Last updated: 7 October 2026
This notice covers the Tourist app and this public website. Tourist is currently in private beta. The app uses account-based cloud services; it is not a service where all processing happens solely on your iPhone.
Account and travel information
Tourist stores account information such as your sign-in identity, profile name, username, photo and preferences, alongside information you add about home places, trips, bookings, saved ideas and travel documents. Firebase Authentication handles sign-in. Firestore and Cloud Storage support account records and uploaded files.
Photo-library access and locations
Photo access is optional and controlled through iOS. If you use travel-history reconstruction, Tourist reads the permitted assets’ dates, local identifiers and available location metadata. This metadata and the inferred journey associations can sync to your account. Your photo-library originals remain in Apple Photos; a library scan is not a blanket upload of every original.
Thumbnails can be analysed on the device to help select travel images. Files you deliberately share or upload are handled separately. Inferences may be incomplete or wrong. Removing a photo reference from Tourist does not delete the original from Apple Photos. You can change photo access in iOS Settings.
Documents and extraction
Uploaded bookings, passport scans, visas and other documents can be stored in Cloud Storage, with extracted fields in account-linked records. Google Cloud Vertex AI’s Gemini service can process the uploaded file to extract details. These files may contain sensitive identity information. Document files are not included in public profiles, and numbers and birth details are kept out of ordinary booking notes by the extraction logic.
Cloud storage and access controls are used; Tourist does not claim end-to-end encryption. Review extracted fields and avoid uploading documents belonging to someone else without permission.
Tourist AI
Questions and relevant saved travel context can be sent to Gemini through Google Cloud Vertex AI. Some travel-history questions are answered from structured records without a model request. Contextual tips and discovery can use your trips, bookings, travel history and saved interests. Tourist AI does not independently book, cancel or send messages on your behalf.
For public travel questions, the service can use Google Search. The implementation instructs it not to submit personal account identifiers, names, private notes or document data to Search. AI output can be inaccurate; verify travel requirements and time-sensitive information with official sources.
Optional connections and sharing
Where available and enabled by you, email connections request read access to import travel information. Connection credentials are stored encrypted by the integration service. Disconnecting stops imports and requests revocation. The availability of each connection depends on beta configuration.
Public profiles and explicit travel-sharing settings determine what other people can see. Family links and trip sharing use acceptance and scope controls. Files shared from another iOS app are first placed in an account-bound local inbox for review.
Services and technical information
Tourist uses Google Firebase and Google Cloud for authentication, hosting, storage, database and server processing; Gemini for AI; and destination/search services for place information. Apple services provide photo access, on-device location lookup and iOS sharing. Opening a booking provider sends you to that provider, whose privacy notice applies there. No commercial partnership is implied by a provider link.
The app records technical usage and cost measurements, including internal account ID, session, feature, request counts and date. Server logs can contain technical identifiers and error information. This website does not include advertising pixels, a Firebase client SDK or a web analytics tracker. Hosting infrastructure still processes network requests, including IP addresses and request details.
Retention and removal
Saved account records and uploaded files can remain stored until removed. Some removals mark records as deleted or excluded so they do not reappear during syncing; this does not guarantee immediate physical erasure of every underlying record or backup.
You can remove supported items and revoke device permissions in the app. Full-account deletion, backup retention and service-provider retention need to be confirmed for the private beta; no immediate, universal deletion promise is made here. Contact Tourist to request account access, correction or removal when the support channel is available.
Your rights and contact
Depending on where you live, you may have rights to access, correct, delete or obtain a copy of personal information, restrict or object to processing, withdraw permission, and complain to your local data-protection authority. Withdrawing device permission stops future access; it does not itself remove data already stored.
Privacy enquiries
A public support contact is being prepared. This page will be updated with a direct contact channel before wider beta access opens.
Private beta informationPrivate-beta notice
The operating entity, postal contact, formal processing bases, international-transfer safeguards and complete retention schedule are being finalised. This notice will be updated before wider release. The published feature descriptions do not replace that operational and legal review.