Voyage

Voyage privacy policy

Effective date: 1 October 2026.

About this policy

Voyage helps you plan and manage trips, bookings and travel information. This policy explains how the iOS private beta handles that information.

Voyage's developer is Jack Wachter, based in Australia. For privacy questions, access or correction requests, or complaints, contact jack_wachter@icloud.com.

Information you choose to add

Voyage stores information you enter or select, such as:

You decide how much information to enter. Information about other travellers or people should only be added or shared when you have permission to do so.

Do not add passports, passport numbers, primary identity-document scans, account passwords or payment-card details. Allowed travel documents, such as visas or insurance papers, may still contain sensitive information: only add what you need. Voyage's warning is not an automatic detector or guarantee that prohibited information cannot be added.

How Voyage uses information

Voyage uses your information to display and organise your trips, show your schedule and costs, open your chosen documents, maintain your travel history, provide selected reminders and support enabled cloud sync and invitations.

The beta uses the iCloud account signed into your device. It does not ask you to create a separate Voyage password or give Voyage your Apple Account password. Account-related identifiers help separate workspaces and verify cloud access.

The beta has no advertising or added third-party tracking or analytics SDK. Voyage does not connect to your email inbox or automatically read booking apps.

On-device storage and selected files

Voyage keeps an account-scoped database and copies of chosen files in its app storage on your device. Selecting a photo or file does not give Voyage access to your entire library. Voyage uses the items you choose through the system picker.

New image imports are processed on-device to validate the file, optimise storage where appropriate and remove unnecessary image metadata. Compression is not guaranteed to make every image smaller. PDFs are validated and retain their document contents rather than being flattened into images. Where document extraction is used, it is processed on-device and suggested fields should be checked before you save them; it is not a reliable replacement for reviewing a booking confirmation.

Your source image or PDF remains in Photos, Files or its original location. Deleting Voyage's copy does not delete that source.

Saved app data and documents may be included in your device backups according to your Apple settings. Temporary processing files and disposable cloud caches are excluded from device backup. Device backup and Voyage cloud sync are separate features; neither should be treated as a guaranteed backup of every ticket.

Cloud sync and trip sharing

When you enable cloud sync for a trip, its structured itinerary, route, bookings, traveller information and costs are sent to Apple's CloudKit service for storage and sync within your private iCloud account. CloudKit also handles account and sharing information needed to identify records and their permitted participants.

Sharing a trip gives invited and accepted participants access according to the permissions granted by the owner. Viewers can read the shared trip; editors can also change its information. Shared core information can include booking references, notes, addresses and costs. A viewer invitation is not an automatically redacted, inspiration-only version of your trip.

Booking screenshots and PDFs use separate, optional document sharing. The owner must choose to include booking documents and grant access. Only eligible owner-added booking files are uploaded through that sharing feature. Personal Trip Documents, activity files, editor-local originals, import source files and Globe memory images are not automatically included in a trip invitation.

The owner can change permissions and withdraw access. Cloud access changes need an iCloud connection. Booking-document withdrawal is separate from core-trip removal and may wait for the owner to reconnect. Removing access cannot recall screenshots, exported files or copies another person has already saved, and it does not guarantee immediate removal from an offline device.

The developer does not receive your private trip content as part of ordinary support contact. Information you voluntarily send in support or TestFlight feedback is different and may be visible to the developer.

Maps, weather and other services

Online providers receive technical connection information, such as your IP address, when requests reach their services. Apple's services and any external services you choose operate under their own terms and privacy policies. Their processing may occur outside Australia; Voyage does not promise Australia-only storage or name unverified processing countries.

The privacy-policy webpage is hosted separately by Cloudflare Pages. Visiting that page sends ordinary web request information, including your IP address, to Cloudflare. The page itself has no added analytics, external fonts, forms or tracking scripts. Hosting the policy does not send your Voyage trips or saved documents to Cloudflare.

Notifications and beta feedback

If you allow notifications, Voyage can schedule booking-related reminders. Your iOS settings control permission and Lock Screen visibility. Notifications are not a guarantee that a payment or booking deadline will be noticed.

Apple's TestFlight service can provide the developer with beta testing, diagnostic and crash information and feedback you submit. This may include tester contact information, device/build details and screenshots or comments. Do not include real tickets, sensitive documents or private booking details in feedback unless necessary and knowingly chosen. Emailing support shares your email address, message and any attachments with the developer and email providers.

Support emails and copies of beta feedback downloaded by the developer are kept until 90 days after this private beta ends, then deleted unless needed to resolve an outstanding issue. In that case they are retained until the issue is resolved, then deleted. Apple controls the retention of information within TestFlight. This support-record policy does not set an expiry date for your saved trips or documents.

Security

Voyage uses iOS Data Protection for saved files and Apple's CloudKit security and encrypted record fields for relevant cloud content. The dedicated Trip Documents section requires device-owner authentication and is hidden in the app-switcher when appropriate. Booking attachments remain accessible through their booking screens; they do not all have the same additional biometric gate.

These protections reduce risk but cannot guarantee that information will never be lost, accessed improperly or disclosed. Beta sharing, offline behaviour and device transitions are still being tested. Keep important original tickets and confirmations somewhere independent of Voyage.

Retention, deletion and your choices

You can edit or remove trips, bookings, attachments and travel-history entries using the available controls. Deletion of synced content needs a connection to reach iCloud and other devices. Leaving a shared trip does not delete the owner's trip. Uninstalling the app should not be treated as a request to delete cloud data. Device backups and copies held by other participants may remain separately.

Voyage retains ordinary saved content while it remains in your workspace. Incomplete booking-import candidates and their temporary sources expire after 30 days; abandoned trip drafts expire after 180 days. Confirmed unreferenced attachment files have a 24-hour cleanup safety window. Some cleanup runs when the app next opens rather than precisely at the expiry time.

Sync queues, recovery copies and minimal deletion/access markers can remain to complete pending operations, prevent deleted content from returning or recover from interrupted changes. There is currently no general automatic expiry period for sync recovery copies. Deleting a record is therefore not a promise that every recovery, backup or participant copy is erased immediately.

You can decline cloud sync, avoid sharing, limit what you attach, manage device notification permissions and contact the developer with privacy questions. Some features require iCloud or a network connection and may not work without them.

Access, correction and privacy complaints

Use the app's controls to view, correct or remove the information available in your workspace. Contact the address above if you need help or want to raise a privacy concern. Describe the issue without sending passwords or unnecessary documents. We may need limited information to verify a request, but will not ask for your Apple Account password. Support cannot necessarily retrieve private iCloud content or erase copies held by another traveller.

Jack reviews privacy requests and complaints received at the contact email and aims to respond within 30 days. A response may ask for clarification, explain available app controls or describe the outcome and any further steps. If more time is needed, we will explain why. If you are dissatisfied, reply to request further review. This process does not limit any rights you may have to contact an applicable privacy regulator.

Changes to this policy

The policy will be updated when Voyage's practices change. The published version will show its effective date. Changes to account providers, storage, analytics or document sharing will be reflected in an updated policy.