Privacy Policy
This notice explains what personal data Sybilla Travel collects, why, who we share it with and what you can do about it. It is written to be read, not to be survived.
1.Who is responsible
The data controller is [RAGIONE SOCIALE], with registered office at [INDIRIZZO COMPLETO], VAT number [P.IVA].
For any request about your data, write to [EMAIL PRIVACY]. We have not appointed a Data Protection Officer, as we are not required to.
2.What we collect and why
We only process what the Service needs in order to work. The table below is the complete picture.
| Data | Why | Legal basis |
|---|---|---|
| Name, email address and account identifier from your Google sign-in | To create your account, identify you and let others share projects with you | Performance of the contract |
| Your projects: places, notes, itineraries, icons, images you upload | To provide the core function of the Service and to sync your work across devices | Performance of the contract |
| Messages you send to the AI assistant | To generate the itineraries and answers you ask for | Performance of the contract |
| Searches for places and addresses | To find locations and calculate routes on the map | Performance of the contract |
| Plan, credit balance and credit history | To apply your plan limits and keep an accurate record of consumption | Performance of the contract |
| Date of your last access, technical logs | To keep the Service secure, diagnose faults and prevent abuse | Our legitimate interest in a working, secure service |
| Record of your consent: date, document version, IP address, browser | To prove that consent was given or withdrawn, as the law requires us to | Legal obligation |
| Your email address, if you opt in to marketing | To send you product news and offers | Your consent — optional, revocable at any time |
Only marketing is based on consent. Everything else is what the Service needs to exist. Turning marketing off — or never turning it on — changes nothing about your account, your plan or the features available to you.
3.The AI assistant and your content
When you use the assistant, the text of your request and the relevant parts of your project are sent to a third-party language model provider, which processes them on our behalf in order to produce the answer. This provider is located outside the European Union; see section 5 for how that transfer is protected.
We do not use the content of your projects or conversations to train AI models, and our provider is contractually bound not to do so either.
4.Places, maps and location
Sybilla Travel does not track your device location in the background. Addresses and place names you search for are sent to our mapping provider to be resolved into coordinates and routes.
Bear in mind that the places you save can say a lot about you — where you go, when, and with whom. Treat a project as you would a travel diary, and think twice before sharing a link to one publicly.
5.Who else processes your data
We rely on a small number of providers, each acting as a processor on our instructions and bound by a data processing agreement. Where data leaves the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses.
| Provider | What it handles | Where |
|---|---|---|
| Google (Firebase Authentication) | Sign-in and account identity | EU / United States |
| Cloudflare | Hosting, application database, content delivery | EU / global network |
| Cloudinary | Storage and delivery of the images you upload | EU / United States |
| MapTiler | Map tiles, address lookup and routing | EU / Switzerland |
| [NOME PROVIDER LLM] | Generation of itineraries and assistant replies | Outside the EU |
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes. We may disclose data where the law requires it, or to establish or defend a legal claim.
6.How long we keep it
- Account and projects — for as long as your account exists.
- After you delete your account — your projects, images, conversations and itineraries are removed. A short technical grace period may apply before deletion becomes final, so that an accidental or unauthorised deletion can be undone.
- Consent records — kept after deletion for as long as needed to demonstrate that consent was validly obtained or withdrawn.
- Accounting and tax records — kept for the period required by Italian law, currently ten years, where a payment took place.
- Security logs — kept for a limited period, then deleted.
Where we must keep a record but no longer need to identify you, we remove or anonymise the personal data it contains.
7.Your rights
Under the GDPR you can ask us to:
- Access the personal data we hold about you, and receive a copy;
- Correct data that is inaccurate or incomplete;
- Delete your data, by closing your account or by asking us;
- Restrict or object to processing based on our legitimate interest;
- Receive your data in a portable, machine-readable format;
- Withdraw consent to marketing at any time, without giving a reason and without any consequence for your account.
Marketing: one switch, no questions. Open your profile, go to Privacy & legal and turn off email marketing. It takes effect immediately. Withdrawing consent does not affect the lawfulness of what we sent before.
To exercise any of these rights, write to [EMAIL PRIVACY]. We will reply within one month. If you believe we have mishandled your data, you can lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or with the authority of the country where you live.
8.Cookies and local storage
Sybilla Travel does not use advertising or analytics cookies, and does not profile you.
We store data on your device only to make the Service work: your sign-in session, so you are not asked to log in on every visit, and a local copy of your projects, so the map keeps working when the connection drops. This is strictly necessary for a service you asked for, which is why you are not shown a cookie banner. Clearing your browser storage removes it and signs you out.
9.Security
Data is transmitted over encrypted connections and stored on infrastructure operated by the providers listed above. Access to production data is limited to the people who need it to operate the Service. No system is perfectly secure: if a breach occurs that is likely to put your rights at risk, we will inform you and the supervisory authority as required by law.
10.Children
The Service is not intended for children under 14. We do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.
11.Changes to this notice
We may update this notice, for example when we add a feature or change provider. Every version has its own date and remains available at a permanent address.
If a change is significant — a new purpose, a new category of recipient — we will tell you inside the app or by email before it takes effect. If a new purpose requires your consent, we will ask for it separately and specifically: silence is never taken as agreement.