Back to home

Privacy Policy

Last updated: September 14, 2026

See previous versions

RoamDrop is built to be private by default. Your trips, documents and tickets are stored on your iPhone, and recognition of your tickets and bookings runs entirely on your device — your tickets do not leave your phone. The one exception is a trip you choose to share: a shared trip syncs through Apple’s iCloud, described below.

1. Who this applies to

This Privacy Policy explains how RoamDrop (“RoamDrop,” “we,” “us”) handles information when you use the RoamDrop iPhone app and this website. RoamDrop is operated by Mariia Tararova (OIB 17233930874), Primorska 8, 51000 Rijeka, Croatia. If you do not agree with this policy, please do not use RoamDrop.

2. Our local-first approach

RoamDrop is designed to keep your travel information on your device. By default:

Recognition runs on your device. If that ever changes, this policy will be updated before the feature ships and the change will require an explicit action from you.

We only handle personal information where it is needed to provide a feature you use.

3. Information we handle

We do not sell your personal information.

4. How information is used

5. Recognition & Smart Import

In the current app, when RoamDrop reads a screenshot, photo or PDF to suggest a date, time, place or price, that processing happens entirely on your device — including Apple's on-device model used to fill in fields on supported iPhones. Your tickets, boarding passes and booking documents are never sent to RoamDrop servers or to any third party to be read. You can review and correct any recognized detail before it is saved.

To make recognition better, RoamDrop sends anonymous quality reports about how well recognition performed (see “Recognition quality reports” in section 3). These reports never include your documents or anything read from them — no text, images, names, or field values — and you can turn them off in Settings at any time. If you additionally opt in to document text donation, the recognized text of corrected documents is sent as well; that switch is off by default and described in section 3.

RoamDrop does not use your documents for advertising. If any third-party processor is ever introduced, it must be listed in this policy before launch and configured with appropriate data-processing terms.

6. Passport, ID & payment documents

RoamDrop is not designed to collect, store or process passports, identity cards, visas, payment cards or similar identity/payment documents. Recognition runs on your device, so no imported content is sent anywhere to be read. Content that appears to contain passport, ID, visa, MRZ, document-number or payment-card data is blocked from recognition, with manual card creation offered instead.

RoamDrop does not store passport numbers, document numbers, MRZ lines, visa numbers or payment-card data as trip card fields, and does not use those values for model training, analytics, advertising or personalization.

7. Link previews, maps & diagnostics

Some features make limited network requests from your device:

Anonymous usage statistics in the app. Since version 1.0 the app reports how it is used to PostHog (PostHog Inc., EU cloud, Frankfurt, Germany), our processor under a signed data processing agreement, so that we can see where people get stuck and what they never find. What is sent: the names of events such as "trip created", "card placed on a day" or "PDF exported", the screen a person opened, and coarse counts in ranges such as "3 to 5 cards". What is never sent: the contents of your cards, document text, titles, notes, links, your name, your Apple ID, your email, your precise location or your IP address, which PostHog is instructed to discard on arrival. The only identifier is a random number the app makes up on your device; it is not derived from the device and is not shared with any other app or service. It does let us tell one installation's events apart from another's over time, which is how we count whether people come back — but it is not joined to your name, your Apple ID or anything else about you, and no profile is built from it. The statistics are on by default and can be switched off at any time in Settings under "Anonymous usage statistics"; switching them off deletes the random identifier and anything not yet sent, so the device stops existing for us rather than merely stops reporting. The data stays in the EU. If accounts, cloud sync or paid Smart Drops are introduced, we will update this policy before those features ship.

This website is a separate matter from the app. Since 26 August 2026, roamdrop.app measures visits with PostHog (PostHog Inc., EU cloud), which acts as our processor under a signed data processing agreement. It is configured so that no cookie and no browser storage entry is written and no profile is created. Since 14 September 2026 the question of how many people those visits represent is answered on PostHog's servers: your IP address and browser details are combined with the name of the site and a secret that changes every day, and turned into an irreversible hash, which is what we see. The hash cannot be turned back into your IP address, the day's secret is destroyed once that day has been counted, and neither your IP address nor your browser details are stored. Because the secret changes daily, someone who returns next week is counted again rather than recognised. What is recorded is the page visited, the referring link, coarse device type, and whether the waitlist button was pressed. Because nothing is stored on your device, there is nothing to consent to and no banner is shown. The data is held in PostHog's EU region (Frankfurt, Germany), so it does not leave the EEA. Setting "Do Not Track" in your browser switches the measurement off entirely.

8. Storage & retention

Your trip content stays on your device until you delete it. Deleting a card, document or trip removes it from the app. Removing the app from your iPhone deletes the trips and documents stored locally by it. Device backups you create (for example, an encrypted iCloud or computer backup) are controlled by you and Apple, not by RoamDrop.

Recognition quality reports are kept for 24 months from the day they are sent. After that the app deletes them automatically, and you can delete them yourself at any time from Settings, "Your data", "Delete my recognition data". Donated document text, if you turned that on, is deleted on the same schedule and by the same buttons.

A published page is the other thing that lives outside your device, and only if you put it there. When you publish a trip as a web page, RoamDrop encrypts the page on your phone and stores the encrypted copy in Apple's public CloudKit database. The key that opens it is not stored with it: it travels only in the part of the link after the "#", which browsers never send to any server. So Apple holds a file it cannot read, this website holds nothing at all, and the trip is put back together in the reader's own browser. Anyone you give the link to can read the page, and only they can.

What goes on a published page is a shortened version of the trip, not all of it: the days, the cards and their times and places, and shared packing lists. Your documents, recognised text, booking and ticket numbers, seat numbers, amounts, deposits, personal packing lists, and the names and email addresses of the people on the trip are never published. While the link is on, the page follows the trip: changes you make in the app reach it automatically, within seconds, without asking you again. Turning the link off is how you stop that. Taking the page down deletes it, you can do that at any time from the trip's Share screen, and it also comes down when you delete the trip. A page that is never changed again expires and stops working 365 days after its last update. Because we keep no list of anyone's pages, taking one down needs the device that published it, or another device signed in to the same iCloud account.

9. Sharing

RoamDrop does not share your trip content except when you ask it to:

10. iCloud sharing & sync

Trip sharing uses Apple’s iCloud (CloudKit). When you share a trip, or accept a trip someone shares with you, that trip’s cards, documents and participant list sync through the Apple accounts involved — not through RoamDrop servers. Apple’s handling of iCloud data is governed by Apple’s privacy policy. If you do not share a trip, its content stays only on your device.

Broader multi-device backup of all your trips is a separate feature that is not active today; if introduced it is expected to be opt-in and to use your own Apple account, and we will update this policy before it ships.

11. Your choices & rights

Because your content is stored on your device, you can view, edit and delete it directly in the app at any time, and export a complete copy of everything RoamDrop knows via Settings → “A copy of my data.” Depending on where you live, you may have additional rights (such as access, correction, deletion or objection) regarding any personal information we hold. To make a request, contact us at privacy@roamdrop.app. You may also have the right to complain to your local data-protection authority.

12. Legal bases & regional rights

EEA & UK. Where data-protection law applies, we rely on these legal bases: performance of a contract (to provide the app and respond to support), legitimate interests (to keep the app secure and reliable), consent (for any optional feature that asks for it, such as future cloud sync or marketing), and legal obligation (to comply with the law). You may have the right to access, correct, delete, port, restrict or object to processing, and to lodge a complaint with your local supervisory authority.

United States. We do not sell your personal information, and we don’t use it for cross-context behavioral advertising. If that ever changes, we will provide the opt-out controls your state law requires. You may request access to or deletion of personal information we hold about you.

13. Where information is processed

RoamDrop is operated from Croatia, in the European Union. Your trips and documents stay on your device, so most of what you keep in RoamDrop is not transferred anywhere at all.

Three services process limited information for us, and each may do so on servers outside the European Economic Area:

Where a transfer outside the EEA takes place, it relies on the European Commission's Standard Contractual Clauses or on an adequacy decision, as applicable to that provider. We do not sell personal information and do not transfer it for advertising.

14. Children

RoamDrop is not directed to children under the age required for digital consent in your country, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will address it.

15. Security

We use reasonable technical and organizational measures appropriate to a local-first app to help protect information, and we rely on the security of your device and Apple’s platform. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.

16. Changes to this policy

We may update this Privacy Policy as the product evolves. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the app or on this site.

17. Contact

Questions about privacy? Email privacy@roamdrop.app. The data controller is Mariia Tararova (OIB 17233930874), Primorska 8, 51000 Rijeka, Croatia. See also our Terms of Use and Support page.