No Signal Travel — Privacy Policy
Effective Date: 20 June 2026
Last Updated: 16 July 2026
This Privacy Policy explains how Devang Shah ("we", "us", "our") collects, uses, stores, and shares information when you use the No Signal Travel mobile application ("the App"). Please read it carefully. By creating an account or using the App, you agree to the practices described here.
⚠ This policy contains important disclosures about data sent to third-party services — including an AI service (Anthropic Claude) used for itinerary import — and about local-network peer-to-peer sync. Review Section 5 carefully.
1. Who We Are (Data Controller)
Devang Shah is the data controller for the personal information collected through the App.
Contact:
Email: dontknowtechnologies@gmail.com
If you are in the European Economic Area (EEA) or United Kingdom, we are the controller of your personal data as defined under the General Data Protection Regulation (GDPR) and UK GDPR respectively.
Given the limited scale of our processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. You can still reach us for any data protection matter using the contact details above.
2. Information We Collect
2A. Account Information
When you create an account, we collect:
• Email address
• Password (not stored by us — handled by Firebase Authentication, a Google service)
• Display name (the name you choose)
You may use the App without an account in offline-only mode. In that case, no account information is collected.
2B. Trip & Itinerary Data
All trip content you create is stored locally on your device in an encrypted SQLite database. If you enable cloud sync or create/join a shared trip, the following is also stored in Google Firestore:
• Trip names, destinations, dates, and budget
• Day-by-day itinerary items (activity titles, location names, GPS coordinates you pin, times, notes)
• Free-text trip and day notes
• Pre-departure checklist items
• Emergency medical notes, if you add them (see Section 2M)
For shared trips, this data is visible to all members you invite.
Hospital and embassy directory entries you add on the SOS screen are not included in this list — see Section 2M for how that data is handled.
2C. Expense & Budget Data
Expense records (amounts, currencies, categories, descriptions) are stored locally and, if you enable cloud sync, in Google Firestore.
Receipt photos you attach to expenses are stored as files on your device only. They are never uploaded to our servers or any cloud storage.
2D. Travel Documents
The App maintains two tiers of document storage:
• Personal documents (passport, travel insurance, etc.): These are encrypted on your device using AES-256-GCM. The encryption key is stored in your device's secure hardware enclave (iOS Keychain / Android Keystore). Personal documents are NEVER transmitted to our servers, Firebase, or any other external service.
• Shared trip documents (flight tickets, hotel confirmations, etc.): When you explicitly upload a document to a shared trip, it is stored in Google Firebase Storage and is accessible to all members of that shared trip.
2E. Location Data
Location access is optional and always requires your explicit permission.
• Your real-time GPS position is used on-device to display your location on the map, to rank nearby points of interest, and to show you the nearest itinerary stop. This position is NOT stored in the App's database or sent to our servers.
• When you request walking directions, your start coordinates are sent to Project OSRM (router.project-osrm.org) to compute a route. See Section 5 for details.
• When you download an offline map pack, a geographic bounding box is sent to the Overpass API (overpass-api.de) to retrieve nearby place data (cafés, ATMs, hospitals, etc.). This does not identify you personally.
You can revoke location permission at any time in your device's Settings.
2F. AI-Assisted Itinerary Import
⚠ Important: When you use the "Import from document" feature with AI parsing enabled, the text content of your travel document is transmitted to Anthropic, Inc. (anthropic.com) for processing. This may include flight numbers, hotel names, booking references, travel dates, and destination names. Anthropic processes this data under their Privacy Policy (https://www.anthropic.com/privacy). Do not use AI import if you do not consent to this. You can always use manual import or Excel/CSV import instead.
The Claude Haiku model processes your text and returns structured JSON. We do not store the raw document text after the import is complete.
2G. Camera & Photo Library
The App may request access to your camera and photo library solely to let you attach receipt images to expenses. Images are stored locally on your device and are never uploaded.
2H. Local Network (Peer-to-Peer Sync)
The App includes an optional peer-to-peer sync feature. When enabled, your device broadcasts a service on your local Wi-Fi network using mDNS (Bonjour/Avahi). Another device running the App on the same network can discover and connect to it via TCP to exchange trip data.
Data transferred includes: trips, trip days, expenses, and itinerary items. This transfer occurs entirely on your local network and no data passes through our servers. You must initiate the sync deliberately.
2I. Exchange Rate Data
The App fetches current exchange rates from Frankfurter (api.frankfurter.app) to convert expense amounts. This request contains no personal information — only a request for currency data.
2J. Map Tiles
Map tiles are served by Maptiler (maptiler.com). When you use the map screen, encrypted (HTTPS) requests for map tiles are sent to Maptiler servers. These requests include tile coordinates and your device's IP address. Maptiler's Privacy Policy applies to this data.
2K. Geocoding / Location Search
When you search for a place by name, the search query is sent to the Nominatim geocoding service (nominatim.openstreetmap.org), operated by the OpenStreetMap Foundation. The request includes your search text and your device's IP address. The OpenStreetMap Foundation Privacy Policy applies.
2L. Technical & Diagnostic Data
We do not use any analytics SDK, crash reporting service, or advertising network. We do not automatically collect device identifiers, advertising IDs, or browsing behaviour. If you contact us by email for support, we collect your email address and the contents of your message solely to respond to you.
2M. Emergency & Medical Information
⚠ The SOS screen lets you add a free-text notes field for medical information such as blood type, allergies, medications, and insurance policy numbers. This is health information about you. It is entirely optional — leave it blank if you prefer not to record it.
This data is handled differently depending on the feature:
• Emergency medical notes: stored locally by default. If the trip is a shared trip, these notes are also stored in Google Firestore and are visible to every member you invite to that trip — the same as other shared trip data described in Section 2B.
• Hospital and embassy directory entries (name, phone, address of local medical/consular facilities you look up or add): stored locally on your device only. These are never uploaded to Firestore or any server, even for shared trips.
Because medical information is treated as a special category of data under GDPR Article 9, we only store it in the cloud with your explicit action (adding a note on a trip you have chosen to share) — see Section 4.
3. How We Use Your Information
We use the information we collect for the following purposes:
• To provide and operate the App (creating/syncing your trips, displaying maps, calculating expenses, enabling shared trips)
• To authenticate your account and maintain its security
• To sync your data across your devices via Firebase (if you choose cloud sync)
• To enable sharing of trip data with people you explicitly invite
• To send you a verification email upon registration
• To respond to your support requests
• To improve the App (based on direct feedback only — we have no analytics)
We do not use your personal information for advertising, profiling, or sale to third parties.
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the EEA or United Kingdom, we process your personal data under the following legal bases:
• Performance of a contract: Processing your account information, trip data, and cloud sync is necessary to provide the service you signed up for.
• Legitimate interests: Maintaining the security and integrity of the App, preventing fraud, and ensuring technical functionality — where these interests do not override your fundamental rights.
• Consent: Processing your precise location is based on your explicit permission. You can withdraw this consent at any time in device Settings. Similarly, using AI import is based on your voluntary choice.
• Explicit consent (special category data): Emergency medical notes (Section 2M) are "special category" data under Article 9 GDPR. We only process this data in the cloud because you have explicitly and voluntarily entered it into a trip you chose to share — your act of typing this optional field on a shared trip constitutes your explicit consent under Article 9(2)(a). You may delete this data at any time, which withdraws that consent.
You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5. Third-Party Services & Data Sharing
We do not sell your personal information. We share data only as described below.
Firebase (Google LLC)
We use Firebase Authentication, Cloud Firestore, and Firebase Storage, all operated by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Data processed: account credentials, trip data, expenses, itinerary items, notes, checklists, emergency medical notes (Section 2M), and shared trip documents.
Transfers: Data is stored on Google's servers, primarily in the United States. For EEA/UK users, Google relies on Standard Contractual Clauses (SCCs) as the legal basis for cross-border transfers. See Google's Privacy Policy at https://policies.google.com/privacy.
Anthropic, Inc. (AI Itinerary Import)
Used only when you explicitly invoke the AI import feature.
Data processed: the full text of your uploaded travel document.
See Anthropic's Privacy Policy at https://www.anthropic.com/privacy.
Project OSRM (Walking Directions)
Used only when you request walking directions in the App.
Data processed: GPS coordinates of your start point and destination.
OSRM is a free, open-source routing service. Requests are made to router.project-osrm.org.
OpenStreetMap / Nominatim (Geocoding)
Used when you search for a location by name or when importing an itinerary with location names that need geocoding.
Data processed: your search query, your IP address.
Operated by the OpenStreetMap Foundation. See https://wiki.osmfoundation.org/wiki/Privacy_Policy.
Overpass API (Offline POI Data)
Used when you download an offline map pack to fetch local points of interest.
Data processed: the geographic bounding box of your chosen region.
No personal data is transmitted. Operated by overpass-api.de.
Maptiler (Map Tiles)
Used to render the map screen when connected to the internet.
Data processed: tile coordinates, your IP address.
See Maptiler's Privacy Policy at https://www.maptiler.com/privacy-policy.
Frankfurter (Exchange Rates)
Used to fetch current exchange rates for expense conversion.
No personal data is transmitted — the request is a simple HTTP GET for currency data.
Other App Users (Shared Trips)
When you create or join a shared trip, trip data (itinerary, expenses, notes, checklists, and any emergency medical notes you've added — see Section 2M) is visible to all members of that shared trip. Shared documents you upload to the "Shared with group" area are accessible to all members; the app will prompt you to confirm a shared upload does not contain a passport, ID, or other personal identification before it uploads. Hospital/embassy directory entries are never shared — they stay on your device only. Only invite people you trust.
6. Data Retention
• Account data and cloud-synced trip data: retained for as long as your account is active. If you delete your account (Account → Delete Account), your Firebase Auth account and all Firestore documents under your user ID are permanently deleted within a commercially reasonable time.
• Shared trip data: if you created the shared trip, deleting the trip removes the data from Firestore. Data added by other members persists until those members delete it.
• Local device data: deleting or uninstalling the App removes the local SQLite database and encrypted documents. Encrypted document keys in the device Keychain/Keystore are also removed on uninstall on most platforms.
• Receipt photos: removing a receipt within the App deletes the local file. They are not in cloud storage.
• Emails to us: retained for as long as needed to resolve your inquiry, then deleted.
7. Data Security
We implement the following security measures:
• Local document encryption: AES-256-GCM with per-device keys stored in the device's secure hardware enclave (iOS Keychain / Android Keystore).
• Transport security: all network communication (Firebase, AI import, geocoding, routing) uses HTTPS/TLS.
• Firebase security rules: Firestore and Storage rules restrict read and write access so that each user can only access their own data, and shared trip data is accessible only to verified members of that trip.
• Account security: passwords are hashed by Firebase and never stored by us in plain text.
No security measure is 100% foolproof. We encourage you to use a strong, unique password and to protect your device with a lock screen.
Data breach notification: if a security incident occurs that creates a material risk to your personal data, we will notify affected users and any competent supervisory authority without undue delay, and in any event within the timeframe required by applicable law (for example, 72 hours under Article 33 GDPR where feasible).
8. Your Rights
All Users
• Access your data: all your trip data is viewable within the App.
• Delete individual data: expenses, itinerary items, documents, checklist items, and entire trips can each be deleted at any time without deleting your account.
• Delete your account: Account → Delete Account permanently removes your cloud data and Firebase account.
• No app access? If you can no longer sign in (for example, you uninstalled the App), email dontknowtechnologies@gmail.com with your account email and we will delete your account and data within 30 days.
• Export your expenses: Budget screen → Download icon exports a CSV of all trip expenses.
• Revoke location permission: Settings → No Signal Travel → Location.
• Disable cloud sync: use the App in offline-only mode without signing in.
EEA & UK Residents (GDPR / UK GDPR)
Under the GDPR and UK GDPR, you have the right to:
• Access: request a copy of the personal data we hold about you.
• Rectification: request correction of inaccurate data.
• Erasure ("right to be forgotten"): request deletion of your personal data where there is no compelling reason for its continued processing.
• Restriction of processing: request that we restrict how we process your data.
• Data portability: receive your personal data in a structured, machine-readable format.
• Object: object to processing based on legitimate interests.
• Withdraw consent: where processing is based on consent (e.g. location access), you can withdraw it at any time.
• Lodge a complaint: you have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
To exercise any of these rights, contact us at dontknowtechnologies@gmail.com. We will respond within 30 days.
California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to:
• Know: request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell.
• Delete: request deletion of personal information we have collected.
• Correct: request correction of inaccurate personal information.
• Opt-out of sale or sharing: We do not sell or share your personal information with third parties for cross-context behavioural advertising. There is nothing to opt out of. We honor Global Privacy Control (GPC) signals as a valid opt-out request, though since we do not sell or share data this has no additional effect on how we process your information.
• Limit use of sensitive personal information: We collect two categories of Sensitive Personal Information under the CPRA — precise geolocation (Section 2E) and health information (emergency medical notes, Section 2M). We use both solely to provide the specific features you request (map display, nearest-POI ranking, and storing the medical notes you choose to enter) — we do not use Sensitive Personal Information to infer characteristics about you or for any other secondary purpose, so no additional opt-out mechanism beyond deleting the data (Section 8, "All Users") is required under the CPRA's exemption for use limited to providing the requested goods or services.
• Non-discrimination: we will not discriminate against you for exercising your CCPA rights.
Categories of personal information collected: identifiers (email, display name), geolocation data (when location is enabled), travel itinerary and financial information (expenses), health information (emergency medical notes, if you add them), and the contents of documents you choose to process with AI import.
To submit a request, contact us at dontknowtechnologies@gmail.com.
9. International Data Transfers
The App uses Firebase services hosted on Google's infrastructure, which may include servers in the United States and other countries.
If you are located in the EEA, UK, or Switzerland, transfers of your data to Firebase's US infrastructure are made under Standard Contractual Clauses (SCCs) as approved by the European Commission, and under the UK Addendum to the SCCs for UK transfers. Google's Data Processing Terms are available at https://cloud.google.com/terms/data-processing-addendum.
Anthropic is based in San Francisco, CA, USA. If you use AI import from outside the USA, your document text is transferred internationally. Anthropic's transfer mechanisms are described in their Privacy Policy.
10. Children's Privacy
The App is not directed to children under 13 years of age (or under 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at dontknowtechnologies@gmail.com and we will delete it promptly.
If you are under 13 (or under 16 in the EEA/UK), do not use the App or provide any personal information to us.
11. Third-Party Links
The App may display links or content from third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any external services you access through the App.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, by showing an in-app notice or sending an email to your registered address.
Continued use of the App after a policy change constitutes your acceptance of the updated policy. If you do not agree, you should stop using the App and delete your account.
13. Contact Us
For any questions, concerns, or rights requests regarding this Privacy Policy:
Email: dontknowtechnologies@gmail.com
Subject: Privacy Policy — No Signal Travel
We aim to respond to all requests within 30 days. For complex GDPR requests, we may extend this by a further two months and will notify you.
© 2026 Devang Shah. All rights reserved.
No Signal Travel — com.dkt.nosignaltravel