Last updated: 20 September 2026
Privacy Policy
Safara is a trip-planning app. This policy explains what we collect, why, and what we do not do. It covers the Safara mobile app and safara.dev.
The short version. We collect what the app needs to plan your trips and nothing else. We do not sell your data, we do not show ads, and we do not track you across other apps or websites.
Who we are
Safara is run by an individual developer. For any privacy question, or to ask for a copy of your data, email privacy@safara.dev.
What we collect
| What | Why |
|---|---|
| Email address and password | To create and secure your account. Passwords are stored hashed by our authentication provider — we never see them. |
| Username, and optionally a display name and profile photo | So other people on a shared trip know who you are. Your username is visible to anyone you share a trip with. |
| Your trips — destinations, dates, saved places, day plans, notes, and flight and hotel details you enter | This is the app. It is stored so your trips sync across your devices and to anyone you invite. |
| Travel details, if you choose to enter them: legal name, date of birth, Known Traveler Number, Redress number, passport number, country and expiry, and loyalty programme numbers | Entirely optional. Kept so you do not have to find them again when booking. See “Travel details” below. |
| Booking confirmation screenshots you choose to scan | Sent once to be read, then discarded. See “Scanning a confirmation” below. |
What we do not collect
- We never ask for, and never store, a Social Security Number or any national identity number of that kind.
- We do not collect your location. The app never asks for location permission.
- We do not collect your contacts.
- We have no advertising identifiers, no ad networks and no cross-app tracking.
Travel details
Travel details are optional, and the app works fully without them. They are stored so that only your own account can read them.
They are never shared automatically. On each trip you choose, field by field, what to share — and it is off by default. Someone you share with sees only the fields you picked, only on that trip. You can stop sharing at any time, and sharing ends automatically if you leave the trip.
Scanning a confirmation
If you scan a booking confirmation, the image is sent to Anthropic's Claude service to read the flight or hotel details out of it, and the results are put on the form for you to check before anything is saved.
The image is not stored by us — not on your device beyond your own photo library, and not on our server. It is held in memory only long enough to be read. Anthropic does not use data sent through their API to train their models.
The app is instructed to skip passenger names, loyalty numbers and payment details when reading your confirmation.
Photo library and camera
The app asks for photo library access so you can pick a profile picture or a confirmation screenshot, and for camera access so you can photograph a confirmation. Both are optional, are only used when you tap those buttons, and can be refused or revoked in your phone's settings without breaking the rest of the app.
Profile photos
If you upload a profile picture, it is stored in a way that makes it viewable by anyone who has its direct web address, so that it can load quickly for people on your trips. The address is not published or listed anywhere, and is not guessable in practice, but it is not access-controlled either. Please don't use a photo you would mind being seen. You can remove or replace it at any time in Account, and it is deleted with your account.
Shared trips
When you invite someone to a trip, they can see that trip's contents and the names of everyone on it. When you invite by email address, we send that person an email telling them you invited them. If you invite someone by their username, their email address is never revealed to you or to anyone else on the trip.
Who we share data with
We do not sell your data and we do not share it for advertising. We use these service providers to run the app:
| Provider | What it does |
|---|---|
| Supabase | Stores your account, trips and profile. Hosted in the United States. |
| Render | Runs our server. |
| Google (Places API) | Supplies place search results, details and photos. Searches are sent to Google without your account identity attached. |
| Anthropic (Claude) | Reads scanned confirmations and writes short place descriptions. Not used to train their models. |
| Resend | Sends account and invitation emails. |
We may also disclose data if we are legally required to.
How long we keep it
Your data is kept while your account exists. When you delete your account, your trips, profile, travel details and sharing settings are deleted. Trips you shared with other people are removed along with your account if you own them.
Deleting your account
You can delete your account at any time from inside the app: Account → Delete account. It is immediate and permanent. If you cannot get into the app, see this page.
Your rights
Depending on where you live, you may have the right to see, correct, export or delete the data we hold about you, and to object to how we use it. Most of this you can do yourself in the app. For anything else, email privacy@safara.dev and we will respond within 30 days.
Children
Safara is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has given us data, email us and we will delete it.
Security
All traffic is encrypted in transit with HTTPS. Access to your trips is enforced by the database itself, not only by the app, so another account cannot read your trips even if the app is tampered with. No system is perfectly secure, and we cannot guarantee absolute security.
Changes
If we change this policy in a way that matters, we will update the date at the top and tell you in the app.