Last updated: 29 September 2026

Privacy Policy

Safara is a trip-planning app. This policy explains what we collect, why, and what we do not do. It covers the Safara mobile app and safara.dev.

The short version. We collect what the app needs to plan your trips and nothing else. We do not sell your data, we do not show ads, and we do not track you across other apps or websites.

Who we are

Safara is run by an individual developer. For any privacy question, or to ask for a copy of your data, email privacy@safara.dev.

What we collect

WhatWhy
Email address and passwordTo create and secure your account. Passwords are stored hashed by our authentication provider, so we never see them.
If you sign in with Google or Apple: your email address and name from that accountTo create your account without a password. We never see your Google or Apple password. If you choose “Hide My Email” with Apple, we only receive Apple's relay address.
Username, and optionally a display name and profile photoSo other people on a shared trip know who you are. Your username is visible to anyone you share a trip with.
Your trips: destinations, dates, saved places, day plans, notes, and flight and hotel details you enterThis is the app. It is stored so your trips sync across your devices and to anyone you invite.
Travel details, if you choose to enter them: legal name, date of birth, Known Traveler Number, Redress number, passport number, country and expiry, and loyalty programme numbersEntirely optional. Kept so you do not have to find them again when booking. See “Travel details” below.
Booking confirmation screenshots you choose to scanSent once to be read, then discarded. See “Scanning a confirmation” below.
Email addresses of people you inviteTo send them the invitation and link it to their account when they join.
Basic technical data: IP address and the time of each request to our serverTo keep the service secure and stop abuse (for example, limiting repeated sign-in attempts). Kept only in short-lived server logs, and never used to build a profile of you.

What we do not collect

Travel details

Travel details are optional, and the app works fully without them. They are stored so that no other user can ever read them unless you choose to share them. We do not look at them, and they are never used for anything except showing them back to you and to the people you share them with.

They are never shared automatically. On each trip you choose, field by field, what to share, and it is off by default. Someone you share with sees only the fields you picked, only on that trip. You can stop sharing at any time, and sharing ends automatically if you leave the trip.

Scanning a confirmation

If you scan a booking confirmation, the image is sent to Anthropic's Claude service to read the flight or hotel details out of it, and the results are put on the form for you to check before anything is saved.

The image is not stored by us. Not on your device beyond your own photo library, and not on our server. It is held in memory only long enough to be read. Anthropic does not use data sent through their API to train their models.

The app is instructed to skip passenger names, loyalty numbers and payment details when reading your confirmation.

Planning with AI

If you use the AI travel agent (on Home, or inside a trip), what you type is sent to OpenAI's ChatGPT service to write the replies. When you ask about a trip, that trip's name, dates, places, where you're staying, saved things to do and day plan (including notes on its days) go with it, along with its flights' airline, flight number, airports, dates and times. Confirmation numbers, seats and boarding groups are never sent. Your travel details, email address, and the names of the people on the trip are never sent.

Your conversations are saved in your account, private to you. There is one per trip (and one on Home while you plan a new trip), so you can pick up where you left off on any device. Nobody else on a trip can see yours. A conversation is deleted when you tap New conversation, when the trip is deleted, when you leave the trip, or when you delete your account. OpenAI does not use data sent through its API to train its models, and may keep it for up to 30 days to check for abuse before deleting it.

The AI travel agent only suggests real places from Google. It builds a new trip only after you tell it to, and never changes an existing trip by itself: nothing is added, moved or re-dated until you tap Apply.

Photo library and camera

The app asks for photo library access so you can pick a profile picture or a confirmation screenshot, and for camera access so you can photograph a confirmation. Both are optional, are only used when you tap those buttons, and can be refused or revoked in your phone's settings without breaking the rest of the app.

Profile photos

If you upload a profile picture, it is stored in a way that makes it viewable by anyone who has its direct web address, so that it can load quickly for people on your trips. The address is not published or listed anywhere, and is not guessable in practice, but it is not access-controlled either. Please don't use a photo you would mind being seen. You can remove or replace it at any time in Account, and it is deleted with your account.

Shared trips

When you invite someone to a trip, they can see that trip's contents and the usernames and names of everyone on it. When you invite by email address, we send that person an email telling them you invited them, and the address is visible to the other people on that trip. If you invite someone by their username, or they join with an invite link, their email address is never revealed to you or to anyone else on the trip.

Invite links. The trip's organizer and anyone helping plan it can create an invite link. Anyone who has the link and signs in can see the trip's name, dates, places and who shared it, and can join the trip. Only share it with people you want on the trip. The organizer can reset a link at any time, which stops the old one working.

Who we share data with

We do not sell your data and we do not share it for advertising. We use these service providers to run the app:

ProviderWhat it does
SupabaseStores your account, trips and profile. Hosted in the United States.
RenderRuns our server.
Google (Places API)Supplies place search results, details, opening hours and photos. Searches are sent to Google without your account identity attached. Google's use of this data is covered by the Google Privacy Policy.
Google and Apple (sign-in)Only if you choose to sign in with them. They confirm who you are and tell us your email address and name.
Anthropic (Claude)Reads scanned confirmations, writes short place descriptions and suggests which kinds of places suit a destination. Only the scan contains anything of yours. Not used to train their models.
OpenAI (ChatGPT)Writes the AI travel agent's replies, only when you use it: what you type and, when you ask about a trip, that trip's plan. Not used to train their models.
ResendSends account emails (sign-up and password codes) and trip invitations.
CloudflareHosts this website and delivers email sent to our @safara.dev addresses.

We may also disclose data if we are legally required to.

How long we keep it

Your data is kept while your account exists. When you delete your account, your trips, profile, travel details and sharing settings are deleted. Trips you shared with other people are removed along with your account if you own them. Server logs are kept for a short time and then deleted automatically.

Deleting your account

You can delete your account at any time from inside the app: Account → Delete account. It is immediate and permanent. If you cannot get into the app, see this page.

Your rights

Depending on where you live, you may have the right to see, correct, export or delete the data we hold about you, and to object to how we use it. Most of this you can do yourself in the app. For anything else, email privacy@safara.dev and we will respond within 30 days.

Where your data is stored

Our service providers store and process data in the United States. If you use Safara from another country, your data is transferred to and stored in the United States, and we protect it as this policy describes wherever you are.

Children

Safara is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has given us data, email us and we will delete it.

Security

All traffic is encrypted in transit with HTTPS. Access to your trips is enforced by the database itself, not only by the app, so another account cannot read your trips even if the app is tampered with. If you don't use Safara for 30 days (7 days on the website), we sign you out of that device and remove the trips stored on it, so a lost phone or a shared computer doesn't stay signed in; your trips stay safe in your account. You can also sign out of all your devices at once from Account. No system is perfectly secure, and we cannot guarantee absolute security.

Changes

If we change this policy in a way that matters, we will update the date at the top and let you know by email or in the app before it takes effect.

Contact

privacy@safara.dev