Data Roam.io uses
Roam.io stores account and profile details such as your display name, optional username, profile picture, bio, home country, languages, travel pace, traveler types, interests, and traveler-discovery choice. Your sign-in email is held by Supabase Auth and is not copied into the public profiles table.
Trip data can include destinations, cities, dates, timezone, itinerary days, activities, tasks, task assignees and due dates, notes, booking links, confirmation values, collaboration roles, invitations, and trip history. People sharing a trip can see the content their role permits. Activity history keeps the display-name snapshot captured when an event occurred.
Traveler discovery and friends
Traveler discovery is optional and off by default. If you enable it, authenticated Roam.io users can find the display name and username you chose. Search does not expose your email, trips, location, credits, private profile details, or avatar to unrelated searchers.
Friend-request participants and accepted friends can view each other’s selected profile picture through a temporary private link. A trip owner can select an accepted friend for a collaboration invitation; Roam.io resolves the recipient’s confirmed email only inside the protected invitation service and does not reveal it to the owner. The friend must still accept before receiving trip access. Friendship does not itself grant access to trips, and trip collaboration does not automatically create a friendship. Roam.io does not provide a public social feed or upload your contact book for matching.
Private messages and safety
Accepted friends can exchange private one-to-one text messages. Messages are stored and processed for conversation delivery and are visible only to their participants under application access controls. Roam.io does not offer public messages, contact syncing, or push-notification message previews in this phase, and does not claim that messages are end-to-end encrypted.
Blocking prevents new friendship requests and messages in both directions without changing shared trips. You may report a traveler or a received message for safety review. Reports are not visible to ordinary users, and report details are not included in Realtime broadcasts or application logs.
Photos, maps, and location
Optional trip covers are processed on your device and stored in a private Supabase Storage bucket. Signed links are temporary.
Geocoding runs only after an explicit foreground action. Roam.io can hand a place to an external maps app. Roam.io does not continuously track location and does not request background location tracking.
Preferences and device storage
Appearance, language, currency, time format, map choice, trip pace, dietary defaults, AI defaults, and notification preferences may be stored on your device. Roam.io Credits usage and completed generation history are stored with your account so the service can enforce daily limits and show your usage.
AI-assisted planning
Authenticated owners and editors may ask a server-side Edge Function for city or activity suggestions. The relevant trip context and the planning preferences you enter are sent to OpenAI to generate the requested draft. Do not include passport numbers, payment details, medical records, or other unnecessary sensitive information in AI prompts or trip notes. Suggestions are saved only after review and explicit acceptance.
Minimal operational audit rows can record the user, trip, action, model, status, request identifier, token counts, credit usage, web-search use, and safe error code. Prompts, generated drafts, preferences, notes, booking information, confirmations, exact addresses, tokens, sessions, and API keys are deliberately excluded from AI audit rows and shared activity metadata.
Sharing and service providers
Supabase provides authentication, database, private storage, Realtime updates, and Edge Functions. OpenAI processes AI planning requests. External geocoding and map applications process searches you explicitly request. A configured transactional email provider may deliver invitations and service messages.
These providers may process information in countries other than your own under their applicable contractual and legal safeguards. Row Level Security, private storage, and server-side authorization restrict access, but no system can promise absolute security or uninterrupted availability. Roam.io does not sell traveler profiles, friendship data, trip content, or contact information.
Retention and deletion
Account, profile, trip, friendship, collaboration, messaging, and preference data remains while needed to provide the service. Operational, abuse-prevention, security, and audit records are retained only for as long as reasonably needed for those purposes or as required by law. Deleting an owner account removes its owned trips and dependent content. Memberships in other owners’ trips, friend requests, accepted friendships, traveler blocks, read markers, and traveler-discovery profile data are removed with the account.
Removing a friendship does not delete previous messages; the conversation becomes read-only until friendship is restored. After account deletion, previously delivered messages may remain for the surviving participant, but the deleted sender’s name, username, email, and profile are removed and replaced with “Former traveler”. Safety reports may be retained with deleted-account identity minimized. Historical shared-trip events use the same Former traveler treatment. Private owned-trip covers are removed before deletion is finalized.
Your choices and requests
You can edit profile and preference information, opt out of traveler discovery, remove connections, leave shared trips where permitted, and delete your account from Settings. Contact the privacy address shown with this policy to request access, correction, deletion, or other rights available under applicable law. Roam.io may need to verify the request before acting on it.
Age and policy updates
Roam.io is not directed to children under 13, and you must meet the minimum age required to consent to online services in your country. Do not create an account if you cannot lawfully agree to these terms. Material privacy changes will be reflected by updating the effective date and, when appropriate, providing an in-app notice.