Privacy Policy

Last updated: 7 September 2026

Ler em português · Leer en español

The honest summary: your trip stays on your device. You use the app with no sign-up at all — an account only comes into existence if you want cloud backup, trip sharing or flight watching. Your documents are not sent to us, with one exception that is yours to make: if you turn on backup, the file holding them goes to our server because you sent it. Everything that leaves the device, and when, is listed below.

1. Who we are

VoyageFy is a trip organiser app. The party responsible for the data described here is:

2. What stays on your device only

This data is written to the app's private storage. It is not sent to us — the only way it leaves the device is if you ask for cloud backup or share a trip, and both are explained in section 6:

Document edge detection, when you scan, happens inside the device, through the operating system itself — ML Kit on Android and VisionKit on iOS. Creating a trip, attaching a document, opening the PDF at the airport, scanning, logging an expense and getting a reminder all work with no internet.

3. When an account exists

Using the app requires no account. You install it and start. An account exists for four features that depend on our server and only work if it knows whose is what: cloud backup, trip sharing, flight watching, and counting how many AI readings you have used.

There are two ways in, and you choose: a six-digit code sent to your email, or signing in with Google or with Apple (section 4). There is no password — a password in a travel app tends to be a password recycled from somewhere else, which would turn a leak of ours into somebody's bank problem.

Of the account itself, we keep:

Of what keeps you signed in we keep only the cryptographic hash: neither the six-digit code nor the session token exists in our database in readable form. A database dump cannot become access to anybody's account. The sign-in code is valid for ten minutes, dies on first use and allows at most five attempts.

We also keep, per session, the device identifier generated by the app itself and the platform (Android or iOS) — that is what lets you sign out of one specific device.

4. Signing in with Google or Apple

If you choose that path, the party checking who you are is Google or Apple. Your password never passes through us — the app receives a signed assertion from the provider and our server only verifies the signature.

From that assertion we read and keep two things:

We request only the basic identification permissions (openid, email and public profile). We do not ask for, and do not have, access to your contacts, your calendar, your Drive, your photos or any other data in your Google or Apple account.

If you use Apple's Hide My Email, the address we receive is the relay address it creates — and that is the only one we keep.

5. Subscriptions

Paid plans are charged by the App Store or Google Play. Payment happens entirely inside the store: we do not see and do not receive card numbers, billing addresses or bank details.

To know whether a subscription is active we use RevenueCat, which receives an anonymous purchase identifier and the subscription state from the store. That identifier carries neither your name nor your email.

6. What leaves the device, and when

Every situation below is started by you. The first four happen without an account; the last four only exist if you created one.

Destination photo

When you create a destination, the app looks for a photo of the city. Only the city name is sent — first to Unsplash and, if there is no result, to Wikimedia Commons. No other data from your trip goes with that search. The photo is saved on the device so it works offline afterwards.

Exchange rates

The app asks our server for the day's rate table, which it gets from a public exchange-rate provider. Nothing of yours goes in that call — it is the same table for everybody, and the server caches it precisely so it does not have to ask the provider once per person.

Weather forecast

When you check the weather for a destination, the coordinates of that destination are sent to our server, which asks Open-Meteo. These are the coordinates of the city on your itinerary — not your location. The app neither asks for nor uses the location permission.

Flight status

When you check a flight, the flight number and date go to our server, which asks an aviation data provider. The answer is cached per flight, not per person: everybody on the same flight shares one lookup, and the provider receives nothing that identifies you.

AI document reading

An optional feature, part of the paid plans. When you tap to fill in an expense or an itinerary item from a document, text recognition happens on your device and only the already recognised text is sent to our server, over an encrypted connection. Our server passes that text to Google's artificial intelligence service (Gemini) purely to extract the fields, and returns the result.

The document image never leaves the device. Neither we nor Google keep that text to train a model. We do not store the content sent: it is used to answer and discarded. What does get stored is only a counter — how many readings you have used in the period — with no fragment of the document.

Cloud backup

This is the one case where your documents leave the device, and it only happens when you ask. The .voyage file holds your trips and the attachments — including photos of documents — and is sent to our server over an encrypted connection, in chunks, so it survives a poor network.

We keep one backup per account: the most recent one. It sits in a per-account folder on the server's disk, and access is restricted to your authenticated session. Be clear with yourself about what that means: the file is not end-to-end encrypted. There is no password of yours that only you know — if there were, losing it would mean losing the backup, which is the exact opposite of what a backup is for. In exchange, whoever administers the server would be able to open the file. If that trade does not suit you, do not turn cloud backup on: the app is complete without it, and you can export the .voyage file wherever you like.

Deleting the backup in the app deletes the file from our server.

Sharing a trip

When you share a trip, that trip — and only that one — is sent to our server, along with the email address of the person you invited. The recipient downloads a copy; there is no two-way editing.

Inviting somebody means handing that person the contents of that trip, attachments included. Invite with the same judgement you would apply to sending the files by message. Revoking the invitation, or deleting the trip from the server, removes their access and removes the file from our side — but it does not erase what they have already downloaded onto their device.

If you were invited and the invitation arrived for an email address that does not have an account yet, we keep that address until the invitation is accepted, declined or revoked.

Flight watching

You ask the server to follow a flight. We keep the flight number, the date, the departure time and the label you gave it (for example, "outbound to Lisbon"). The server asks the aviation data provider from time to time and records the changes — gate, terminal, baggage belt, status and delay — so it can tell you. The provider receives only the flight number and date.

Push notifications

For flight watching to tell you anything, the app registers with our server the device's notification token and the chosen language. The token is generated by the operating system, changes when you reinstall, and does not identify you outside the notification service. It is sent to Firebase Cloud Messaging (Android) or to Apple's push notification service (iOS) to deliver the alert. The alert text is written on our server and contains no document and no expense data.

7. Who the data is shared with

We do not sell, rent or trade data. The third parties below receive only what the entry says, only to provide the service described:

We may also hand over data if legally compelled by a competent authority. If that happens and we are allowed to say so, we will tell you.

8. Where the data lives

The VoyageFy server is in France, in the European Union (Contabo GmbH). If you are in Brazil, that is an international data transfer: it goes to a country with a recognised adequate level of protection, and it is made on the basis of performing the contract between you and us — under article 33 of the Brazilian LGPD.

9. How long we keep it

10. What we do not do

11. Permissions the app asks for

The app does not ask for location, contacts, microphone, the phone's calendar, or access to your gallery beyond a file you pick yourself.

12. Your rights, and how to delete the account

If you never created an account, there is nothing of ours to look up or delete: control is entirely yours, and uninstalling the app erases everything.

If you do have an account, you may at any time confirm, correct, obtain a copy of, or delete what we hold. To delete, write from inside the app or to suporte@voyagefy.com from the account's email address. We delete within 15 days: the account, the backup, the shared trips, the watched flights, the counters and the sessions. It is permanent and not reversible — download your backup first if you still want the data.

These rights are set out in the Brazilian LGPD (Law 13.709/2018) and in the GDPR. If you are not satisfied with our answer, you may complain to the ANPD in Brazil, or to the data protection authority in your country.

13. Security

All traffic between the app and the server is encrypted (TLS). The sign-in code and the session token are stored only as a cryptographic hash. Backups and shared trips sit in per-account folders, reachable only by the authenticated session of whoever owns them.

No system is perfectly secure, and promising otherwise would be a lie. If an incident affects your data, we will tell you and the competent authority as the law requires.

14. Children

VoyageFy is not directed at children under 13 and does not knowingly collect data from children.

15. Changes to this policy

If something changes materially — a new service receiving data, for instance — we update this page and the date at the top. It is worth re-reading after a large app update.