Privacy policy
Version 1.1 · last updated 28 September 2026
Voyu is a shared workspace for planning a trip with a group. This notice explains what we store when you use it, who else can see it, where it is processed, what is switched on by default and how to change that, and what you can ask us to do with your data. It applies to the web app at voyu.app and to the Voyu mobile app.
Who is responsible
[COMPANY LEGAL NAME], [STREET], [POSTCODE CITY], Switzerland, is the controller of your personal data. You can reach the people responsible at info@voyu.app. Company details are in the imprint.
For people in the European Union our representative under Art. 27 GDPR is [EU REPRESENTATIVE, ADDRESS, E-MAIL]; for people in the United Kingdom, [UK REPRESENTATIVE, ADDRESS, E-MAIL]. You can address any request to them as well as to us.
What we store
- Your account: e-mail address, first and last name, a password hash if you sign up with e-mail, a profile picture if you upload one (stored at a public link, so anyone holding the link can open it), and, if you sign in with Google, the name and profile-picture link Google gives us. We also record which version of the terms you accepted and when, and every privacy setting you change, with the time you changed it.
- Your trips: everything you and your group put into a trip. Trip name and dates, places (including addresses, coordinates and, for places picked from Google, the phone number and website Google returns), the itinerary, expenses and who paid or owes what, settlement payments, tasks, packing and shopping lists, notes and captions, polls and how each member voted, whether each member is in, out or maybe for an activity or reservation, and the links members make between items.
- Files you upload: photos, videos and documents such as tickets and booking confirmations, including saved e-mails. When you upload a photo we read the date it was taken and, if the photo contains one and you have not switched this off, where it was taken. We keep the location rounded to about a kilometre (enough to name the town, not the street) and remove the exact position and the other camera metadata from the stored file. Videos are stored as uploaded, including any location their container carries.
- Activity history: a log of changes in each trip (who added or changed what), shown to the group as the trip history. Locations, file paths, captions, phone numbers and invite codes are never written to it.
- Notifications: if you enable them on your phone, a push token that identifies the device, and which trips you have muted.
- Feedback and reports: the title, description and optional screenshot of any bug report or suggestion you send us, and any content report you make, together with your name and e-mail so we can answer.
- Technical logs: our hosting providers keep request logs with your IP address, browser or device type and the pages or functions you used, for a short period set by the provider. We also count how often each account uses certain features, such as place search or the data export, to prevent abuse.
- Error and usage reports (web app only): the web app reports errors, page load times, the pages you open and which navigation items you click, together with your browser and device type, to Grafana (see below), so we can find faults and see which parts of Voyu are used. Page addresses can contain a trip’s identifier, but not its name or content. For our own statistics we also count activity in Voyu, such as how many trips are created. These counts carry no names, titles, amounts or locations, and every identifier is replaced by a key, so they do not show Grafana who you are or which trip it is. We do not use advertising or cross-site tracking, and the mobile app sends no such reports.
Who can see what
- Everyone in a trip sees everything in that trip: the itinerary, expenses and balances, files, lists, the activity history and the member list. The member list shows each member’s name, picture and, unless that member has switched it off, their e-mail address, so that the people you travel with can reach you. The trip owner sees each member’s e-mail address either way. Photos show the town they were taken in, unless the person who added them has switched that off.
- Anyone who has an invite link can see the trip’s name, cover picture and number of members before they join, and messaging apps may show that preview when the link is shared. Only signed-in people can join. A new trip’s invite link works from the start, and the owner can switch it off or replace it at any time.
- Private packing items are visible only to the person who created them.
- The Voyu team can see bug reports and content reports you send, including any screenshot. We do not look into trips unless you ask us to for support or a report requires it.
Your settings and what is on by default
Two things are on from the moment you create an account. Both are explained on the screen where they first apply, and you can switch either off in your profile on the web or on the Account screen in the app. A change takes effect at once, in every trip you are on, and we never ask you again.
| Setting | What it does | Default | Why we do it | Where to change it |
|---|---|---|---|---|
| Show my e-mail to trip members | Members of your trips see your e-mail address in the member list, so they can contact you about the trip. The owner sees it regardless. | On | Voyu has no chat and does not handle money, so the people you travel with need a way to reach you. This is our legitimate interest and the group’s; switching it off is your objection, and we honour it immediately. | Profile (web) · Account (app) · the “Turn off” link when we tell you about a change |
| Show where my photos were taken | A photo you add shows the town it was taken in, to about a kilometre. The exact position is removed from the file. | On, but nothing is stored until you have answered a one-time question the first time you add a photo that has a location | The album can group photos by place. Photo location is data we treat with more care than the rest, so before the first one is stored we ask you in the app, and either answer is recorded. | Profile (web) · Account (app) · the first-photo question |
If you created your account before 12 September 2026, these settings stay off until you have seen the summary of this change and continued past it; you can switch either off on that screen before it applies to any trip.
Why we process it and on what basis
You must be at least 16 to use Voyu.
- Running the service you signed up for (account, trips, files, lists, history, the settings above): performance of our contract with you (GDPR Art. 6(1)(b)).
- Showing your e-mail address to trip members, and showing where your photos were taken: our legitimate interest and that of the people you travel with, as set out in the table above (Art. 6(1)(f)). You can object at any time with the switch, and we have written down the balancing behind each of these defaults; ask us for it. Where you answered the first-photo question with “Keep on”, we also rely on that answer as your consent (Art. 6(1)(a)), which you withdraw with the same switch.
- Keeping the service secure and running (technical logs, error and usage reports, abuse handling, backups): our legitimate interest (Art. 6(1)(f)).
- Notifications, camera and photo access: the permissions you grant on your device, which you can withdraw in the app or in your device settings (Art. 6(1)(a)).
- Answering your requests, feedback and reports: our legitimate interest and, for rights requests and content reports, our legal obligations (Art. 6(1)(c)).
Under Swiss law we rely on the same grounds and on the principles of the Federal Act on Data Protection; where we process on the basis of a legitimate interest, we have assessed that the processing is proportionate and does not unlawfully infringe your personality.
Providers we rely on
Your data is stored by Supabase on servers in Zurich, Switzerland. The following providers process data on our behalf or receive data when you use a feature:
- Supabase (database, file storage, sign-in, push queue) and its infrastructure providers Amazon Web Services and Cloudflare; request logs may be processed outside Switzerland.
- Vercel hosts the web app and processes each page request.
- Google: Google Sign-In if you use it; Google Maps to show maps; Google Places and Routes when you search for a place or we compute a route; place photos, which your browser or phone loads from Google directly. When a member opens a photo that has a location, we send that location, rounded to about a kilometre, to Google to name the place.
- Grafana Labs receives the web app’s error and usage reports, and the activity counts described above, in which every name and identifier is replaced by a key.
- Unsplash provides trip cover pictures; your browser or phone loads them from Unsplash directly.
- Open-Meteo provides the weather forecast through our server, which sends it the coordinates and dates of the stay.
- Flight and airline data providers receive a flight number and date when you add a flight, and airline codes for airline names and logos.
- Expo, Apple and Google deliver push notifications to your phone. A notification contains the trip name and a short sentence about what changed, such as who added an expense, which may include the title of an expense, item or poll; it never contains amounts, addresses or locations.
Several of these providers are in the United States. Transfers there rely on the Swiss-US and EU-US Data Privacy Framework where the provider is certified and otherwise on the providers’ standard contractual clauses.
How long we keep it
- Trip content stays as long as the trip exists. The trip owner can delete the trip, and members can delete what they uploaded; deleting a photo deletes its location.
- The activity history of a trip is kept for the life of the trip.
- Delivered notification entries are removed after 30 days.
- Your account, your settings history and your acceptance of the terms stay until you delete the account.
- Provider request logs and the web app’s error and usage reports are kept for the short period set by each provider.
Your rights
You can ask us for a copy of your data, to correct it, to delete your account and the content you uploaded, to receive it in a portable format, or to object to a particular use. For the two settings above, the switch in the app is the fastest way to object and needs no e-mail. For anything else, write to info@voyu.app from the address on your account and we will answer within 30 days. You can delete your account yourself from your profile in the web app or the Account screen in the mobile app; what that removes and what stays with your trips is explained at voyu.app/legal/delete-account. A copy of your data, including your settings history, is one click away on the same screens (“Data export” under “Your data” on the web, “Export my data” in the app). You can edit your name in the app and leave any trip at any time. If you are in the EU or UK you may also complain to your data protection authority; in Switzerland that is the Federal Data Protection and Information Commissioner.
Cookies and storage on your device
The web app sets a sign-in cookie so you stay logged in and a cookie with your time zone so times show correctly, and keeps your light or dark theme and a few display choices, such as whether a trip opens on its map or its photo, in your browser’s storage. The error and usage reporting described above keeps a session identifier there too. It uses no advertising cookies. The mobile app keeps your session and a copy of your trips on the phone so they open without a connection; signing out removes that copy.
Changes
When we change what Voyu does with your data in a way that matters, we show you a summary in the app the next time you sign in and ask you to continue past it before the change applies to you; the summary lets you switch off anything new before it takes effect. The terms of service are published separately, and each version of both documents carries the date it took effect.
What changed
Version 1.1 (28 September 2026) corrects version 1.0 so that it describes what Voyu does today. Nothing new is collected because of it:
- It names the error and usage reports the web app sends to Grafana, and our pseudonymised activity counts, which version 1.0 wrongly said did not exist.
- It lists everything the web app keeps in your browser: the time-zone cookie, display choices and the reporting session identifier.
- A new trip’s invite link now works from the start.
- It lists polls and votes, In / Out / Maybe answers, links between items and our abuse counters, and that place photos load from Google directly.
Version 1.0, compared with the interim notice of 3 September 2026:
- Your e-mail address is shown to members of your trips by default, so they can reach you; before, only the trip owner saw it. Switch it off in your settings.
- Photos you add show the town they were taken in by default, after a one-time question in the app; before, this was off unless you switched it on. Switch it off in your settings or at that question.
- We now state the legal basis for each of these defaults, keep a record of every setting you change, and include that record in your data export.
- Weather requests now go through our server rather than from your device.