Privacy Policy
Effective 29 August 2026
TravelStory ("the app", "we") is a travel journal app that lets you record GPS tracks, upload photos, and organize them into journeys and trips. This page explains what data we collect, why, and how you can control it. See also our Terms of Service.
Who we are
TravelStory is operated by Paul Sherwood, trading as TravelStory, of Amherst, Harnham Lane, Withington, Cheltenham, Gloucestershire, GL54 4DD, United Kingdom. For UK GDPR purposes, Paul Sherwood is the data controller for the personal data described on this page. You can reach us at paul.sherwood@hostedcompanies.co.uk.
Where your data is held
Your journeys, tracks, photos, videos, and account data are stored on servers we own and operate directly, located in the United Kingdom. We don't use a third-party cloud provider to host your content - it stays on infrastructure under our own control. Some supporting features do call third-party services (see "Third-party services we use" and "International transfers" below), but your core content itself is UK-hosted.
What we collect
- Account information- email address, username, display name, date of birth (used only to confirm you're old enough to use TravelStory - see "Children's privacy" below), city (optional), and password (stored hashed, never in plain text).
- Location data - GPS track points recorded while you record a trip (latitude, longitude, elevation, speed, bearing, and timestamp), and any GPX/KML/KMZ track files you import.
- Photos and videos you upload, including any embedded EXIF metadata (such as the location and time a photo was taken), which we use to place your photos on the map.
- Content you create - journey and trip names, descriptions, map annotations, and comments (including any @mentions of other users) you post on photos, routes, journeys, trips, or annotations.
- Vehicles and fuel records, if you add them - a vehicle's name and type, and per-fill fuel stop records (date, location, litres, cost, fuel type).
- Places data - check-ins, star ratings and written reviews, and photos you attach to a real-world place.
- Friend and companion connections - friend requests you send or receive, and any companions you tag on a journey or trip to let them contribute photos or annotations.
- Public interest tags- if you add any (like "vanlife" or "solotravel"), they're shown on your profile and used to surface you to other users via Discover. This only ever applies if your profile privacy toggle allows you to be found by people who don't already know your exact username - Discover never surfaces an account you've set to not be found this way.
- Beta application data - while TravelStory is in private beta, we keep the confidentiality agreement you sign to apply, including your typed signature, the date, and the IP address it was signed from.
- Device information used to deliver push notifications on the mobile app, if you enable them.
- IP address and browser characteristics, processed by Cloudflare Turnstile to confirm sign-up and login requests come from a real person rather than a bot (see "Third-party services we use"), and recorded in our own access logs for security purposes (see "Data retention and deletion").
How we use it, and our lawful basis
We use your data to provide the app's core features: plotting your tracks and photos on a map, resolving place names from GPS coordinates, organizing your journeys, and sharing content with friends or the public exactly as you choose. We do not sell your data, and we do not use your location or photos for advertising. Under UK GDPR, we rely on one of the following legal bases for each purpose:
| Purpose | Lawful basis |
|---|---|
| Account creation, journeys, trips, tracks, photos, sharing | Performance of a contract |
| Push notifications | Consent |
| Abuse moderation, comment retention, rate limiting, security | Legitimate interests |
| Bot protection (Turnstile) | Legitimate interests |
| Reviewing reported content (moderators) | Legitimate interests |
A small number of trusted, identity-verified users are granted moderator access to review content that's been reported - this is the one case where content you post may be seen by someone other than the people you shared it with. Moderators only ever see what a specific report concerns (never your account or content more broadly), are bound by confidentiality obligations, and suspected child sexual abuse material is never shown to them at all - see Terms' "Moderation and reporting" section for the full design.
Visibility and sharing
A new journey defaults to Private, and every photo has its own visibility independent of the journey it's in - making a journey more visible doesn't automatically expose photos you've kept more restricted. The visibility levels are:
- Private - only you.
- Friends - your accepted friends.
- Workspace - members of your TravelStory workspace.
- Public - anyone, including people without an account.
- Unlisted - anyone with the direct link - excluded from public listings.
- Group - a friend circle you've defined yourself (photos only, not a whole journey).
A Public journey also has its own optional "identity- confirmed viewers only" toggle, separate from the account-wide filters described under "Identity verification" below - it's not available on Unlisted, since a shareable link is already Unlisted's own access control. Unlike the account-wide filters, this toggle (and its account-wide equivalent, restricting who can see your Public journeys generally) is checked every time someone views the journey, so turning it on takes effect immediately for anyone not identity-confirmed, not just for new viewers.
For a journey you're still actively recording, live trackingis off by default and a separate opt-in from ordinary sharing - turning a journey Public or Unlisted shares your completed trips, but an in-progress trip stays invisible to anyone but you until you also switch live tracking on. When it's on, you additionally set a minimum delay (in minutes) and a minimum distance (in miles) - a viewer never sees a track point, photo, or annotation newer than those limits allow, so a shared live trip can't be used to pinpoint exactly where you are right now.
A comment you post follows the visibility of whatever it's attached to, and @mentioning someone in a comment notifies them, but only if they're already able to see that comment's target.
Other people's data
You may upload photos that include other people, tag friends as companions on a journey, or write a review of a business. You're responsible for making sure you have the right to share content involving someone else, and for respecting their own preferences about being photographed or named. If someone contacts us because they appear in content on TravelStory and want it addressed, write to us at paul.sherwood@hostedcompanies.co.uk and we'll look into it.
Identity verification
Verifying your identity is optional and only relevant on the Paid plan, where it unlocks filters that restrict who can friend, companion-invite, comment on, or see your public journeys to other verified users. If you choose to verify, you complete the process directly with our verification provider, Didit - we never see or store your ID document, name, date of birth, or any biometric data. We only keep whether you're verified, when, an age band (not your exact age), and a reference id Didit gives us to look the result up again if needed. Choosing not to verify doesn't restrict anything about how you can use TravelStory.
Third-party services we use
- Reverse geocoding (turning GPS coordinates into place names) is provided by OpenStreetMap's Nominatim service.
- The optional Places layer, which shows nearby restaurants, shops, and points of interest on the map, is powered by Foursquare's places data.
- Transactional emails (password resets, friend requests, referral invites) are sent via Resend.
- Push notifications on the mobile app are delivered via Expo's push notification service.
- Cloudflare Turnstile checks that sign-up and login requests come from a real person rather than a bot; it may process your IP address and browser characteristics to do this.
- Optional identity verification (Paid tier) is provided by Didit - see "Identity verification" below for what that does and doesn't involve.
- The AI Assistant is an internal development tool, not a travel-journal feature - see below.
The AI Assistant
A small number of accounts (developers and testers helping build TravelStory) have access to an internal AI Assistant that answers questions about the TravelStory platform's own database structure and source code. It runs entirely on our own infrastructure (a self-hosted Ollama instance) - it is never sent to a third party, and nothing you enter into it is used to train any model. It does not have access to, and does not process, your journeys, photos, tracks, or any other personal travel content. Most accounts never see this feature at all.
Cookies and similar technology
We don't use cookies for tracking or advertising, and we don't run any analytics that profile you across visits. The web app keeps you signed in using your browser's local storage rather than a cookie. The only third-party script we load is Cloudflare Turnstile (see above), which may set its own cookie as part of confirming you're not a bot. Because nothing beyond this strictly-necessary use is set, we don't show a cookie consent banner.
International transfers
Your core content - journeys, tracks, photos, videos - is stored on our own UK servers and doesn't leave the UK. A few third-party services we rely on for supporting features may process data outside the UK. Where they do, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses as the safeguard:
- Foursquare - Places layer
- Resend - transactional email
- Expo - push notifications
- Cloudflare - Turnstile bot protection
- Didit - optional identity verification (Paid tier)
OpenStreetMap's Nominatim service is hosted in the EU, which the UK recognises as providing an adequate level of protection, so no additional safeguard is needed there. The AI Assistant is self-hosted on our own infrastructure and involves no international transfer at all.
Data retention and deletion
- Journeys, trips, tracks, photos, videos, fuel logs, and annotations are permanently deleted the moment you delete them - not archived or soft-deleted. We take hourly backups of the database and your photo/video library, retained for 7 days before being overwritten - deleted content can persist in these backups for up to 7 days, but backups are only used for disaster recovery, never to restore something you deliberately deleted.
- A deleted comment is hidden immediately, but its text and edit history are kept for 120 days in case a report of abuse needs reviewing, then permanently purged.
- Check-ins and reviews belong to the real-world place, not the journey they were made on - deleting a journey doesn't delete check-ins or reviews you left on places during it. You can remove an individual check-in or review from within the app at any time.
- You can permanently delete your entire account and everything in it - including check-ins and reviews - yourself, at any time, from Settings (iOS, and Android once it's released) or your Profile page (web). It requires re-entering your password and typing a confirmation phrase, takes effect immediately with no grace period, and is irreversible once confirmed (subject to the 7-day backup window above). Before deleting, you can export a full copy of your data - see "Your rights" below. You can also contact us if you'd rather we do it for you.
- Free-plan accountsthat go unused for 90 days get a reminder email; if there's still no login after a further 14 days, a final-notice email; if there's still no login 14 days after that (around 4 months of inactivity in total), the account and everything on it is permanently deleted. Logging in at any point resets this completely - there's no partial credit for logging in once and going quiet again. Paid accounts are never subject to this, regardless of how long since you last opened the app.
- Access logs (IP address, requested page, timestamp) are kept for 30 days for security purposes, then automatically deleted.
- Beta application data (your signed confidentiality agreement, typed signature, date, and signing IP address) is kept for 6 years after your account closes or the beta program ends, whichever is later - long enough to serve as evidence of the agreement for as long as it could still matter under the standard limitation period for a UK contract.
Security
Traffic between your device and our servers is encrypted in transit (TLS/HTTPS). Passwords are stored hashed, never in plain text, and we never see or store your password itself. Access to the underlying servers and database is restricted to the people operating TravelStory. No system is perfectly secure, but we take reasonable, proportionate steps to protect your data given the scale we operate at.
Your rights
Under UK GDPR, you have the right to:
- Access a copy of your data - use Export my data in Settings/Profile for an instant self-service copy (everything: journey data as GPX, your photos, and a JSON export of the rest), or ask us directly.
- Rectification - correct inaccurate data, most of which you can edit directly in the app.
- Erasure - delete individual content or your whole account, as described above.
- Restriction of processing, in certain circumstances.
- Data portability - the data export above gives you your GPS tracks as standard GPX files, usable in other tools, plus your photos and a structured JSON dump of everything else.
- Object to processing based on legitimate interests.
- Withdraw consent at any time (for example, by turning off push notifications), without affecting anything already done while consent was in place.
- Complain to the Information Commissioner's Office(ICO) if you're unhappy with how we've handled your data - see ico.org.uk. We'd welcome the chance to sort things out directly first, but you're not required to contact us before complaining to the ICO.
To exercise any of these rights, email us at paul.sherwood@hostedcompanies.co.uk. We'll respond within one month.
Automated decision-making
We don't use automated decision-making or profiling that produces legal or similarly significant effects on you.
Children's privacy
TravelStory is an adult service. You must be 18or older to create an account, and we don't knowingly collect data from anyone under 18. We ask for your date of birth at sign-up and rely on you providing it accurately - we don't carry out separate identity or age verification there, which is the standard, proportionate approach for a consumer app like this rather than one aimed at, or believed accessible to, children.
If you believe an account belongs to someone under 18, tell us at paul.sherwood@hostedcompanies.co.uk and we'll investigate and remove the account if that's confirmed.
Changes to this policy
If this policy changes, we'll update the effective date at the top of this page, and for material changes we'll also let you know in-app or by email rather than relying on you noticing the date change yourself.
Contact
Questions about this policy or your data can be sent to paul.sherwood@hostedcompanies.co.uk.