Who this policy covers
This policy applies to the Travelist iOS app, its widgets and Live Activities, the Travelist backend, and the Permafrostudio account services used by Travelist. Permafrostudio is responsible for the processing described here.
Travelist is an offline-first travel planner. Some information stays only on your device; account, synchronisation, sharing, support, AI and purchase features require server processing.
Data we process
Account and profile
Account identifier, email address or Apple/Google sign-in identifier, display name, avatar, interface language, time zone, and optional age range or gender if you choose to provide them.
Trips and content
Destinations, dates, transport details, collaborators, packing lists, events and notes, budgets and currencies, documents, and the photos or videos you explicitly choose to upload or share.
AI suggestions
Trip context sent for a request — such as destination, season, transport and traveller count — optional profile details, the request text, generated suggestions and which suggestions you select.
Purchases
Product identifiers, transaction identifiers, purchase state, entitlements, token balance and token history. Apple processes payment credentials; Travelist does not receive your full card details.
Support and safety
Support conversations and attachments, content reports, notification tokens, installation identifier, locale, request timestamps, rate-limit records and limited security or error logs.
Stays on your device
Your Health step counts are read only with permission and stored locally for trip summaries and widgets. Travelist does not upload them. Your full photo library is not uploaded; only items you select are processed.
Why we use it
- Provide Travelist: authenticate you, save and synchronise trips, support collaboration, photos, notifications, widgets and offline restoration.
- Provide requested AI features: generate packing suggestions and improve their relevance from suggestion and selection signals.
- Process purchases: verify one-time purchases, maintain tokens and entitlements, restore purchases and prevent duplicate grants.
- Support and security: answer conversations, investigate reports, prevent spam, fraud and abuse, and maintain service reliability.
- Comply with law: maintain records where required and respond to valid legal requests.
When you block another traveler, Travelist records that choice, separates shared trips between the two accounts, prevents future shared-trip invitations and stops content and collaboration notifications between them. You can review and remove your own blocks in Travelist Settings.
Where applicable, these activities rely on performing our service agreement with you, your consent for optional permissions and profile details, our legitimate interests in security and support, and legal obligations.
Retention and deletion
Deleting Travelist
In Travelist, open Settings → App accounts, tap the bin beside Travelist, and confirm. This deletes your Travelist trips, lists, events, budgets, attachments, shared photos, app-scoped AI history, notification registration and other Travelist data from active systems.
Travelist is one app under a separate Permafrostudio studio account. Deleting Travelist removes the Travelist app account and membership, but does not automatically delete the studio identity, cross-app token ledger or purchase records used by other Permafrostudio apps and for purchase restoration. Contact us if you want to make a broader privacy request concerning the studio account.
Deleted information may remain briefly in encrypted, access-restricted backups until the rolling backup cycle replaces it, or longer where retention is legally required. It is not restored to the active service except for disaster recovery or legal necessity.
Your privacy choices
You can control Travelist without waiting for support:
Edit or delete contentChange trips and profile details, remove shared content, leave shared trips, or delete support discussions inside Travelist.
Manage permissionsUse iOS Settings to withdraw Photos, Health, notifications and Live Activities permissions at any time.
Delete TravelistUse Settings → App accounts to delete the Travelist app account and its associated Travelist data.
Exercise privacy rightsAsk for access, correction, portability, restriction or deletion by contacting us. Rights vary by location, and we may verify your identity.
Security and international processing
We use encrypted network connections, private storage, access controls, signed file links, rate limits and account-scoped authorisation. No service is risk-free, so please avoid placing unnecessary highly sensitive information in free-text notes or support messages.
Our primary infrastructure is configured in the European Union. Apple, Google, RevenueCat, AWS and Mailjet may process information in other countries under their applicable safeguards and agreements.
Children
Travelist is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data, contact us so we can investigate and delete it where appropriate.
Changes to this policy
We may update this policy when Travelist, its providers or legal requirements change. We will update the effective date and, for material changes, provide an appropriate notice in the app or through the account contact channel.
Contact
Permafrostudio is the contact point for Travelist privacy matters.
contact@permafrostudio.com