DRAFT: not legal advice. Have it reviewed by a qualified lawyer before publishing.
Written by the engineering team from the code on sprint-3-full-app (2026-09-29). Placeholders are in [square brackets]. Items marked [CONFIRM] depend on a decision or a setting that isn't in the code yet.

LocalSide Privacy Policy

Effective date: [Date of publication]
Last updated: [Date]

This policy explains what personal information LocalSide collects, why, who processes it for us, how long we keep it, and the choices you have. It covers the LocalSide mobile app for iOS and Android ("the app") and the website at https://www.localsidetravel.com ("the site").

LocalSide is operated by [Company legal name], [registered address] ("LocalSide", "we", "us"). For privacy questions, email privacy@localsidetravel.com.

The short version

1. Information we collect

Information you give us

DataWhenWhy
Email addressSign-upTo create and secure your account, sign you in, send verification and password-reset codes, and let friends send you a friend request by email.
PasswordSign-upTo sign you in. It is handled by Amazon Cognito; we never see or store it ourselves.
Name and bio (optional)ProfileShown on your profile and to friends you've connected with.
Travel interestsInterest quizTo personalise your itineraries (for example Coffee Shops, Local Gems, Thrifting).
PreferencesProfileYour default budget and notification and email settings.
Trip contentPlanning and editing tripsDestinations or start and end points, dates, budget, pace, solo or group, and the activities, times, places, costs and notes in each itinerary.
Diary entriesTravel DiaryThe notes you write for each day of a trip.
PhotosTravel DiaryPhotos you choose from your library or take with your camera, uploaded to your trip's diary. The app asks for photo library or camera permission only when you use those features, and it only uploads the photos you pick.
Friend connectionsFriendsWho you've sent or accepted friend requests to or from, and which trips you've shared with whom.
BlocksBlocking someoneWho you've blocked, and when, so we can keep them away from you (see section 4).
ReportsReporting a trip, diary entry or personWhat you reported, why, and any details you add (see section 4).
Messages to usIf you email usTo answer you.
Waitlist emailThe site's waitlist formTo tell you when the app launches (see section 8).

Information collected automatically

What we don't collect

Stored only on your device

The app stores your sign-in tokens in the device's secure storage (iOS Keychain or Android Keystore), and keeps a copy of your quiz answers on the device so it can save them to your account after you sign up. Signing out removes them.

2. How we use your information

We use your information to:

  1. Provide the service: create your account, generate and store itineraries, show trips on a map, keep your diary, and let you connect and share with friends.
  2. Personalise itineraries using your interests, budget, pace and group type.
  3. Keep LocalSide secure and working: verify your email, reset passwords, limit abuse (for example, rate-limiting sign-in attempts), review reports and enforce our Terms, keep people you've blocked away from you, and find and fix bugs.
  4. Communicate with you about your account (verification and password-reset codes) and, if you've asked for it, about LocalSide updates.
  5. Meet legal obligations.

We don't sell your personal information, and we don't use it for targeted advertising. We don't use your trips, diary or photos to train AI models.

Legal bases (for users in the EEA, UK and similar jurisdictions): performance of our contract with you (items 1, 2 and account emails in 4), our legitimate interests in running a secure and reliable service (item 3), your consent (the waitlist and any optional marketing email, and photo and camera access, which you can withdraw at any time), and legal obligation (item 5).

3. Who processes your information for us

We use the following service providers ("processors"). They handle data on our instructions and are not allowed to use it for their own purposes.

ProviderWhat it does for LocalSideData involved
Amazon Web Services (Amazon Cognito)Accounts, sign-in, verification and password-reset emailsEmail, password (hashed by Cognito), user ID
Amazon Web Services (Amazon DynamoDB)DatabaseProfile, interests, preferences, trips, diary notes, friend connections, shares, blocks, reports
Amazon Web Services (Amazon S3)Photo storage. The bucket is private; photos are shown through links that expire after 6 hours.Diary photos (and profile photos, if that feature is added)
Amazon Web Services (AWS Lambda, Amazon API Gateway, Amazon CloudWatch)Running our servers, and loggingEverything the app sends to our API, and logs
Amazon Web Services (Amazon Location Service)Looking up the places you type, and placing itinerary stops on the map. Place data comes from Esri.The text of place searches, and the addresses of itinerary activities
Amazon Web Services (Amazon Bedrock), running Anthropic Claude modelsGenerating itinerariesSee "What we send to the AI" below
Sentry (Functional Software, Inc.)Error and crash reportingDiagnostics, as described in section 1
Apple Maps (iOS) / Google Maps (Android)Drawing the map in the appYour device requests map images from Apple or Google directly, which reveals the map area you're viewing and your device's IP address to them. Their own privacy policies apply.
Google WorkspaceOur emailEmails you send us
[Waitlist email provider, CONFIRM]Storing waitlist sign-ups and sending the launch emailWaitlist email address

Our AWS resources are in the United States (the us-east-1 region).

What we send to the AI

When you ask LocalSide to plan a trip (or retry one), our server sends a Claude model on Amazon Bedrock a prompt that contains only:

It does not include your name, email, user ID, diary notes, photos, or other trips. The model's reply (the itinerary) is saved to your trip. Under AWS's terms for Amazon Bedrock, prompts and responses are not used to train the models and are not shared with the model provider. [CONFIRM: counsel to check this against the current AWS Service Terms. Bedrock model-invocation logging must stay off, or this section needs updating.]

4. Sharing with other LocalSide users

Your trips are private by default. What other people can see:

We don't otherwise disclose your information, except (a) to comply with law, a court order or a valid legal request, (b) to protect the rights, safety or property of our users, the public or LocalSide, or (c) as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to your information.

5. How long we keep your information

DataHow long
Account, profile, interests, preferences, trips, diary entries, photos, friend connectionsUntil you delete them or delete your account
BlocksUntil you unblock the person, or either of you deletes your account
Reports12 months after the report is made, then deleted automatically. A report is kept for that time even if you or the person you reported deletes their account, so a report can't be erased by deleting the account it's about.
A deleted tripRemoved immediately, with its diary entries, photos, and shares
Database backupsOur databases keep continuous point-in-time backups for 35 days, so deleted data is permanently gone from backups within 35 days
Photo storage[CONFIRM: whether the S3 bucket has versioning on. If it does, state how long old versions are kept.]
Server logs30 days
Error reports (Sentry)[CONFIRM: 90 days is Sentry's usual retention; confirm for our plan.]
Waitlist emailsUntil the launch email has been sent plus [6 months], or until you unsubscribe or ask us to delete it
Emails with usAs long as needed to handle your request, then [2 years]

6. Deleting your account

You can delete your account at any time in the app: Profile, then Delete Account. Deletion is permanent and removes:

What isn't removed at once: copies in database backups (gone within 35 days), server logs and error reports (kept for the periods in section 5), reports you made or that were made about your content (kept for 12 months from when they were made, see section 5), and emails you've sent us. If you can't access the app, email privacy@localsidetravel.com from the address on your account and we'll delete it for you.

7. Your rights and choices

Depending on where you live, you may have the right to:

To make a request, email privacy@localsidetravel.com. We may need to verify that the account is yours, and we'll reply within the time the law requires (usually 30 days, or 45 days under the CCPA). If you're in the EEA or the UK, you can also complain to your local data protection authority.

California residents: we don't sell or share personal information for cross-context behavioural advertising, and we don't use sensitive personal information to infer characteristics about you. The categories we collect are listed in section 1, the purposes in section 2, and the categories of recipients in section 3.

8. The website and waitlist

The site is a static page with no cookies, analytics or trackers. If you join the waitlist, we store your email address so we can tell you when the app launches. We won't use it for anything else unless you agree. Every email we send has an unsubscribe link, or you can email privacy@localsidetravel.com. Our web host keeps standard server access logs (IP address, time, page requested) for security. [CONFIRM: host and log retention once hosting is chosen.]

9. Children

LocalSide is only for people aged 18 or over. We don't knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, email privacy@localsidetravel.com and we'll delete it.

10. Security

Data travels between the app and our servers over HTTPS. Sign-in tokens are kept in the device's secure storage. Our database and photo storage are encrypted at rest by AWS, photos are only reachable through links that expire after 6 hours, and every API request apart from sign-up and sign-in has to carry a valid sign-in token. No system is perfectly secure. If we learn of a breach that affects your information, we'll notify you and the authorities as the law requires.

11. International transfers

We're based in [Country] and store data in the United States. If you use LocalSide from elsewhere, your information will be transferred to the United States. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses in our providers' data processing terms. [CONFIRM with counsel.]

12. Changes to this policy

If we change this policy, we'll update the "Last updated" date. If the changes are significant, we'll tell you in the app or by email before they take effect.

13. Contact

[Company legal name]
[Registered address]
Email: privacy@localsidetravel.com
[EU/UK representative, if required: name and address]