Privacy Policy
Where Tickets ยท Effective 4 October 2026
Where Tickets is built so that we cannot read your travel documents or the names of the people you travel with. That is not a promise about our intentions โ it is how the app is built. Your documents are encrypted on your phone, with keys that never leave your devices in readable form.
Who we are
Where Tickets is developed by Alexander Shleyko, the data controller for the purposes of the GDPR. You can reach us at privacy@wheretickets.app.
What the app does
You add tickets and bookings โ a PDF, a photo, a screenshot โ and the app organises them into a trip: flights, trains, accommodation, in order. Your trips sync between your own devices, and you can share a trip with the people you are travelling with.
What we cannot see
The following are encrypted on your device before they are sent anywhere, and we hold only unreadable ciphertext:
- Your uploaded documents โ tickets, boarding passes, hotel and apartment bookings.
- The names of travellers, including your travel companions.
- Document file names, trip names, and any notes or free text you write.
The keys that decrypt this material are held on your devices. We store them only in a form sealed to your own keys, which we cannot open. If you lose all your devices and your recovery code, we cannot recover this data for you โ nobody can.
What the service does hold
- Your account. Sign-in is handled by Amazon Cognito. We hold the email address you sign in with (or the one your Google account provides) and an opaque account identifier.
- Non-personal trip structure. So the app can assemble a route, the service holds cities, dates and times, prices, booking references, and document types in readable form. It does not hold who is travelling โ travellers are represented by tokens that are meaningless without your device's key.
- Encrypted document contents and sealed keys, as above.
- Your plan. How many documents you have added against your free allowance, and, if you pay, which plan you hold and its status โ for example, when it renews or ends.
The one exception: reading a new document
When you add a document, it is read once so the app can work out what it is โ a flight, a hotel, which city, which date. For those few seconds the document passes through our service and through an AI provider (Anthropic) in readable form. It is then deleted: what remains is the encrypted copy and the non-personal details above.
This is inherent to reading a document automatically. We disclose it plainly rather than describing the app as fully zero-knowledge, because during that window it is not.
Crash reports
When the app or the service fails, a report is sent to Sentry so we can fix it. Those reports are deliberately stripped: they contain no traveller names, no document contents, no file names, no email address and no account identifier. A report carries a random identifier for the installation, which is not linked to you or your account and does not survive reinstalling the app.
One thing we cannot remove: Sentry derives an approximate location โ country, region and city โ from the network address the report arrives from, and does so after our own filtering has run. We have tested the available controls and none prevent it. If you are travelling when the app fails, that approximate location may reflect where you were.
Purchases
Your first documents are free; after that you can buy a plan for unlimited documents. Payments go through Google Play. We never see your card or other payment details โ Google handles them under its own privacy policy.
To show the plans, process purchases and restore them, the Android app uses a purchase service, Adapty. It connects when you sign in, whether or not you buy anything. Adapty receives:
- an anonymous account number โ a random number created for this purpose, not your email address or sign-in identifier;
- your purchases: which plan, when it was bought, and whether it is active, renewed, cancelled or refunded;
- when the screen with the plans is shown to you โ the app tells Adapty each time it opens it;
- basic technical details: your device model, its operating system version and the app version;
- your country, from your Google Play account and, approximately, from your connection.
Adapty never learns your name, your email address, your trips or your documents, and the app does not send it an advertising identifier. When you delete your account, its Adapty profile is deleted too.
Where your data is held
Trip data and encrypted documents are stored in Amazon Web Services in Stockholm,
Sweden (eu-north-1). Crash reports are stored on Sentry's European
infrastructure. The AI provider that reads a newly added document may process it
outside the EU, and so may Adapty and Google Play for purchases.
Sharing a trip
When you share a trip, the people you invite can read that trip's documents and the traveller names in it โ they are given the key, by you. We are not given it. Sharing is free for everyone involved. Invites are one-time codes and can be declined or left.
What we never do
- We do not sell or rent your data to anyone.
- There is no advertising in the app, and no advertising identifiers are collected.
- We do not use analytics or tracking software to profile you.
- We do not read your email or connect to your inbox.
How long we keep things
Trips and documents are kept until you delete them or close your account. A deleted document's encrypted copy is removed from storage. Your plan and purchase records are kept until you close your account. Crash reports are retained for a limited period by Sentry and then deleted automatically.
Your rights and deleting your account
You can delete your account and everything in it yourself, from the app: open Account, tap Delete account, and confirm by typing your email address. It takes effect immediately and cannot be undone. The steps, and exactly what is deleted, are on our delete your account page.
Deleting your account also deletes its purchase records and its Adapty profile. It does not cancel a Google Play subscription: cancel it in Google Play first, or it will keep charging you.
If you have uninstalled the app or cannot sign in, write to privacy@wheretickets.app from the address you signed in with. We will delete the account and its data within 30 days.
Under the GDPR you may also request access to your data, its correction, and a copy of it in portable form. Because most of your content is encrypted with keys only you hold, what we can provide is the readable non-personal data described above, together with the ciphertext.
Children
Where Tickets is not directed at children under 13, and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects you, we will update this page and change the date at the top. Material changes will also be announced in the app.
Questions about any of this: privacy@wheretickets.app.