PackPal
PackPal is a group-travel planning app. This policy describes exactly what the app stores, where it is stored, and who else can see it. It describes the app as it is actually built — where a feature exists in the code but is not switched on, that is stated rather than glossed over.
PackPal (the “app”) is operated by [[ TO CONFIRM: legal entity / trading name ]], [[ TO CONFIRM: registered address ]]. In this policy, “we” and “us” mean that entity, and “you” means the person using the app.
To create an account you provide an email address and either a password or a Sign in with Apple credential. Two sign-in methods are available:
You may optionally add a display name, an avatar colour, and a profile photo. Your display name and avatar are visible to other people on trips you share.
Everything you enter into a trip is stored so that it can be shared with the other people on that trip:
| Category | What it includes |
|---|---|
| Trips | Trip name, destinations and stops, travel dates, currency, budget cap |
| People | Names of travellers you add to a trip, and their role on it |
| Money | Expenses, amounts, categories, how each expense is split, and records of payments between members |
| Decisions | Polls, the options on them, and how each member ranked those options |
| Plans | Itinerary days and entries, times, locations, and saved places |
| Arrivals | How and when each member arrives — travel mode, an optional flight number or origin, and arrival time |
| Lists and notes | Packing items and who is bringing them; notes posted to the trip board |
| Files | Receipt photos attached to expenses, and documents uploaded to a trip’s vault |
Files are held in three private storage areas. None of them is publicly readable — every file is served through a short-lived signed link to someone entitled to see it.
Photos and documents may contain more than you intend — a boarding pass carries a booking reference, and a photo may carry location metadata. Only upload what you are willing to share with the other people on that trip.
PackPal offers optional in-app purchases: an additional trip, and a pack of extra seats for a trip. Purchases are processed entirely by Apple. We never see your card details. We receive confirmation that a purchase was verified, and we keep a record of the transaction so that the credit can be applied to your account and reconciled later.
Stated plainly, because these are the things people most often assume an app of this kind takes:
The only permissions the app asks for are the camera (to take a profile photo) and calendar write access (to add confirmed plans to your calendar, if you choose to). Choosing an existing photo uses Apple’s photo picker, which hands over only the image you pick.
Your data is used to run the app and nothing else:
We do not use your trip content to build advertising profiles, and we do not use it to train machine-learning models.
We use a small number of providers to run the service. They process data on our behalf:
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Hosts the database, authentication and file storage | All account and trip data described in section 2 |
| Apple | Sign in with Apple; in-app purchases; map and place search; on-device intelligence | Your sign-in credential; purchase details; the text of place searches you type |
| Cloudflare | Hosts this website only | Standard web request information for this site. It holds no app data. |
PackPal uses AI for two things: suggesting places for a trip, and reading an itinerary out of a document you import. Both run on your device, using Apple’s on-device models. Where the device model is unavailable, the app falls back to a built-in non-AI method rather than sending your data anywhere.
Your trip content is not sent to any AI provider. The server-side code contains a hook for an external language model, but it is disabled: the code path is commented out, it requires an API key that is not configured, and the app does not call it. If that ever changes, this policy will be updated before the change ships.
Your data is stored by Supabase in the us-west-1 region — that is, in the United States. If you use the app from outside the United States, your information is transferred there and handled under United States law.
[[ TO CONFIRM: if you have users in the UK/EU, the transfer mechanism (e.g. Standard Contractual Clauses) and any UK/EU representative must be named here ]]
We keep your account and trip data for as long as your account exists. Trip content lives as long as the trip does — deleting a trip deletes its contents.
[[ TO CONFIRM: whether any fixed retention periods apply — the app currently defines none, so data persists until you or another member deletes it ]]
One exception survives account deletion, described next.
You can delete your account from within the app, under Account. Deletion is permanent. Here is precisely what happens, because the outcome affects other people:
If you want your name removed from a trip you no longer wish to appear on, ask that trip’s owner to remove it, or leave the trip before deleting your account.
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict its processing, and to complain to a data-protection authority.
You can exercise most of these in the app directly: your name, avatar and photo are editable under Account, and account deletion is available there too. For anything else, contact us at [[ TO CONFIRM: privacy contact email address ]] and we will respond within the period required by applicable law.
PackPal is not intended for children. You must be at least 13 years old to create an account. [[ TO CONFIRM: some jurisdictions require 16 — confirm the minimum age for the markets you ship to ]] If we learn that we hold data from a child below the applicable minimum age, we will delete it.
Data is transmitted over encrypted connections. Access to every table and every stored file is governed by row-level security rules enforced by the database, so a request can only ever return data belonging to trips you are a member of. Files are private and reachable only through short-lived signed links.
No system is perfectly secure, and we cannot guarantee absolute security. Use a strong, unique password, and be careful who you send invite links to.
If we change this policy we will update the date at the top of this page. Where a change materially affects how your data is handled — for example, if trip content were ever to be sent to an external AI provider — we will say so in the app before the change takes effect.
Questions about this policy, or about your data: [[ TO CONFIRM: contact email address ]], [[ TO CONFIRM: postal address ]].
Governing law and jurisdiction for this policy: [[ TO CONFIRM: jurisdiction ]].