LocalSide Privacy Policy
Effective date: [Date of publication]
Last updated: [Date]
This policy explains what personal information LocalSide collects, why, who processes it for us, how long we keep it, and the choices you have. It covers the LocalSide mobile app for iOS and Android ("the app") and the website at https://www.localsidetravel.com ("the site").
LocalSide is operated by [Company legal name], [registered address] ("LocalSide", "we", "us"). For privacy questions, email privacy@localsidetravel.com.
The short version
- We collect what we need to run your account and your trips: your email, an optional name and bio, your travel interests, the trips you plan, and the diary notes and photos you add.
- To plan a trip with AI, we send your trip details and interests (not your name, email or photos) to an Anthropic Claude model through Amazon Bedrock.
- The app never asks for your device's location, and it has no ads, no advertising identifiers and no third-party analytics or tracking.
- Your trips are private until you share one with a friend you've accepted.
- You can delete your account in the app (Profile, then Delete Account), which deletes your data as described below.
1. Information we collect
Information you give us
| Data | When | Why |
|---|---|---|
| Email address | Sign-up | To create and secure your account, sign you in, send verification and password-reset codes, and let friends send you a friend request by email. |
| Password | Sign-up | To sign you in. It is handled by Amazon Cognito; we never see or store it ourselves. |
| Name and bio (optional) | Profile | Shown on your profile and to friends you've connected with. |
| Travel interests | Interest quiz | To personalise your itineraries (for example Coffee Shops, Local Gems, Thrifting). |
| Preferences | Profile | Your default budget and notification and email settings. |
| Trip content | Planning and editing trips | Destinations or start and end points, dates, budget, pace, solo or group, and the activities, times, places, costs and notes in each itinerary. |
| Diary entries | Travel Diary | The notes you write for each day of a trip. |
| Photos | Travel Diary | Photos you choose from your library or take with your camera, uploaded to your trip's diary. The app asks for photo library or camera permission only when you use those features, and it only uploads the photos you pick. |
| Friend connections | Friends | Who you've sent or accepted friend requests to or from, and which trips you've shared with whom. |
| Blocks | Blocking someone | Who you've blocked, and when, so we can keep them away from you (see section 4). |
| Reports | Reporting a trip, diary entry or person | What you reported, why, and any details you add (see section 4). |
| Messages to us | If you email us | To answer you. |
| Waitlist email | The site's waitlist form | To tell you when the app launches (see section 8). |
Information collected automatically
- Account identifier. Amazon Cognito assigns each account a random user ID, which we use to link your data to your account.
- Diagnostics. If the app or our servers hit an error, an error report is sent to Sentry (see section 3). Reports can include the error and stack trace, device model, operating system and app version, the screen or request involved, and recent app events such as screen changes and the addresses of recent requests to our API. Reports aren't linked to you: we don't attach your user ID, email or IP address, and performance tracing is off. Before a report leaves the app or our servers, we remove the query part of request addresses (such as the text of a place search), replace trip and user IDs in request addresses with a placeholder, remove email addresses and sign-in tokens from error messages, and don't include request bodies or the values of program variables. [CONFIRM: "Prevent storing IP addresses" is turned on in the Sentry project.]
- Server logs. Our servers write operational logs (for example, request errors and itinerary-generation progress, which can include trip IDs and place names) to Amazon CloudWatch. They're deleted after 30 days.
What we don't collect
- Device location. The app does not request or use your device's GPS or location. When you type a destination, the place name you type is looked up to show it on the map.
- Advertising identifiers, contacts, browsing history or health data.
- Analytics or tracking. The app contains no advertising or analytics SDKs, and we don't track you across other companies' apps or websites.
Stored only on your device
The app stores your sign-in tokens in the device's secure storage (iOS Keychain or Android Keystore), and keeps a copy of your quiz answers on the device so it can save them to your account after you sign up. Signing out removes them.
2. How we use your information
We use your information to:
- Provide the service: create your account, generate and store itineraries, show trips on a map, keep your diary, and let you connect and share with friends.
- Personalise itineraries using your interests, budget, pace and group type.
- Keep LocalSide secure and working: verify your email, reset passwords, limit abuse (for example, rate-limiting sign-in attempts), review reports and enforce our Terms, keep people you've blocked away from you, and find and fix bugs.
- Communicate with you about your account (verification and password-reset codes) and, if you've asked for it, about LocalSide updates.
- Meet legal obligations.
We don't sell your personal information, and we don't use it for targeted advertising. We don't use your trips, diary or photos to train AI models.
Legal bases (for users in the EEA, UK and similar jurisdictions): performance of our contract with you (items 1, 2 and account emails in 4), our legitimate interests in running a secure and reliable service (item 3), your consent (the waitlist and any optional marketing email, and photo and camera access, which you can withdraw at any time), and legal obligation (item 5).
3. Who processes your information for us
We use the following service providers ("processors"). They handle data on our instructions and are not allowed to use it for their own purposes.
| Provider | What it does for LocalSide | Data involved |
|---|---|---|
| Amazon Web Services (Amazon Cognito) | Accounts, sign-in, verification and password-reset emails | Email, password (hashed by Cognito), user ID |
| Amazon Web Services (Amazon DynamoDB) | Database | Profile, interests, preferences, trips, diary notes, friend connections, shares, blocks, reports |
| Amazon Web Services (Amazon S3) | Photo storage. The bucket is private; photos are shown through links that expire after 6 hours. | Diary photos (and profile photos, if that feature is added) |
| Amazon Web Services (AWS Lambda, Amazon API Gateway, Amazon CloudWatch) | Running our servers, and logging | Everything the app sends to our API, and logs |
| Amazon Web Services (Amazon Location Service) | Looking up the places you type, and placing itinerary stops on the map. Place data comes from Esri. | The text of place searches, and the addresses of itinerary activities |
| Amazon Web Services (Amazon Bedrock), running Anthropic Claude models | Generating itineraries | See "What we send to the AI" below |
| Sentry (Functional Software, Inc.) | Error and crash reporting | Diagnostics, as described in section 1 |
| Apple Maps (iOS) / Google Maps (Android) | Drawing the map in the app | Your device requests map images from Apple or Google directly, which reveals the map area you're viewing and your device's IP address to them. Their own privacy policies apply. |
| Google Workspace | Our email | Emails you send us |
| [Waitlist email provider, CONFIRM] | Storing waitlist sign-ups and sending the launch email | Waitlist email address |
Our AWS resources are in the United States (the us-east-1 region).
What we send to the AI
When you ask LocalSide to plan a trip (or retry one), our server sends a Claude model on Amazon Bedrock a prompt that contains only:
- the trip type (a single destination or a road trip) and the destination, or the start and end points, as you typed them
- the number of days, and the start and end dates if you set them
- whether you're travelling solo or in a group
- your budget and pace (1 to 5)
- your interests from the quiz
It does not include your name, email, user ID, diary notes, photos, or other trips. The model's reply (the itinerary) is saved to your trip. Under AWS's terms for Amazon Bedrock, prompts and responses are not used to train the models and are not shared with the model provider. [CONFIRM: counsel to check this against the current AWS Service Terms. Bedrock model-invocation logging must stay off, or this section needs updating.]
4. Sharing with other LocalSide users
Your trips are private by default. What other people can see:
- Friend requests. Anyone who knows your email address can send you a friend request. If someone sends you one, you can see their name, email address and profile photo (if set) in your requests, so you can decide. If you send one, you see only the email address you typed until the other person accepts: not their name, not their photo, and not whether that address has a LocalSide account. A request to an address with no account looks exactly the same as one to a real account. You can decline a request, or withdraw one you sent.
- Friends. Once a request has been accepted, you and that friend can see each other's name, email address and profile photo (if set).
- Shared trips. When you share a trip with a friend, they can view that trip's itinerary, and its diary notes and photos. They can't edit it. You can stop sharing a trip, or remove a friend, at any time, and their access ends straight away.
- Blocking. If you block someone, any friendship or pending request between you ends, trips either of you shared with the other stop being shared, and neither of you can send the other a friend request. They aren't told they've been blocked: a request they try to send looks sent to them but never reaches you. Only you can see who you've blocked, and you can unblock them at any time.
- Reports. You can report a trip, a diary entry or a person you can see in the app, if you think it breaks our Terms of Service. A report stores your user ID, what you reported (and whose it is), the reason you chose, any details you write, a copy of the reported text as you saw it (for example the diary note, or the trip's title), and when you made it. Photos are referenced, not copied. The person you report isn't told who reported them. We use reports only to review content and enforce our Terms, and we review each one within 24 hours.
We don't otherwise disclose your information, except (a) to comply with law, a court order or a valid legal request, (b) to protect the rights, safety or property of our users, the public or LocalSide, or (c) as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to your information.
5. How long we keep your information
| Data | How long |
|---|---|
| Account, profile, interests, preferences, trips, diary entries, photos, friend connections | Until you delete them or delete your account |
| Blocks | Until you unblock the person, or either of you deletes your account |
| Reports | 12 months after the report is made, then deleted automatically. A report is kept for that time even if you or the person you reported deletes their account, so a report can't be erased by deleting the account it's about. |
| A deleted trip | Removed immediately, with its diary entries, photos, and shares |
| Database backups | Our databases keep continuous point-in-time backups for 35 days, so deleted data is permanently gone from backups within 35 days |
| Photo storage | [CONFIRM: whether the S3 bucket has versioning on. If it does, state how long old versions are kept.] |
| Server logs | 30 days |
| Error reports (Sentry) | [CONFIRM: 90 days is Sentry's usual retention; confirm for our plan.] |
| Waitlist emails | Until the launch email has been sent plus [6 months], or until you unsubscribe or ask us to delete it |
| Emails with us | As long as needed to handle your request, then [2 years] |
6. Deleting your account
You can delete your account at any time in the app: Profile, then Delete Account. Deletion is permanent and removes:
- every trip you created, with each trip's diary entries, photo records and stored photo files, and the records of who each trip was shared with
- your profile photo files, if any
- your access to trips other people shared with you, and your name on those trips' share lists
- all your friend connections and pending requests, in both directions, including your access to friends' trips
- the people you've blocked, and any blocks other people made against your account
- your profile record (email, name, bio, interests, preferences)
- your sign-in account in Amazon Cognito, which is deleted last
What isn't removed at once: copies in database backups (gone within 35 days), server logs and error reports (kept for the periods in section 5), reports you made or that were made about your content (kept for 12 months from when they were made, see section 5), and emails you've sent us. If you can't access the app, email privacy@localsidetravel.com from the address on your account and we'll delete it for you.
7. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you and get a copy of it
- correct it (you can edit your name, bio, interests and preferences in the app)
- delete it (see section 6)
- export it in a portable format
- object to or restrict some processing
- withdraw consent where we rely on consent, for example by unsubscribing from the waitlist or turning off photo or camera access in your device settings
- not be discriminated against for exercising these rights
To make a request, email privacy@localsidetravel.com. We may need to verify that the account is yours, and we'll reply within the time the law requires (usually 30 days, or 45 days under the CCPA). If you're in the EEA or the UK, you can also complain to your local data protection authority.
California residents: we don't sell or share personal information for cross-context behavioural advertising, and we don't use sensitive personal information to infer characteristics about you. The categories we collect are listed in section 1, the purposes in section 2, and the categories of recipients in section 3.
8. The website and waitlist
The site is a static page with no cookies, analytics or trackers. If you join the waitlist, we store your email address so we can tell you when the app launches. We won't use it for anything else unless you agree. Every email we send has an unsubscribe link, or you can email privacy@localsidetravel.com. Our web host keeps standard server access logs (IP address, time, page requested) for security. [CONFIRM: host and log retention once hosting is chosen.]
9. Children
LocalSide is only for people aged 18 or over. We don't knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, email privacy@localsidetravel.com and we'll delete it.
10. Security
Data travels between the app and our servers over HTTPS. Sign-in tokens are kept in the device's secure storage. Our database and photo storage are encrypted at rest by AWS, photos are only reachable through links that expire after 6 hours, and every API request apart from sign-up and sign-in has to carry a valid sign-in token. No system is perfectly secure. If we learn of a breach that affects your information, we'll notify you and the authorities as the law requires.
11. International transfers
We're based in [Country] and store data in the United States. If you use LocalSide from elsewhere, your information will be transferred to the United States. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses in our providers' data processing terms. [CONFIRM with counsel.]
12. Changes to this policy
If we change this policy, we'll update the "Last updated" date. If the changes are significant, we'll tell you in the app or by email before they take effect.
13. Contact
[Company legal name]
[Registered address]
Email: privacy@localsidetravel.com
[EU/UK representative, if required: name and address]