Privacy Policy
Last updated: September 14, 2026
On this page
- Who this applies to
- Our local-first approach
- Information we handle
- How information is used
- Recognition & Smart Import
- Passport, ID & payment documents
- Link previews, maps & diagnostics
- Storage & retention
- Sharing
- Optional cloud sync (coming soon)
- Your choices & rights
- Legal bases & regional rights
- Where information is processed
- Children
- Security
- Changes
- Contact
1. Who this applies to
This Privacy Policy explains how RoamDrop (“RoamDrop,” “we,” “us”) handles information when you use the RoamDrop iPhone app and this website. RoamDrop is operated by Mariia Tararova (OIB 17233930874), Primorska 8, 51000 Rijeka, Croatia. If you do not agree with this policy, please do not use RoamDrop.
2. Our local-first approach
RoamDrop is designed to keep your travel information on your device. By default:
- Your trips, cards, notes and attached documents are stored locally on your iPhone.
- The current app's recognition of screenshots, photos and PDFs runs on your device using Apple’s on-device frameworks.
- The app does not send raw recognition text, correction records or the contents of your cards to RoamDrop servers. What it can send is anonymous usage statistics, described in section 7 and switched off in Settings.
- You do not need to create an account to use the core app.
Recognition runs on your device. If that ever changes, this policy will be updated before the feature ships and the change will require an explicit action from you.
We only handle personal information where it is needed to provide a feature you use.
3. Information we handle
- Trip content you add: trip names, dates, places, notes, links, and the screenshots, photos, PDFs, tickets and booking confirmations you choose to import. This content is stored on your device.
- Text extracted from your documents: dates, times, places, prices and similar details recognized from images and PDFs. This is stored on your device alongside the original and is not uploaded.
- Smart Drops and purchase information: if Smart Drops launch, RoamDrop may process purchase receipts, balance changes, transaction history and spend reasons to provide paid features and support refunds or account/device recovery.
- Links and place strings you use: when you add a link, RoamDrop may fetch that webpage from your device to show a preview. When you use map/route features, place names may be looked up through Apple MapKit services.
- App & device information: basic technical information such as app version, device model and operating system, which may be used for diagnostics and stability.
- Support messages: if you email us, we receive your message, your email address, and anything you choose to include.
- Early-access sign-up: if you leave your email on this website to be notified at launch, that address is stored for us by our website host, Netlify, and used only to send you launch news about RoamDrop. You can ask us to delete it at any time at privacy@roamdrop.app.
- Recognition quality reports (we ask first, and they are off until you agree): after you have used recognition a few times, RoamDrop asks whether it may send anonymous quality reports. Until you say yes, nothing is sent. If you agree, the reports contain: which document type was guessed and which one you saved, which fields you edited, and thumbs-up/down votes. These reports never contain your documents, their text, images, names, or any field values — only counters and category labels. They are submitted through Apple's iCloud (CloudKit) infrastructure operated for RoamDrop, which records which iCloud account sent a report. We do not use that to identify you and never connect it to your trips, and you can turn reports off at any time. You can change your answer any time in Settings → “Improve recognition,” and withdrawing is as easy as agreeing was.
- Document text donation (off by default, opt-in): separately from the reports above, you can choose to also send the recognized text of a document whose card you corrected, so we can reproduce the mistake and fix it. This is off until you turn it on in Settings → “Send document text too.” Donated text can contain whatever the document contained — names, booking codes, addresses — so please enable it only if you are comfortable with that. The original files (images and PDFs) are never sent under any setting. Donated text is used solely to improve recognition and is deleted with the rest of your reports if you use “Erase my reports.”
- Future account & sync data (opt-in): if and when you choose to enable cloud sync, see “Optional cloud sync” below.
We do not sell your personal information.
4. How information is used
- To provide the app: import, recognize, organize, store, display and export your trips and documents.
- To read a document you add: extract dates, times, places and prices on your device and create a reviewable trip card.
- To fetch previews for links you add and look up map locations for places you choose to view on the route/map surfaces.
- To maintain reliability: diagnose crashes and improve stability and performance.
- To respond to support requests you send us.
- To comply with legal obligations where applicable.
5. Recognition & Smart Import
In the current app, when RoamDrop reads a screenshot, photo or PDF to suggest a date, time, place or price, that processing happens entirely on your device — including Apple's on-device model used to fill in fields on supported iPhones. Your tickets, boarding passes and booking documents are never sent to RoamDrop servers or to any third party to be read. You can review and correct any recognized detail before it is saved.
To make recognition better, RoamDrop sends anonymous quality reports about how well recognition performed (see “Recognition quality reports” in section 3). These reports never include your documents or anything read from them — no text, images, names, or field values — and you can turn them off in Settings at any time. If you additionally opt in to document text donation, the recognized text of corrected documents is sent as well; that switch is off by default and described in section 3.
RoamDrop does not use your documents for advertising. If any third-party processor is ever introduced, it must be listed in this policy before launch and configured with appropriate data-processing terms.
6. Passport, ID & payment documents
RoamDrop is not designed to collect, store or process passports, identity cards, visas, payment cards or similar identity/payment documents. Recognition runs on your device, so no imported content is sent anywhere to be read. Content that appears to contain passport, ID, visa, MRZ, document-number or payment-card data is blocked from recognition, with manual card creation offered instead.
RoamDrop does not store passport numbers, document numbers, MRZ lines, visa numbers or payment-card data as trip card fields, and does not use those values for model training, analytics, advertising or personalization.
7. Link previews, maps & diagnostics
Some features make limited network requests from your device:
- Currency rates: to show a budget converted into one currency, RoamDrop fetches published exchange rates from a rates provider. The request contains only the currency code, never your trip, your amounts or anything about you, and the provider receives normal request information such as your IP address.
- Link previews: if you add or share a URL, RoamDrop may request that page to read its title, description and preview image. The website you link to may receive normal request information such as your IP address and user agent.
- Maps and places: when you use route/map surfaces, RoamDrop may ask Apple MapKit to resolve trip destinations or card/place names into map coordinates.
- Diagnostics: RoamDrop uses Apple system diagnostics frameworks and local diagnostic files to help understand crashes or hangs. Diagnostic files are kept on your device unless you choose to share them with support or unless Apple provides crash information through its developer tools.
Anonymous usage statistics in the app. Since version 1.0 the app reports how it is used to PostHog (PostHog Inc., EU cloud, Frankfurt, Germany), our processor under a signed data processing agreement, so that we can see where people get stuck and what they never find. What is sent: the names of events such as "trip created", "card placed on a day" or "PDF exported", the screen a person opened, and coarse counts in ranges such as "3 to 5 cards". What is never sent: the contents of your cards, document text, titles, notes, links, your name, your Apple ID, your email, your precise location or your IP address, which PostHog is instructed to discard on arrival. The only identifier is a random number the app makes up on your device; it is not derived from the device and is not shared with any other app or service. It does let us tell one installation's events apart from another's over time, which is how we count whether people come back — but it is not joined to your name, your Apple ID or anything else about you, and no profile is built from it. The statistics are on by default and can be switched off at any time in Settings under "Anonymous usage statistics"; switching them off deletes the random identifier and anything not yet sent, so the device stops existing for us rather than merely stops reporting. The data stays in the EU. If accounts, cloud sync or paid Smart Drops are introduced, we will update this policy before those features ship.
This website is a separate matter from the app. Since 26 August 2026, roamdrop.app measures visits with PostHog (PostHog Inc., EU cloud), which acts as our processor under a signed data processing agreement. It is configured so that no cookie and no browser storage entry is written and no profile is created. Since 14 September 2026 the question of how many people those visits represent is answered on PostHog's servers: your IP address and browser details are combined with the name of the site and a secret that changes every day, and turned into an irreversible hash, which is what we see. The hash cannot be turned back into your IP address, the day's secret is destroyed once that day has been counted, and neither your IP address nor your browser details are stored. Because the secret changes daily, someone who returns next week is counted again rather than recognised. What is recorded is the page visited, the referring link, coarse device type, and whether the waitlist button was pressed. Because nothing is stored on your device, there is nothing to consent to and no banner is shown. The data is held in PostHog's EU region (Frankfurt, Germany), so it does not leave the EEA. Setting "Do Not Track" in your browser switches the measurement off entirely.
8. Storage & retention
Your trip content stays on your device until you delete it. Deleting a card, document or trip removes it from the app. Removing the app from your iPhone deletes the trips and documents stored locally by it. Device backups you create (for example, an encrypted iCloud or computer backup) are controlled by you and Apple, not by RoamDrop.
Recognition quality reports are kept for 24 months from the day they are sent. After that the app deletes them automatically, and you can delete them yourself at any time from Settings, "Your data", "Delete my recognition data". Donated document text, if you turned that on, is deleted on the same schedule and by the same buttons.
A published page is the other thing that lives outside your device, and only if you put it there. When you publish a trip as a web page, RoamDrop encrypts the page on your phone and stores the encrypted copy in Apple's public CloudKit database. The key that opens it is not stored with it: it travels only in the part of the link after the "#", which browsers never send to any server. So Apple holds a file it cannot read, this website holds nothing at all, and the trip is put back together in the reader's own browser. Anyone you give the link to can read the page, and only they can.
What goes on a published page is a shortened version of the trip, not all of it: the days, the cards and their times and places, and shared packing lists. Your documents, recognised text, booking and ticket numbers, seat numbers, amounts, deposits, personal packing lists, and the names and email addresses of the people on the trip are never published. While the link is on, the page follows the trip: changes you make in the app reach it automatically, within seconds, without asking you again. Turning the link off is how you stop that. Taking the page down deletes it, you can do that at any time from the trip's Share screen, and it also comes down when you delete the trip. A page that is never changed again expires and stops working 365 days after its last update. Because we keep no list of anyone's pages, taking one down needs the device that published it, or another device signed in to the same iCloud account.
9. Sharing
RoamDrop does not share your trip content except when you ask it to:
- Trips you share: when you share a trip, its content syncs through Apple’s iCloud to the people who join by your link, and they can edit the trip with you. This uses Apple CloudKit and your own Apple account — RoamDrop does not run its own copy of your trip on its servers. You control who has access and can stop sharing.
- Exports you create: when you export a trip as a PDF and share it, you control who receives it.
- Pages you publish: when you publish a trip as a web page, anyone holding the link can read it, on any device, with no account and no app, and it keeps up with the trip until you turn the link off. See "Storage & retention" above for what a page contains and how to take it down.
- Service providers: if we use providers for limited functions such as diagnostics or, in the future, cloud Smart Import, they may process information on our behalf under appropriate obligations. Any such providers will be described here.
- Legal reasons: we may disclose information if required by law or to protect rights and safety.
10. iCloud sharing & sync
Trip sharing uses Apple’s iCloud (CloudKit). When you share a trip, or accept a trip someone shares with you, that trip’s cards, documents and participant list sync through the Apple accounts involved — not through RoamDrop servers. Apple’s handling of iCloud data is governed by Apple’s privacy policy. If you do not share a trip, its content stays only on your device.
Broader multi-device backup of all your trips is a separate feature that is not active today; if introduced it is expected to be opt-in and to use your own Apple account, and we will update this policy before it ships.
11. Your choices & rights
Because your content is stored on your device, you can view, edit and delete it directly in the app at any time, and export a complete copy of everything RoamDrop knows via Settings → “A copy of my data.” Depending on where you live, you may have additional rights (such as access, correction, deletion or objection) regarding any personal information we hold. To make a request, contact us at privacy@roamdrop.app. You may also have the right to complain to your local data-protection authority.
12. Legal bases & regional rights
EEA & UK. Where data-protection law applies, we rely on these legal bases: performance of a contract (to provide the app and respond to support), legitimate interests (to keep the app secure and reliable), consent (for any optional feature that asks for it, such as future cloud sync or marketing), and legal obligation (to comply with the law). You may have the right to access, correct, delete, port, restrict or object to processing, and to lodge a complaint with your local supervisory authority.
United States. We do not sell your personal information, and we don’t use it for cross-context behavioral advertising. If that ever changes, we will provide the opt-out controls your state law requires. You may request access to or deletion of personal information we hold about you.
13. Where information is processed
RoamDrop is operated from Croatia, in the European Union. Your trips and documents stay on your device, so most of what you keep in RoamDrop is not transferred anywhere at all.
Three services process limited information for us, and each may do so on servers outside the European Economic Area:
- Apple (iCloud and CloudKit): trip sharing runs through your own Apple account, and the recognition quality reports are stored in Apple's CloudKit. Apple operates data centres in several regions and handles such transfers under its own contractual terms.
- Netlify: hosts this website and stores the early-access email addresses left on it.
- Migadu: handles email sent to our addresses, including anything you write to support or about privacy.
Where a transfer outside the EEA takes place, it relies on the European Commission's Standard Contractual Clauses or on an adequacy decision, as applicable to that provider. We do not sell personal information and do not transfer it for advertising.
14. Children
RoamDrop is not directed to children under the age required for digital consent in your country, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will address it.
15. Security
We use reasonable technical and organizational measures appropriate to a local-first app to help protect information, and we rely on the security of your device and Apple’s platform. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.
16. Changes to this policy
We may update this Privacy Policy as the product evolves. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the app or on this site.
17. Contact
Questions about privacy? Email privacy@roamdrop.app. The data controller is Mariia Tararova (OIB 17233930874), Primorska 8, 51000 Rijeka, Croatia. See also our Terms of Use and Support page.
