are kept for as long as accounting and fraud-prevention obligations require. Server logs are kept for a short period for security and debugging.
When you request deletion, we delete everything linked to your anonymous user ID, except records we are legally required to keep.
Your rights
If you are in the European Economic Area or the United Kingdom, the GDPR gives you the right to:
- access the data we hold about you;
- have it corrected or deleted;
- receive a copy in a portable format;
- restrict or object to certain processing;
- lodge a complaint with your local data protection authority.
To exercise any of these rights — including full deletion of everything linked to your device — email privacy@wayfaro.app. Because Wayfaro accounts are anonymous, we may ask you for details from your app installation (such as your anonymous user ID) to locate your data. We honor deletion requests from everyone, not only where the law requires it.
Children
Wayfaro is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as Wayfaro evolves. We will post the new version on this page and update the date above. If a change is material, we will say so prominently in the app or on this site.
Contact
Wayfaro is operated by an independent developer based in France. For anything related to your data, email privacy@wayfaro.app.