Legal

Privacy Policy

Last updated: September 1, 2026

Altrove ("Altrove", "we", "us", "our") builds a travel app that turns videos and posts you share from Instagram, TikTok, and YouTube into pins on a personal map. This policy explains what information we collect across our app, website, and shared map pages, why we collect it, who we share it with, and the choices and rights you have over it.

On this page
  1. 1. Scope of this policy
  2. 2. Information we collect
  3. 3. How we use your information
  4. 4. AI processing of shared content
  5. 5. How we share information
  6. 6. Public profiles & social features
  7. 7. Data retention
  8. 8. Your rights & choices
  9. 9. Children's privacy
  10. 10. International data transfers
  11. 11. Security
  12. 12. Cookies & similar technologies
  13. 13. Changes to this policy
  14. 14. Contact us

1.Scope of this policy

Who we are. Altrove is run by Daniel Gustafsson, an individual based in Sweden, who is the data controller for the personal data described in this policy. Postal address: Kaptensgatan 11, 211 41 Malmö, Sweden. For anything in this policy — including a request to exercise the rights in §8 — email [email protected].

This policy covers the Altrove mobile app (iOS and Android), the altrove.app website, and the shared map pages we generate when you make your profile public (e.g. altrove.app/public/<you>). It does not cover third-party services we link to or that you connect through Altrove — Instagram, TikTok, YouTube, Google, Apple, and your device's app store each have their own privacy practices, and we encourage you to review them separately.

2.Information we collect

Account information. When you create an account, we collect your email address and a password (stored as a one-way hash — we never see or store your password in plain text). If you sign in with Google or Apple instead, we receive your email, name, and a unique identifier from that provider, but never your Google or Apple password. Optionally, you may add a display name, username, profile photo, bio, country, and birth year.

Content you add. Places you pin, notes you write, collections/trips you create, and any photos or links (Instagram, TikTok, YouTube URLs) you share into the app.

Location data. The GPS coordinates and place details (via Google Places/Geocoding) for locations you pin. If you use the "detect visited countries" feature, the app reads GPS metadata already embedded in photos on your device to suggest places you've been — those photos themselves are not uploaded to our servers for this feature. If you separately choose to pick a photo to identify a location with AI, or use bulk import (Google Photos Takeout / Instagram data export), that file is uploaded to our storage for processing (see §7 for how long we keep it).

Passport details (optional). Whether you need a visa depends on the passport you travel on, so the pre-departure briefing can't answer that question without knowing which passports you hold and when they run out. You can type both in, or photograph the machine-readable zone — the two lines of characters at the bottom of the data page — and let us read them for you. If you use the photo, it is sent to our AI provider to transcribe those two lines and is not stored anywhere afterwards. What we keep is the issuing country and the expiry date, nothing else: we never store the passport number, your personal identity number, your photograph, or any other field printed on the document. Both the scan and the passport list are optional, skippable at signup, and can be cleared from your profile at any time.

Travel confirmations you forward (optional). If you switch on the booking inbox, mail you forward to your own personal @altrove.app address is read so that flights, hotels and reservations attach themselves to the right trip. Those messages are processed by our AI provider, and the booking details extracted from them are stored on your trip. The message itself is kept for up to 30 days so we can work out what went wrong if a confirmation is misread, and is then deleted automatically. Altrove never connects to your mailbox and cannot see anything you don't forward — you set up a rule for one address yourself, and you can remove it whenever you like.

Files attached to those confirmations. Where a forwarded confirmation carries a document — a boarding pass, a hotel voucher, a rental agreement — we store the file so you can open it from the booking it belongs to. Only documents are kept (PDFs, images and Apple Wallet passes, up to 5 MB each); anything else attached to the message is discarded unread. These files are stored privately, are never public, and are not sent to our AI provider. Unlike the message text, they are not deleted on a timer — a boarding pass that disappeared before the flight would be worse than not keeping it — so they stay until you remove them from the booking or delete your account.

Social activity and safety. Who you follow and who follows you, the accounts you block, trips you share or are invited to, and reports you file about other people's content or that other people file about yours.

Contacts (optional). If you grant contacts permission, Altrove uses your device contacts locally to show which friends are already using the app and to help you invite others. Contacts are matched on your device and are never stored on our servers beyond the email addresses you actively choose to send an invite to.

Device & usage data. Push notification tokens, app crash and error reports (via Sentry), and basic request logs (IP address, device/platform, timestamps) used for security, abuse prevention, and debugging.

Payment information. Subscriptions and credit-pack purchases are billed through the Apple App Store or Google Play — we never receive or store your card details. We use RevenueCat to manage subscription status and entitlements on our end.

3.How we use your information

If you're in the EU/EEA or the UK, the lawful bases we rely on are: performing our contract with you — running your account, storing your pins and trips, processing imports and purchases; your consent — contacts, location, notifications, the passport scan and the booking inbox, each asked for separately and each withdrawable at any time without affecting anything you did before; our legitimate interests — keeping the service running and secure, preventing abuse, acting on reports, and debugging; and legal obligation — the accounting and tax records we're required to keep.

4.AI processing of shared content

Altrove sends content to a third-party AI provider — currently Google's Gemini models, reached through OpenRouter — so that a machine can read it and hand back a result. That happens in five places: identifying a location from a caption, a video frame or a photo you share; transcribing the two machine-readable lines on a passport, if you choose to scan one; reading a travel confirmation you forward to your booking inbox; writing the pre-departure briefing for a country; and generating an itinerary or a packing list for a trip.

In every case the content is sent to produce your result and nothing else. We do not use it to train our own models, and we don't permit our provider to train on it. AI output can be wrong — see the accuracy disclaimers in our Terms of Service.

5.How we share information

We do not sell your personal information. We share it only with the service providers ("subprocessors") that help us run Altrove, each bound to use it solely to provide their service to us:

ProviderPurpose
GoogleSign-In, Maps & Places, GeocodingAuthentication (optional), place details and map rendering
AppleSign In with AppleAuthentication (optional, iOS/Android)
OpenRouter and the model provider it routes to (currently Google Gemini)Reading shared content, passport scans, forwarded confirmations; generating briefings and itineraries
RevenueCatSubscription and purchase management
SentryCrash and error reporting
ResendTransactional email (invites, verification codes)
Expo and Google FirebaseDelivering push notifications to your device
CloudflareStoring uploaded photos and pin covers; receiving travel confirmations you forward
Cloud hosting providersRunning our servers and database

We may also disclose information if required by law, to protect the rights, safety, or property of Altrove or our users, or in connection with a merger, acquisition, or sale of assets — in which case we'll notify you before your information becomes subject to a different privacy policy.

6.Public profiles & social features

Your profile is public by default, and signing up asks you which you want before the account is created. While it is public, your name, username, avatar, visited countries, and the pins you choose to include are visible to other users and to anyone with your shared map link — including people who don't have an Altrove account. You can switch to private at any time from your profile settings, and your profile stops appearing in search and discovery from that moment.

7.Data retention

8.Your rights & choices

Depending on where you live, you may have the right to:

To exercise any of these rights, contact us at [email protected].

9.Children's privacy

Altrove is not directed at children and you must be at least 16 years old to create an account. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us at [email protected] and we'll delete it.

10.International data transfers

We and our service providers operate in multiple countries. Where we transfer personal data out of the EU/EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses, or transfer to countries recognized as providing adequate protection.

11.Security

We use technical and organizational measures to protect your information, including encryption in transit (HTTPS/TLS), hashed passwords, and access controls on our infrastructure. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

12.Cookies & similar technologies

The altrove.app website does not use advertising or analytics cookies. We use minimal, strictly necessary local storage in the mobile app (e.g. to keep you signed in) and may introduce privacy-respecting analytics in the future — if we do, we'll update this section first.

13.Changes to this policy

We may update this policy from time to time. If we make material changes, we'll notify you in the app or by email before they take effect. The "Last updated" date at the top of this page always reflects the current version.

14.Contact us

Questions about this policy or your data? Email [email protected], or write to Daniel Gustafsson, Kaptensgatan 11, 211 41 Malmö, Sweden. If you are in the EU/EEA and think we have handled your data badly, you can also complain to your national data protection authority — in Sweden that is Integritetsskyddsmyndigheten (IMY).