Privacy Policy
Last updated: October 2, 2026
This Privacy Policy explains what data this app collects, how that data is used, and the choices you have. It applies to every PantaLabs app that shares this stack-level disclosure profile. Because individual apps may differ in features, some sections below appear only when the relevant SDK or behavior is actually used.
Data Controller
PantaLabs (the "operator") is the controller responsible for personal data processed in connection with this app. For privacy, terms, or rights-related inquiries, contact admin@pantalabs.net. Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies and the operator is not established in the European Economic Area or the United Kingdom, requests under those laws may be sent to the same address; the operator will respond within the statutory deadlines.
Data Stored On Your Device
The trips you create in the app (itineraries and related content such as packing lists and expenses) are stored in a local database on your device. To manage the links you share, the app also keeps an anonymous owner key in the device's secure storage (Keychain on iOS, Keystore-protected storage on Android); on iOS, if iCloud Keychain is on, this key can follow your Apple ID to a new iPhone. Deleting the app removes the on-device data. Backups made by the operating system (iCloud, Google One, etc.) follow each platform's privacy policy. The sections below describe the only data that leaves your device.
Shared links and encrypted backup (trip organizer)
The app has no accounts. The first time you share a trip, the app asks our server for an anonymous owner key. It is a random value that is not linked to your name, email address, phone number or store account; it only proves that later changes to your links come from you. - Shared links: your itinerary is encrypted on your device before it is uploaded. The key needed to read it exists only in the part of the link after "#", which is never sent to our server, so we cannot read your itinerary. To run the link, the server stores the encrypted document together with the link token, the anonymous owner ID, a random trip identifier created by the app, the trip's end date (to know when to delete the link), whether the link is a snapshot or live, its version, the times it was created and updated, and how many times it has been opened. The server also records when your owner key was last used. - Encrypted backup (on by default; you can turn it off in the app's Settings): your trips are encrypted on your device with a recovery code that only you hold. The server stores only the encrypted file, its size and version, and an identifier derived from the recovery code. We cannot read the backup or restore it without your code. This data is used only to provide sharing, live updates and backup.
People who open a shared link (companions)
Opening a trip that someone shared with you does not require an account either. When you join a shared trip in the app, you choose a nickname (1–12 characters), and our server stores: that nickname, your app language, a push notification token (if notifications are allowed), the time you last used the shared features, and a random companion key that identifies your app installation. Checks and comments you leave on an itinerary are stored with that link; comments are encrypted on your device with the link's key, so we cannot read them. The trip organizer and anyone else who has the same link can see your nickname together with your checks and comments. The list of trips shared with you is stored only on your device and is not sent to our server. - Retention: a companion record is deleted after 90 days without use once it is no longer connected to any shared link (links themselves are deleted 90 days after the trip ends), and in any case after 12 months without use. Checks and comments are deleted together with the link or with your companion record, whichever comes first. - Deletion: "Delete my data" in the app's settings immediately deletes your companion record on our server together with your checks and comments, and clears the list of trips shared with you on your device.
Shared link web page
When a shared link (pantalabs.net/t/…) is opened in a web browser, the page helps you open the trip in the app or install it. The decryption key in the part of the link after "#" is read only inside your browser to pass the full link on to the app; it is not sent to our server, to the app stores or to anyone else. The page loads no analytics, advertising or other third-party scripts, and tells the browser not to send the link as a referrer. As with any website, our hosting provider (Vercel) processes the request, including your IP address, in order to deliver the page.
Advertising (Google AdMob)
This app shows advertisements through Google AdMob, a service provided by Google LLC. To serve, measure, and prevent fraud in advertising, Google may collect: the device's resettable advertising identifier (IDFA on iOS, AAID on Android), IP address, coarse geo-location derived from IP address, device type, operating system version, screen size, language and time zone, in-app ad interactions, and a unique per-app installation identifier. In regions that require prior consent for personalized advertising - the European Economic Area, the United Kingdom, and Switzerland - the app presents Google's User Messaging Platform (UMP) consent dialog on first launch. You can change your choice at any time through the in-app "Ad Personalization" link, or from the device's system settings. See the Ad Personalization page for details.
Rewarded ads and live link unlock
If you watch a rewarded ad to unlock live updates for a trip, Google AdMob confirms the reward directly to our server (server-side verification). The confirmation contains your anonymous owner ID, the trip identifier, the number of days unlocked and an ad transaction ID. We store these to know until when that trip's live link is unlocked. Your owner key itself is never included.
Analytics, remote configuration and push (Firebase)
The app uses the following Firebase services provided by Google LLC: - Firebase Analytics: aggregates anonymous events (app launches, session length, key actions, in-app purchases, etc.). Your itineraries, nicknames, comments and link keys are not sent to Firebase Analytics. - Firebase Remote Config: adjusts app settings without an app update. - Firebase Cloud Messaging: delivers companion notifications (see "Notifications"). Firebase data is processed under Google's data processing terms. More: https://firebase.google.com/support/privacy
In-App Purchases
All in-app purchases are processed by Apple (App Store) or Google (Google Play Billing). We never see your payment method, billing address or store account credentials. On iOS, the app sends the signed purchase record for the Pro upgrade to our server. The server checks Apple's signature and stores only the result and the purchase's original transaction ID with your anonymous owner key. This is used only to decide whether your live links can stay live without a time limit. Refund eligibility, cancellations and disputes follow the published policies of the platform that processed the payment. - Apple: https://support.apple.com/en-us/HT204084 - Google: https://support.google.com/googleplay/answer/2479637
Notifications
Companion notifications are on by default. When you open a shared link in the app, you are subscribed to that trip and are notified when the organizer changes it, at most once every 10 minutes per link. After you choose a nickname, the app asks once for the system notification permission. If you allow it, your device's push token is sent to our server, and notifications are delivered through Firebase Cloud Messaging (Google) and, on iOS, Apple Push Notification service. A notification carries no itinerary content, only a signal that the trip changed; the app composes the text on your device. You can turn notifications off at any time with the toggle in the app's settings (this deletes your push token from our server) or in your device's system settings: iOS: Settings → Notifications → the app; Android: Settings → Apps → the app → Notifications.
Third-Party SDKs and Services
The app relies on the following third-party services, each governed by its own privacy policy: - Google AdMob (ads and rewarded ad verification): https://policies.google.com/privacy - Google Firebase Analytics, Remote Config and Cloud Messaging: https://firebase.google.com/support/privacy - Apple Push Notification service and Apple In-App Purchase (iOS): https://www.apple.com/legal/privacy/ - Google Play Billing (Android): https://policies.google.com/privacy - Amazon Web Services (hosting of our server): https://aws.amazon.com/privacy/ - Vercel (hosting of the shared link web page): https://vercel.com/legal/privacy-policy We have no read access to personal data these services may collect independently. Data sent to each service is limited to what the features described above need.
Legal Basis for Processing (GDPR / UK GDPR)
Where the EU General Data Protection Regulation (Regulation (EU) 2016/679) or the UK GDPR applies, we process personal data on the following legal bases: - Performance of a contract (Art. 6(1)(b)): shared links, companion reactions and comments, live update notifications, and verifying a purchase or rewarded unlock, all of which you request by using those features. - Consent (Art. 6(1)(a)): personalised AdMob ads, where consent is given through the in-app UMP consent screen, and the notification permission you grant on your device. You may withdraw consent at any time; withdrawal does not affect the lawfulness of prior processing. - Legitimate interests (Art. 6(1)(f)): the encrypted backup, which is on by default so your trips are not lost with your phone (it is encrypted on your device so we cannot read it, and you can turn it off in the app's Settings at any time), non-personalised ads, aggregated analytics, protecting the service against abuse, and automatically deleting inactive records. You may object at any time via the email above. - Compliance with a legal obligation (Art. 6(1)(c)): retaining transaction records to meet tax or consumer protection law, where applicable.
International Data Transfers
We are located in the Republic of Korea. Our server, which stores shared links, companion records and encrypted backups, is hosted by Amazon Web Services in Seoul, Republic of Korea. The third-party services listed above (Google, Apple, Vercel) may process personal data in other jurisdictions, including the United States. Where data is transferred out of the European Economic Area, the United Kingdom or Switzerland, the transfer relies on the safeguards adopted by the receiving provider - typically the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), or, where applicable, the EU–US Data Privacy Framework. Each provider's transfer safeguards are described in the privacy policies linked above.
Retention and deletion
- On your device: until you delete it in the app, delete the app or clear its storage. - Shared links (with the encrypted itinerary, checks, comments and notification subscriptions): deleted automatically 90 days after the trip's end date, or immediately when you stop sharing the link or delete the trip in the app. - Encrypted backup: deleted 2 years after the last upload, or immediately with "Delete my data". - Owner key: deleted after 180 days without use if it has no shared links, no rewarded unlock record and no verified purchase. A key with a rewarded unlock record or a verified purchase is kept so that the unlock or purchase keeps working, until you delete it with "Delete my data". - Companion record: see "People who open a shared link (companions)" above. "Delete my data" in the app's settings deletes the server copies immediately: it removes all your shared links, your owner key together with its rewarded unlock and purchase records, your encrypted backup, and your companion record with your checks and comments. If your device is offline at that moment, the on-device data is still deleted and any server copies that could not be reached are removed by the retention periods above. Personal data handled by third-party services (AdMob, Firebase, store platforms, hosting providers) is retained according to their own policies linked above. Where you have a statutory right to erasure, you can exercise it directly with those providers or ask us for help.
Security
Shared itineraries, companion comments and backups are end-to-end encrypted (AES-GCM) on the device. The keys stay in the part of the link after "#" or in your recovery code and never reach our server, so a copy of our database would reveal only encrypted content plus the plain items listed above (nicknames, languages, push tokens, anonymous IDs, trip end dates, transaction IDs, times and counts). This also means we cannot recover a trip or a backup for you. Notifications contain no itinerary text. All traffic between the app and our server is encrypted with HTTPS/TLS. Our server necessarily receives your device's IP address with each request; we use it only to deliver the response and to limit abusive request rates, and technical logs are rotated and overwritten automatically. On-device data is protected by the operating system's standard safeguards (iOS Data Protection, the Android app sandbox). Operator-side secrets such as API keys are kept out of public source control. No system is perfectly secure, so we cannot guarantee absolute protection against unauthorised access, but we commit to reasonable technical and organisational measures proportionate to the sensitivity of the data.
Children's Privacy
This app is not directed at children. The operator does not knowingly collect personal data from children under the age limits set by applicable law: - 13 years old in the United States (Children's Online Privacy Protection Act, COPPA). - 14 years old in the Republic of Korea (Personal Information Protection Act, Article 22-2). - 16 years old in the European Union (GDPR Art. 8, subject to lower thresholds set by individual member states). If a parent or guardian becomes aware that a child has provided personal data, they may contact the operator at the email address above to request deletion. Behavioral or interest-based advertising is not delivered to users identified as children.
Your Rights
Depending on where you reside, you may have the following rights, which you can exercise by contacting admin@pantalabs.net. Please describe your request and, where helpful, indicate your jurisdiction. - European Economic Area, United Kingdom, Switzerland (GDPR / UK GDPR / FADP): right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and the right to lodge a complaint with a supervisory authority. - California, United States (CCPA / CPRA, Cal. Civ. Code §§ 1798.100–1798.199.100): right to know, right to delete, right to correct, right to opt out of the sale or sharing of personal information, right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. - Republic of Korea (Personal Information Protection Act, Articles 35–37): right to access, correct, delete, and to suspend processing. - Japan (Act on the Protection of Personal Information): right to disclosure, correction, and cessation of use. - Australia (Privacy Act 1988, Australian Privacy Principles): right to access and correct personal information. - Canada (PIPEDA, Principle 4.9): right to access and correct personal information. "Do Not Sell or Share My Personal Information" (CCPA / CPRA): the operator does not sell personal information for monetary consideration. The use of an advertising identifier for personalized advertising may, however, be classified as "sharing" under the CCPA/CPRA. California residents may opt out by selecting non-personalized advertising via the in-app Ad Personalization link, or by resetting the advertising identifier on their device.
Changes to This Policy
This policy may be updated when the app's data practices change, when new third-party services are added, or when the law changes. The "Last updated" date at the top of this page always reflects the most recent change. Material changes will be highlighted in-app where reasonable. Continued use of the app after a change becomes effective constitutes acceptance of the updated policy.
Contact
For privacy, terms, or rights-related inquiries, contact PantaLabs at admin@pantalabs.net.