Privacy Policy

Last updated: 17 June 2026

1. Data Controller

Voyura operates this Service and acts as the data controller for personal information collected through it. By using the Service, you consent to the collection and use of your information as described in this policy.

2. What We Collect

Account information: Name, email address, and profile picture (from Google OAuth or manual signup). Optionally: username and home city.

Trip data: Destinations, itineraries, day plans, and timelines you create or save.

Documents: Files you upload to trips, stored securely on Cloudflare R2.

Usage data: AI generation counts, feature usage, and timestamps — used to enforce plan limits and prevent abuse.

Billing data: Payment information is handled entirely by Stripe. We store only your Stripe customer ID and subscription status — we never see your card details.

Log data: When you use the Service, our servers automatically record information including your IP address, browser type, operating system, referring URLs, pages visited, and timestamps. This data is used for security monitoring, debugging, and aggregate analytics.

3. How We Use Your Data

  • To provide and improve the Service
  • To generate personalised AI itineraries based on your inputs
  • To enforce plan limits and prevent re-signup abuse
  • To send transactional emails (receipts, password resets) — no marketing without consent
  • To share trip data with collaborators you explicitly invite
  • To detect and prevent fraud, abuse, and security incidents
  • To comply with legal obligations

4. Legal Bases for Processing (GDPR)

If you are in the EU or UK, we process your personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you signed up for (account, trips, billing)
  • Legitimate interests: Security monitoring, abuse prevention, and improving the Service — where these do not override your rights
  • Consent: Marketing communications (where applicable) and optional features
  • Legal obligation: Retaining certain records as required by law

5. Data Sharing

We do not sell your personal data. We share data only with the following service providers, each of whom has their own privacy policy governing their use of your data:

  • Stripe — payment processing
  • Cloudflare R2 — document storage
  • Anthropic — AI itinerary generation (prompts include destination and preferences, not personal identifiers)
  • Google — if you sign in with Google OAuth

We may also disclose your information if required by law or to protect the rights, property, or safety of Voyura or others.

6. Cookies and Tracking

We use session cookies for authentication only. We do not use advertising trackers or third-party analytics by default.

You can configure your browser to refuse cookies, but some parts of the Service may not function correctly without them. Third-party services we integrate with (Google, Stripe) may set their own cookies governed by their respective privacy policies.

7. Data Retention

Your data is retained as long as your account is active. If you delete your account, your profile and trips are permanently deleted within 30 days. Uploaded documents are removed from storage within 30 days of deletion.

AI generation usage records (email + count only) are retained to prevent re-signup quota abuse. Server log data is retained for up to 90 days.

8. International Data Transfers

Voyura uses service providers based in the United States (Stripe, Cloudflare, Anthropic). If you are located in the EU or UK, your data may be transferred to and processed in the US. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) to ensure your data receives adequate protection.

9. Security

Passwords are hashed with bcrypt. All data is transmitted over HTTPS. Document files are stored in private Cloudflare R2 buckets and accessed only via short-lived signed URLs. Despite these measures, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

10. Your Rights

You can access, export, or delete your data at any time from your profile page. You may also contact us to request a full data export or erasure.

If you are in the EU or UK, you have the following rights under GDPR:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection / Restriction: Object to or restrict certain types of processing
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, contact us at privacy@voyurago.com. We will respond within 30 days.

11. Children

Voyura is not directed at children under 13. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

12. Third-Party Services

The Service may contain links to or integrations with third-party websites and services. This policy applies only to information collected by Voyura. We encourage you to review the privacy policies of any third-party services you use through or alongside the Service.

13. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email or in-app notice. Continued use of the Service after changes are posted constitutes acceptance of the revised policy.

14. Contact

For privacy questions or data requests: privacy@voyurago.com.