Roam Roam
How it works Features Pricing For Teams
Download free
Back to Roam

Privacy Policy

Effective date: 11 April 2026  ·  Last updated: 11 April 2026

This Privacy Policy explains what personal data we collect when you use Roam, how we use it, who we share it with, and the rights you have over it. If you have any questions, contact us at [email protected].

1. Who we are

Roam (the "app") is operated by Luboš Dušek ("we", "us", "our"), based in the United Kingdom.

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the data controller for the personal data described in this policy.

2. What personal data we collect

We collect only the data necessary to provide Roam and improve your experience.

2.1 When you sign in

Roam uses Sign in with Apple as its only authentication method. When you sign in, Apple provides us with:

Data When we receive it Why
A stable Apple user identifier unique to you and to Roam Every sign-in To recognise you across sessions and devices
Your email address (real or Apple's "Hide My Email" relay) First sign-in only To contact you about your account, service notices, and (with consent) marketing
Your name First sign-in only, if you choose to share it Displayed as your username in-app; can be changed later

If you choose "Hide My Email", Apple gives us a relay address like [email protected]. Emails we send are forwarded to your real inbox via Apple. We never see your real email in that case.

2.2 Data you create in Roam

As you use the app, we store:

  • Profile picture you upload
  • Username you display
  • Marketing consent (your opt-in to receive travel tips and offers by email)
  • Trip data: destinations, dates, accommodation addresses, travel preferences (budget, pace, interests, vibe), generated itineraries, daily plans, events, shared trip participants
  • Token balance and usage history: how many trips you have available, how many you've generated
  • Purchase history: records of in-app purchases (token packs and subscriptions) including amount, currency, and transaction date
  • Subscription status: whether you have an active subscription and when it renews or expires
  • App preferences: dark mode toggle and similar user-interface settings

2.3 Data we do NOT collect

For transparency, Roam does not collect:

  • Your device location (we only process destinations you explicitly type)
  • Your browsing history
  • Your contacts or calendar entries (unless you explicitly tap "Add to Calendar", in which case iOS handles the export directly, we never see it)
  • Analytics from third-party SDKs (we don't use Google Analytics, Firebase Analytics, Mixpanel, Amplitude, or similar services)
  • Advertising identifiers
  • Biometric data
  • Health or fitness data

2.4 Payments

We never see your payment details. All in-app purchases are processed by Apple. We only receive a confirmation that a purchase succeeded, along with the product identifier and transaction ID, never your card number, expiry, or billing address. Refund requests are handled by Apple directly at reportaproblem.apple.com.

2.5 Crash reports and diagnostic data

Apple's built-in crash reporting may send anonymised crash logs to us via App Store Connect if you have enabled "Share With App Developers" in your iOS Settings → Privacy & Security → Analytics & Improvements. You can opt out at any time in that same setting. We use these reports solely to diagnose and fix bugs.

3. How we use your data

We use your data to:

  1. Provide the service, authenticate your account, generate itineraries, store your trips, deliver purchases, process subscriptions
  2. Sync your data across devices, when you sign in on a new device, we restore your trips, profile, and settings from our servers
  3. Share trips you choose to share, when you send a share code or invite a collaborator, we deliver the relevant trip data to those users
  4. Communicate with you, service notices about your account, purchase receipts via Apple, and (only if you opted in) marketing emails about travel tips and offers
  5. Improve the service, understand which features are used so we can fix bugs and prioritise improvements
  6. Comply with legal obligations, tax records for purchases, responses to lawful data requests, fraud prevention

4. Legal bases for processing (GDPR)

If you are in the European Union, the United Kingdom, or another jurisdiction covered by similar laws, we rely on the following legal bases under Article 6 of the GDPR:

Processing activity Legal basis
Creating and maintaining your account, authenticating you, providing the app's features Contract (Article 6(1)(b))
Processing in-app purchases and subscriptions Contract (Article 6(1)(b))
Storing purchase records for tax and accounting Legal obligation (Article 6(1)(c))
Fraud prevention, service security, preventing abuse Legitimate interest (Article 6(1)(f))
Sending marketing emails Consent (Article 6(1)(a)), you can withdraw at any time
Sending service notices about your account Contract (Article 6(1)(b))

5. Who we share your data with

We share your data only with the third parties necessary to operate Roam. We do not sell your personal data to anyone, and we do not share it with advertising networks.

5.1 Service providers

Third party What they process Where
Apple Inc. App distribution, Sign in with Apple, in-app purchases, App Store Connect analytics Global
Anthropic PBC (Claude API) The contents of your itinerary generation request, city, dates, preferences, interests, optional hotel address. Used solely to generate the itinerary, then discarded by Anthropic per its data retention policy. United States
Supabase Inc. Our primary database and authentication backend. Stores your account data, trip history, purchase history, subscription status, and profile picture. United Kingdom
Open-Meteo Weather forecasts for trip destinations. We do not send any personal data, only the destination city name. European Union

5.2 Other users

When you share a trip with another user via a share code or invite them to collaborate, they will see the trip contents and (for collaborators) the username of the person who originally created it. Only share trips containing personal information with people you trust.

5.3 Legal requests

We may disclose your data if required to do so by law (for example, in response to a court order or lawful request from a government authority), or where we believe in good faith that disclosure is necessary to protect our legal rights, the safety of users, or the integrity of the service.

6. International data transfers

Some of our service providers are based outside your country of residence. Specifically, Anthropic is based in the United States. When we transfer your data to providers outside the European Economic Area (EEA) or the United Kingdom, we rely on Standard Contractual Clauses adopted by the European Commission to ensure your data receives an equivalent level of protection.

Supabase stores data in the United Kingdom. If this is inside the EEA, no international transfer is required for core account storage.

7. Data retention

Data Retention period
Account data (Apple user ID, email, name, profile picture, preferences) Until you delete your account
Trips and itineraries Until you delete them, or until you delete your account
Purchase history and subscription records 7 years after the transaction (required for tax and accounting)
Marketing consent records Until you withdraw consent or delete your account
Crash reports and diagnostic data 90 days
Backups Removed within 30 days after account deletion

When you delete your account (via Profile → Settings → Delete account → Delete account & data, or by emailing us), we remove your account data from our active systems immediately. Backups containing residual data are overwritten within 30 days. Purchase records are kept for legal accounting purposes.

8. Security

We take reasonable measures to protect your data, including:

  • HTTPS/TLS encryption for all data in transit between the app and our servers
  • Encryption at rest for data stored on Supabase
  • Apple's Sign in with Apple authentication, you never create a password for Roam, which means we cannot leak one
  • Row-level security on our database to ensure users cannot access each other's data
  • Regular review of access controls and service provider security practices

No system is 100% secure. If we become aware of a data breach that affects your personal data, we will notify you and the appropriate authorities as required by law (within 72 hours under GDPR).

9. Your rights

9.1 If you are in the EEA, UK, or Switzerland (GDPR)

You have the following rights over your personal data:

  • Right of access, request a copy of the data we hold about you
  • Right to rectification, correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"), delete your account and associated data
  • Right to restrict processing, ask us to limit how we use your data
  • Right to data portability, receive your data in a machine-readable format
  • Right to object, object to processing based on legitimate interests, or to direct marketing
  • Right to withdraw consent, where we rely on your consent (e.g. marketing emails), you can withdraw it at any time
  • Right to lodge a complaint, with your local data protection authority. The contact details for EU authorities can be found at edpb.europa.eu. The UK authority is the Information Commissioner's Office.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days (or earlier if required by applicable law).

9.2 If you are in California, USA (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act):

  • Right to know what personal information we collect, use, and share about you
  • Right to delete personal information we hold about you, subject to certain exceptions
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information, we do not sell or share personal information for cross-context behavioural advertising, and we have never done so
  • Right to limit use of sensitive personal information, we do not use sensitive personal information for purposes beyond providing the service
  • Right to non-discrimination, we will not discriminate against you for exercising any of these rights

To exercise your California rights, email [email protected].

9.3 Everywhere

Regardless of where you live, you can:

  • Delete your account in-app via Profile → Settings → Delete account & data
  • Turn off marketing emails via Profile → Settings → Email updates
  • Change your display name via Profile → Settings → Username
  • Remove your profile picture via Profile → Settings → Profile picture
  • Revoke Sign in with Apple access via iOS Settings → [Your Name] → Sign-In & Security → Sign in with Apple → Roam → Stop Using Apple ID

10. Children

Roam is not intended for children under 13 years old (or the equivalent minimum age in your country, 16 in some EU countries). We do not knowingly collect personal data from children under this age. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it.

11. Marketing communications

If you opt in during sign-up or via Profile → Settings → Email updates, we may send you occasional emails about new features, travel tips, and special offers. You can unsubscribe at any time by:

  • Toggling off Email updates in Settings, or
  • Clicking the unsubscribe link in any marketing email, or
  • Emailing [email protected] and asking to be removed

Unsubscribing from marketing emails does not affect essential service communications (such as purchase receipts or account notifications), which we send based on our contract with you.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes that affect how we handle your personal data, we will notify you (for example, by email or through an in-app notice) and update the "Last updated" date at the top of this document.

We recommend reviewing this policy periodically to stay informed about our data practices.

13. Contact us

If you have any questions, concerns, or requests about this Privacy Policy or your personal data, please contact us:

  • Email: [email protected]
  • Name: Luboš Dušek
  • Address: 19 Harrisons Court, 10 Myers Lane, London, SE14 5RY

If you are in the EEA/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (see section 9.1).

Roam

Travel like you live there.

App

Download Features Pricing

Legal

Terms of Service Privacy Policy Support
© 2026 Roam. All rights reserved.