Trevel Privacy Policy
Last updated: August 23, 2026
Trevel is made by Trevel Technologies, Inc., a Delaware corporation (“Trevel,” “we,” “us”). This policy explains what information the Trevel app and the trevel.app website collect, why, who sees it, and the choices you have. We wrote it to be read, not skimmed — and where a promise is specific, it is because the app is built that way.
The short version
- Trevel is a passport for places you have actually been. To stamp a place, the app reads your phone’s location at the moment you press the stamp, and we keep that stamp (the place, the time, and the coordinates) in your account.
- Your photos stay on your phone unless you choose to attach one to a stamp. The optional photo-import feature reads only the location and date tags of your photos, on your device, and never uploads a photo.
- We do not sell your information, we do not run advertising, and we do not share your location with data brokers or advertisers.
- You can make your profile private, keep your photos private (the default), block and report people, turn off any notification, and delete your account from inside the app.
If anything here is unclear, email privacy@trevel.app.
1. Who this policy covers
This policy applies to the Trevel mobile app (iOS and, when available, Android), the trevel.app website, and any related services (together, the “Service”). It applies whether you use Trevel as a guest or with an account.
2. Information we collect
2.1 Information you give us
- Account details. When you create an account we receive your email address and a sign-in identifier from the provider you choose (Sign in with Apple, Google, or an email sign-in link). If you use Apple’s “Hide My Email,” we receive the relay address Apple gives us. You choose a username and may add a display name, a home country, and a profile picture.
- Guest mode. You can use Trevel without an account. A guest session gets a random identifier and no email. Guest data (your stamps and settings) lives on the same account record, so if you later create an account, your passport comes with you. Guests cannot be seen by other users, cannot follow or be followed, and cannot post photos.
- Photos you attach to stamps. When you take a photo inside Trevel to attach to a stamp, or later pick a photo from your library to add to a stamp you already earned, that photo is uploaded to our storage. We keep the original you uploaded (including its embedded location and time tags, which we use to help check that the stamp is real) and make resized copies for display; the copies we show to you and to other users have those tags removed, and the original is never shown to anyone.
- Places you tell us you’ve been. During onboarding (and any time from your Passport) you can mark places you visited before you had Trevel, by searching or tapping, or by using photo import (section 3). These are recorded as self-reported stamps.
- Profile and social content. Your username, display name, profile picture, the up-to-three photos you choose to showcase, the people you follow, and the people you block.
- Reports. If you report a user or a photo, we record who reported it, what was reported, the reason you selected, and any details you typed.
- Support messages. If you email us, we keep the message and your email address so we can reply.
- Waitlist. If you join the waitlist on trevel.app, we keep the email address you enter (and the date you joined) to send you your invite and, occasionally, news about Trevel. Every message includes a way to unsubscribe, and you can ask us to remove your address at any time.
2.2 Information collected automatically when you use Trevel
- Location when you stamp. Stamping is the core of Trevel. When you press “Stamp,” the app reads your phone’s current GPS position and sends it to our servers along with its accuracy. We store those coordinates, the timestamp, and which place they matched. A place you tapped on the map is treated as intent only — the coordinates always come from a fresh reading of your device.
- Location in the background (optional). After you have earned a few stamps, Trevel may ask for “Always” location permission so it can wake briefly when you arrive somewhere new and suggest a stamp. If you allow it, iOS wakes the app when you move a significant distance (roughly half a kilometer or more). On each wake the app sends your position to our servers to work out where you are and records a short “presence” entry (position, accuracy, time). Presence entries are deleted automatically after 24 hours. They are used only to help confirm that a stamp is real; they are never shown to anyone and never shared. You can turn background location off at any time in your phone’s Settings; Trevel works fully without it.
- Device integrity signals. To keep stamps honest, Trevel uses Apple’s App Attest (part of DeviceCheck) to confirm that a stamp is coming from a genuine copy of the app on a real device. This gives us a per-device cryptographic key identifier and a counter. It is not an advertising identifier and we do not use it to identify you across other apps or services. On Android, the app may also record whether the operating system reported a “mock location” setting at the time of a stamp.
- Push notification token. If you allow notifications, we store the device token needed to deliver them and remove it when you sign out.
- Time zone. So daily quests and reminders line up with your local day.
- Usage analytics. We record a small number of product events (for example “app opened,” “stamp created,” “guest converted,” and the steps of the photo-import flow as counts). These events carry your account identifier and simple values such as counts — never your location, your email, or your photos. There is no screen recording or session replay.
- Crash and error reports. If the app or our servers hit an error, we receive a technical report (device model, OS version, app version, and a stack trace). We have configured this reporting so that it does not include your email, request contents, or IP address.
- Technical basics. Like any internet service, our servers and the providers that host them see your IP address and standard request details while they handle your requests, for security and rate-limiting. We do not keep IP addresses in your account record.
2.3 Information we do not collect
- We do not access your contacts, calendar, microphone, or health data.
- We do not use advertising SDKs, advertising identifiers, or “fingerprinting.”
- We do not collect precise location while the app is closed unless you have granted “Always” permission, and then only on the significant-change wakes described above.
- We do not scan the contents of your photos for faces, objects, or text.
3. Photo import — how it works and what leaves your phone
Photo import is an optional way to fill in past travels using the location tags your camera already wrote into your photos. Because this feature asks for access to your whole photo library, here is exactly what happens:
- You start it. The feature only runs when you tap “Import past travels.” The photo-library permission prompt appears only after an explanation screen, never during normal use.
- Everything is read on your device. The app reads the location tag and the date of each photo from your phone’s local photo database. It does not download photos from iCloud, does not read the image itself, and does not send any photo, thumbnail, or per-photo data to us.
- Your phone groups photos into places. The app groups nearby photos into rough “place groups” on the device and keeps only summary information for each group (an approximate center point, how many photos, and which days) plus a few thumbnails to show you in the review list. Those thumbnails are displayed from your own library and never uploaded.
- We match approximate points to cities. To name each place group, the app sends only the center point of each group, rounded to about one kilometer — no dates, no photo counts, no photo identifiers — to our servers, which reply with the matching city. Our servers do not store these points; they answer the request and forget it.
- You review and confirm. You see the suggested places and choose which to keep.
- What we store. For each place you confirm, we store a self-reported stamp for that city and the date of your earliest photo there (so the stamp reads as when you were there). Nothing else from the import is stored.
If you grant only limited photo access, the import works with the photos you selected. You can revoke photo access at any time in your phone’s Settings. Outside of photo import, Trevel asks for library access only when you choose to pick a photo for a stamp or a profile picture, and then it uploads only the photo you picked.
Self-reported stamps (whether from photo import or manual entry) earn reduced points, are labeled as self-reported, and do not count toward leaderboards, badges, or rarity.
4. How we use information
- To run Trevel: create and verify stamps, keep your passport and map, calculate points, levels, ranks, streaks, quests, and badges, and show your profile to the people you allow.
- To keep stamps honest: location, accuracy, timing, device-integrity signals, and presence entries are used to detect spoofed or impossible stamps. We may withhold, remove, or mark stamps that fail these checks.
- To provide social features: follows, blocks, leaderboards, an activity feed of people you follow, and user search.
- To send notifications you have chosen: stamp suggestions, quest reminders, streak nudges, badge awards, and follow activity — each category can be turned off individually.
- To improve the product: the analytics events and crash reports described above.
- To keep the Service safe: rate-limiting, abuse prevention, bot protection, and reviewing reports.
- To communicate with you: service messages about your account, and replies to your support requests. If we ever send marketing messages, you will be able to opt out.
- To comply with law and enforce our Terms.
Legal bases (for people in the EEA, UK, and similar jurisdictions). We process account and stamp data because it is necessary to provide the Service you asked for (contract). We process device-integrity, anti-abuse, analytics, and crash data for our legitimate interest in running a fair, reliable service. Background location, photo-library access, and push notifications are processed only with your consent, which you can withdraw in your device settings. We process data to comply with legal obligations where required.
5. Who can see what (your visibility settings)
- Profile visibility. Profiles are public by default, which lets people tap through from leaderboards. A public profile shows your username, display name, profile picture, rank, points, and stamp counts, plus your map, places, and badges. You can switch to private in Settings: then new followers need your approval, and non-followers see only your identity and rank.
- Photos. Your stamp photos are private by default. People you have accepted as followers can see them; the public can see them only if you turn on “Photos public” in Settings.
- Guests are never visible to anyone.
- Blocking is mutual: when you block someone, neither of you can see the other’s profile, stamps, or photos, and any follow between you is removed.
- Leaderboards show username, display name, profile picture, rank, and verified points only.
6. Who we share information with
We do not sell personal information, and we do not share it with advertisers or data brokers. We share information only:
- With service providers who process it for us, under contracts that restrict them to our instructions:
| Provider | What they do for Trevel | Data involved |
|---|---|---|
| Supabase (hosted on Amazon Web Services, Oregon, USA) | Sign-in and our database | Account data, stamps, locations, social data |
| Fly.io (San Jose, USA) | Runs our servers | All requests pass through |
| Cloudflare | Photo and profile-picture storage (R2); bot protection on sign-in (Turnstile); DNS for trevel.app | Photos; IP address during a request |
| Mapbox | Map tiles and styles | Your device requests map tiles for the area you view (Mapbox usage telemetry is switched off in the app) |
| Apple | Sign in with Apple; App Attest; push notification delivery (APNs) | Sign-in identity; device-integrity keys; push tokens |
| Google Sign-In | Sign-in identity | |
| Expo (Expo Application Services) | App builds and push-notification routing | Push tokens and notification contents |
| PostHog (USA) | Product analytics | Account identifier and event names/counts |
| Sentry | Crash and error reporting | Technical crash data (no personal details attached) |
| Google Workspace | Our email (support@, privacy@) | Your messages to us |
- With other users, according to your visibility settings (section 5).
- When the law requires it, or to protect the rights, safety, or property of Trevel, our users, or the public.
- In a business transfer. If Trevel is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; this policy will continue to apply until a new one is posted.
Our map and place data is built on open data (OpenStreetMap, Natural Earth, Wikidata, GeoNames, OurAirports). We do not send your personal information to those projects.
7. How long we keep information
| Information | Kept for |
|---|---|
| Account, stamps (including coordinates), points, badges, settings | The life of your account |
| Photos you attach to stamps, profile pictures, showcase photos | Until you remove them or delete your account |
| Uploaded photos that were never attached to a stamp | Deleted automatically after 48 hours |
| Background “presence” entries | Deleted automatically after 24 hours |
| Reports you file or that are filed about you | Until reviewed and for as long as needed to enforce our Terms; removed when either account is deleted |
| Push tokens | Until you sign out or disable notifications |
| Analytics events and crash reports | Retained by our providers on rolling windows (typically 90 days to 1 year) |
| Deletion record | After you delete your account, we keep only a record that your sign-in identifier was deleted, so an old login token cannot recreate the account |
| Support emails | As long as needed to resolve your request and for our records |
| Waitlist email address | Until you receive your invite and create an account, or until you ask us to remove it |
8. Your choices and rights
Choices built into the app
- Delete your account: Settings → Delete account. This immediately removes your account record, stamps, photos, follows, blocks, reports, preferences, and push tokens from our systems and deletes your sign-in identity. It cannot be undone. Copies in our encrypted database backups age out within 7 days.
- Profile and photo visibility: Settings (section 5).
- Notifications: turn each category on or off in Settings, or turn off all notifications in your phone’s Settings.
- Location: choose “While Using,” “Always,” or “Never” in your phone’s Settings. Stamping needs location while using; everything else is optional.
- Photo library: grant, limit, or revoke access in your phone’s Settings.
- Block and report: from any profile or photo.
- Change your username (once every 30 days), display name, home country, and profile picture in Settings.
Rights you can exercise by contacting us
Depending on where you live, you may have the right to access, receive a copy of, correct, delete, or restrict the use of your personal information, to object to certain processing, to withdraw consent, and to complain to a data-protection authority. Everyone can ask us for a copy of the information in their account, and we will provide it in a machine-readable format (a complete export of your account, stamps with coordinates and timestamps, photos, follows, blocks, and settings). To make a request, email privacy@trevel.app from the address on your account. We will verify the request and respond within the time the applicable law allows (generally 30 days, and usually much sooner). We will not treat you differently for exercising your rights.
California residents. We do not sell or “share” (for cross-context behavioral advertising) personal information, and we have not done so in the preceding 12 months. You may request the categories and specific pieces of information we hold about you, request deletion, and request correction, using the contact above. You may designate an authorized agent to make a request on your behalf.
EEA, UK, and Switzerland. Trevel Technologies, Inc. is the controller of your personal information. Our servers are in the United States; when we transfer your information there we rely on our providers’ standard contractual clauses and comparable safeguards. You may lodge a complaint with your local supervisory authority.
9. Children
Trevel is not intended for children under 13, and we do not knowingly collect personal information from anyone under 13. Where local law sets a higher age for consenting to an online service, you must meet that age. If you believe a child has provided us with personal information, email privacy@trevel.app and we will delete it.
10. Security
We protect your information with encryption in transit (TLS) and at rest, short-lived signed links for photos, row-level access controls in our database, device attestation, rate limits, and access limited to the people who need it. No system is perfectly secure; if we learn of a breach affecting your information we will notify you as the law requires.
11. International use
Trevel is operated from the United States and your information is stored there. If you use Trevel from elsewhere, you understand that your information will be transferred to and processed in the United States.
12. Changes to this policy
When we make material changes we will update the date above and, where appropriate, notify you in the app or by email before the change takes effect. Continued use after the effective date means you accept the updated policy.
13. Contact us
Trevel Technologies, Inc. Email: privacy@trevel.app (privacy) · support@trevel.app (everything else) Mail: Trevel Technologies, Inc., c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808, USA