DRAFT — requires legal counsel review before store submission
TravelMapReel — Privacy Policy
Last updated: 2026-07-08 · MVP draft (English)
TravelMapReel (“TravelMapReel”, “we”, “us”) turns the photos from a road trip into a short animated map reel. This policy explains what we read from your photos, what we store, where we store it, and how you can delete all of it. It is written to meet our obligations under the EU General Data Protection Regulation (GDPR) and the app-store privacy requirements.
If anything here is unclear, contact us at privacy@travelmapreel.com (placeholder — confirm before publishing).
1. What we read from your photos
To place your trip on a map and order it in time, TravelMapReel reads only two things from each photo you choose:
- When it was taken — the photo’s timestamp (EXIF
DateTimeOriginal). - Where it was taken — the photo’s GPS coordinate (EXIF/location metadata), when your device makes it available and you have granted photo-location access.
That is the entirety of the “time and place” metadata we use. We do not run facial recognition, we do not analyse the content (the pixels) of your photos with any third-party service, and we do not read photos you did not select for a trip.
2. Your original photos stay on your device
TravelMapReel never uploads your original photo files to build a trip. Timestamp and location are extracted on your device, and only that small metadata (plus any photo you explicitly add to a reel) leaves the phone. Your camera roll stays yours.
When a photo is used as a frame in a reel, only that image is uploaded for rendering — see the next section for how it is stored and for how the finished reel is stripped of metadata.
3. What we store, where, and for how long
- Trip data — the stops, route, dates, distances and titles you create — is stored in our database so you can come back to your trips. It is hosted in the European Union.
- Media (photos used in a reel, generated narration audio, and the finished MP4) is
stored in object storage under a per-user prefix (
u/{your-user-id}/…) in an EU-jurisdiction bucket. Objects in one user’s prefix are never mixed with another’s. - Access is via short-lived signed URLs. We do not make your media public. Every read or upload uses a signed URL that expires (at most seven days, usually far less), so a link cannot be shared or indexed indefinitely.
- Account data — your email (for magic-link sign-in) and authentication records — is kept while your account exists.
We keep this data until you delete it (Section 6) or delete your account.
4. The reels we produce carry no hidden location data
The finished video is re-encoded (H.264/MP4) and is EXIF/GPS/timestamp-free: the file you download or repost does not embed the coordinates or capture times of your source photos. This is a deliberate privacy guarantee — you can share a reel without leaking where a photo was actually taken. We test for this on every release so it cannot silently regress.
5. Analytics
We may use privacy-preserving product analytics (hosted in the EU) to understand which features are used and to fix crashes. This analytics:
- is about app usage, never the content of your photos;
- does not send your photos or your photo metadata to any third-party analytics provider;
- runs with image-masking enabled and session replay disabled so screens that show your photos are never recorded.
6. Deleting your data (GDPR right to erasure)
You can permanently delete your account and all associated data from inside the app (Settings → Delete account). When you confirm:
- every database row tied to your account — trips, stops, photos metadata, route legs, render jobs, credits, entitlement history, push tokens and your sign-in identity — is hard deleted; and
- every object under your
u/{your-user-id}/media prefix is erased from storage, including any photo or rendered video you made before signing in (while using the app as a guest) — those still live under your prior, guest-era prefix once your guest session links to your account, and deletion reaches them there too, not just under your current prefix.
Separately from account deletion: if you cancel a render (or it fails) while it’s still in progress, we make a best-effort attempt to delete its video from storage right away, once the render finishes — it isn’t meant to be kept around for an account you haven’t deleted. This immediate cleanup can occasionally fail to go through (e.g. a storage hiccup); when that happens the video is still removed the next time you delete your account (Section 6), which is what we guarantee, rather than the immediate best-effort attempt.
This is a true erasure, not a “deactivation”, and it is irreversible. It is served by our
authenticated DELETE /me endpoint and is idempotent (re-running it changes nothing).
Deleting your TravelMapReel account does not cancel a paid subscription you bought through Apple or Google. See the Terms of Service and Section 7 below.
7. Payments
Purchases (the one-off Trip Pass and any subscription) are processed by Apple and Google through their in-app-purchase systems and by our payments/entitlements provider. We receive a record that an entitlement was granted; we never see or store your full card details. Cancelling or refunding a store purchase is handled by Apple/Google, not by deleting your TravelMapReel account.
8. Your rights
Under the GDPR you have the right to access, correct, and erase your personal data, and to object to or restrict certain processing. Erasure is available immediately in-app (Section 6); for any other request, contact privacy@travelmapreel.com. You also have the right to lodge a complaint with your local data-protection authority.
9. Children
TravelMapReel is not directed at children under 16 (or the minimum age in your country) and we do not knowingly collect their data.
10. Changes to this policy
We will update this page when our practices change and revise the “Last updated” date above. Material changes will be surfaced in the app.