Legal
LifeTravel Privacy Policy
1. Controller and contact
Lythos, established in the Netherlands, operates LifeTravel and is the controller for personal data processed through the service. Contact [email protected] for privacy matters, or [email protected] for the operator. This policy applies to lifetravel.app, its installed web application, and related support communication.
2. Data we process
We process account identifiers, email address, display name, username, profile fields, authentication methods, verified-email state, sessions, security events, and legal-consent records. Product data can include trips, locations, routes, dates, budgets, expenses, collaborators, messages, packing lists, journal entries, photos, encrypted travel documents, passport countries, achievements, friends, feedback, and notification preferences. Billing records include Stripe customer, price, checkout, subscription, and entitlement identifiers, but not full payment-card details. Technical data can include IP address, user agent, timestamps, error traces, push endpoints, and audit events.
3. Sources
Most data comes from you or a collaborator who adds you to a trip. Google provides basic account information when you choose Google sign-in. Stripe provides payment and subscription events. The legacy migration contains historical LifeTravel records from the supplied Firebase export; history is linked only after an exact email address is verified. Retired legacy identities remain attribution-only and cannot sign in.
4. Purposes and legal bases
- Contract: create and secure accounts, provide planning and sharing features, synchronize collaboration, deliver requested messages, manage subscriptions, and provide exports.
- Legitimate interests: prevent abuse, investigate incidents, maintain audit logs, improve reliability, support users, protect legal claims, and operate encrypted backups. We balance these interests against user rights.
- Legal obligation: retain records required for tax, accounting, fraud prevention, lawful requests, and consumer protection.
- Consent: optional browser push notifications and any future non-essential marketing. Consent can be withdrawn without affecting earlier lawful processing.
LifeTravel does not use solely automated decisions that produce legal or similarly significant effects.
5. Sharing and public content
Trip members can see content within trips they are authorized to access. A public journey or public journal entry can be viewed by anyone and may be indexed by search engines. A link-only journey can be viewed by anyone holding its unguessable link until the owner rotates it. Do not publish passports, booking references, addresses, or other sensitive information. We disclose data to authorities only when legally required, and to service providers only as needed to operate a requested feature.
6. Infrastructure and providers
Core application data, authentication, PostgreSQL, encrypted file storage, Stalwart mail, Roundcube webmail, backups, and GlitchTip error monitoring are self-hosted on Oracle Cloud infrastructure managed through Coolify. Cloudflare provides DNS, TLS, and web-edge services. Optional integrations are Google OAuth, Google Maps, Google Gemini, Stripe, OCI Email Delivery, Open-Meteo, and the Frankfurter currency API. Gemini receives the destination, trip length, and interests entered for an AI request; avoid entering sensitive personal data. Maps, weather, and currency providers receive only the parameters required for the chosen feature. Provider terms and privacy notices also apply.
7. International transfers
Some providers may process data outside the European Economic Area. Where required, Lythos relies on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism and evaluates supplementary safeguards. Current provider and transfer information can be requested from the privacy contact.
8. Retention
- Account and product data: while the account is active, then deleted or anonymized after a verified deletion request unless retention is required.
- Authentication sessions: until sign-out, revocation, or their configured expiry.
- Operational and security audit data: normally up to 12 months, longer when needed for an incident or legal claim.
- Support and feedback: normally up to 24 months after closure.
- Stripe and accounting records: as required by Dutch tax and accounting law, commonly seven years.
- Encrypted server backups: 14 days by default. Separately downloaded disaster-recovery copies are rotated under the backup procedure.
- Failed delivery and webhook diagnostics: normally up to 90 days after resolution.
Deletion from backups occurs through normal rotation. Restored data is re-subjected to active deletion records before normal service resumes.
9. Security
LifeTravel uses server-side authorization, database-backed revocable sessions, verified-email account claims, rate limiting, signed Stripe webhooks, restrictive browser headers, network segmentation, encrypted transport, AES-256-GCM file encryption, encrypted backups, audit logging, and self-hosted error monitoring. No service can guarantee absolute security. Report suspected vulnerabilities to [email protected].
10. Your rights
Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. The authenticated data export provides a machine-readable copy of your own contributions. Contact us from the account email; we may request proportionate identity verification. We normally respond within one month. You may complain to the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, or another competent supervisory authority.
11. Children
LifeTravel is not directed to children under 16 and does not knowingly permit them to create an account. A parent or guardian should contact us if a child has provided personal data.
12. Changes
Material changes will be announced in the service and, when required, renewed acceptance will be requested. Earlier versions can be requested from the privacy contact.
Effective 18 July 2026. Policy version 2026-07-18.