Legal Center
Security & Trust
Last updated: June 26, 2026
RoamDrop is built local-first. The simplest security guarantee is structural: your trips and documents live on your device, and reading a screenshot or PDF happens on the device too, so there is no upload to secure.
How your information is protected
- Stored on your device today. Your trips, cards, notes and attached documents are kept on your iPhone, protected by your device’s security (passcode, Face ID / Touch ID, and Apple’s on-device encryption). We don’t keep a copy on our servers in the current local-first app.
- Recognition happens on your device. Screenshots and PDFs are read on-device. Should that ever change, it would require an explicit user action and an updated privacy policy and App Store disclosure first.
- Sensitive-document guardrails. Passport, ID, visa, MRZ, document-number and payment-card content is not a supported import. RoamDrop blocks that content from recognition and offers manual card creation instead.
- Encryption in transit. The limited network requests the app makes (for example, fetching a preview of a link you paste or resolving places through Apple MapKit) use encrypted connections where supported by the destination service.
- Minimal data. We don’t run analytics on your document content. The app reports anonymous usage statistics — event names and coarse counts, never the contents of your cards or documents — to PostHog in the EU, and you can switch it off in Settings. See the Privacy Policy for exactly what is and is not sent.
- Opt-in cloud features. Optional cloud sync is planned and not active today. When introduced, it’s expected to use Apple’s iCloud, so data syncs through your own Apple account under Apple’s encryption.
Our practices
- We follow least-privilege principles for any internal access and limit who can touch production systems.
- We maintain a process to triage, contain, and remediate security issues, and to notify people where required by law.
- We keep dependencies minimal to reduce the attack surface.
- We keep recognition correction data local unless a future privacy decision, opt-in flow and policy update explicitly changes that.
What you can do
- Use a strong device passcode and biometric lock.
- Keep encrypted device backups so you don’t lose your trips.
- Be thoughtful about who you share an exported trip with, especially if it contains sensitive documents.
- Always verify recognized details (dates, times, places, prices) against the original before relying on them.
- Delete documents you no longer need.
Reporting a vulnerability
If you believe you’ve found a security issue in RoamDrop, please email security@roamdrop.app with enough detail to reproduce it. Please don’t publicly disclose it until we’ve had a reasonable chance to investigate and fix it. We appreciate responsible disclosure.
Contact
Security: security@roamdrop.app · Privacy: privacy@roamdrop.app. See also our Privacy Policy and Legal Center.
