Privacy policy
Last updated: 11 August 2026
Contact: help@carry-on-app.com
The short version
CarryOn is a trip planner that works entirely on your device. You do not need an account to use it, and if you never create one, nothing you type ever leaves your phone.
If you do create an account, your trip data syncs to our server so you can reach it from another device and share a trip with the people you are travelling with.
We do not run analytics. We do not show ads. We do not track you across apps or websites, and we do not sell or rent your information to anybody.
When we collect nothing
CarryOn is offline-first by design. Without an account, every trip, expense and note you create is stored only in the app's local database on your device. It is not transmitted anywhere, and we cannot see it.
Uninstalling the app deletes that local database.
What we collect when you create an account
Creating an account is optional and enables cloud backup and trip sharing.
Account information
- Your email address and a password. Passwords are handled by our authentication provider (Supabase) and are stored hashed — we never see or store your password ourselves.
- An account identifier (a random UUID).
Your traveler profile — all optional, all editable or clearable at any time:
- A display name, and the city and country you live in (used to pick a sensible home currency).
- Trip-planning preferences: party size, whether children or older travellers are along, preferred pace, budget level, transport and interests.
- Accessibility needs: tags such as wheelchair access, dietary restrictions, service animal or sensory-friendly, plus an optional free-text note.
We treat accessibility information as sensitive. You are never required to provide it. It exists so that suggested activities actually suit you. It is used only to plan your trip — never for advertising, profiling or any decision about you — and it is included in the AI request described below, which is the single place it leaves our own systems. If you would rather it did not, leave those fields empty and use the app normally, or avoid the AI features.
Your trip content — whatever you choose to put in the app:
- Trips, dates, cities and countries; your day-by-day calendar and the activities on it, including titles, locations, notes and map links.
- Accommodation, transport legs and car rentals, including booking confirmation numbers if you enter them.
- Reminders, saved activity ideas, and your to-book list.
- Expenses: amounts, currencies, categories, notes, who paid, and how a cost is split between the names you add. These are your own records of what a trip cost. We never connect to a bank and never handle a card or payment.
Who else can see it
People you share a trip with. Sharing is something you do deliberately, by generating an invite code and giving it to someone. Anyone who joins a trip can see and edit that trip's contents, and can see the other members. Members are shown to each other by display name, or by a masked email (qc…@gmail.com) if no name is set — never a full email address.
You can leave a trip, and a trip's owner can remove a member, at any time.
Our service providers.
- Supabase hosts our database, authentication and server functions. Your account and synced trip data live there. Access is restricted per account by database-level security rules.
- An AI provider, only when you tap "✨ Suggest" or "Plan my days". Those requests are relayed through our own server function, which holds the API key. What is sent is the trip context needed to answer: destination city and country, the category asked for, your preference filters, party composition, your accessibility tags and note, and the names of activities already in your list. Your email address, your account identifier and your trip identifier are not sent. The current provider is OpenRouter; we may change providers, and this policy will be updated if we do. We do not log the content of these requests.
Nobody else. We do not share your information with advertisers, data brokers or analytics companies, because we do not use any.
Other network connections
Two connections carry no personal information but do reveal your device's IP address to a third party, as any web request does:
- Currency rates are fetched from a public, keyless exchange-rate feed (jsDelivr / currency-api). The request contains no data about you and no account information.
- Place photos in the Explore section may be fetched from Wikimedia at a higher resolution than the copy bundled in the app. This reveals which place photo was requested. Every card already works from an image shipped inside the app, so this only ever improves quality; it is never required.
What we deliberately do not collect
- No location. The app never asks for or accesses your device's location. Cities are typed by you and matched against a place list bundled in the app.
- No analytics or usage tracking. There is no analytics SDK in the app.
- No advertising, and no advertising identifier (IDFA). We do not track you across other companies' apps or websites, in the sense the App Store's App Tracking Transparency rules use that word.
- No crash or diagnostics reporting in the builds we distribute.
- No access to your photos, camera, contacts, microphone or health data.
- No device fingerprinting or advertising identifiers.
- Notifications are local. Trip reminders are scheduled by your own device. There is no push server, and we hold no push token.
How long we keep it
Synced trip data is kept while your account exists, so that it is there when you open the app on another device. Deleted trips are retained briefly as soft-deleted records so the deletion can propagate to your other devices, then removed.
Your choices and your rights
- Use the app without an account. Then we hold nothing at all.
- Sign out at any time, from the account screen.
- Leave a shared trip at any time.
- Delete your account and its data, from inside the app: open Account (the person icon) and choose Delete account. You will be asked for your password to confirm. This permanently removes your account, the trip data synced to our servers, and the copy stored on that device. It cannot be undone. Trips you shared are not destroyed — the other travellers keep them, along with the expense history; your membership is removed and, if you owned the trip, ownership passes to another member.
- Access, correction and erasure. Depending on where you live (for example under the UK/EU GDPR or California law) you may have rights to access, correct, export or erase your personal information, and to object to certain processing. Write to the contact address above and we will act on it.
Children
CarryOn is not directed at children and we do not knowingly collect information from anyone under 13. The profile's "children in the party" field is a count used for planning; it holds no information about a child.
This is beta software
During the beta, CarryOn's server runs on a development project. Please do not store information in it that you could not stand to lose, and keep your own copy of anything critical — a booking confirmation, in particular. We may reset beta data between builds; we will tell testers before we do.
Changes
If this policy changes materially we will update the date at the top and, where it matters, tell testers directly.
Contact
Questions about this policy, or a request about your own data, go to help@carry-on-app.com and a person will read them.