Reizo

Privacy Policy

Last updated: 18 June 2026

Reizo (“Reizo”, “we”, “us”) is a travel-planning and travel-journal app and website. This policy explains what personal data we collect, why, who we share it with, and the rights you have. It covers the Reizo iOS app and the website at reizo.app (the “Service”).

Data controller: Sam Apostel, Lodewijk de Meesterstraat 18, 9100 Sint-Niklaas, Belgium. Contact: privacy@reizo.app.

A short summary

  • We collect the account details you give us and the trip content you create (itineraries, notes, journal entries, photos, places, budgets, etc.).
  • We do not sell your data, we do not run third-party advertising, and we do not track you across other apps or websites.
  • Your trips are private by default. They become visible to others only if you explicitly invite an editor or share an unguessable link. There is no public directory, feed, or search.
  • You can export your data and delete your account from inside the app and the website.

What we collect

Account data. When you create an account we process your email address and authentication credentials. We support passwords, passkeys, and Sign in with Apple. If you use Sign in with Apple and choose to hide your email, we receive Apple’s private relay address rather than your real one.

Trip content you create. Everything you put into a trip: titles and dates, regions and day-by-day itineraries, places and map pins (which can reveal locations you plan to visit), accommodation and booking details, budgets and expenses, checklists, food/diary/journal entries, links, and photos you upload (which may contain image metadata). Some of this can be sensitive, so we treat it as private by default.

Sharing and collaboration data. If you invite an editor or share a link, we record the access grants needed to enforce who can see or edit a trip.

Technical and diagnostic data. Standard server logs (IP address, timestamps, user-agent) needed to run and secure the Service, plus any crash/diagnostic data we collect to keep the app stable.

Device permissions (iOS). Only when you grant them, and only for the stated purpose:

  • Location — to show your position on the trip map and sort nearby places.
  • Photos / Camera — to attach images to your trips, journal, and food log.
  • Calendar (write-only) — to add itinerary days to your calendar.
  • Notifications — trip countdowns and reminders.

We do not collect contacts, health, financial account, or advertising identifiers.

Who we share it with

We use a small number of service providers to run the Service (hosting and database, photo storage, map tiles, weather, and transactional email). We share only what each needs, and we do not sell data. We do not use a payment processor — the iOS app is a one-time paid download handled entirely by Apple; we never see your payment details, and the web app is free. If we add or change a sub-processor we will update this policy.

The embedded MCP / automation interface

Reizo can expose an authenticated MCP (Model Context Protocol) interface so that an AI assistant you connect (e.g. Claude) can read and edit your own trips on your behalf. This runs under your own authenticated session and is scoped to your data. We do not send your data to any AI provider ourselves; any such connection is one you initiate and authorise.

How long we keep it

We keep account and trip data for as long as your account exists. When you delete your account we remove or irreversibly anonymise your personal data and uploaded assets. Because trips are stored as an event log, we may redact personal data from historical events (stripping identifying content and deleting assets) rather than deleting raw rows, and retain non-identifying structural records. Backups containing residual data are purged on their normal rotation.

Your rights

Depending on where you live (GDPR/UK GDPR/CCPA and similar) you can access and export your data (available in-app), delete your account and data (available in-app), rectify inaccurate data, object to or restrict certain processing, withdraw consent, and lodge a complaint with your data protection authority. To exercise rights you can’t complete in-app, contact privacy@reizo.app; we respond within the legally required timeframe (one month under GDPR). For California residents: we do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA.

Children

Reizo is not directed to children under 16 and we do not knowingly collect data from children under that age. If you believe a child has given us data, contact us and we will delete it.

Security

We protect data in transit with HTTPS, store credentials using industry-standard hashing, and restrict access to production systems. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of trip data.

Changes to this policy

We may update this policy. Material changes will be announced in-app or by email, and the “Last updated” date above will change.

Contact

Sam Apostel, Lodewijk de Meesterstraat 18, 9100 Sint-Niklaas, Belgium. Email: privacy@reizo.app.