Privacy
Privacy Policy
Last updated: July 22, 2026
Summary
Peaceful Journey is designed as a local-first travel planning app. The app uses personal travel data only to provide planning, active-trip assistance, memories, receipts, safety context, and user-requested sharing features.
We do not sell personal data. We do not use data to track users across other companies' apps or websites.
Travel Plans And Local App Data
The app may store travel plans, itinerary items, destinations, notes, diary or travelogue content, receipts, expenses, and attached files created by the user. The product is designed to keep core travel data local-first.
Peaceful Journey does not use personal reservation numbers, raw calendar text, payment information, or exact lodging addresses as server-side owned assets. If a user chooses an export or sharing workflow, only the selected content is handled for that workflow.
Location
Location may be used when the user allows it for active-trip context, destination relevance, arrival or reminder support, nearby search, weather relevance, and hazard relevance. The app should avoid collecting exact location when a coarse or trip-context location is enough.
Photos, Camera, And Media
Photos, videos, camera captures, and photo metadata may be used when the user attaches media or asks the app to match trip memories. Large original media should stay outside CloudKit by default unless the user chooses a sharing or export flow.
Journey Lens Translation processes one rear-camera frame only after the user presses the shutter, recognizes text with Apple Vision, and uses Apple's on-device translation and user-approved language packs on supported iOS versions and language pairs. Translation frames and recognized or translated text are not automatically saved or uploaded to a Peaceful Journey server; the Photos flow is used only when the user explicitly chooses to save a photo.
Calendar
Calendar access may be used when the user imports booking events or adds trip plans to Apple Calendar. The app should avoid treating raw calendar text as a server asset. Users can control calendar permission in iOS Settings.
Microphone And Local Network
Local Guide Radio uses microphone and Local Network access only after a verified Pro user starts it on the same Wi-Fi and grants the relevant iOS permissions. It does not use hosted calling or store raw audio files.
Free or locked preview screens may explain why microphone or Local Network permission would be needed, but they should not start an active communication session by themselves.
CloudKit, App Groups, And Secure Storage
Core travel data is intended to work locally on the user's device. Some protected files may be stored in an encrypted secure vault inside the app container. App Groups may be used for app-owned shared storage needed by approved app components.
If CloudKit or iCloud sharing is enabled, selected user content may be synced or shared through Apple's iCloud infrastructure according to the user's iCloud settings and sharing choices.
Public Data And Airport Operation Context
Airport operation context may use official or public data sources, including public airport or government data where available. The app can display context and source links, but it does not rewrite a user's itinerary.
Public-data API keys, when required, are intended to be kept on a server or Worker rather than embedded in the app binary.
Weather, Hazard, And Disaster Context
The app may show weather or hazard context when supported by current source data and official source links. It is not a substitute for government warnings, emergency services, or local authority instructions. Users should follow official local guidance during emergencies.
Natural disaster and weather information should provide links to official sources where possible. The app should avoid language that promises live coverage or personal safety outcomes.
Agent Itinerary Import And Advisory Updates
Agent itinerary import is a user-supplied workflow: users may discuss a plan with an external Agent, then bring the decided Peaceful Journey JSON back into the app for validation and review.
The current release does not include Peaceful Journey-owned model-provider API usage, in-app model credits, or server-assisted advisory generation. Agent-assisted results remain external reference material that users must review before applying.
Agent-assisted results are reference material and should be reviewed by the user before being applied to a trip, wishlist, bulletin, checklist, or travel library item.
Purchases And IAP
Paid plans and in-app purchases are processed by Apple. We do not receive full payment card details from Apple. StoreKit entitlements may be used by the app to decide which paid features are available.
Starting Local Guide Radio requires a verified one-time Peaceful Journey Pro purchase entitlement. Safety controls such as stop, all-off, leave, and mute remain available during an active session and are not separately monetized.
Affiliate And Partner Links
The website or app may show clearly labeled affiliate, sponsored, or advertising links for travel services such as lodging, transport, events, or local experiences. Booking, payment, refund, cancellation, availability, taxes, and fees are handled by the partner website and its policies.
Some labeled links may pass through go.peacefuljourney.app for campaign validation and redirect handling. The early redirect design avoids user IDs, exact GPS, sensitive profiles, receipts, photos, contacts, calendar data, passport data, payment card data, and full itinerary text.
Read the Affiliate And Advertising Disclosure for details.
Retention And Deletion
User-created app data remains until the user deletes it, removes the app, or uses an available export/delete workflow. Data synced through iCloud may also be controlled through the user's Apple ID and iCloud settings.
Peaceful Journey server ledgers are limited to purchase entitlement checks, app-account-token hashes, feature usage counters, and privacy-safe request keys. They do not store trip titles, reservation text, receipt bodies, passenger names, or private itinerary notes.
When a verified deletion request is processed, app-account-token-scoped entitlement and usage ledger rows are deleted or anonymized within 30 days unless a longer period is legally required for purchase, refund, dispute, abuse, security, or tax records. Managed backups or point-in-time recovery may retain deleted rows until the backup window expires.
Peaceful Journey Pro is a one-time in-app purchase processed by Apple. Deleting server records does not cancel the App Store purchase entitlement or its device restore history.
Contact
For privacy questions or deletion requests, contact [email protected].