Privacy Policy

Last updated 6 September 2026 · draft under review ahead of public launch

Reveldays helps you turn travel booking emails into organised trips. This policy explains what we collect, why, who processes it on our behalf, and the control you have. The short version: we only ever process the booking emails you choose to forward or upload — never the rest of your inbox — and you can delete everything, anytime.

Who we are

Reveldays (“we”, “us”) is the data controller for the personal data described here. The operating entity is Holaday Limited. For any privacy question or request, contact privacy@holaday.app.

What we collect

  • Account details — when you sign in with Google we receive your name, email address and profile photo. We do not receive your Google password.
  • Your account photo — we save a copy of your Google profile photo and use it as your account picture, rather than loading it from Google each time (that way viewing Reveldays doesn’t tell Google what you’re looking at). It appears next to your name to people you invite or share a trip with, and on any trip you choose to publish with your name on it. You can remove it any time in Settings ▸ Account — that deletes our copy — and put it back just as easily. Deleting your account deletes it too.
  • The booking emails you send us — the confirmations you forward to your import address or upload as files, and the trip details we extract from them (flights, stays, cars, reservations, dates, places and amounts). To let you re-check an email when our reading of it improves, we keep the email’s content for about 14 days, encrypted, and then delete it automatically; it is also deleted immediately if you delete the email data or your account. After that, only the extracted trip details remain. Ticket and voucher attachments (like a boarding pass or car-rental voucher PDF) are saved to your trip’s Wallet so you can open them at check-in; they are stored privately and deleted when you delete your email data or your account. We also read the scannable barcode on those tickets (the QR or boarding-pass code) and keep a picture of it, plus what it encodes, so you can scan straight from the app at the gate. A barcode is like the ticket itself, so it stays strictly yours — never visible to people you share a trip with — and it is deleted with your email data or your account.
  • Trips you create, save or clone, the people you follow, and any notes or edits you add.
  • Minimal product analytics — first-party events (e.g. “a landing page was viewed”, “an import started”) tied to an anonymous device id, so we can understand and improve the product. At the start of each visit we also record how you got here — the referring site’s domain (never the full address) and the utm_source / utm_medium / utm_campaign tags on the link you followed — plus your device type (phone/tablet/desktop), browser family, and the country you connected from. The country is worked out on our own server from your connection address at that moment, against an offline database (GeoLite2 data created by MaxMind); the address itself is immediately discarded and is never sent anywhere. These events never include your IP address, and we don’t fingerprint your device. They carry no email content, prices, booking codes or names. Your browser talks only to us: we use no third-party advertising or tracking scripts. To analyse these events (funnels, feature usage) we mirror them, server-side and with the same minimal content, to PostHog’s EU cloud (see sub-processors below).
  • Device location on the map — only if you ask, never stored. On the trip map you can tap “Show my location” to see where you are relative to your plans. Your location is read once, on your device, in your browser, and used only while that view is open. It is never saved and never sent to our servers or anyone else.
  • Device location on a trip day — the place is never stored; the stop is, while “Remember my visits” is on. On a trip’s day view you can tap “Show distances” to see how far away your next stop is. Your location is read once, on your device, and the location itself is never saved and never sent to our servers — not on this flow either. Separately, when “Remember my visits” is on in Settings ▸ Personalisation — you can switch it off there at any time, and nothing is recorded unless and until your browser grants this site location access, a prompt that is yours to accept or refuse — your browser also works out which of that day’s stops you reached and saves that conclusion — the stop, whether you reached it or went past it, and when. The working out happens on your device; we never receive the coordinate, and we deliberately do not store how far you were from anything, because distances from several known places would add up to a position. Only you can see these; the people you travel with cannot. Switch it off and nothing new is recorded; use Forget my visit history to erase what already is.

How we use it

  • To read your booking confirmations and file them into the right trip, automatically.
  • To show, cost, time-line and map your trips, and to power optional AI trip planning.
  • To run the optional Public Trips feature — if (and only if) you publish a trip, we show an anonymised version (places and a rough budget band, never your identity or exact prices) so others can discover and clone it.
  • To keep the service secure, working and improving.

Automated processing & AI

To read a confirmation we can’t parse ourselves, and to generate the AI trip plans you ask for, we send the relevant content to Google’s Gemini API. That is the text of a booking, and — where you use those features — the booking screenshots and receipt photos you upload. We send only what the task needs, and we don’t keep the images afterwards.

We use Gemini on a paid plan, and under Google’s terms for paid use your content and Gemini’s responses are not used to train or improve Google’s models. Google retains them for a limited period only, to detect abuse of its own service. Unlike the rest of our processing, this step is not confined to the EU — Google may process or cache the content in any country where it operates facilities.

Results may occasionally be imperfect, so always check important details against your original booking.

Personalised recommendations

Reveldays tries to suggest trips, plans and places that actually suit you. To do that we use only your own first-party data: your answers to the travel-taste questions (how you like to travel, what draws you, your usual budget and trip length), the trips you track, save, clone or review here, and — if you fill them in — the interests on your companion profile. Those signals are combined into a private taste profile that shapes what we recommend to you: the “For you” shelf, the starting points in the AI planner, and suggestions we show inside your own account.

There is one further signal, and it has both its own switch and its own permission gate: the stops you actually reached on a trip. With Remember my visits on (Settings ▸ Personalisation), your browser works out on your own device which of a day’s planned stops you got to, and saves that conclusion — the stop, reached or passed, and when. Never the coordinate, never how far away you were. It marks those stops as done on your day and, in time, helps us suggest places that suit how you really travel rather than how you said you would. It is private to you: the people you travel with cannot see it. Turn it off and nothing new is recorded; use Forget my visit history, in the same place, to erase every visit we hold — your trips are untouched.

Things you tell us about how you travel. If you tell Reveldays something about the way you travel — “we always want a pool”, “no red-eye flights”, “we travel with two primary-school-age children” — we write that one sentence down, show it to you under Settings ▸ Personalisation ▸ What Reveldays knows about you, and use it to shape later answers. We store only sentences you typed, never anything we inferred about you, and never a child’s name or date of birth — only a party shape (how many adults, how many children, and an age band). You can edit or delete any of them at any time, turn the whole thing off with Remember what I tell you, or use “Forget everything you’ve learned about me” to erase them all at once. We keep them until you delete them or delete your account, they are included in your data download, and they are never shown to travel companions. To shape an answer they are sent to Google’s Gemini API as part of the context for that answer, on the same terms as the rest of your AI use (see Automated processing & AI above).

Three of these are on unless you switch them off, and every part has its own switch. Using your own trips, your travel-taste answers and the things you tell us about how you travel to personalise what we suggest is enabled when you create an account, so the product is useful from your first trip; each has its own switch in Settings ▸ Personalisation and each takes effect immediately. Remembering the stops you reach is different: it needs your browser’s location permission before it can record anything at all, and it needs you to tell us once, in the app, that you want it — until you do, nothing is recorded. We never sell or share any of this data, and we never use it to advertise to you. With one exception, described below, none of it is shown to another traveller.

You can turn taste personalisation off at any time in Settings ▸ Personalisation. With it off we stop building the profile and stop using it — nothing is deleted, so turning it back on picks up where you left off; if you’d rather erase it, use Delete my taste profile in the same place, which removes the profile outright (your trips are untouched).

None of this is shown to other travellers. Your taste profile, your recommendations and the signals behind them are private to your account. The one optional feature that shows anything taste-related to another person — “travellers like you”, which can display a shared interest such as food or mountains — requires you to have completed the taste questions and to have separately switched on the public opt-ins for it (a public profile and personalisation), on both sides. Turn either off and you disappear from it.

Who processes data for us (sub-processors)

  • Supabase — our database, authentication and storage, hosted in the European Union.
  • Google — Google sign-in (OAuth) and the Gemini API used for booking extraction and AI plans. Gemini runs on a paid plan: your content is not used to train Google’s models, and it may be processed outside the EU.
  • Google Firebase App Hosting — runs the Reveldays app (European region).
  • ipwho.is — when you first sign in, we send your IP address to ipwho.is to estimate your country, so we can set your default currency and units. We do not store your IP address.
  • Photon (komoot) — when you search for a destination, for a place to put on a stop in your plan, or for the town or village you set as your home base, the text you type is sent to komoot’s Photon geocoder (built on OpenStreetMap data) to find matching places and their coordinates. Ask AI uses the same map: when you ask it to find somewhere — “a ramen place near the hotel” — it sends a short search term (“ramen”) and the coordinates of where you will be that day, so the results are near you. It never sends your question, your name, your account or which trip you are on. We don’t store any of these searches with your identity — only the place you choose is saved, to your trip or to your own profile. For a home base we ask for a town or village, never a street address, and never your device’s location.
  • Google Search (through the Gemini API) — for a handful of questions that nothing in your Reveldays account can answer, and only those: whether there is a strike or a closure, what a country’s entry or visa rules are, opening times the map does not record, what is on somewhere. When that happens we run one web search, and we write the search words ourselves from a fixed template — the place and a word or two about the subject. Your question is never sent, and neither is your name, your account, your trip, anything you have told us, or your location. The sources we used are shown under the answer, along with Google’s own search suggestions, which Google’s terms require us to display with the result and to keep unchanged; those are stored on that message so they are still there when you re-open the conversation, and they go when you delete it.
  • OpenStreetMap (Overpass API) — when you ask about a place’s opening hours, we look up the opening-hours entry the public map holds for a place you have just searched for, so we can quote it to you with the date it was last edited. We send the map’s own id for that place and nothing else — no question, no account, no trip.
  • Ticketmaster — when you ask what is on, we can look up ticketed events (music, sport, theatre) near where you will be. We send a rounded location — an area of roughly a few kilometres, never a precise point — and a date range. We never send who you are or which trip you are on. This is not switched on yet.
  • Stripe — payments, only if you subscribe to Reveldays Pro. Stripe collects your card details and billing address directly on its own checkout pages (we never see your full card number) and takes your payments. We store only your subscription’s status, dates and Stripe’s identifiers for it, never the card. Deleting your account cancels the subscription and deletes your customer record at Stripe; Stripe keeps the invoices it is legally required to keep as a payment institution.
  • PostHog (EU cloud) — product analytics. We send our own minimal, first-party usage events (never email content, prices, booking codes, names, your IP address or location) from our servers to PostHog’s EU region so we can see funnels and feature usage. Your browser never connects to PostHog. Deleting your account deletes the events linked to your account there too.

Your data is stored in the EU. Where a processor transfers data internationally, that transfer relies on appropriate safeguards (such as the European Commission’s standard contractual clauses).

Cookies

We use only the essential cookies needed to keep you signed in. We do not use advertising or cross-site tracking cookies.

Keeping & deleting your data

We keep your data for as long as your account is active. You are in control at any time from Settings:

  • Delete email data — removes your imported emails and the data derived from them.
  • Delete account — permanently removes your account and associated data.

You can also ask us to access, correct or export your personal data by emailing privacy@holaday.app. If you’re in the UK or EU you have rights under the UK GDPR / GDPR, including the right to complain to your local data protection authority.

Children

Reveldays isn’t intended for children under 16, and we don’t knowingly collect their data.

Changes

We’ll update this page if our practices change and revise the “last updated” date above. Questions? privacy@holaday.app.

Privacy Policy · Reveldays