Privacy Policy

Last Updated: August 30, 2026

1. Introduction

Semicolon D, LLC ("we," "our," or "us") respects your privacy and is committed to protecting it through compliance with this policy. This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit the website or use the TravelDay mobile application (collectively, the "Service") and our practices for collecting, using, maintaining, protecting, and disclosing that information.

2. Information We Collect

We collect several types of information from and about users of our Service, including:

  • Account Information: When you register, we collect your email address. If you sign up via Google or Apple, we may receive your name and profile picture.
  • Newsletter Information: If you separately request the TravelDay Weekly Briefing, we store your email address, topic preference, confirmation and unsubscribe history, and delivery status. Creating an account does not subscribe you.
  • Trip Data: We collect and store details about your trips, including destinations, dates, and itineraries, to provide relevant safety alerts.
  • Documents: Files you upload to your Secure Vault (such as passports, visas, and insurance documents). These are stored securely and can be encrypted client-side.
  • Emergency & Trusted Contacts: We collect the names, email addresses, and phone numbers of contacts you designate as "Trusted Contacts" or "Emergency Contacts" to facilitate safety check-ins and emergency alerts.
  • Device Information: We collect information about your mobile device, including model, operating system, and push notification tokens, to deliver alerts and ensure app compatibility.
  • Product and AI Reliability Metadata: We collect limited technical measurements such as feature actions, response time, token counts, model identifier, tool name and status, approximate cost, error category, app version, and an optional thumbs-up/down rating with a predefined reason. These records use your account's pseudonymous identifier so we can diagnose failures across devices. They do not contain your chat message, the assistant's answer, tool arguments or results, destinations, travel dates, voice recording, or transcript.
  • Location Data: With your explicit permission, we access your device's precise location to:
    • Verify your location during a Safety Check-in.
    • Display your position on the Safety Map.
    • Show relevant local emergency numbers.
    • Record which country and city you are in — as a date and place name only — to build your Travel History, if you use that feature.
    • Share your current location with audiences you choose, if you turn on the optional Location Sharing feature. A location you submit from the web or mobile app is stored for up to 24 hours and may be shown as a country, region, city, or precise pin according to your settings. You can stop sharing or clear it at any time.
    If you separately enable background travel-history tracking, the app may receive occasional location updates while it is not open. Each update is resolved on your device to a date, country, and city; the coordinates are then discarded and are not uploaded or stored as a route. Background tracking is off by default, is best-effort rather than continuous, may stop after an iOS force-quit, and can be disabled at any time from Travel History Sources.
  • Photo Library (Travel History): With your explicit permission, the app reads the date and location stamps on photos in your library to reconstruct your travel history. This processing happens entirely on your device: your photos are never uploaded, and the GPS coordinates in them never leave your phone. Only derived conclusions — country, city name, and date ranges (for example, "Colombia, March 3 to May 4") — are synced to your account so your history follows you across devices. You can delete your travel history at any time, and deleting your account removes it from our servers.
  • Calendar (Travel History): With your explicit permission, the app scans calendars you choose on your device for travel-shaped events. Raw calendar contents are not uploaded. Normalized travel evidence such as a date, country, city, airport codes, flight number, duration, and a short provenance label may be synced to your account so the result can appear on your other devices and be reviewed.

3. How We Use Your Information

We use information that we collect about you or that you provide to us, including any personal information:

  • To provide the Service and its contents to you, including safety alerts and trip briefings.
  • To process your subscription payments via RevenueCat (mobile) or Stripe (web).
  • To send you push notifications regarding safety advisories affecting your trips.
  • To send the TravelDay Weekly Briefing only after you confirm your subscription, and to honor unsubscribe, bounce, and complaint requests.
  • To facilitate the "Safety Check-in" feature, notifying your trusted contacts if you fail to check in.
  • To provide AI-powered safety advice and trip summaries.
  • To let you open bookings with our affiliate partners. These cover tours and tickets (for example Viator and Klook), eSIM data (for example Yesim), travel insurance, airport transfers and car rental, and flight search. Every affiliate link is labelled as a paid link where it appears.

4. Artificial Intelligence (AI) Features

Our Service includes AI-powered features, such as the Safety Chat Assistant and Advisory Summaries. When you use these features:

  • Your chat messages are processed by our AI provider (OpenRouter, which routes to the underlying model) to understand your question and to phrase the answer.
  • To answer questions about your own travel, the assistant sends a short, derived summary alongside your message — for example "days recorded in Portugal: 62 of 90", your passport country, or your upcoming trip's destination and dates. These are computed totals, never your underlying location history: we do not send your photos, your photo metadata, your GPS coordinates, or the day-by-day ledger stored on your device. The day counting itself happens on our servers, not at the AI model.
  • Chat messages are not used to train any model, and we do not retain your conversation history on our servers. We store only a per-day count of how many messages you sent and how many tokens they used, so we can apply fair-use limits.
  • We measure whether the assistant completed a request, which model and TravelDay tool it used, response time, token count, approximate provider cost, and closed-choice feedback to monitor reliability. We do not send chat messages, assistant replies, system instructions, tool arguments or results, voice recordings, or transcripts to our analytics or error-monitoring providers.
  • We do not send the contents of your secure documents or your private emails to AI models, with two exceptions, both of which you control:
  • Mining your connected inbox. If you enable the optional "Let AI read emails our parser can't" setting, individual emails that our standard (non-AI) parser could not read are sent to our AI provider solely to extract the booking details (flights, dates, hotels). This is off by default, applies only to the emails that failed standard parsing, and can be left off with no loss of the standard functionality.
  • Emails you forward to us. When you forward a booking to your private TravelDay address, and our standard (non-AI) parser cannot read it, that email is sent to our AI provider to extract the booking details. There is no separate toggle for this one because forwarding a specific email is the choice: it applies only to the messages you personally send us, one at a time, and never to anything else in your mailbox. Extraction only — the content is not retained by us after parsing and is not used to train any model.
  • We do not use your personal data to train public AI models, and our AI providers are not permitted to train on it either.

5. Data Security & Storage

We implement industry-standard security measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure.

  • Secure Vault: Documents uploaded to the Vault are encrypted on your device before they are uploaded, using a key generated there, and stored in private storage buckets. That key is wrapped with a master key held by our servers, so we are able to decrypt a document where the service requires it. This is strong encryption at rest; it is not zero-knowledge storage, and we do not claim that your files are unreadable to us.
  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest in our database.
  • Access Control: Every query that reads your data is scoped to your account, and an automated test blocks any change that would remove that scoping. Access to the production database is limited to the application and to authorised administrators.

6. Third-Party Services

We may share data with specific third-party service providers to operate the Service:

  • Clerk: For account creation and authentication.
  • Neon: For database hosting.
  • Cloudflare (R2 and Workers): For document storage and map tile delivery.
  • OpenStreetMap Nominatim: When you explicitly update a shared location from TravelDay, its coordinates are used to resolve the city and state or province label.
  • RevenueCat & Stripe: For processing subscription payments. We do not store your credit card information.
  • OpenRouter: Our AI gateway. It routes requests to the underlying model provider for the assistant, safety scoring, and content analysis.
  • PostHog: For privacy-limited product analytics, content-free AI reliability traces, performance and cost measurements, and optional closed-choice assistant feedback. Session recording and automatic content capture are disabled.
  • Sentry: For application error and performance monitoring. Request bodies, headers, cookies, query strings, console breadcrumbs, screenshots, and view hierarchies are excluded from reporting.
  • Amazon Web Services (SES): For transactional email and, if you opt in, newsletter delivery and suppression management.
  • Affiliate partners and the Travelpayouts network: If you choose to open an affiliate offer, strictly necessary referral data may be shared with that merchant, or with the Travelpayouts network where it routes the link. Partners cover tours and tickets (such as Viator and Klook), eSIM data (such as Yesim), travel insurance (such as SafetyWing), airport transfers, car rental, and flight search. We never send a partner your account, trip, or location data.
  • YouTube (Google): Destination videos play in YouTube's embedded player. We use the privacy-enhanced player domain and never autoplay, so nothing is sent to YouTube until you press play on a video. Once you do, YouTube receives that request directly and handles it under the Google Privacy Policy. We do not send YouTube your account, trip, or location data.

7. Cookies and Local Storage

We use cookies and browser storage to run the site and, if you allow it, to understand what people click. We do not use them for advertising, and we do not let anyone build a profile of you across other websites.

You choose when you first arrive, and you can change your mind at any time from Cookie settings in the footer of the home page. Rejecting is one click, in the same place and at the same size as accepting. If we ever add a category, your stored choice stops counting and we ask again.

Strictly necessary (always on)

These make sign-in, payment and security work. There is no way to turn them off and still have an account, so we do not ask.

  • Clerk session cookies: keep you signed in and protect the sign-in flow. Set on our domain when you have an account. Without them every page load signs you out.
  • Stripe: payment happens on Stripe's own hosted checkout page, so any cookie Stripe sets is set there and not here. We load no Stripe script on our own pages.
  • Your own saved settings, in local storage: the map layers you picked, your flight-price origin airport, the places you looked at recently, your Discover and trip view, your last device location, and your cookie choice itself. These never leave your browser and are never sent to us. Clearing them would delete your settings, not protect your privacy, so they are not treated as tracking.
  • Sentry error monitoring: sets no cookie and no device identifier, and reports only that a page broke and where. Request bodies, headers, cookies, query strings and console logs are stripped before anything is sent. It runs regardless of your choice, because the crashes worth knowing about include the ones that stop the cookie banner from loading.

Analytics (off unless you allow it)

  • PostHog: which pages get opened and which buttons get used. It does not start at all until you allow it, so if you reject or have not answered, nothing is loaded and nothing is stored. When you do allow it, it sets ph_* entries on our own domain (analytics is proxied through /ingest, so it is a first-party request). Session recording, automatic click-text capture, performance capture and location lookup are all disabled, and query strings are removed from every URL before it is sent. Withdraw consent and we opt you out with PostHog's own API, discard the identifier, and delete those entries; deleting your account additionally queues erasure of events already collected.

Things that look like tracking and are not

  • Affiliate link measurement: when you open a partner offer we record the click on our own servers, with the provider, the category, the place, and which part of the site the link was on. It writes nothing to your browser and reads nothing from it, so there is no cookie to consent to. The outbound link carries a fixed partner code that is the same for every visitor and never contains an identifier for you. If you are signed in the row is linked to your account so we can reconcile commission and answer support questions about a booking; that link is removed when you delete your account.
  • Destination videos: embedded from youtube-nocookie.com, and nothing is requested from YouTube until you press play on a specific video. Pressing play is the choice; from that point YouTube handles the request under the Google Privacy Policy.
  • Map tiles and images: served through our own domain, so the tile and image hosts never see your browser directly.

Your browser can also block or delete all of this itself. Doing so will sign you out and clear your saved settings, because those are stored the same way.

8. Email Integration

If you use our "Forward to Import" feature, we parse the emails you forward to us solely to extract trip details (flight, hotel, dates). We discard the raw email body and attachments immediately after extraction. Where an email produces a trip or a flight in your history, we keep that message's subject line and sender address so you can trace the entry back to its source; the subjects of messages that produced nothing are not kept.

This includes flight-history export files (CSV or text) attached to a forwarded email, such as exports from Flighty, myFlightradar24, OpenFlights, JetLovers, or App in the Air. We read only the flight fields we display (date, airports, flight number, duration, aircraft) plus the file's name, which we keep as a label so you can trace an imported flight back to its source. Seat assignments, fare classes, booking references, notes, and the file itself are discarded and never stored.

If you opt-in to "Inbox Connect" (Google OAuth), Google grants us read access to your Gmail account. We search it only for travel confirmations — messages from known travel providers, or with booking-related subject lines — and we do not open anything outside that search. We do not store your email history.

The Weekly Briefing uses double opt-in. You can unsubscribe from any issue or change your preference using its signed link. After an ordinary unsubscribe, we retain the address and consent history needed to honor that choice. After a permanent bounce, spam complaint, or account deletion, we retain a minimal hashed suppression record so that we do not send marketing email again.

9. Data Retention & Deletion

We retain your personal information only for as long as necessary to fulfill the purposes for which we collected it. You may delete your account at any time within the app settings. Deleting your account permanently removes your account data, including trips, documents, and contacts, from our application servers. If your account is linked to a newsletter subscription, deletion also unsubscribes and unlinks it; a minimal suppression record may remain to prevent future marketing sends. Limited pseudonymous analytics or error metadata may remain with our service providers until its configured retention period expires or a provider deletion request is completed. You may contact us at the address below to request deletion of that metadata.

10. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are under 16, do not use or provide any information on this Service.

11. Contact Information

To ask questions or comment about this privacy policy and our privacy practices, contact us at: hello@semicolon-d.com

Back to Home