Privacy Policy

Last updated: 28 August 2026

MadHopper is a personal travel planner that turns your forwarded booking confirmations, calendars, and saved places into one timeline and map. This policy explains what we collect, why we are allowed to, who else sees it, and what you can require of us.

Who is responsible for your data

The data controller is Alisa Halamai, Individual Entrepreneur, Yunatska Street 10, 03066 Kyiv, Ukraine.

You can reach us about anything in this policy at privacy@madhopper.app.

We have not appointed a Data Protection Officer — the scale and nature of our processing does not require one. A message to the address above reaches the person who can act on it.

What we collect, why, and on what legal basis

Each purpose below names the legal basis we rely on under Article 6 GDPR, and how long the data stays.

Running your account — your email address and password, or your Google email, name and profile picture if you sign in with Google. Basis: performance of our contract with you (Art 6(1)(b)). Kept until you delete your account.

Building your timeline — booking confirmation emails you forward, or booking files (PDFs / screenshots) you upload: the sender, subject and message body, or the file’s contents, from which we extract flights, stays, cars, trains, buses, ferries and tickets. We do not keep the original email or file unless you choose to ("Keep the original file"): if you do, it is stored privately, readable only by you, and removed when you delete that item or your account. Tickets and confirmations only, never identity documents. Basis: contract (Art 6(1)(b)), because forwarding or uploading is you asking us to do this; keeping the file is your explicit choice. Kept until you delete the trip or your account; unreviewed drafts — and any file kept with them — are deleted automatically after about 90 days.

Visas and days of stay — if you forward an e-visa document, the country, validity dates and permitted days of stay we read from it. Basis: contract (Art 6(1)(b)). Kept until you delete the visa or your account. We do not store the document, your passport number, your name or your date of birth, and we do not read photographs of visa stickers at all.

Your map and calendars — places you save, events from any ICS feed you subscribe to, GPX tracks (kept in your browser only), and Strava activities if you connect Strava. Basis: contract (Art 6(1)(b)). Kept until you remove them or delete your account.

Feedback and support — the message you send us, any screenshot you attach, and your app version, screen, language, timezone and browser. Basis: our legitimate interest in fixing defects and improving the app (Art 6(1)(f)). Kept indefinitely, because a report may still be the reason a fix is in progress; see "If you delete your account" below.

Keeping the service secure — server logs and abuse prevention. Basis: our legitimate interest in keeping the service available and free of abuse (Art 6(1)(f)).

Subscriptions and purchases — if you buy MadHopper Pro or an import pack: your plan, its billing period, the store it was bought in, and the payment provider’s transaction identifier. We never see or store your card number — payment details go directly to the payment provider. Basis: contract (Art 6(1)(b)), and a legal obligation for accounting records (Art 6(1)(c)). Kept while your account exists; accounting records for as long as tax law requires.

We do not sell your data, we do not use it for advertising, and we do not profile you.

What you must provide, and what happens if you do not

An email address is required to create an account — without it we cannot identify you or let you sign back in.

Everything else is optional. If you do not forward booking emails, you can enter trips by hand. If you do not connect Strava or subscribe to a calendar, those parts of the app simply stay empty. Declining any of this does not limit the rest of the service.

Automated parsing, and the AI we use

Recognising a booking or a visa from a document is done automatically. We first try structured data and pattern rules on our own servers.

When that fails, the text may be sent to Anthropic (Claude) to extract the fields. Before anything leaves our servers we remove payment card numbers, security codes and passport numbers. For visa documents the extraction tool can only return four values — country, start date, end date and permitted days — because it has no field for a name, passport number or date of birth. Anthropic processes the text to return a result under a data processing agreement and does not use it to train its models.

Nothing parsed automatically is applied on its own. Every booking and every visa lands in a review queue, and a person — you — confirms or corrects it before it is used. Because a human decides, this is not automated decision-making within the meaning of Article 22 GDPR, and you are never subject to a decision made solely by a machine.

You can correct any parsed field before or after it is saved.

Content you share from other services

When you share an Instagram post or a Google Maps saved list, we ask a specialist provider (Apify) to read that page for us, because neither platform offers a way for applications to read it directly. We send the link you shared and nothing else about you.

That content is written by other people and can mention them. We use it only to find place names, we keep only the places, and we do not build profiles of the authors — creator handles and any names attached to shared lists are discarded deliberately. Contacting every such author individually would be impossible, which Article 14(5)(b) GDPR recognises; if you are one of them and want your details removed, write to us and we will remove them.

Who else sees your data

These providers process data only on our instructions, under a data processing agreement ("processors"):

Supabase — database and authentication. Data is stored in the EU (Frankfurt); the company is Singapore-based.

Anthropic (US) — AI parsing of forwarded documents, as described above.

Apify (Czechia) — reading an Instagram post or Google Maps list when you share one.

Cloudflare (US) — routing your forwarded emails to us.

Fly.io (US; servers in Warsaw) and Vercel (US) — application hosting.

RevenueCat (US) — keeping your subscription status in sync across devices, if you buy Pro or a pack in a mobile app. It receives your account identifier and the store’s purchase token, never your card details.

These decide for themselves how they use data, so they are independent controllers rather than our processors — their own privacy policies govern, and we cannot instruct them on your behalf:

Google — sign-in, if you choose it, and the YouTube Data API when you share a YouTube link.

Strava — your activities, only if you connect it.

OpenStreetMap Foundation (UK) — turning place names into map coordinates.

Creem (merchant of record for web purchases) — if you buy on the web, your purchase is made through Creem, which collects your payment details and billing information under its own privacy policy. We receive confirmation of the purchase, not your card details.

Apple App Store and Google Play — if you buy in a mobile app, the purchase and your payment details are handled by Apple or Google under their own terms and privacy policies.

Separately from these providers: our administrators can read feedback you send us — the message, the screenshot and the email address of the account it came from — because that is how a bug report gets acted on. Nothing else in your account is readable this way.

Sending data outside the EU

Several of the providers above are in the United States, so your data is transferred outside the European Economic Area. The United States has no general adequacy decision from the European Commission.

Where a provider is not covered by an adequacy decision, we transfer on the basis of the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with the technical measures described in this policy — encryption in transit, and removal of payment and passport identifiers before any document is sent for parsing.

You can obtain a copy of the clauses we rely on by emailing privacy@madhopper.app.

The United Kingdom, where the OpenStreetMap Foundation is based, is covered by an adequacy decision, so no additional safeguard is needed for that transfer.

Cookies and data stored in your browser

We do not use advertising or analytics cookies, and there is no cookie banner because there is nothing to consent to.

We store two things in your browser, both necessary for the service you asked for:

Your sign-in session, so you stay logged in between visits. Kept until you sign out or it expires.

GPX tracks you upload, which never leave your device.

Under the ePrivacy rules, storage strictly necessary to provide a service you requested does not require consent — but you are entitled to know it happens, which is what this section is for. Clearing your browser storage signs you out and removes your uploaded tracks.

How long we keep things

Retention is listed per purpose above. In short: your own content stays until you remove it or close your account; unreviewed booking drafts are deleted automatically after about 90 days; feedback is kept indefinitely and anonymised if you close your account.

If you delete your account

You can delete your account at any time in Settings → Account. That permanently removes your trips, places, calendars, visas, drafts and sign-in record.

Two things are kept. Feedback you sent us stays, with your account no longer linked to it — the report describes the app rather than you, and it may already be the reason a fix is underway; once your account is gone we can no longer tell whose report it was. And if you made purchases, the accounting records tax law requires us to keep (the transaction, never your card details) are retained for the statutory period.

Your rights

Under the GDPR you can ask us to:

give you a copy of your data (Art 15);

correct anything inaccurate (Art 16);

delete your data (Art 17);

restrict how we use it while a dispute is resolved (Art 18);

hand it over in a machine-readable format, or send it to another provider (Art 20) — this covers data you gave us that we process by automated means on the basis of your contract with us;

stop processing based on our legitimate interests (Art 21) — see the separate section below.

Some of these have limits in the law: we may have to keep something to comply with a legal obligation, and portability does not cover data we derived ourselves. We will always tell you which limit applies rather than refusing without a reason.

Some of this you can do yourself in the app: you can edit your profile, and you can delete your account and its data in Settings → Account. For a copy of your data, or to hand it over in a machine-readable format (Art 15 and 20), email support@madhopper.app — we send you a structured archive of the data you gave us. For anything else, write to privacy@madhopper.app. We answer within one month, and will tell you if a complex request needs longer, as the GDPR allows. Exercising your rights is free.

Your right to object

You have the right to object, at any time and on grounds relating to your particular situation, to our processing of your data based on our legitimate interests — that is, feedback handling and service security.

To object, email privacy@madhopper.app. We will stop that processing unless we can show compelling legitimate grounds that override your interests.

Complaining about us

If you think we have handled your data unlawfully, you can complain to a data protection supervisory authority. You may go to the authority in the country where you live, where you work, or where the problem happened.

The list of national authorities is published by the European Data Protection Board at edpb.europa.eu. We would rather hear from you first and fix it — but this right exists whether or not you contact us.

Security

Data is encrypted in transit and at rest. Your trips, places, calendars and visas are scoped to your account at the database level, so no other user can read them. Passwords are hashed by our authentication provider — we never see them.

Screenshots you attach to feedback are stored privately and are not reachable by any public link. Please keep in mind before attaching one that it shows whatever was on your screen.

No system is perfectly secure. If a breach affects your data and is likely to put you at risk, we will tell you.

Children

MadHopper is not intended for anyone under 16, and our Terms set 16 as the minimum age. We do not knowingly collect data from children.

If you believe a child has an account, write to privacy@madhopper.app and we will delete it.

Changes to this policy

We may update this policy. The date at the top always reflects the current version, and for any change that affects your rights or introduces a new recipient of your data we will tell you in the app before it takes effect.

Contact

Questions about this policy, your data, or to exercise any right: privacy@madhopper.app.

Postal: Alisa Halamai, Individual Entrepreneur, Yunatska Street 10, 03066 Kyiv, Ukraine.