Privacy policy
Last updated: 18 July 2026
1. Data controller
Dora Travels is developed by Elio Meriggi. For any privacy-related request: [email protected].
2. In short
- No ads, no selling of data, no behavioral analytics.
- The only diagnostics tool is Firebase Crashlytics (technical, anonymous crash reports).
- The app can be used without an account (guest mode): in that case all your data stays on your device.
- Your location is never stored on our servers.
- Your photos are never uploaded: scanning happens only on your device.
3. Guest mode
You can use Dora Travels without creating an account. In guest mode your data (saved countries, preferences, etc.) stays only on your device and we do not collect any personal data.
4. Account data
If you choose to create an account, we process:
- Authentication data: email address and name, provided at sign-up (email/password), via Sign in with Google or via Sign in with Apple (Apple may, at your choice, provide an "@privaterelay.appleid.com" relay email instead of yours).
- User identifier: a unique ID assigned by Firebase Authentication.
- Content you create, stored on Cloud Firestore in your personal space: saved and visited countries, trips, wishlists and related notes, and your important dates (recurrences such as birthday or anniversary).
This data is used solely to let you find your content on all your devices. Legal basis (GDPR): performance of the service you request.
5. Public social profile (optional)
The social features are opt-in: they are only activated if you create a public profile. The profile uses a pseudonym and contains only: username, nickname, city (optional), emoji and count of visited countries. It never contains your real name or your email.
If you use the social features we also process:
- Friend requests and friend lists (connections between public profiles).
- Collaborative trips: trips shared via an invite code are visible only to those who hold the code and take part in them.
A newly created profile is not searchable by others until you enable visibility yourself. Legal basis: consent (art. 6.1.a GDPR), revocable at any time by making your profile non-searchable or deleting it.
6. Error reports (Crashlytics)
Since version 1.0.8 we use Firebase Crashlytics to automatically receive crash reports and fix issues. A report contains technical data only: the error stack trace, device model, operating system and app version, and an installation identifier. It does not contain your identity, your email or your content. We do not use any other analytics tool.
Legal basis: our legitimate interest in keeping the app stable and secure (Art. 6(1)(f) GDPR). Reports are retained by Google for about 90 days and then deleted automatically. You can object to this processing by writing to us.
7. Location (Copilot only)
The Copilot may ask for permission to access your location, used only while you use the feature to show you:
- the weather (Open-Meteo);
- nearby places (OpenStreetMap/Overpass);
- nearby events (Ticketmaster Discovery: receives an approximate area via geohash, never your exact address);
- stories and trivia about your surroundings (Wikipedia/Wikimedia Foundation: receives coordinates to find nearby entries; CC BY-SA content);
- the name of the locality (system geocoding).
Your coordinates are sent to these services for the sole purpose of answering your request and are not stored on our servers. The permission is optional and can be revoked from your device settings. Legal basis: consent.
8. Photo scan (optional)
The "Import from photos" feature reads the GPS metadata of your photos to infer the countries you have visited. Everything happens exclusively on your device: no photo and no location is ever uploaded or transmitted. The permission is optional and revocable. Legal basis: consent.
9. Data stored only on your device
Some preferences stay local and never leave your device: tools grid layout, home city for flights, exchange-rate and flight-price caches, onboarding flags.
Important dates (Valentine's Day, birthday, anniversary, custom dates) stay on your device only in guest mode; if you have an account they are instead synced to your personal space on Cloud Firestore (see point 4), so you can find them on all your devices.
10. Flight prices
Indicative flight prices are downloaded from a file hosted on our Firebase hosting: the request does not send any personal data.
11. Partner links (affiliate)
The app contains links to partner sites and apps (e.g. Booking, Aviasales/Travelpayouts, Amazon, GetYourGuide). Opening one of these links takes you out of the app to the partner with an anonymous affiliate code (it serves to recognize that the visit comes from Dora Travels, not to identify you). From that moment the partner's privacy policy applies. We do not receive any personal data about you from partners.
12. Sharing
The sharing features (friend invites, collaborative trip codes) use the system share sheet: you choose who to share with and through which app; we neither see nor record the recipients.
13. Where your data is stored (providers)
We use Google Firebase (Authentication, Cloud Firestore, Crashlytics, Hosting), provided by Google Ireland Limited and Google LLC, as our infrastructure: account data and content are stored on Google servers, with encrypted transfers (HTTPS). For social sign-in, if you choose it, we use Google Sign-In or Sign in with Apple. The external services mentioned (Open-Meteo, OpenStreetMap/Overpass, Ticketmaster, Wikimedia, Viator) receive only the minimal data indicated above, at the time of the request; country and city images in the app are loaded from the Wikimedia, Pexels and Unsplash CDNs (which receive the device IP, with no profiling cookies). This website is served by Cloudflare, Inc. (see section 18).
13-bis. International transfers
Some providers (Google, Cloudflare, Ticketmaster, Wikimedia Foundation, Tripadvisor/Viator, Pexels, Unsplash) are based in the United States: transfers of data to the US take place on the basis of the EU-U.S. Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission, with additional security measures (encryption in transit).
13-ter. No profiling
We do not carry out any profiling or automated decision-making that produces legal effects concerning you (Art. 22 GDPR). Travel suggestions in the app are computed locally from the content you save.
14. Retention and erasure (right to be forgotten)
We keep your data for as long as you keep your account. You can delete your account at any time directly from the app (Settings → Delete account): this permanently erases the account and all associated data (content, public profile, friendships). Alternatively you can request erasure by writing to [email protected]: we will comply within 30 days.
15. Your rights (GDPR)
You can exercise your rights of access, rectification, erasure, portability, restriction and objection by deleting your account from the app or by writing to [email protected]. You also have the right to lodge a complaint with a supervisory authority (in Italy, the Garante per la protezione dei dati personali).
16. Children
The app is intended for users aged 14 and over (the digital consent age in Italy, art. 2-quinquies of the Italian Privacy Code) and does not knowingly collect data from children under 14.
17. Changes
Any changes to this policy will be posted at this address and reflected in-app, along with the date of the update.
18. The doratravels.app website
This section concerns the website (not the app):
- Newsletter: if you enter your email in the "Notify me" form and tick the consent box, the data controller (see section 1) uses it to notify you when the app launches and to send you Dora Travels news (infrequently, no spam). Legal basis: consent (art. 6.1.a GDPR), given via the unticked-by-default checkbox. The address is managed through Brevo (Sendinblue SAS, Paris, France), acting as a data processor under art. 28 GDPR, with data stored in the European Union. You can withdraw your consent at any time via the unsubscribe link in every email or by writing to us: the address is deleted. Addresses previously collected through the waitlist remain on Cloudflare infrastructure (Cloudflare, Inc.) until they are migrated or deleted at your request.
- IP addresses: to protect the form from abuse, the IP is used for an anti-spam count kept for a maximum of 2 hours, then deleted automatically (legal basis: legitimate interest in security).
- No tracking cookies: the site does not use tracking cookies, analytics or advertising.
- Images: the Explore pages — like the country and city cards in the app — load images from upload.wikimedia.org (Wikimedia Foundation), images.pexels.com (Pexels) and images.unsplash.com (Unsplash): your browser or the app sends your IP to these providers to download them; no profiling cookies; Wikimedia images are under Creative Commons licence, with attributions shown where required.
- Web app (/app): the web version of the app runs in your browser; if you use the Copilot it may ask for your location (browser permission, revocable) and calls external services directly — Open-Meteo (weather), OpenStreetMap/Overpass (nearby places), Wikipedia/Wikimedia (stories), Ticketmaster (events), Viator (nearby bookable activities, receives only an approximate area) — sending the coordinates needed for the response; these services receive your browser's IP; nothing is saved on our servers.