Privacy
Privacy policy
What this website collects, why, who sees it, and how to make it go away.
Last updated
This policy covers both halves of Vromp, operated by Vromp LLC: the
website at vromp.app — the waiting list, the trip checkout at
/plan, the conversational trip-planning agent at /plan/chat, signing
in at /login, and the post-trip feedback survey — and the Vromp iPhone app, which is where your trip is delivered and where it runs while you drive.
The app collects things the website never does, above all your location, and it does so in the background while you’re on a trip. That has its own section below — start there if the app is what you came to read about.
What we collect, and why
Joining the waiting list
The signup form on our homepage asks for your email address (required), your name (optional), where you’d road-trip first (required, free text), a few travel-style checkboxes (optional), and whether you want an early trip or just to be on the list (required). We use this to tell you about Vromp and to understand what kind of trips people want. A hidden field also records how you found us, for our own attribution — it’s not shown to you and it doesn’t track you elsewhere.
Buying a trip
When you build a trip at /plan, we collect the tier you chose, your travel dates,
how many adults and children are traveling (a headcount for pricing and trip sizing — not
a child’s personal information), your starting city, the region you want to roam, and any
lodging preferences you type in. This goes to Stripe, our payment processor,
along with your email and account id, to run the checkout. We never see or store your card number — Stripe collects your payment details directly, on Stripe’s own checkout page.
Planning your trip in conversation
/plan/chat is the widest data collection on this site, and we want to be direct about
it rather than bury it in a generic clause. As you talk with the planning agent, it can record: household
composition (how many adults, children’s ages, whether anyone in your party is 65 or older),
pets and any special needs they have, accessibility needs (things like wheelchair use, use of a walker
or cane, limited fitness or a cardiac condition, pregnancy, sensitivity to noise or crowds, photosensitive
epilepsy, or hearing or vision impairment), dietary restrictions (vegetarian, vegan, gluten-free or
celiac, kosher, or halal), and trip preferences you type in your own words, which we keep verbatim.
It also records the practical shape of the trip: the kind of vehicle you’re driving, roughly what you want to spend, the occasion — if there is one — the part of the country you’re thinking about, how you want the route to run, and, if children are coming, what they’re interested in.
Some of that is sensitive by nature — a pregnancy, a cardiac condition, or an observed faith practice like keeping kosher or halal can be read from these fields even though we never label them that way. We collect it only because trip planning genuinely needs it — to route around stairs, plan realistic driving days, or pick restaurants that work for your party — and we don’t use it for anything else.
We never treat allergies as data, on purpose. The planning agent is instructed never to ask about allergies, and our system refuses to record one as a stored preference even if you volunteer it. This is a deliberate safety decision: we don’t want a trip recommendation to ever look like medical advice about what’s safe for you to eat, and we never screen stops for allergens.
Being precise about the limit of that promise, because it matters: if you type an allergy into the conversation, that sentence is still part of the transcript, and the transcript is stored and sent to the AI provider like everything else you typed. What we refuse to do is turn it into a field we act on. Don’t rely on telling us as a way of staying safe — check for yourself at every stop.
Because the planning agent runs on a third-party AI model, your conversation — including everything described above — is sent to Anthropic, the company whose model powers it. See “How we use AI to plan your trip” below.
We also send your trip request to a feasibility-checking service that tells the planning agent whether a trip like the one you’re describing can actually be built. That service runs on Fly.io. To be clear about what that includes: it is everything you told the planner about the trip itself — your starting point, dates, party size, and every preference you gave, including any accessibility needs, dietary restrictions, children’s ages, and pet needs. It does not include your name, your email address, or your payment details.
One clarification worth stating plainly: when you type a starting city or a region you want to roam, that’s text you typed — not your device’s location. This site does not request or read your device’s location; see “Location” below.
Signing in and creating an account
You can create a Vromp account with an email address and a password, or sign in with Apple. If you use a password, we never see it — it is handled and stored by our sign-in provider, not by us. If you sign in with Apple, Apple tells us the email address you chose to share; if you use Apple’s Hide My Email, what we receive is the relay address, not your real one. Creating an account sends you a confirmation email.
Telling us how your trip went
If you fill out the post-trip feedback survey, we keep your written responses, your per-stop ratings, and the name we had for you, alongside the trip they describe. The survey opens from a private link rather than a login, so you don’t sign in — but the record is not anonymous to us.
The survey also asks two consent questions: whether we may quote your words publicly, and whether we may call you to follow up. Both default to no, and we record your answer. We only quote or call if you said yes.
The Vromp iPhone app
The app is where a trip you bought actually happens. It needs to know when you arrive somewhere, because arriving is what unlocks the writing about each stop. That single mechanic is the reason it asks for the most sensitive permission we ask for anywhere.
Location, and why it’s the “Always” kind
Vromp asks for Always location access, not the while-you’re-using-it kind. We ask for it because the reveal has to fire while your phone is in your pocket and your maps app is on screen — if the app could only see your location while you were looking at it, arriving somewhere would do nothing until you happened to open Vromp.
You may also see the location prompt earlier than that, when you start planning a Detour. That one is a leftover from a feature we didn’t finish, and it asks for more than that screen needs. We’re removing it.
Being specific about what that means, because “Always” is a large thing to grant:
- While a trip day is running and you’re signed in, the app records your position roughly every 75 metres of travel. On a highway that’s a point every few seconds.
- This continues when the app is closed, and it survives you force-quitting the app or restarting your phone. That is deliberate — a trip that stops working because you swiped the app away would be a broken product.
- Between trips, we don’t record a trail. Recording starts when you start a day and stops when the day closes out or you abandon the trip. The app still reads your current location when you open the map, to centre it — that reading isn’t stored.
- If you’re not signed in, we don’t record the continuous trail. A sample drive still saves a single point at each milestone — starting the day, setting off, arriving, revealing, finishing — on your device only.
The app also asks for motion data. To be accurate about why: the location library we use reads it to decide how often to take a GPS reading, which is what keeps the battery cost reasonable. We don’t store it and we don’t send it anywhere.
Turning it off
You can change or withdraw location access at any time in iOS Settings → Privacy & Security → Location Services → Vromp, where you can move Vromp from “Always” to “While Using the App” or switch it off entirely. The app can’t do this for you — iOS deliberately gives apps no way to reduce their own access, so that switch is yours alone. Vromp’s own Settings screen has a Permissions row that takes you straight there. The same applies to notifications and motion.
It’s a real choice with a real consequence, and we’d rather say so plainly: the arrival reveals are the product, and without location the app can’t tell when you’ve arrived.
Where your location goes — and where it doesn’t
The trail itself never leaves your phone. The route line you see on your completed-trip map is drawn from data stored on the device. We hold no latitude or longitude for you on our servers — there is no column for one — and no analytics or advertising service receives your coordinates. Location-bearing fields are stripped out of crash reports before they’re sent.
What does reach our servers is a record of the stops you reached. When you arrive at a stop, reveal one, skip one, or drive past one, we save that — the stop, when it happened, and what the outcome was — tied to your account. It’s not a coordinate, but it is a list of places you’ve been, and we’d rather call it that than hide it under a technicality. One of those records is written without you doing anything: driving through a drive-past stop marks it seen a few seconds later.
Three related things also go to our servers. When you ask for a new trip or a Detour, the app sends the list of stops you’ve already visited — up to the 500 most recent — so we don’t send you somewhere twice. When you ask for a Detour, the starting point you type is saved with the request. And while a trip is running, the app keeps our servers updated on where you are in it — which day, which stop is next, whether the reveal has happened — so the trip survives you changing phones. That’s your position in the itinerary, not your position on the map.
Signing in, and notifications
You sign in with Apple or a link sent to your email. Signing in with Apple asks Apple for your name and email address; if you use Apple’s Hide My Email, what we get is the relay address rather than your real one. If you turn on notifications, we store a device token so we can send the ones your trip needs.
How the app protects what’s on your phone
Trip data and your sign-in session are stored in the app’s own private area, encrypted by iOS and readable only after you’ve unlocked your phone at least once since restarting it. That last part is deliberate rather than ideal: the app has to be able to notice you’ve arrived somewhere while your phone is locked in a cup holder, which rules out the strictest setting.
Who the app talks to
- Supabase — our database and sign-in provider, as on the website.
- Sentry — crash and error reporting. It receives crash reports, a trail of what you did in the app beforehand (including which things you tapped), and your device model and iOS version. Reports carry an identifier that is stable for your installation, so treat them as connected to you. Location-bearing fields are stripped, but we can’t promise an email address never appears inside an error message. There is currently no in-app switch to turn crash reporting off.
- OpenFreeMap — the map imagery. Any time a map is on screen, that service sees your IP address and which part of the world you’re looking at. This happens on the map you can see before signing in, too.
- Expo — delivers push notifications and checks for app updates each time you open the app, which means it sees your IP and which version you’re running.
- Apple — Sign in with Apple, and the delivery of push notifications.
- Google — two separate things. When you tap to navigate, the destination opens in Google Maps or Apple Maps, which means that app receives where you’re headed. And a component we use to detect whether you’re online checks a Google address periodically, which shows Google your IP.
No advertising, no tracking, no data brokers. The app contains no advertising or attribution SDK, doesn’t touch your device’s advertising identifier, and doesn’t track you across other companies’ apps or sites.
How long the app keeps things
Recorded trails stay on your phone until you remove them. There is no automatic expiry. You can clear them yourself with Clear road history in Settings, and signing out or deleting your account clears them too. Older trips drop off once the stored history grows past a fixed size.
Two things worth knowing about that button. “Clear road history” clears your recorded trails, but not the separate list of stops you’ve visited that the app keeps to avoid repeating them — that list clears when you sign out or delete your account. And the location library we use keeps its own short-lived working copy of recent readings on the device, which that button doesn’t reach either; it clears when you delete the app.
Deleting your account deletes it — the account, your trips, your visit records, and your planning conversations. The one exception is an account you share with another traveler, which can’t be deleted out from under them. The full detail is here.
How we use AI to plan your trip
The conversational planner at /plan/chat is built on a commercial API from Anthropic. Two things about that are worth separating, because they’re different promises:
- Training. Anthropic’s commercial terms state plainly that Anthropic may not train its models on data sent through this kind of API access. Your conversation is not used to make their models smarter.
- Retention. Separately from training, Anthropic holds onto what’s sent to and returned from its API for about 30 days under its standard commercial terms, after which it’s deleted on their end — except that content flagged for abuse review can be kept longer. That 30-day window is Anthropic’s retention of the raw exchange, separate from how long we keep your conversation in our own systems (see “How long we keep things” below).
We’d also rather over-disclose than under-disclose one more thing: if you start a planning conversation and don’t finish it — you decline every suggestion, or you just leave — we keep that conversation. We use abandoned and declined conversations, alongside completed ones, to review and improve how the planning agent works. We do not use them to contact you or to build an advertising profile.
Who we share data with
We use a small number of outside companies to run Vromp, and we don’t sell your information to anyone. Here’s everyone who receives data from the website, and what they get. The app talks to a partly different set, listed in the app section above — Sentry, OpenFreeMap and Expo are app-only.
Wherever we hand your information to one of these companies, we do it under terms that require them to protect it to the same standard we describe on this page, to use it only to do the job we’ve asked them to do, and not to use it for their own purposes.
- Stripe — processes payment, receives your email and trip details.
- Supabase — our database and sign-in provider. Everything described above that we store, we store with Supabase. It also sends the confirmation email when you create an account.
- Apple — only if you choose “Sign in with Apple.” Doing so sends you to Apple to authenticate, so Apple knows you signed in to Vromp. We never see your Apple password.
- Vercel — hosts this website and runs its serverless backend, and provides Vercel Analytics (see “Analytics” below).
- Anthropic — the AI provider behind the trip-planning conversation at
/plan/chat; see “How we use AI to plan your trip” above. - Fly.io — hosts the feasibility-checking service the planning agent calls; see above.
- Google Fonts — every page on this site loads typefaces from Google’s font servers. That means Google receives your IP address and browser user-agent on every page you visit here, whether or not you ever fill out a form. This is the one third party that sees something about every visitor, not just people who sign up or check out.
Every one of those companies only receives what it needs to do its job for us — payment processing, hosting, email delivery, or the specific AI/feasibility functions described above — and none of them is an advertising network or a data broker.
What Vromp does not do
- No advertising or data-broker trackers. There is no ad pixel, no remarketing tag, and no cross-site profiling on this site.
- Location is blocked, not just unused. This site sends a browser instruction (a Permissions-Policy header) that blocks any script on the page from requesting your device’s location, even if one tried to. We don’t know where you are unless you type a place name into a form.
- No card numbers touch our servers. Stripe’s checkout collects those directly.
- We don’t sell your personal information, and we don’t share it for cross-context behavioral advertising.
Analytics
On the app side there is no separate analytics service: the equivalent information — which screens you opened, which buttons you tapped — rides along with the crash-reporting tool described above, and there’s no way to switch it off separately.
On the website, we use Vercel Analytics to understand how people use it — which pages get visited, which buttons get clicked, roughly how far someone scrolled. It works from a fixed, closed list of named events (things like “pricing tier selected” or “checkout started”) carrying only interaction details — never your email, your name, or anything you typed in free text. It doesn’t use cookies and doesn’t fingerprint your device, which is also why this site doesn’t show you a cookie banner: there’s nothing here that requires one under current law.
What’s stored in your browser
Separately from anything sent to our servers, a few things live only in your own browser:
- Your sign-in session. If you create a web account, your session is kept in your browser’s local storage so you stay signed in between visits.
- Handbook reading progress. If you read our road-trip handbook, your browser remembers which chapter and page you left off on, so a “resume reading” banner can bring you back. This never leaves your device.
- An in-progress trip plan. While you’re using
/plan, the trip you’re configuring — and the price we quoted for it — is held in your browser’s temporary session storage so it survives a page reload, and is cleared once your trip is confirmed. - Identifiers that tie your visit together. While you’re planning, your browser also holds the id of your planning conversation and, after payment, a short-lived id used to hand your trip off to the app. Both are references to records described above, not new information about you.
None of this is shared with us unless the underlying action — signing in, checking out — sends it to our servers as part of that action.
Server logs and IP addresses
Like any website, our hosting provider keeps ordinary access logs — which pages were requested and from what IP address — and our own server-side code writes operational logs that can include an account identifier. These exist to run and debug the site, not to build a profile of you, and we don’t combine them with advertising data because we have none.
Children’s information
Vromp is not directed at children, and we don’t knowingly collect personal information from anyone under 13. Trip planning does record children’s ages and, if you tell us, what they’re interested in — but that is provided by the adult planning the trip, describing their own travel party so we can size and shape the trip. It is not collected from a child, and we don’t ask a child anything. If you believe a child has provided us with their own personal information directly, email us at the address below and we’ll remove it.
How long we keep things
Two different things, so we’ll separate them. On your phone, recorded trails are dropped oldest-trip-first once the stored history passes a fixed size, and you can clear them yourself at any time. On our servers, nothing expires on a schedule — including the record of stops you’ve visited. Deleting your account is what removes it.
We’ll say this plainly rather than dress it up: today, nothing on this site automatically expires your data. We keep waiting-list entries, trip and account records, planning conversations, and feedback until you ask us to delete them. That includes conversations from trips you never booked. We think an honest “we keep it until you ask us not to” is better than a specific-sounding number we don’t actually enforce in our systems — and we’d rather tell you that directly than publish a promise our code doesn’t keep.
See deleting your account for exactly what deletion removes, what stays behind and why, and how to ask us to erase everything the automatic path doesn’t reach.
Deletion and your choices
You can delete your account yourself from Settings in the app, or by emailing us. Deleting removes your personal details as described on our deletion page. You can also ask us, at any time, to stop processing your information, to correct something that’s wrong, or — if you gave us information through the waiting-list form or a planning conversation and never created an account — to delete that too. Email hi@vromp.app to ask for any of this, and see the deletion page for the full detail.
Security
We rely on established providers — Stripe for payment, Supabase for our database and authentication, Vercel for hosting — rather than running our own servers, specifically because they carry security certifications and practices we couldn’t match alone. Access to our database is protected by row-level security policies scoped to each signed-in user, our site is served entirely over encrypted HTTPS connections, and we never handle or store your card number ourselves. No system is unbreakable, and if something ever goes wrong, we’ll tell you.
California privacy rights
California’s Online Privacy Protection Act requires us to tell you how we handle do-not-track signals and cross-site data collection, and we extend the substance of California’s privacy rights to everyone who uses this site, regardless of where they live:
- Do Not Track and Global Privacy Control. This site does not respond differently to a Do Not Track or Global Privacy Control signal, because we don’t perform the kind of cross-site tracking those signals are designed to turn off — there is no advertising or data-broker script here for a signal to disable.
- Third parties across sites over time. The companies listed under “Who we share data with” each receive data to do a specific job for us — payment, hosting, email, AI, feasibility-checking, or fonts. To our knowledge, none of them uses what they receive from this site to build a profile of you across other, unrelated websites, and none of them is an advertising network.
- Your rights. You can see what we have about you, correct it, delete it, and be treated the same either way, regardless of which state you live in. We don’t sell personal information and we don’t share it for cross-context behavioral advertising. Reach us by deleting your account in the app or by emailing hi@vromp.app.
Changes to this policy
If we change what we collect or how we use it, we’ll update this page and change the “last updated” date above. We keep the history of this document, so if you need to see what it said on a particular date — for instance, the date you made a purchase — email us and we can find it.
Contact us
Questions about this policy, or a request about your data: email hi@vromp.app. This policy is published by Vromp LLC. See also our terms of service and refund policy.