Русский

Privacy Policy

Travel Chronicle · updated September 28, 2026

In short. The app works without an account. Trips are stored on your device without automatic cloud sync. Publishing sends your selected content. Creating a route with the built-in AI sends your planning form through our server to the DeepSeek AI, only when you press “Create with AI”.

What is stored on your device

Routes, days, activities, budgets, wallets, photos, documents, notes, mood and impressions are stored locally in the device's browser storage (IndexedDB). The developer has no access to them and cannot read them.

Deleting the app deletes this data permanently. You can make your own backup via “More → Export / backup”.

Creating a route with AI

There are two ways to create a route.

Your own AI. The app builds the request; you transfer it to any AI yourself and bring the answer back. Nothing is sent automatically.

Built-in AI. Before sending, the app asks for your consent; without it the form is not sent anywhere. You can withdraw consent in the app: “More → About”. If the data sent or the provider changes, the app will ask for consent again.

After you consent and press “Create with AI”, the app sends everything filled in the form to the Travel Chronicle server in Russia (Saint Petersburg), which passes it to the DeepSeek AI (DeepSeek, People’s Republic of China) to build the route: destination, dates and cities, budget and currency, travellers and transport, arrival and departure (dates, times, places), hotels (names, addresses, check-in dates and times), must-see places, “already booked” and your notes. Documents, photos, expenses and other saved trips are not sent. Do not enter passport or booking numbers, payment details or health information in the form.

Our server does not write the form or the AI’s answer to disk or to logs. So that a dropped connection does not trigger a second generation, the answer is kept in the server’s memory for up to 10 minutes and then discarded.

To enforce the free limit (a few routes per day and per 7 days), each request carries the app identifier from your device — a random string created by the app. It is the same identifier used when publishing routes, so it links AI requests with this device’s publications; it is not anonymous. The server keeps it with the request times for up to 8 days, and a keyed hash of the IP address for up to 2 days. The IP address itself is not stored. These records are not included in the server’s backups.

We do not control how DeepSeek processes and stores the requests it receives; see the DeepSeek privacy policy. Parsing the answer and saving the trip take place on your device.

What is sent to the publication server

Only when you explicitly publish a route. In that case the server receives:

EXIF metadata, including capture coordinates, is stripped from photos before they are sent.

Published content is stored on the Travel Chronicle server in Russia (Saint Petersburg) until you or a moderator delete it. After deletion, a publication may remain in the server’s nightly backups for up to 14 days and is then removed from them too. Reports are kept for up to 90 days (resolved ones for up to a year) and are included in those backups as well.

Private links never reach the server at all: the data is packed into the URL fragment after #, which browsers do not transmit to servers.

No accounts

No registration is required. Control over a publication is proven by a secret key stored on your device. You can back the keys up under “More → My publications → Publication keys”. Without the key, control cannot be restored — not even by the developer.

Map and geocoding

When you publish a guide, the city names and street addresses you typed into the route may be sent to a geocoding provider configured by us, in order to place them on the map. This happens on your device at the moment of publishing, and only for the places contained in that guide.

The app never reads your device location. There is no GPS permission and no background location. The places on the map are the ones you typed yourself.

Map tiles are loaded from the configured map provider when you view a guide, so displaying the map requires a network connection. Guide text and photos you have already opened remain readable offline; the map background does not.

Reporting identifier

When you report a guide, a random identifier is created once on your device and sent with the report. It is not linked to your identity, is separate from the publisher identifier, and exists only so that repeated reports from the same device can be recognised. The server keeps it in a de-duplication record for up to 24 hours.

Analytics and advertising

No third-party behavioral analytics, no trackers, no advertising, no profiling. The service keeps only an aggregate per-publication view counter. It is not tied to a reader's identity and stores no IP addresses.

Moderation and reports

Published routes are reviewed by hand before they become publicly visible. You can report content from the app (the import screen for someone else's route) or from the guide page. Reports are reviewed as soon as we can. A report stores the reason, your comment and the contact you provide. The IP address itself is not stored: a pseudonymous truncated keyed hash is kept for 24 hours purely to limit spam and abuse. It is not used for advertising, profiling or tracking.

Children's data

The app is not directed at children under 13 and does not knowingly collect personal data from them.

Your rights

Contact

Questions, reports and deletion requests: alexeikazaku@yandex.com. We reply as soon as we can.