Legal
Privacy Policy
Effective: August 2, 2026 · Last updated: August 11, 2026
DepartBuddy is operated by Miguel Carranza ("DepartBuddy," "we," "us," or "our"). This Privacy Policy explains how DepartBuddy handles information when you use the DepartBuddy iPhone or iPad application, email-import service, and read-only trip-sharing service (together, the "Service").
Contact: hello@departbuddy.com
1. Summary
- DepartBuddy does not require a DepartBuddy account or access to your email inbox.
- Trips are stored on your device and, when available, in your private Apple iCloud database.
- Booking emails are processed only when you forward them to your private DepartBuddy address.
- Optional Calendar Sync runs on-device and writes only to calendars you select.
- Trip sharing is optional, read-only, privacy-filtered, revocable, and automatically expires.
- Pending forwarded-email content is deleted after it is resolved and otherwise expires within seven days.
- We do not sell personal information, show third-party ads, or track you across apps or websites.
2. Information We Process
Trip and reservation information
When you create or save a trip, DepartBuddy may process information such as trip names and dates, destinations, passenger names, reservations, confirmation codes, seats, prices, notes, checklists, addresses, booking links, ticket or pass-code payloads, and a trip cover image you choose.
This information is provided by you or extracted from a booking email that you choose to forward. It is used to organize and display your trips, create in-app attention checks, and sync your data privately through iCloud when available.
Forwarded booking emails
When you forward a booking email, the email-import service may process the sender and recipient, subject, message text, travel details, passenger names, contact information contained in the message, confirmation codes, prices, ticket or pass-code data, and text extracted from supported attachments. DepartBuddy does not connect to, monitor, or continuously access your email account.
The email service temporarily stores the original forwarded message, normalized source text, and parsed reservation results while the import is pending.
DepartBuddy first uses its own rules-based parser. When the optional low-confidence fallback is enabled and that parser cannot confidently complete an import, the normalized message and supported attachment text may be sent to Google Gemini for one automated extraction attempt. The result is validated by DepartBuddy before it is shown for your review. Complete high-confidence imports are not sent to Gemini through this fallback.
Anonymous identifiers
DepartBuddy creates random identifiers to recover your private forwarding address, enforce the free email-import allowance, and maintain subscription access. These include an anonymous email-import account ID, a cryptographic hash of a random install token, a private forwarding address, and an anonymous RevenueCat App User ID. When iCloud Keychain is enabled, these identifiers may sync through your iCloud account so the same anonymous identity can be recovered on another device.
Subscription information
If you view, purchase, or restore DepartBuddy PRO, Apple and RevenueCat process purchase history, product, entitlement, renewal, expiration, and related transaction information. We do not receive your full payment-card details. We use subscription information to provide PRO access, prevent fraud, support purchases and restores, and understand subscription performance.
Photos and camera
If you choose a custom trip cover, the selected image is stored with your trip and may sync through your private iCloud database. If you choose to scan a pass code from the camera or a screenshot, recognition occurs on-device. DepartBuddy stores the extracted payload and code format but does not retain the scanned source image for that purpose.
Calendar
If you enable Calendar Sync, DepartBuddy requests full Calendar access so you can select writable calendars and so the app can create, update, and remove events for the trip categories you choose. DepartBuddy uses reservation identifiers stored in managed events to keep those events synchronized and avoid duplicates. Your calendar contents are processed on-device and are not sent to DepartBuddy's email-import service or other DepartBuddy servers.
Read-only trip sharing
When you create a share link, DepartBuddy sends only the trip snapshot you selected to the sharing service. Itinerary Only includes ordinary itinerary information such as trip dates, routes, times, providers, and lodging locations. If you choose Detailed, you can separately include traveler names and seats, confirmation codes, prices, or notes and checklists.
Share snapshots never include ticket or pass-code payloads, raw forwarded-email content, loyalty membership numbers, or private manage-booking links. The sharing service processes an encrypted snapshot, cryptographic hashes of random read and management tokens, expiry and update timestamps, and limited operational metadata such as access timestamps. Anyone who receives the capability link can view the selected snapshot until you revoke it or it expires, so you should share it only with people you trust.
Support and technical information
If you contact us, we process your message, email address, and any information you include so we can respond. Cloudflare, Apple, RevenueCat, and websites you choose to open may also process basic network information such as IP address, device/browser information, and request timestamps for delivery, security, fraud prevention, and operation of their services.
3. How We Use Information
We use information only as needed to:
- provide trip organization, email import, review, storage, private sync, and optional read-only sharing;
- display reservations, tickets, pass codes, maps, links, notes, checklists, and in-app alerts;
- operate the free email-import allowance and DepartBuddy PRO;
- maintain security, prevent abuse, troubleshoot failures, and comply with law;
- respond to support, privacy, and deletion requests; and
- improve the Service using subscription reporting and direct user feedback.
We do not use travel details, forwarded-email content, or pass-code data for advertising.
4. Storage and Retention
- Trips and local content: kept on your device and, when enabled, in your private iCloud database until you delete it. Deleting synced trip data removes it from devices using the same private iCloud store, subject to Apple's normal synchronization and backup behavior.
- Pending email imports: deleted after the last related reservation is saved, discarded, or purged, and automatically deleted no later than seven days after receipt.
- Email-import identity: the anonymous account ID, token hash, forwarding address, accepted import count, subscription linkage, and related timestamps are retained while needed to recover the service, enforce the import allowance, and provide PRO access, or until a valid deletion request is completed.
- Accepted-import ledger: retains only an opaque pending-import ID, anonymous account ID, and acceptance timestamp for lifetime free-allowance accounting. It does not retain the email or parsed reservation.
- Destination-image cache: cached on-device and automatically pruned or removed when the app's local data is removed.
- Calendar events: managed by the calendar provider you select under its retention and sync settings. DepartBuddy removes its managed events when you disable Calendar Sync, delete the related reservation or trip, or deselect that calendar while Calendar permission remains available. If PRO becomes inactive, existing calendar events remain unchanged.
- Shared trip snapshots: encrypted on Cloudflare and retained until you revoke the link or its fixed expiry. Upcoming or active trip links expire seven days after the trip ends; completed-trip links expire seven days after creation. Expired rows and older revoked rows are removed by automated cleanup. A copy already imported by a recipient is separate and is not deleted by revoking the original link.
- Support records: kept only as long as reasonably needed to resolve the request and meet legal obligations.
- Purchase records: retained by Apple and RevenueCat under their policies and as required for financial, fraud-prevention, and legal purposes.
5. Service Providers and External Services
We use the following providers only to operate DepartBuddy:
- Apple: App Store distribution and payments, iCloud/CloudKit private sync, iCloud Keychain, Apple Maps, and system services. See Apple's Privacy Policy.
- Cloudflare: email routing, serverless processing, security, encrypted read-only trip snapshots, and temporary database and object storage for email imports. See Cloudflare's Privacy Policy.
- Google: Gemini may process the minimum useful normalized booking-email and supported attachment text only when the optional low-confidence import fallback is enabled. See Google's Privacy Policy.
- RevenueCat: subscription entitlement management, purchase validation, restores, and subscription reporting. See RevenueCat's Privacy Policy.
- Wikimedia/Wikipedia: destination names may be sent in a lookup request to retrieve a relevant destination image. See the Wikimedia Privacy Policy.
When you choose to open a map, flight-tracking page, manage-booking link, or another provider link, the destination service receives the normal information associated with a web request and applies its own privacy policy.
We require service providers that process information for us to protect it consistently with this Policy and applicable law. We may also disclose information if legally required or necessary to protect the rights, safety, and security of users, the public, or the Service. We do not sell or rent personal information.
6. Your Choices and Deletion
- You can create and use manual trips without forwarding an email.
- You can review an import before saving it, discard one import, or purge all pending imports from Settings.
- You can delete individual trips and reservations, or use Delete all trips & data in Settings.
- You can manage iCloud and iCloud Keychain in Apple device settings. Turning them off causes DepartBuddy to operate locally where possible but does not itself delete existing iCloud data.
- You can manage or cancel DepartBuddy PRO in your Apple Account subscription settings. Deleting the app does not cancel a subscription.
- You can stop camera access in iOS Settings. Photo selection uses Apple's system picker and does not require full photo-library access.
- You can disable Calendar Sync in DepartBuddy Settings or revoke Calendar access in iOS Settings.
- You can preview what a trip link will contain, choose its disclosure settings, and revoke it from the trip. Deleting a shared trip or all travel data attempts to revoke its active link. If the device is offline and revocation cannot complete, the server's fixed expiry remains the backstop.
To request access, correction, or deletion of server-side email-import identity data, contact hello@departbuddy.com. Include your DepartBuddy forwarding address if possible so we can locate the anonymous record. We may need to verify control of that address or associated token before completing a request. We will respond as required by applicable law.
Deleting the app removes its local data but may not remove data already held in iCloud, pending email imports, active share snapshots, subscription systems, or backups. Revoke active links before deleting the app, use the controls above, or contact us for those records.
7. Legal Bases for Processing
Where applicable, we process information to perform the Service you request, with your consent when you choose to forward content or grant device access, to pursue legitimate interests such as security and abuse prevention, and to comply with legal obligations. You may withdraw consent by stopping the relevant feature and using the deletion choices above. Withdrawal does not affect processing already lawfully completed.
8. International Processing
Our service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, transfers are made using provider safeguards and lawful transfer mechanisms.
9. Security
We use reasonable technical and organizational safeguards, including HTTPS, random bearer tokens, hashed server identifiers, encrypted shared snapshots, Apple Keychain, private CloudKit storage, access controls, and limited retention. No storage or transmission method is completely secure, and we cannot guarantee absolute security.
10. Children
DepartBuddy is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information without appropriate permission, contact us and we will take appropriate action.
11. Changes to This Policy
We may update this Policy as the Service changes. We will publish the revised Policy and update the date above. If a change materially affects how we process information, we will provide additional notice when required.
12. Contact
Miguel Carranza
Email: hello@departbuddy.com