Privacy Policy
Last updated: 7 September 2026
1. Who we are
VoyageFy is a trip organiser app. The party responsible for the data described here is:
- Trading name: Meigston Servicos Tech
- Company registration (CNPJ, Brazil): 32.598.125/0001-51
- Address: Rua 24 de Maio, 411, Conj. 201, Andar SB, Cond. Folador, Ed. Bloco Bl A — Rebouças, Curitiba/PR, 80220-060, Brazil
- Contact: suporte@voyagefy.com
2. What stays on your device only
This data is written to the app's private storage. It is not sent to us — the only way it leaves the device is if you ask for cloud backup or share a trip, and both are explained in section 6:
- your trips, destinations, dates and itinerary;
- the documents you attach — tickets, bookings, insurance, ID;
- the photos you scan with the camera;
- the schedule, the reminders and the packing list;
- expenses, budget, currency purchases and the settle-up between travellers;
- the name, email and photo of the companions you add;
- your name, your profile photo and your preferences.
Document edge detection, when you scan, happens inside the device, through the operating system itself — ML Kit on Android and VisionKit on iOS. Creating a trip, attaching a document, opening the PDF at the airport, scanning, logging an expense and getting a reminder all work with no internet.
3. When an account exists
Using the app requires no account. You install it and start. An account exists for four features that depend on our server and only work if it knows whose is what: cloud backup, trip sharing, flight watching, and counting how many AI readings you have used.
There are two ways in, and you choose: a six-digit code sent to your email, or signing in with Google or with Apple (section 4). There is no password — a password in a travel app tends to be a password recycled from somewhere else, which would turn a leak of ours into somebody's bank problem.
Of the account itself, we keep:
- your email — it is the account's address, and it is how somebody can share a trip with you;
- your name, if you provide it or if the social sign-in provider passes it along. It is optional and is there to write "so-and-so shared a trip with you";
- the date it was created and the date it was last used, so we know what can be discarded;
- how long Plus is valid for and the anonymous purchase identifier, which comes from the store and carries no name.
Of what keeps you signed in we keep only the cryptographic hash: neither the six-digit code nor the session token exists in our database in readable form. A database dump cannot become access to anybody's account. The sign-in code is valid for ten minutes, dies on first use and allows at most five attempts.
We also keep, per session, the device identifier generated by the app itself and the platform (Android or iOS) — that is what lets you sign out of one specific device.
4. Signing in with Google or Apple
If you choose that path, the party checking who you are is Google or Apple. Your password never passes through us — the app receives a signed assertion from the provider and our server only verifies the signature.
From that assertion we read and keep two things:
- the identifier the provider gives you inside VoyageFy — a code that is only good here, and that is what lets us recognise you next time;
- your email, and your name when the provider sends it.
We request only the basic identification permissions
(openid, email and public profile). We do not ask for, and
do not have, access to your contacts, your calendar, your Drive, your
photos or any other data in your Google or Apple account.
If you use Apple's Hide My Email, the address we receive is the relay address it creates — and that is the only one we keep.
5. Subscriptions
Paid plans are charged by the App Store or Google Play. Payment happens entirely inside the store: we do not see and do not receive card numbers, billing addresses or bank details.
To know whether a subscription is active we use RevenueCat, which receives an anonymous purchase identifier and the subscription state from the store. That identifier carries neither your name nor your email.
6. What leaves the device, and when
Every situation below is started by you. The first four happen without an account; the last four only exist if you created one.
Destination photo
When you create a destination, the app looks for a photo of the city. Only the city name is sent — first to Unsplash and, if there is no result, to Wikimedia Commons. No other data from your trip goes with that search. The photo is saved on the device so it works offline afterwards.
Exchange rates
The app asks our server for the day's rate table, which it gets from a public exchange-rate provider. Nothing of yours goes in that call — it is the same table for everybody, and the server caches it precisely so it does not have to ask the provider once per person.
Weather forecast
When you check the weather for a destination, the coordinates of that destination are sent to our server, which asks Open-Meteo. These are the coordinates of the city on your itinerary — not your location. The app neither asks for nor uses the location permission.
Flight status
When you check a flight, the flight number and date go to our server, which asks an aviation data provider. The answer is cached per flight, not per person: everybody on the same flight shares one lookup, and the provider receives nothing that identifies you.
AI document reading
An optional feature, part of the paid plans. When you tap to fill in an expense or an itinerary item from a document, text recognition happens on your device and only the already recognised text is sent to our server, over an encrypted connection. Our server passes that text to Google's artificial intelligence service (Gemini) purely to extract the fields, and returns the result.
The document image never leaves the device. Neither we nor Google keep that text to train a model. We do not store the content sent: it is used to answer and discarded. What does get stored is only a counter — how many readings you have used in the period — with no fragment of the document.
Cloud backup
This is the one case where your documents leave the
device, and it only happens when you ask. The
.voyage file holds your trips and the attachments —
including photos of documents — and is sent to our server over an
encrypted connection, in chunks, so it survives a poor network.
We keep one backup per account: the most recent one. It
sits in a per-account folder on the server's disk, and access is
restricted to your authenticated session. Be clear with yourself about
what that means: the file is not end-to-end encrypted.
There is no password of yours that only you know — if there were, losing
it would mean losing the backup, which is the exact opposite of what a
backup is for. In exchange, whoever administers the server
would be able to open the file. If that trade does not suit you,
do not turn cloud backup on: the app is complete without it, and you can
export the .voyage file wherever you like.
Deleting the backup in the app deletes the file from our server.
Sharing a trip
When you share a trip, that trip — and only that one — is sent to our server, along with the email address of the person you invited. The recipient downloads a copy; there is no two-way editing.
Inviting somebody means handing that person the contents of that trip, attachments included. Invite with the same judgement you would apply to sending the files by message. Revoking the invitation, or deleting the trip from the server, removes their access and removes the file from our side — but it does not erase what they have already downloaded onto their device.
If you were invited and the invitation arrived for an email address that does not have an account yet, we keep that address until the invitation is accepted, declined or revoked.
Flight watching
You ask the server to follow a flight. We keep the flight number, the date, the departure time and the label you gave it (for example, "outbound to Lisbon"). The server asks the aviation data provider from time to time and records the changes — gate, terminal, baggage belt, status and delay — so it can tell you. The provider receives only the flight number and date.
Push notifications
For flight watching to tell you anything, the app registers with our server the device's notification token and the chosen language. The token is generated by the operating system, changes when you reinstall, and does not identify you outside the notification service. It is sent to Firebase Cloud Messaging (Android) or to Apple's push notification service (iOS) to deliver the alert. The alert text is written on our server and contains no document and no expense data.
7. Who the data is shared with
We do not sell, rent or trade data. The third parties below receive only what the entry says, only to provide the service described:
- Unsplash and Wikimedia Commons — the city name.
- Open-Meteo — the coordinates of the city on the itinerary.
- Aviation data providers (AeroDataBox via RapidAPI, AviationStack, OpenSky) — the flight number and date.
- Google (Gemini) — the already recognised document text.
- Google and Apple — only when you choose to sign in with them, and the flow runs the other way: they hand us your identification, we hand them nothing.
- Firebase Cloud Messaging and Apple Push Notification service — the device token and the alert text.
- RevenueCat — the anonymous purchase identifier.
- The email provider we use to send the sign-in code — your address and the code.
- Contabo GmbH — the company hosting the server. It does not access the content; it operates the machine the content runs on.
We may also hand over data if legally compelled by a competent authority. If that happens and we are allowed to say so, we will tell you.
8. Where the data lives
The VoyageFy server is in France, in the European Union (Contabo GmbH). If you are in Brazil, that is an international data transfer: it goes to a country with a recognised adequate level of protection, and it is made on the basis of performing the contract between you and us — under article 33 of the Brazilian LGPD.
9. How long we keep it
- The account — for as long as it exists. You can ask for it to be deleted at any time (section 12).
- The backup — until you delete it or delete the account. We keep only the most recent one; a new upload replaces the previous.
- The shared trip — until you revoke the share or remove it from the server.
- The sign-in code — ten minutes, and it is discarded on use.
- The session — valid for 400 days, renewed on each use, and deleted when it expires or when you sign out.
- The changes on a watched flight — 30 days. A closed watch is deleted 30 days later.
- The notification token — 180 days without use, or immediately when the notification service says it is dead.
- The usage counters — previous months are discarded; the current one stays.
10. What we do not do
- We do not require a sign-up to use the app.
- We do not show ads.
- We use no analytics, tracking or profiling tools.
- We do not sell, rent or share data for advertising.
- We do not ask for, and do not have, your location.
- We receive no copy of your documents, unless you turn on cloud backup.
11. Permissions the app asks for
- Camera — to scan a document. The image is written to the app's private storage.
- Notifications — for check-in, check-out and layover reminders, scheduled on the device itself, and for flight-watch alerts, which come from our server.
- Biometrics — optional, to unlock the app. The party checking your face or fingerprint is the operating system; the app receives only a yes or a no, and no biometric data ever reaches it.
The app does not ask for location, contacts, microphone, the phone's calendar, or access to your gallery beyond a file you pick yourself.
12. Your rights, and how to delete the account
If you never created an account, there is nothing of ours to look up or delete: control is entirely yours, and uninstalling the app erases everything.
If you do have an account, you may at any time confirm, correct, obtain a copy of, or delete what we hold. To delete, write from inside the app or to suporte@voyagefy.com from the account's email address. We delete within 15 days: the account, the backup, the shared trips, the watched flights, the counters and the sessions. It is permanent and not reversible — download your backup first if you still want the data.
These rights are set out in the Brazilian LGPD (Law 13.709/2018) and in the GDPR. If you are not satisfied with our answer, you may complain to the ANPD in Brazil, or to the data protection authority in your country.
13. Security
All traffic between the app and the server is encrypted (TLS). The sign-in code and the session token are stored only as a cryptographic hash. Backups and shared trips sit in per-account folders, reachable only by the authenticated session of whoever owns them.
No system is perfectly secure, and promising otherwise would be a lie. If an incident affects your data, we will tell you and the competent authority as the law requires.
14. Children
VoyageFy is not directed at children under 13 and does not knowingly collect data from children.
15. Changes to this policy
If something changes materially — a new service receiving data, for instance — we update this page and the date at the top. It is worth re-reading after a large app update.