Privacy policy
Last updated: June 10, 2026
Jettag is an iOS app that turns travel itineraries into a living travel companion. It is designed to work without an account, without an email address, and without tracking you. This policy explains what data is processed, where, and why — both in the app and on this website.
Data controller: Iván Cabezón (Madrid, Spain). Contact: privacy@jettag.app.
Summary
- Your trips are stored on your device and in your private iCloud. We cannot access them.
- There is no sign-up: no email, no password, no profile. The app uses an anonymous identity.
- The only content that leaves your device is the itinerary text you choose to process with AI.
- We don't sell data, show ads, or use advertising identifiers.
Data that stays on your device and in your iCloud
Trips, days, stops, reservations, and attachments (ticket PDFs, passes, etc.) are stored on your device and synced between your devices through your private iCloud account, under your Apple ID. This data never passes through our servers and we cannot read it. iCloud processing is governed by Apple's privacy policy.
- Location: with your permission (while using the app only), a single coordinate is captured when you add a stop on the go, to place it on the map. Location is never sent to our servers and is never tracked in the background.
- Calendar: with your permission, the app reads events around your trip dates to detect flights and suggest schedule adjustments. This happens on-device only.
- Photos: with your permission, only the date and location of your photos are accessed, to associate them with stops. Your photos never leave your device.
- Weather: to show forecasts, the coordinates of your stops are sent to Apple's WeatherKit service, with no personal data attached.
Data processed by our servers
We only process server-side what is strictly needed for three features:
1. AI itinerary processing
When you paste an itinerary and ask to process it, that text is sent to our backend, which forwards it to an AI provider (Anthropic or OpenAI) to turn it into a structured trip. The text is used solely for that purpose: under their commercial terms, these providers do not use data sent via API to train their models. Processing job records are kept only as long as needed to complete the job and resolve errors, then deleted.
Legal basis: performance of the service you request (Art. 6(1)(b) GDPR).
2. Anonymous identity and abuse prevention
The app creates an anonymous identity (a random identifier — no email, no name) so it can handle your processing requests. We also use Apple's App Attest to verify that requests come from a legitimate copy of the app, which generates an anonymous cryptographic identifier per install. None of these identifiers reveal who you are.
Legal basis: legitimate interest in protecting the service from abuse (Art. 6(1)(f) GDPR).
3. Push notifications
To notify you when your itinerary is ready, we store your device's Apple push notification (APNs) token along with your language and app version. The token contains no personal data and is used only to send you app-related notifications.
Legal basis: performance of the service you request (Art. 6(1)(b) GDPR).
Analytics
We use TelemetryDeck, an EU-based anonymous analytics service, to understand how the app is used (for example, which screens are opened). No trip content, stop names, addresses, files, or any identifier that could reveal your identity is ever sent.
Website waitlist
If you join the beta waitlist on this website, we store your email for the sole purpose of letting you know when the beta opens and when the app launches. We don't use it for newsletters or share it with third parties, and we delete it once it's no longer needed. You can request deletion at any time by writing to privacy@jettag.app.
Processors and international transfers
We work with these providers as data processors:
- Supabase — backend infrastructure (anonymous identity, processing jobs, push tokens, waitlist).
- Anthropic / OpenAI — processing of the itinerary text you submit.
- Apple — iCloud, push notifications, and WeatherKit.
- TelemetryDeck — anonymous analytics (EU).
- Cloudflare — hosting of this website.
Some of these providers are based in the United States. Where international data transfers occur, they are covered by the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
What we don't do
- We don't sell or rent data.
- We don't show ads or use advertising identifiers (IDFA).
- We don't track your location in real time or in the background.
- We don't store your trip content on our servers.
- We don't process payment data — the app has no purchases.
Retention
Server-side data (anonymous identity, push tokens, processing records) is kept while you use the app or for as long as needed for the purpose described, and deleted afterwards. Data on your device and in your iCloud is under your control: it is removed when you delete your trips, or uninstall the app and clear the iCloud container.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction, and portability by writing to privacy@jettag.app. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your local supervisory authority. Note that most of your data (your trips) lives only on your device and in your iCloud, where we have no access and cannot intervene.
Children
Jettag is not directed at children under 14, and we do not knowingly collect data from children.
Changes to this policy
If we change this policy, we will publish the updated version on this page with its date. If the change is material, we will give notice inside the app.