Periplous is operated by Nikolaos Lathiotakis. For data-related enquiries contact: privacy@periplous.app
• Account information: name, email address, profile photo (optional) • Authentication data when signing in with Google • Travel content you create: itineraries, posts, journal entries, packing lists • Travel preferences: destination, duration, budget, travel style • Device information: language preference, app settings stored locally • Purchase information: subscription status (managed by Apple; we do not store payment card data)
We process your data under the following legal bases: • Contract (Art. 6(1)(b)): to provide the Periplous service you signed up for • Legitimate interest (Art. 6(1)(f)): to improve and secure the app • Consent (Art. 6(1)(a)): for optional features such as profile photos and push notifications • Legal obligation (Art. 6(1)(c)): to comply with applicable law
Your data is used to: • Operate the app and provide your account • Generate personalised travel itineraries and packing lists using your stated preferences • Enable social features (journal posts, reviews) • Send trip reminders and notifications (with your consent) • Improve app performance and fix issues We do not sell your data to third parties or use it for advertising.
When you generate an itinerary or packing list, your travel preferences (destination, duration, budget, travel style, and travel dates) are sent to Anthropic, Inc. to be processed by their Claude AI model. No personally identifiable information (name, email, account details) is included in these requests. AI-generated content is provided for informational purposes only and may not always be accurate. You should verify all travel information independently.
We use the following third-party services to operate Periplous. Each has its own privacy policy and, where required, a Data Processing Agreement with us: • Supabase, Inc. (EU region) — authentication, database, and file storage • Anthropic, Inc. — AI itinerary and packing list generation (travel preferences only; no personal identifiers) • Google LLC — optional Google Sign-In authentication • Apple, Inc. — App Store payments and subscription management • RevenueCat, Inc. — subscription status verification • Open-Meteo — weather forecast data (no personal data sent) • Komoot GmbH (Photon) — location search autocomplete (no personal data sent) • Expo (Expo SDK) — app infrastructure and push notification delivery
If you are in the EU/EEA you have the right to: • Access your personal data (Art. 15) • Correct inaccurate data (Art. 16) • Request deletion of your data (Art. 17) • Restrict or object to processing (Art. 18, 21) • Data portability (Art. 20) • Withdraw consent at any time without affecting prior processing • Lodge a complaint with your local data protection authority To exercise any of these rights contact privacy@periplous.app
Periplous uses AI to generate personalised itineraries and packing lists based on your stated preferences. This constitutes automated processing under GDPR Art. 22. It does not produce legal or similarly significant effects — the output is travel suggestions only. You can always choose not to use AI features and plan your trip manually.
You may request full account and data deletion at any time from Profile → Settings → Delete Account. Deletion is processed immediately for your in-app data and within 30 days for any residual server-side data. You may also email privacy@periplous.app.
We retain your data for as long as your account is active. After account deletion, anonymised aggregate data (e.g. destination popularity counts) may be retained indefinitely. Locally stored data (trip notes, packing lists) remains on your device until you uninstall the app or delete your account.
Some third-party processors (Anthropic, RevenueCat) are based in the United States. Where data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal transfer mechanism.
Periplous is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact privacy@periplous.app and we will delete it promptly.
If you are a California resident, you have the right to know what personal information we collect, request deletion of your personal information, and opt out of the sale of your personal information. We do not sell your personal information to any third party, and we have not done so in the past 12 months. To exercise your California privacy rights, contact privacy@periplous.app.
We may update this policy from time to time. We will notify you of significant changes via the app. Continued use after changes constitutes acceptance of the updated policy.
Data Controller: Nikolaos Lathiotakis, operating as Periplous Email: privacy@periplous.app For EU residents: you have the right to lodge a complaint with your national supervisory authority if you believe your data has been processed unlawfully.