Privacy
Last updated: 9 August 2026 Effective: 9 August 2026
This policy explains what Voyagr collects, why, who can see it, and what control you have. It is written to be read, not to be skimmed past. If something here doesn’t match what the app actually does, the app is wrong and we want to know: privacy@appvoyagr.com.
Who we are. Voyagr is operated by Voyagr Travel Communities Inc., a Delaware corporation with its registered address at 251 Little Falls Drive, Wilmington, DE 19808, United States (“Voyagr”, “we”, “us”). For users in the European Economic Area and the United Kingdom, we are the data controller for the personal data described in this policy.
1. The short version
We collect what you type into your profile, the photos you upload, the messages you send, and which club you belong to. That’s essentially it.
We run no analytics SDKs, no advertising SDKs, and no third-party trackers. We do not collect your location. We do not access your contacts. We do not use advertising identifiers.
We have never sold or shared personal information, and we do not.
Your profile is visible to other members of clubs you belong to — not to the public, not to search engines.
Club organizers can see a roster of their own members and aggregate statistics about their club. Details in §4.2.
You can export everything we hold on you, and delete your account, from inside the app. No email required, no waiting period.
2. What we collect
2.1 Information you give us
Account and identity — collected when you sign up:
Data · Notes
Email address — Your sign-in identity. Also used for password resets and account notices.
Password — Stored only as a salted hash by our authentication provider. We never see it.
First name — Shown on your card to people who can see you.
Date of birth — Collected once at signup to confirm you are 18 or older. Your age is shown on your card; your full date of birth is not.
Profile content — all optional, all editable or removable at any time:
City
Bio
Travel style
Interests, tags, and languages you speak
Phone number (optional; we do not use it for SMS or marketing)
App language preference
Up to six photos
Preferences — a visibility toggle that controls whether you appear to other members, and your per-category notification settings (announcements, groups, messages, promotions).
Communications you send — the text and timestamps of direct messages and club group messages, and who sent them to whom.
Safety actions — who you block, and any reports you file (the reason, any details you write, and who you reported).
Support requests — when you contact support through the app: your chosen topic, your message, your operating system and version, and the app version. We attach these to your account so we can answer you.
2.2 Information collected automatically
Session token. Stored on your device so you stay signed in. It never leaves your device except to authenticate you to us.
Device push token. If you turn on notifications, your device issues a token that lets us deliver them via Apple’s and Google’s push services. It identifies a device installation, not you personally.
Server logs. Our infrastructure provider records IP address, timestamp, and request metadata for security, abuse prevention, and debugging. These are retained on a short rolling window and are not used to profile you.
2.3 What we deliberately do not collect
We want this stated plainly because it is unusual:
No location data. The app requests no location permission of any kind. The “city” on your profile is text you typed.
No contacts, calendar, microphone, or health data.
No advertising identifiers (IDFA / AAID) and no ad networks.
No analytics, session-replay, heatmap, or attribution SDKs.
No cookies or web beacons for tracking. Our marketing website may use minimal, privacy-respecting analytics; that is covered in §12.
Camera and photo library access is requested only at the moment you add a photo, and we receive only the specific images you select — never your library.
3. Why we use it, and our legal basis
For users in the EEA and UK, GDPR requires us to name a lawful basis for each purpose:
Purpose · Data used · Lawful basis (GDPR Art. 6)
Create and maintain your account — Email, password, name, date of birth · Contract — Art. 6(1)(b)
Show your card to clubmates; let you browse theirs — Profile fields, photos, visibility preference · Contract — Art. 6(1)(b)
Deliver direct and group messages — Message content, sender/recipient, timestamps · Contract — Art. 6(1)(b)
Manage club membership and access — Membership, role, join code · Contract — Art. 6(1)(b)
Confirm you are 18 or older — Date of birth · Legal obligation — Art. 6(1)(c), and legitimate interests — Art. 6(1)(f) in keeping minors off an adult platform
Investigate reports, moderate content, ban abusers — Reports, blocks, message content when reported, profile data · Legitimate interests — Art. 6(1)(f): protecting our users from harm
Secure the service, prevent fraud and abuse — Server logs, account metadata · Legitimate interests — Art. 6(1)(f)
Answer your support requests — Support message, OS/app version, account data · Contract — Art. 6(1)(b)
Send notifications you enabled — Push token, notification preferences · Consent — Art. 6(1)(a)
Send promotional messages — Email, promotions preference · Consent — Art. 6(1)(a); off by default
Provide club organizers with aggregate insight into their club — Membership counts, message counts, aggregated interests · Legitimate interests — Art. 6(1)(f) in enabling clubs to run their community
Comply with law and respond to lawful requests — Whatever is legally required · Legal obligation — Art. 6(1)(c)
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them, largely because the data stays inside a closed community and is never used for advertising or profiling. You can object to any of it — see §8.
We do not use your data to train machine-learning models, and we do not use automated decision-making that produces legal or similarly significant effects on you.
4. Who can see your information
4.1 Other members
Members of clubs you share with. Your card — name, age, city, bio, travel style, interests, tags, languages, and photos — is visible to people who belong to at least one of the same clubs as you. It is not visible to the public, to the web, or to Voyagr users outside your clubs.
Turning yourself off. If you switch visibility off in settings, you stop appearing to other members.
Your messages. Direct messages are visible to you and the person you sent them to. Group messages are visible to everyone in that club group.
Blocking is one-directional and private. The person you block is not told.
An important technical disclosure: photos are held in a private storage bucket that is not readable by the public internet, but is currently readable by any signed-in Voyagr user who knows the file’s path — not only by your clubmates. Paths are not guessable and are not exposed in the app outside your clubs, but we would rather tell you this than imply a stronger guarantee than we enforce. We are tightening this.
4.2 Club organizers
If you join a club, that club’s owner and board members can see, for their own club only:
Your name, city, role in the club, and the date you joined.
Aggregate statistics for the club as a whole: total members, members joined in the last 7 and 30 days, group messages in the last 7 days, number of board members, and count of open reports. These are counts, not per-person activity logs. We may add aggregate summaries such as the club’s most common interests; these describe the group, not identifiable individuals.
Reports filed against members of their club — including the reason, the reported member’s name, and the name of the member who filed the report. If you report someone in your club, your club’s organizers can see that you filed it. Report to us directly at safety@appvoyagr.com if you need that not to be the case.
Club organizers can remove you from their club and change your role within it. Removal ends your access to that club’s groups and to the cards of its members. It does not delete your Voyagr account, your profile, or your direct messages.
Club organizers cannot read your direct messages, cannot see your email address, phone number, date of birth, or bio, and cannot see anything about clubs they do not run.
4.3 Service providers
We use a small number of processors, each bound by contract to handle data only on our instructions:
Provider · Role · Data
Supabase — Database, file storage, authentication, realtime messaging · All application data described in §2
Supabase — Transactional email (confirmation, password reset) · Email address
Expo — App builds, over-the-air updates, push notification relay · Push token, app version
Apple / Google — App distribution and push delivery · Push token, device identifiers held by the platform
4.4 Legal and safety disclosures
We may disclose information when we believe in good faith it is necessary to comply with a law, regulation, subpoena, or court order; to enforce our Terms; or to protect the rights, property, or safety of our users or the public. Where we are legally permitted, we will tell you before we do.
4.5 Business transfers
If Voyagr is acquired, merged, or its assets sold, your information may transfer as part of that transaction. You will be notified, and any acquirer will be bound by this policy or one materially as protective, until you are given notice and a chance to delete.
4.6 What we never do
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We have never done either. Under the CCPA/CPRA, we have not sold or shared personal information in the preceding twelve months, including that of any user we know to be under 16.
5. Where your data is held, and international transfers
Our infrastructure is hosted in the United States (AWS US East, N. Virginia).
If you are in the EEA, the UK, or Switzerland, your personal data is transferred to and processed in the United States. We rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) as the transfer mechanism, supplemented by encryption in transit and at rest and by contractual and technical restrictions on our processors. You can request a copy of the relevant clauses at privacy@appvoyagr.com.
6. How long we keep it
Data · Retention
Account, profile, photos — Until you delete your account
Direct and group messages — Until you delete your account, or until the conversation or group is deleted
Blocks — Until you unblock, or you delete your account
Reports — Kept after resolution, and kept even if the reported account is deleted — see below
Support requests — 24 months after resolution
Server logs — 30 days
Backups — Deleted data persists in encrypted backups for up to 30 days before being overwritten
When you delete your account, deletion is immediate and cascading. Your profile, photos, club memberships, blocks, and the messages you sent — including the copies in other people’s conversations — are removed from our live systems. There is no grace period and no way for us to restore it. If you want your data first, export it before you delete.
One exception: safety reports filed about you are not deleted with your account. If we deleted them, anyone reported for harassment could clear their record by deleting and re-registering. What we keep is the report itself, the display name you had at the time, and a one-way cryptographic hash of your email address — enough to recognise the same person coming back, and not enough to reconstruct your account or contact you. We rely on our legitimate interest in protecting other users from harm (Art. 6(1)(f)). You can object to this under Art. 21 by writing to privacy@appvoyagr.com, and we will weigh your objection against the safety of the people who filed the report.
7. Security
All traffic between the app and our servers uses TLS. Data is encrypted at rest.
Access to your data is enforced at the database level by row-level security policies, not only in app code — a client cannot read rows it has no right to, even if the app is modified.
Photos live in a private bucket that is not publicly readable (with the qualification in §4.1).
Passwords are salted and hashed by our authentication provider; we cannot read them. Changing your password requires re-entering your current one.
Direct messages are not end-to-end encrypted. They are encrypted in transit and at rest, but we hold the keys, which means we are technically able to access message content — and will, if required by law or if necessary to investigate a report. Please do not treat Voyagr messages as a confidential channel.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and the relevant supervisory authority as required by law — within 72 hours of becoming aware, where GDPR applies.
8. Your rights
Available immediately in the app, under Settings → Account:
Export my data — a complete machine-readable JSON file of your profile, photos, memberships, blocks, and messages.
Delete my account — immediate and irreversible, as described in §6.
You can also edit or clear any profile field, remove any photo, turn off visibility, and change notification preferences at any time.
If you are in the EEA or UK
Under GDPR you have the right to: access your data; rectify inaccurate data; erase it; restrict processing; object to processing based on legitimate interests, including a right to object at any time; data portability; and to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your supervisory authority — a list is at edpb.europa.eu, and in the UK the regulator is the ICO at ico.org.uk.
Our representative in the European Union under GDPR Article 27 is Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. Our representative in the United Kingdom under UK GDPR Article 27 is Prighter Ltd, 20 Mortlake Mortlake High Street, London, SW14 8JN, United Kingdom. You may contact either of them instead of us on any matter relating to your personal data.
If you are in California
Under the CCPA/CPRA you have the right to know what we collect and why, to access and receive a copy, to correct inaccuracies, to delete, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we do not use it for inference), and to non-discrimination for exercising any of these. You may use an authorized agent. The categories we collect map to Cal. Civ. Code §1798.140(v)(1) as: identifiers; personal information under §1798.80(e); protected-classification characteristics (age); internet or network activity; and audio/visual information (your photos). Sources, purposes, and recipients are in §2, §3, and §4.
If you are elsewhere in the United States
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have broadly similar rights to access, correct, delete, and port their data, and to opt out of targeted advertising and profiling — neither of which we do. Exercise them the same way.
How to exercise them
Use the in-app tools first — they are faster than we are. Otherwise email privacy@appvoyagr.com. We will verify your identity through the email on your account and respond within 30 days (extendable by 60 days for complex requests, with notice). There is no charge unless a request is manifestly unfounded or excessive.
9. Children
Voyagr is for adults. You must be 18 or older to create an account, and we check date of birth at signup. We do not knowingly collect personal information from anyone under 18. If you believe a minor has an account, email safety@appvoyagr.com and we will remove it. This applies even where a club is affiliated with a school — the age requirement is not waived by a club’s membership.
10. Meeting people in the real world
Voyagr helps people find each other; anything that happens afterwards is outside our systems and outside our knowledge. We do not conduct background checks or verify anyone’s identity. Information on another person’s card is what they typed, not something we have confirmed. Please read our Terms of Service and Community Guidelines before arranging to meet anyone.
11. Changes to this policy
If we make material changes we will notify you in the app and by email before they take effect, and where the law requires consent for the change, we will ask for it. The “last updated” date at the top always reflects the current version. Past versions are available on request.
12. Our website
appvoyagr.com is a marketing site hosted by Framer. It may set strictly necessary cookies and collect aggregate, non-identifying visit statistics. It does not require an account and does not connect visits to your Voyagr profile. Any cookie banner there will let you decline non-essential cookies.
13. Contact
Reason · Address
Privacy questions, data rights requests — privacy@appvoyagr.com
Safety, reports, underage accounts — safety@appvoyagr.com
Everything else — hello@appvoyagr.com
Registered address: Voyagr Travel Communities Inc., 251 Little Falls Drive, Wilmington, DE 19808, United States. This is our incorporation agent’s address, held for legal and regulatory correspondence — the email addresses above are the way to reach our team, and EEA and UK users may also contact our Article 27 representatives named in section 8.