Legal

Privacy Policy

Effective: August 2, 2026 · Last updated: September 26, 2026

DepartBuddy is operated by Miguel Carranza ("DepartBuddy," "we," "us," or "our"). This Privacy Policy explains how DepartBuddy handles information when you use the DepartBuddy application on iPhone, iPad, or Android, its email-import service, and its read-only trip-sharing service (together, the "Service").

Contact: hello@departbuddy.com

1. Summary

2. Information We Process

Trip and reservation information

When you create or save a trip, DepartBuddy may process information such as trip names and dates, destinations, passenger names, reservations, confirmation codes, seats, prices, notes, checklists, addresses, booking links, ticket or pass-code payloads, and a trip cover image you choose.

This information is provided by you or extracted from a booking email that you choose to forward. It is used to organize and display your trips and create in-app attention checks. On Apple devices, saved trip data may sync privately through iCloud when available. On Android, the saved trip record remains in the app's local database. Limited values, such as destination names and map regions, may be sent to service providers to retrieve imagery or render maps as described below; booking details are sent to DepartBuddy servers only when you explicitly forward a booking email or create a trip-sharing link.

Forwarded booking emails

When you forward a booking email, the email-import service may process the sender and recipient, subject, message text, travel details, passenger names, contact information contained in the message, confirmation codes, prices, ticket or pass-code data, and text extracted from supported attachments. DepartBuddy does not connect to, monitor, or continuously access your email account.

The email service temporarily stores the original forwarded message, normalized source text, and parsed reservation results while the import is pending.

DepartBuddy first uses its own rules-based parser. When the optional low-confidence fallback is enabled and that parser cannot confidently complete an import, the normalized message and supported attachment text may be sent to Google Gemini for one automated extraction attempt. The result is validated by DepartBuddy before it is shown for your review. Complete high-confidence imports are not sent to Gemini through this fallback.

Anonymous identifiers

DepartBuddy creates random identifiers to recover your private forwarding address, enforce the free email-import allowance, and maintain subscription access. These include an anonymous email-import account ID, a cryptographic hash of a random install token, a private forwarding address, and an anonymous RevenueCat App User ID. On Apple devices, these identifiers may sync through iCloud Keychain when it is enabled, allowing the same anonymous identity to be recovered on another Apple device. On Android, the email-import token and trip-sharing management tokens are kept in encrypted app storage, while RevenueCat manages its anonymous identifier in app storage. Clearing Android app data or deleting the Android app may remove those local identifiers.

Subscription information

If you view, purchase, or restore DepartBuddy PRO, the applicable platform store (Apple or Google Play) and RevenueCat process purchase history, product, entitlement, renewal, expiration, and related transaction information. We do not receive your full payment-card details. We use subscription information to provide PRO access, prevent fraud, support purchases and restores, and understand subscription performance.

Photos and camera

If you choose a custom trip cover, the selected image or access to it is stored with your trip. On Apple devices, that image may sync through your private iCloud database. On Android, DepartBuddy uses the system document picker and keeps access to the image on your device. If you choose to scan a pass code from the camera or a screenshot, recognition occurs on-device. Android may use Google Code Scanner, a Google Play services component, to present the scanner and recognize the code. DepartBuddy stores the extracted payload and code format but does not retain the scanned source image for that purpose.

Calendar

If you enable Calendar Sync, DepartBuddy requests calendar access so you can select a writable calendar and so the app can create, update, and remove events for the trip categories you choose. On Android, DepartBuddy reads the available writable calendars through Android's Calendar Provider. DepartBuddy uses reservation identifiers stored in managed events to keep those events synchronized and avoid duplicates. Your calendar contents are processed on-device and are not sent to DepartBuddy's email-import service or other DepartBuddy servers.

Maps and destination imagery

DepartBuddy uses saved trip locations to display routes and destination information. On Android, Google Maps may receive normal map-rendering request information, such as your IP address, app and device information, and the map regions needed to display your saved routes. DepartBuddy does not request your device's location. Destination names may also be sent to Wikimedia or Wikipedia to retrieve a relevant destination image.

Notifications

If you enable travel reminders, DepartBuddy schedules notifications locally on your device for supported trip events and attention items. DepartBuddy does not use these notifications for advertising and does not send your notification schedule to DepartBuddy servers.

Read-only trip sharing

When you create a share link, DepartBuddy sends only the trip snapshot you selected to the sharing service. Itinerary Only includes ordinary itinerary information such as trip dates, routes, times, providers, and lodging locations. If you choose Detailed, you can separately include traveler names and seats, confirmation codes, prices, or notes and checklists.

Share snapshots never include ticket or pass-code payloads, raw forwarded-email content, loyalty membership numbers, or private manage-booking links. The sharing service processes an encrypted snapshot, cryptographic hashes of random read and management tokens, expiry and update timestamps, and limited operational metadata such as access timestamps. Anyone who receives the capability link can view the selected snapshot until you revoke it or it expires, so you should share it only with people you trust.

Support and technical information

If you contact us, we process your message, email address, and any information you include so we can respond. Cloudflare, Apple, Google, RevenueCat, and websites you choose to open may also process basic network information such as IP address, app, device, or browser information, and request timestamps for delivery, security, fraud prevention, payment processing, and operation of their services.

3. How We Use Information

We use information only as needed to:

We do not use travel details, forwarded-email content, or pass-code data for advertising.

4. Storage and Retention

5. Service Providers and External Services

We use the following providers only to operate DepartBuddy:

When you choose to open a map, flight-tracking page, manage-booking link, or another provider link, the destination service receives the normal information associated with a web request and applies its own privacy policy.

We require service providers that process information for us to protect it consistently with this Policy and applicable law. We may also disclose information if legally required or necessary to protect the rights, safety, and security of users, the public, or the Service. We do not sell or rent personal information.

6. Your Choices and Deletion

To request access, correction, or deletion of server-side email-import identity data, contact hello@departbuddy.com. Include your DepartBuddy forwarding address if possible so we can locate the anonymous record. We may need to verify control of that address or associated token before completing a request. We will respond as required by applicable law.

Deleting the app removes its local app data, subject to normal operating-system backup and device-transfer behavior, but may not remove data already held in iCloud, pending email imports, active share snapshots, Apple, Google Play, RevenueCat, or other backups. Revoke active links before deleting the app, use the controls above, or contact us for server-side records.

7. Legal Bases for Processing

Where applicable, we process information to perform the Service you request, with your consent when you choose to forward content or grant device access, to pursue legitimate interests such as security and abuse prevention, and to comply with legal obligations. You may withdraw consent by stopping the relevant feature and using the deletion choices above. Withdrawal does not affect processing already lawfully completed.

8. International Processing

Our service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, transfers are made using provider safeguards and lawful transfer mechanisms.

9. Security

We use reasonable technical and organizational safeguards, including HTTPS, random bearer tokens, hashed server identifiers, encrypted shared snapshots, Apple Keychain, private CloudKit storage, encrypted Android storage for email-import and share-management tokens, access controls, and limited retention. No storage or transmission method is completely secure, and we cannot guarantee absolute security.

10. Children

DepartBuddy is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information without appropriate permission, contact us and we will take appropriate action.

11. Changes to This Policy

We may update this Policy as the Service changes. We will publish the revised Policy and update the date above. If a change materially affects how we process information, we will provide additional notice when required.

12. Contact

Miguel Carranza
Email: hello@departbuddy.com