Privacy Policy
Last updated: August 5, 2026
Who is responsible for your data
The data controller for the purposes of the UK/EU General Data Protection Regulation is:
Vaylume UG (haftungsbeschränkt)
[Registered address — to be completed on registration]
Registered at [register court], HRB [number]
Managing Director: Christian Zakhour
Email: legal@vaylume.app
We have not appointed a Data Protection Officer. Article 37 GDPR requires one only where an organisation carries out large-scale systematic monitoring or large-scale processing of special-category data; Vaylume does neither. Data-protection enquiries go to the address above.
Introduction
Vaylume ("Vaylume," "we," "us," or "our") operates the Vaylume mobile application (the "App"), a social trip-planning and travel-companion marketplace that lets people create, browse, and join group trips, chat with fellow travelers, and coordinate safely while traveling together.
This Privacy Policy explains what information we collect when you use the App, why we collect it, how long we keep it, who we share it with, and the choices and rights you have. By using Vaylume, you agree to the practices described in this policy. If you don't agree with something here, please don't use the App, and feel free to reach out to us at the contact info below — we're happy to talk it through.
Vaylume has a minimum age of 13, and anyone aged 13–15 may only use it under a linked parent or legal guardian. We do not knowingly collect information from anyone under 13. See "Children's Privacy and Young People" below.
Information We Collect
Account Information
When you create a Vaylume account, we collect basic profile information such as your name, email address, phone number (if provided), date of birth (to determine which age tier applies to you — see "Children's Privacy and Young People"), profile photo, and any bio or travel-preference details you choose to add. We use Firebase Authentication to manage sign-in, so we may also receive authentication identifiers from that service.
Trip Listings and Content
If you create a trip listing as a host, we collect the listing details you provide — destination, dates, description, price, photos, and similar information. This content is visible to other users browsing or joining trips, as intended.
Chat Messages
Vaylume includes in-app messaging so travelers on the same trip can coordinate. Messages you send are stored so they can be delivered and displayed to the people in that conversation, and so conversation history is available if you reopen the app. We use Firebase Cloud Messaging to deliver push notifications for new messages and other activity.
Photos and Media
Photos you upload — to a trip listing, your profile, or a chat — are stored so they can be displayed within the App.
Ratings and Reviews
After a trip, users may leave ratings and written reviews of hosts and travel companions. These are stored and displayed as part of the relevant profile or listing to help build trust in the community.
Location Information — "Companion Radar"
Vaylume includes an optional feature called Companion Radar that lets you share your real-time, precise (GPS-level) location with the other travelers on a specific trip, for the purpose of coordinating meetups and helping everyone stay aware of the group's whereabouts during that trip.
Some important points about this feature:
- It is off by default. We do not collect or share your precise location unless you actively turn Companion Radar on for a given trip.
- It's scoped to your travel companions on that trip only. Your live location is visible only to the other members of that specific trip, never to the general public or to unrelated Vaylume users.
- You can turn it off at any time. When you disable Companion Radar, we stop collecting your live location and it stops being shared with your companions going forward.
- We don't use it for advertising, analytics, or tracking your movements outside of trip coordination. Location data collected through Companion Radar is used solely for the in-app safety and coordination feature itself — not sold, not shared with advertisers, and not used to build a profile of your movements over time.
- Aside from Companion Radar, we may also collect coarse, approximate location (such as the country or city your device indicates) for basic functionality like showing relevant trips or displaying the correct currency — this is separate from precise GPS tracking and does not require Companion Radar to be enabled.
Payment Information
Vaylume does not process payments or hold funds. Payment for a trip happens directly between a host and their travelers, outside the app, using whatever method they agree on together — Vaylume never collects, stores, or has access to any of it.
Device and Usage Information
We do not track how you use the app. There is no usage analytics, no record of which screens you visit, no advertising identifier, and no profile built from your behaviour. This is a deliberate choice, not an oversight: the only statistics we need are things like how many trips go to a given city, and we count those from the trips themselves — never from your device.
What does reach us automatically is the minimum any app needs to function: your IP address, which is unavoidable in any internet connection, and your device and app version when something goes wrong badly enough to send an error. Crash reports are switched off unless you turn them on, and you can turn them off again at any time.
How We Use Your Information
We use the information above to:
- Create and secure your account, and verify you meet our age requirement
- Operate core features: trip listings, group chat, push notifications, ratings, and Companion Radar
- Detect and prevent fraud, abuse, and violations of our Terms of Service or Community Guidelines
- Respond to support requests and communicate with you about your account or trips
- Improve app performance, fix bugs, and develop new features
- Send you important service notices (for example, changes to this policy or to a trip you've booked)
- Compile aggregate, non-identifying business statistics — for example, how many trips included a given destination or venue — to understand demand and inform our own marketing and business decisions
We do not use your data for third-party advertising, and we do not sell your personal information to anyone. The aggregate statistics described above never identify an individual traveler and are used only for our own business purposes — we do not provide them, or any other user data, to advertising networks or ad-targeting platforms.
Our Legal Bases for Using Your Information
European data protection law requires us to have a specific legal reason for every use of your information, and to tell you what it is. This table is that. Where we rely on "legitimate interests", we also have to tell you what those interests are — so we have written them out rather than using the phrase on its own.
| What we do | Our legal basis | Why |
|---|---|---|
| Create and run your account; publish your trips; deliver your messages | Contract Art. 6(1)(b) GDPR |
You asked us to provide this service. We cannot provide it without this information |
| Collect your date of birth and enforce our minimum age | Legal obligation Art. 6(1)(c) GDPR |
We are required to keep children off an adult service, and to act when we learn someone is underage |
| Automatically check every uploaded photo before it is published | Legitimate interests Art. 6(1)(f) GDPR |
Keeping the service safe and lawful for everyone, and preventing illegal imagery reaching other users. See "Automated Checking of Photos" below |
| Record moderation decisions — a removed message, a suspended account — and keep that record | Legal obligation and legitimate interests Art. 6(1)(c), 6(1)(f) |
We must be able to explain a decision to the person affected, show that we moderate consistently, and recognise repeat behaviour |
| Calculate trust scores, ratings and trip counts | Legitimate interests Art. 6(1)(f) GDPR |
Travellers meet strangers through this app. Reputation signals are how they judge who to travel with |
| Compile aggregate statistics — how many trips went to a destination or venue | Legitimate interests Art. 6(1)(f), read with Art. 5(1)(b) |
Understanding demand, and deciding where to grow. Art. 5(1)(b) treats further processing for statistical purposes as compatible with the purpose we originally collected the data for. The result contains no names and identifies nobody |
| Share your location with your trip companions | Consent Art. 6(1)(a) GDPR |
Off unless you switch it on, and you can switch it off at any moment. Withdrawing costs you nothing else |
| Send crash reports when something goes wrong | Consent Art. 6(1)(a) GDPR and § 25 TDDDG |
Off unless you switch it on. The app works identically either way |
| Keep financial and transaction records | Legal obligation Art. 6(1)(c) GDPR |
German tax and accounting law (§ 147 AO, § 257 HGB) requires it, and overrides a deletion request for those records specifically |
Where we rely on consent, you may withdraw it at any time, and withdrawing is as easy as giving it — a single switch in Settings. Withdrawing does not affect anything we lawfully did beforehand.
Your right to object — please read this one.
Where we use your information on the basis of our legitimate interests — the rows above marked as such, including our aggregate statistics — you have the right to object at any time, on grounds relating to your particular situation (Article 21 GDPR). You do not have to justify it beyond that, and it costs you nothing.
If you object, we will stop that processing unless we can show compelling legitimate grounds that override your interests, or we need it to establish, exercise or defend legal claims. In practice, for our business statistics, we will simply exclude you.
To object, email support@vaylume.app with the subject "Objection to processing". We are required to tell you about this right separately and clearly, rather than burying it in a list — which is why it has its own box.
How Long We Keep Your Information
We retain your account information, trip listings, chat messages, photos, and reviews for as long as your account is active, since they're part of the ongoing service (for example, past trip history and reviews remain useful and visible to the community). If you delete your account, we delete or anonymize your personal information within a reasonable period afterward, except where we're required or permitted to retain certain records longer — for example:
- Records required by financial regulations or tax law may be retained accordingly, where applicable
- Content necessary to resolve an open dispute, complaint, or investigation may be retained until that matter is resolved
- Companion Radar location data is retained only for the duration needed to support the trip it was shared for, and is deleted on a rolling basis afterward — it is not kept as a long-term location history. In practice it is deleted automatically after 7 days without activity, even if you never switch sharing off
- Moderation records — a removed message, a suspended account, a report and how it was resolved — are kept for 12 months. We keep them so we can explain a decision to the person affected, show that we moderate consistently, and recognise repeat behaviour. Records connected to a child-safety matter are an exception and are not deleted on that schedule, because they may be evidence
- A photo that fails or never completes its safety check is deleted within 2 hours and is never published
Who We Share Your Information With
We share information only where it's necessary to operate the App, and never sell it. Specifically:
- Other users. Your profile, trip listings, photos, ratings/reviews, and chat messages are visible to other users as the App's core functionality intends. Precise location is visible only to companions on a trip where you've enabled Companion Radar.
- Firebase / Google. We use Firebase (Firestore database, Firebase Authentication, Firebase Cloud Messaging and, only if you switch it on, Firebase Crashlytics) as our backend infrastructure. Firebase, operated by Google, stores account data and app content and delivers push notifications on our behalf, under Google's own data-processing and security commitments. Your data is stored and processed in Frankfurt, Germany (
europe-west3). Firebase Analytics is disabled — we do not use it, and no usage-analytics data is collected. Nothing is used to build advertising profiles. - Google Cloud Vision. Every photo you upload is sent to Google Cloud Vision's SafeSearch service to be checked automatically for sexual or violent content before it is published. Google processes the image on our behalf as our processor, returns a classification, and does not use your photos to train its models or for any purpose of its own. See "Automated checking of photos" below.
- Reporting child sexual abuse material. Where we become aware that an image is child sexual abuse material — through a user report, or through the human review that any image our automated checks cannot resolve receives — we preserve it in a locked hold, suspend the account, and report it, together with the associated account information, to the competent authorities: as a German company primarily the Bundeskriminalamt (BKA), and to the National Center for Missing & Exploited Children (NCMEC) where a United States connection applies. To be precise about what our automated checking does and does not do: it detects sexual and violent content. It does not compare uploads against databases of known illegal material, which is a different technology that we do not currently use.
- Legal and safety reasons. We may disclose information if required by law, subpoena, or valid legal process, or where we believe in good faith it's necessary to protect the rights, safety, or property of Vaylume, our users, or the public (for example, investigating a safety report).
- Business transfers. If Vaylume is ever involved in a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction, subject to this policy or a materially equivalent one.
We do not share your information with advertising networks, data brokers, or analytics companies for their own marketing purposes.
Your Rights and Choices
Depending on where you live, you may have rights under laws like the GDPR (Europe) or the CCPA (California) — but regardless of location, we're happy to honor the following for all Vaylume users:
- Access — request a copy of the personal information we hold about you
- Correction — update or correct inaccurate information (most of this you can do directly in your profile settings)
- Deletion — request that we delete your account and associated personal information
- Export — request your data in a portable format
- Objection / restriction — object to or request that we limit certain processing of your data
How to exercise these rights: Email us at support@vaylume.app with your request, and we'll respond within a reasonable time (typically within 30 days). You can also handle the two most common requests directly from within the App, under Settings: Export My Data generates a copy of your data on the spot for you to save or share, and Delete Account initiates deletion of your account and personal data per this policy.
If you're an EU/EEA or UK resident and believe we haven't adequately addressed your concern, you also have the right to lodge a complaint with your local data protection authority.
Children's Privacy and Young People
Under 13. Vaylume is not available to anyone under 13, anywhere. We do not knowingly collect personal information from anyone under 13. If we become aware that we have, we delete it promptly and close the account. If you believe a child under 13 has provided us with information, contact us at support@vaylume.app and we will act on it.
13 to 15 — supervised accounts. People aged 13, 14 and 15 may use Vaylume only with a linked Guardian: a parent or legal guardian who holds their own account, is at least 18, and has verified their phone number. The Guardian provides consent for the young person's use of the Service and for the processing of their personal data, and must approve each individual trip they join. Where we rely on consent as our legal basis for processing a 13–15 year old's data, that consent is given or authorised by the Guardian, as required by Article 8 of the UK/EU GDPR. Because member states set this threshold anywhere between 13 and 16, we apply the Guardian requirement to everyone under 16 in every country, rather than varying it — this is at or above the local requirement everywhere.
A supervised account cannot create, change, or remove its own Guardian. A Guardian can end the link at any time, which makes the supervised account unusable until a new Guardian link is established.
What a Guardian can and cannot see. A Guardian sees the trips their young person has asked to join and can approve or decline each one, and can see that young person's live location during a trip if location sharing is enabled. A Guardian does not get access to their private messages.
Everyone under 18. Regardless of tier, for users we know to be under 18 we do not use profiling to recommend content, we do not serve advertising of any kind, and we do not use engagement techniques designed to extend time in the app. Location sharing is off by default for everyone.
Guardians' rights. A Guardian may exercise the rights described under "Your Rights and Choices" on behalf of the young person they supervise, including access, correction, and deletion. Contact support@vaylume.app.
Automated Checking of Photos
Every image you upload — a profile photo, a trip cover photo — is checked automatically before anyone can see it. This is how it works and what it means for your data:
- The image is private until it passes. When you upload, the file goes to a private holding area that no other user can access, and that you cannot share a link to. It is only published if the check passes.
- What the check looks for. Sexual content, graphic violence, files that are not really the image type they claim to be, and matches against known databases of child sexual abuse material.
- It is automated. No person at Vaylume looks at your photo as part of the normal check. A person only reviews an image if the automated result is inconclusive, or if it is reported.
- What we keep. If an image passes, the record of the check is deleted after 7 days. If it is refused, we keep the record for up to 180 days — it is the evidence behind a decision you may want to dispute. We do not keep a copy of a refused image except where the law requires preservation (see below).
- If it is refused, we tell you why, in plain language, in the app.
Legal basis. We do this on the basis of our legitimate interests (Article 6(1)(f) UK/EU GDPR) in keeping the Service safe and lawful for all users, particularly young people, and to comply with our legal obligations regarding child sexual abuse material. We consider this proportionate: it applies only to images you actively choose to upload for publication, it is automated, and the alternative — publishing unchecked content to other users, including minors — carries a far greater risk to others' rights.
Preservation and reporting. Where an image matches a known child sexual abuse database, we are legally required to preserve it and the associated account information, and to report it to the National Center for Missing & Exploited Children and, where applicable, other competent authorities. In that narrow case we retain the material for as long as the law requires (currently one year) and we do not delete it on request, as doing so would destroy evidence of a serious crime.
Security
We take reasonable technical and organizational measures to protect your information, including:
- Encryption in transit. Data sent between your device and our servers is encrypted using industry-standard TLS/HTTPS.
- Firebase Security Rules. Our database access is governed by rules that restrict what data a given user's app instance can read or write, so users can only access information they're authorized to see.
- App Check. We use Firebase App Check to help verify that requests to our backend come from genuine, unmodified copies of the Vaylume app, reducing the risk of abuse from bots or tampered clients.
- Access controls. Access to backend systems and user data is limited to what's needed to operate and support the App.
No system is 100% secure, and we can't guarantee absolute security, but we work to protect your information using practices consistent with standard industry approaches for an app of this kind.
International Data Transfers
Your data is stored and processed in Germany. Our database, our file storage and the servers that run our application code are all located in Frankfurt (europe-west3). The automated safety check on uploaded photos also runs on a European endpoint, so your photos do not leave the EU to be checked.
Our infrastructure provider, Google, is a company headquartered in the United States, so a limited transfer of data outside the EU can occur — for example when their support or engineering staff access systems to resolve a fault. Where that happens, it is covered by the EU–US Data Privacy Framework, the adequacy decision adopted by the European Commission in July 2023 under Article 45 GDPR, and additionally by the Standard Contractual Clauses in our data processing agreement with Google as a fallback safeguard under Article 46.
You may request a copy of the safeguards that apply by emailing legal@vaylume.app.
Changes to This Policy
We may update this Privacy Policy from time to time as our App evolves or as laws change. If we make material changes, we'll notify you through the App (such as an in-app notice) and/or by email before the changes take effect, and we'll update the "Last updated" date at the top of this page. Continuing to use Vaylume after changes take effect means you accept the updated policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, contact us at:
Vaylume UG (haftungsbeschränkt)
General: support@vaylume.app
Data protection and legal: legal@vaylume.app
Child safety: childsafety@vaylume.app
Website: vaylume.app
You also have the right to complain to a supervisory authority. In Germany that is the data-protection authority of the federal state in which we are established.