Privacy policy

Effective from Sep 30, 2026

This says what the travel journal stores about you, who else sees it, how long it is kept and how you get it back or get rid of it. It is written to be read rather than to be survived.

The service is a free preview, and the terms say what that means for what it promises. It changes nothing here: from the moment your email address is in the database somebody is responsible for it under data protection law, and that is not something a preview — or a sentence in the terms — can set aside.

Controller and contact

David Konečný is responsible for the personal data described here — the controller, in the language of the regulation — as a private individual rather than a business, and the same person who runs the service under the terms. Write to david@konecny.eu about anything on this page: a question, a correction, a copy of what is held, or a request to delete it. There is no data protection officer; a service this size is not required to have one, and the address above reaches the person who would be it.

What we store

The account: your email address, the name you give, and the handle your journals live under. Also which version of the terms and of this policy you accepted and on what day, because the service acts on that record, and the last day you were seen signed in — which is what decides whether a free account nobody uses is warned and deleted, together with how many of those warnings have been sent and when the latest one went out.

What you write and upload: your journals and their entries; your photographs and videos; your GPS tracks; documents such as tickets and permits; and expenses, including who owed what to whom. A photograph's original keeps the metadata your camera wrote, location included; the smaller versions a reader's browser downloads have it stripped out.

Your plan. The account stores which plan it is on. During the preview that is always a plan without payment — one the service granted — and it is stored in a second field beside the first, which no page of the app shows you, which is why it is named here.

The payment record, which is empty. Nothing is sold during the preview and no payment method is taken, so the fields that would hold one hold nothing. They are described here anyway, because they exist and because this is the paragraph that will be true the day they fill: an account that has bought a plan stores Stripe's identifier for it as a customer — that is how a payment is matched to an account — and one row about its subscription, kept here so the app can say what the account may do without asking Stripe on every page: Stripe's identifier for the subscription, its status, the price it is on, the plan, billing interval and currency that price stands for, when the current period ends, and whether it is set to stop at the end of it. The card itself is never here; Stripe holds it. If paid plans arrive you will be told before anything is charged, and this policy will be reissued with a new effective date.

A custom domain, if your plan includes one and you have added one: the hostname you typed, whether it is waiting, working or failed, the day it was added and the day it started working. The hostname is registered with Cloudflare so that a certificate can be issued for it, and it travels in your data export.

Reports of illegal content: what the reporter wrote, their name and their email address, and which travel the notice was about — its title and its owner's handle, copied onto the notice so that the record still reads once that travel is deleted.

Suspensions: if staff have hidden a travel after a report, the travel stores when that happened and the reason staff wrote, which its owner reads in their workspace.

Technical records: sign-in links and the sessions they open, and counters that limit how often an address or an internet address may do something — sending sign-in links, inviting co-travelers, filing reports. Those counters are how the service stops being flooded, and they are short-lived.

Photographs, videos and how they are served

Read this if you keep a journal private or share it by secret link. Photographs and videos are served from a storage address of their own, and that address is not guessed: it holds a long random identifier, and there is no listing, no index and no way to walk from one file to the next. But the address itself is not checked against who you are — anyone who has the address, or to whom it is forwarded, can open that one file, even if the travel it belongs to is a draft or shared only by a secret link. The pages are protected; the direct file addresses are unguessable rather than access-controlled. Documents — tickets, permits, anything in the Documents tab — are different on purpose: they go through the app, which checks who is asking before it serves a single byte.

Visits and statistics

Every journal shows its owner how many people read it. To count a reader twice in one day as one person, the service stores a hash of that day's random secret, the reader's internet address and their browser's user agent — never the address itself. The day's secret and the hashes are deleted together every night, so nothing about a reader outlives the day they visited, and no hash can be traced back to an address once its secret is gone. What is kept is the counts: how many views, how many readers, which day, which page, and which site a link was followed from.

The waiting list before launch

An address left on the pre-launch page is kept with the language of the page and where the link came from. It is used for one thing only: to write to you once, when the service opens. Ask at the contact address above and it comes off the list; it also comes off on its own if an account with that address is ever deleted.

Who processes it for us

  • Cloudflare — hosting, the database, file storage, the anti-robot check on the sign-in form, and the certificate for an account's own custom domain.
  • Resend — the emails the service sends.
  • Stripe — payments, and the customer portal where a plan is changed or cancelled.
  • The geocoding provider — place searches, which send the words you typed.
  • Exchange rates — Frankfurter's European Central Bank rates, with currency data on jsDelivr as a fallback. Server to server, a currency pair and a date, no personal data.
  • OpenFreeMap — the map tiles, which the reader's own browser fetches, so it sees that browser's internet address.

Lawful bases and transfers

Your account, your journals and the service that keeps them are processed to perform the contract these terms make. Payments, when there are any, rest on the same contract plus the tax law that says an invoice must be kept. The visit counts and the rate limits rest on our legitimate interest in showing an owner who reads their journal and in keeping the service standing up; both are built to hold as little as will do the job.

A report of illegal content is different, and deliberately so: it is processed to meet a legal obligation. The Digital Services Act requires the service to receive notices, act on them, tell the notifier what was decided and count them in a transparency report. That is why a notice is kept after the reported travel is gone, and why a request to erase it cannot take it out of that record before its retention ends.

Cloudflare, Stripe, Resend and the geocoding provider are reached in the European Union where they offer it, and each of them is a company that may process data outside it. Where that happens it is covered by the European Commission's standard contractual clauses, which are part of our agreement with each of them. Ask at the contact address for the current list.

How long we keep it

Your account and everything in it are kept while the account exists. A free account that owns a journal and that nobody has signed in to for twelve months is warned three times over thirty days and then deleted. Your plan, a plan granted without payment, Stripe's identifier for you as a customer and the subscription row are kept while the account exists and go when it is deleted — the subscription is cancelled, the Stripe customer is deleted, and both the identifier and the granted plan are cleared from whatever record is left.

A report of illegal content is kept until staff have dealt with it and twelve months longer, after which the nightly job deletes it; a report nobody has dealt with yet is never deleted. A suspension note on a travel stays as long as the travel does — longer, therefore, than the report that led to it, because it is the owner's own record of what was decided about their journal and the only place they can read it.

Visit hashes and the day's secret go every night. Sign-in links expire in fifteen minutes and sessions in thirty days. Deleted data can persist for up to 180 days in database backups. Stripe keeps a deleted account's invoices for as long as its own tax law requires, although the customer record — email, name, saved cards — goes with the account.

Your rights: export, deletion and complaints

Access and portability: Download my data on the Account page gives you everything, as a zip you can open — your account, your journals and entries as data and as readable text, your documents, your tracks, and each journal's photographs and videos alongside.

Erasure: Delete account on the same page. It is final. The account closes at once and stops serving its pages, and what it owns is removed from the database and from file storage over the nights that follow — a large account can take several. Entries, photographs and documents you added to other people's journals stay there, under "Former co-traveler", unless you ask for those to go too.

Three things are not in the download, so that the list above stays the fuller answer: Stripe's identifier for you as a customer and a plan granted without payment are not in it — the payments that identifier names are read in Stripe's own customer portal, and a granted plan shows up in the plan that is exported — and a suspension note stays with the travel rather than travelling in the export. Ask at the contact address for any of them.

You can also ask for correction, for restriction, and for a copy of anything above. And you can complain to the Czech data protection authority, the Úřad pro ochranu osobních údajů, at uoou.gov.cz.

Cookies

Strictly necessary cookies only: the one that keeps you signed in, the ones that remember a secret link you have opened, and one that remembers how you like a page laid out. Nothing tracks you across other sites, nothing is sold, and that is why there is no cookie banner here.