Privacy Policy
Last Updated: August 30, 2026
1. Introduction
Semicolon D, LLC ("we," "our," or "us") respects your privacy and is committed to protecting it through compliance with this policy. This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit the website or use the TravelDay mobile application (collectively, the "Service") and our practices for collecting, using, maintaining, protecting, and disclosing that information.
2. Information We Collect
We collect several types of information from and about users of our Service, including:
- Account Information: When you register, we collect your email address. If you sign up via Google or Apple, we may receive your name and profile picture.
- Newsletter Information: If you separately request the TravelDay Weekly Briefing, we store your email address, topic preference, confirmation and unsubscribe history, and delivery status. Creating an account does not subscribe you.
- Trip Data: We collect and store details about your trips, including destinations, dates, and itineraries, to provide relevant safety alerts.
- Documents: Files you upload to your Secure Vault (such as passports, visas, and insurance documents). These are stored securely and can be encrypted client-side.
- Emergency & Trusted Contacts: We collect the names, email addresses, and phone numbers of contacts you designate as "Trusted Contacts" or "Emergency Contacts" to facilitate safety check-ins and emergency alerts.
- Device Information: We collect information about your mobile device, including model, operating system, and push notification tokens, to deliver alerts and ensure app compatibility.
- Product and AI Reliability Metadata: We collect limited technical measurements such as feature actions, response time, token counts, model identifier, tool name and status, approximate cost, error category, app version, and an optional thumbs-up/down rating with a predefined reason. These records use your account's pseudonymous identifier so we can diagnose failures across devices. They do not contain your chat message, the assistant's answer, tool arguments or results, destinations, travel dates, voice recording, or transcript.
- Location Data: With your explicit permission, we access your device's precise location to:
- Verify your location during a Safety Check-in.
- Display your position on the Safety Map.
- Show relevant local emergency numbers.
- Record which country and city you are in — as a date and place name only — to build your Travel History, if you use that feature.
- Share your current location with audiences you choose, if you turn on the optional Location Sharing feature. A location you submit from the web or mobile app is stored for up to 24 hours and may be shown as a country, region, city, or precise pin according to your settings. You can stop sharing or clear it at any time.
- Photo Library (Travel History): With your explicit permission, the app reads the date and location stamps on photos in your library to reconstruct your travel history. This processing happens entirely on your device: your photos are never uploaded, and the GPS coordinates in them never leave your phone. Only derived conclusions — country, city name, and date ranges (for example, "Colombia, March 3 to May 4") — are synced to your account so your history follows you across devices. You can delete your travel history at any time, and deleting your account removes it from our servers.
- Calendar (Travel History): With your explicit permission, the app scans calendars you choose on your device for travel-shaped events. Raw calendar contents are not uploaded. Normalized travel evidence such as a date, country, city, airport codes, flight number, duration, and a short provenance label may be synced to your account so the result can appear on your other devices and be reviewed.
3. How We Use Your Information
We use information that we collect about you or that you provide to us, including any personal information:
- To provide the Service and its contents to you, including safety alerts and trip briefings.
- To process your subscription payments via RevenueCat (mobile) or Stripe (web).
- To send you push notifications regarding safety advisories affecting your trips.
- To send the TravelDay Weekly Briefing only after you confirm your subscription, and to honor unsubscribe, bounce, and complaint requests.
- To facilitate the "Safety Check-in" feature, notifying your trusted contacts if you fail to check in.
- To provide AI-powered safety advice and trip summaries.
- To let you open bookings with our affiliate partners. These cover tours and tickets (for example Viator and Klook), eSIM data (for example Yesim), travel insurance, airport transfers and car rental, and flight search. Every affiliate link is labelled as a paid link where it appears.
4. Artificial Intelligence (AI) Features
Our Service includes AI-powered features, such as the Safety Chat Assistant and Advisory Summaries. When you use these features:
- Your chat messages are processed by our AI provider (OpenRouter, which routes to the underlying model) to understand your question and to phrase the answer.
- To answer questions about your own travel, the assistant sends a short, derived summary alongside your message — for example "days recorded in Portugal: 62 of 90", your passport country, or your upcoming trip's destination and dates. These are computed totals, never your underlying location history: we do not send your photos, your photo metadata, your GPS coordinates, or the day-by-day ledger stored on your device. The day counting itself happens on our servers, not at the AI model.
- Chat messages are not used to train any model, and we do not retain your conversation history on our servers. We store only a per-day count of how many messages you sent and how many tokens they used, so we can apply fair-use limits.
- We measure whether the assistant completed a request, which model and TravelDay tool it used, response time, token count, approximate provider cost, and closed-choice feedback to monitor reliability. We do not send chat messages, assistant replies, system instructions, tool arguments or results, voice recordings, or transcripts to our analytics or error-monitoring providers.
- We do not send the contents of your secure documents or your private emails to AI models, with two exceptions, both of which you control:
- Mining your connected inbox. If you enable the optional "Let AI read emails our parser can't" setting, individual emails that our standard (non-AI) parser could not read are sent to our AI provider solely to extract the booking details (flights, dates, hotels). This is off by default, applies only to the emails that failed standard parsing, and can be left off with no loss of the standard functionality.
- Emails you forward to us. When you forward a booking to your private TravelDay address, and our standard (non-AI) parser cannot read it, that email is sent to our AI provider to extract the booking details. There is no separate toggle for this one because forwarding a specific email is the choice: it applies only to the messages you personally send us, one at a time, and never to anything else in your mailbox. Extraction only — the content is not retained by us after parsing and is not used to train any model.
- We do not use your personal data to train public AI models, and our AI providers are not permitted to train on it either.
5. Data Security & Storage
We implement industry-standard security measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure.
- Secure Vault: Documents uploaded to the Vault are encrypted on your device before they are uploaded, using a key generated there, and stored in private storage buckets. That key is wrapped with a master key held by our servers, so we are able to decrypt a document where the service requires it. This is strong encryption at rest; it is not zero-knowledge storage, and we do not claim that your files are unreadable to us.
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest in our database.
- Access Control: Every query that reads your data is scoped to your account, and an automated test blocks any change that would remove that scoping. Access to the production database is limited to the application and to authorised administrators.
6. Third-Party Services
We may share data with specific third-party service providers to operate the Service:
- Clerk: For account creation and authentication.
- Neon: For database hosting.
- Cloudflare (R2 and Workers): For document storage and map tile delivery.
- OpenStreetMap Nominatim: When you explicitly update a shared location from TravelDay, its coordinates are used to resolve the city and state or province label.
- RevenueCat & Stripe: For processing subscription payments. We do not store your credit card information.
- OpenRouter: Our AI gateway. It routes requests to the underlying model provider for the assistant, safety scoring, and content analysis.
- PostHog: For privacy-limited product analytics, content-free AI reliability traces, performance and cost measurements, and optional closed-choice assistant feedback. Session recording and automatic content capture are disabled.
- Sentry: For application error and performance monitoring. Request bodies, headers, cookies, query strings, console breadcrumbs, screenshots, and view hierarchies are excluded from reporting.
- Amazon Web Services (SES): For transactional email and, if you opt in, newsletter delivery and suppression management.
- Affiliate partners and the Travelpayouts network: If you choose to open an affiliate offer, strictly necessary referral data may be shared with that merchant, or with the Travelpayouts network where it routes the link. Partners cover tours and tickets (such as Viator and Klook), eSIM data (such as Yesim), travel insurance (such as SafetyWing), airport transfers, car rental, and flight search. We never send a partner your account, trip, or location data.
- YouTube (Google): Destination videos play in YouTube's embedded player. We use the privacy-enhanced player domain and never autoplay, so nothing is sent to YouTube until you press play on a video. Once you do, YouTube receives that request directly and handles it under the Google Privacy Policy. We do not send YouTube your account, trip, or location data.
8. Email Integration
If you use our "Forward to Import" feature, we parse the emails you forward to us solely to extract trip details (flight, hotel, dates). We discard the raw email body and attachments immediately after extraction. Where an email produces a trip or a flight in your history, we keep that message's subject line and sender address so you can trace the entry back to its source; the subjects of messages that produced nothing are not kept.
This includes flight-history export files (CSV or text) attached to a forwarded email, such as exports from Flighty, myFlightradar24, OpenFlights, JetLovers, or App in the Air. We read only the flight fields we display (date, airports, flight number, duration, aircraft) plus the file's name, which we keep as a label so you can trace an imported flight back to its source. Seat assignments, fare classes, booking references, notes, and the file itself are discarded and never stored.
If you opt-in to "Inbox Connect" (Google OAuth), Google grants us read access to your Gmail account. We search it only for travel confirmations — messages from known travel providers, or with booking-related subject lines — and we do not open anything outside that search. We do not store your email history.
The Weekly Briefing uses double opt-in. You can unsubscribe from any issue or change your preference using its signed link. After an ordinary unsubscribe, we retain the address and consent history needed to honor that choice. After a permanent bounce, spam complaint, or account deletion, we retain a minimal hashed suppression record so that we do not send marketing email again.
9. Data Retention & Deletion
We retain your personal information only for as long as necessary to fulfill the purposes for which we collected it. You may delete your account at any time within the app settings. Deleting your account permanently removes your account data, including trips, documents, and contacts, from our application servers. If your account is linked to a newsletter subscription, deletion also unsubscribes and unlinks it; a minimal suppression record may remain to prevent future marketing sends. Limited pseudonymous analytics or error metadata may remain with our service providers until its configured retention period expires or a provider deletion request is completed. You may contact us at the address below to request deletion of that metadata.
10. Children's Privacy
Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are under 16, do not use or provide any information on this Service.
11. Contact Information
To ask questions or comment about this privacy policy and our privacy practices, contact us at: hello@semicolon-d.com