Privacy Policy
Roamers
Effective Date: September 15, 2026
Last Updated: September 15, 2026
Version: 2.1
What changed in version 2.1
- Complete list of companies that receive data (§4.2 to §4.4, §12). For each one we say what data it gets, why, on what legal basis, where it is processed, and whether it is in use today. New entries: Hetzner as our hosting provider, Apple's map, place-search and location-name services, Unsplash (group cover suggestions), Apple MapKit JS (the map on share pages), and the services we have built in but not switched on (Google sign-in, in-app purchases).
- Legal bases for each kind of processing (§2.1).
- Presence modes explained exactly (§3.2): "Pinned to town", "Visible to connections" and "Hidden", including what Hidden does not stop.
- Posts, stories and story views: other travelers now see only the day, not the time (§1.4, §4.1).
- Conversations: photos and other files in conversations are stored privately, and in-app live updates use private channels (§5).
- Account deletion now also removes files in your conversations (§7).
- Server logs and sign-in records are described as they actually work today, including where they fall short (§1.6, §6, §7).
What changed in version 2.0
Version 1.0 (February 2026) no longer matched the product. Version 2.0 (September 14, 2026) moved our infrastructure description to our self-hosted server in Germany, introduced town-level location for other travelers, stated that we run no analytics or advertising SDK, and described account deletion across all tables and storage.
Roamers is operated by Make it Nice GmbH.
Introduction
Welcome to Roamers ("we," "our," or "us"). Roamers is a mobile app that helps independent travelers find and meet other travelers safely, and keep a record of their own trips.
This Privacy Policy explains what data the Roamers app ("App") and its backend ("Services") collect, how we use it, who we share it with, and the choices and rights you have.
Contact information:
- Controller (Art. 4(7) GDPR): Make it Nice GmbH, An der Koppel 1, 53909 Zülpich, Germany, registered at Amtsgericht Bonn, HRB 28837, represented by Martin Förster (Geschäftsführer / managing director)
- Privacy email: hallo@makeitnice.de
- Data Protection Officer: none appointed. One is not required because fewer than 20 people regularly process personal data (§ 38 BDSG).
Table of Contents
- [Information We Collect](#1-information-we-collect)
- [How We Use Your Information](#2-how-we-use-your-information)
- [Location Data in Detail](#3-location-data-in-detail)
- [Who We Share Information With](#4-who-we-share-information-with)
- [Data Security](#5-data-security)
- [Data Retention](#6-data-retention)
- [Deleting Your Account](#7-deleting-your-account)
- [Your Rights (GDPR and Others)](#8-your-rights-gdpr-and-others)
- [Analytics and Crash Reporting](#9-analytics-and-crash-reporting)
- [Age Requirement](#10-age-requirement)
- [Wikivoyage and Third-Party Travel Content](#11-wikivoyage-and-third-party-travel-content)
- [International Data Transfers](#12-international-data-transfers)
- [Changes to This Policy](#13-changes-to-this-policy)
- [Contact Us](#14-contact-us)
1. Information We Collect
1.1 Account and sign-in
- Email address: used for sign-in, confirming your account, password reset, account and security notices, and account recovery.
- Password, if you sign up with email. Our authentication server stores it hashed, never in plain text.
- Sign in with Apple: we receive an account identifier from Apple and, if you choose to share them, your name and email address. Apple lets you hide your real email behind a relay address, and we support that.
- Google sign-in is not currently offered in the app. See §4.4.
- We do not offer sign-in with a phone number, and we don't send text messages.
1.2 Profile information
Fields you fill in on your profile, all editable and most optional: display name, bio, date of birth, gender, home country, languages, travel style tags, interests, profile photos, trip status, and (optionally) your Instagram handle.
- Date of birth is collected to enforce the minimum age (see §10) and to show your age to other travelers. Other users only ever receive a computed age. Only you can read your exact date of birth.
- Current town and country: while you share your location (§3.1), the app works out the name of your current town and country on your device and saves it to your profile. Who can see it is described in §3.2.
1.3 Location
Covered in detail in §3. In short: while the app is open, and your presence is not Hidden, your device sends your position to our server. If you turn on route recording for a trip, the app also records your route: while the app is open, and while it's closed only if you allow location access "Always". Other users never receive your exact coordinates, only a town-level position, and only if your settings allow it. The one exception is a time-limited Live share that you start yourself.
1.4 Content you create
- Messages you send in conversations with travelers you're connected with. Sending photos or voice messages is not available yet. When it is, those files are stored privately, and only the two people in the conversation can open them.
- Posts and stories, including their photos and an optional place label you pick. We store the post's location only as an area of about 5 km. Other travelers see the day a post or story was published, not the time. We keep the exact time privately so you can see it on your own posts, and it is deleted together with the post or story.
- Story views: when you view a story, we record that you viewed it and on which day (not the time). The author can see who viewed their story, except across a block.
- Hails: short broadcast posts visible to signed-in travelers nearby while they are open. A hail is placed at town level (about 5.5 km). Your exact position is never stored or shown. Hails are deleted automatically 7 days after they expire or you close them.
- Trip diary entries and check-ins, including photos and, if you tag an entry with a location, that entry's coordinates.
- Photos you upload to your profile, posts, stories, group covers, trip entries, POI reviews or POI photo submissions. Before a photo is uploaded, the app removes embedded location and camera metadata.
- Group posts, comments and guide content you write, and groups you create (including a cover image, see Unsplash in §4.3).
- POI suggestions and reviews you submit for places on the map.
- Likes, saved places and guides, follows, connections and blocks.
- Reports you file about other users or content, and the text you write in them. When you file a report, we keep a copy of the reported content (its text, its author and, for hails, the town-level location) so it can still be reviewed if the content is later deleted.
1.5 Emergency contacts
If you add an emergency contact (Settings → Safety), we store the name, phone number, relationship, and optionally an email address you provide for that contact. We use this only to let you start a live-location share with them from the SOS flow. Roamers never contacts them on your behalf, and we do not monitor the SOS flow (see §3.4 and the Terms of Service §7).
1.6 Device and technical information
- Push notification token (APNs device token), platform and app bundle ID, so we can deliver push notifications to your device. You can turn notifications off at any time in iOS Settings. We remove a token from our database once delivery to it keeps failing.
- Sign-in sessions: our authentication server stores the IP address and device/browser type of each active sign-in session, for account security, until you sign out or the session expires.
- Sign-in audit records: our authentication server records account events, such as sign-up, sign-in, email confirmation and password reset, with the time and the account's email address or identifier. See §6 and §7 for how long we keep them.
- Server logs: our servers write technical log entries for requests. Our API gateway's access log records the time, method, requested address without its query string, response status, size and duration — no IP address. Our authentication, file storage and live-update servers may still record IP addresses, user IDs and, for the authentication server, the device/browser type in their technical logs. We use these logs only to operate and secure the service, and they are deleted after 14 days (§6).
- People who open your share links: see §3.3.
1.7 What we do not collect
We do not run any advertising, analytics or tracking SDK (see §9). We do not access your device's Contacts app. We do not collect precise location for anything you haven't taken an action to enable: opening the app while your presence isn't Hidden, turning on route recording for a trip, tagging a check-in or diary entry, or starting a Live share.
2. How We Use Your Information
- Operate the core product: show your profile to other travelers (per your privacy settings), show nearby travelers on the map at town-level precision, enable hails, matching and messaging, record your trips, and let you follow guides and points of interest.
- Safety and moderation: enforce blocks, review reports, prevent spam and bulk collection (rate limits), and enforce our Terms of Service and minimum-age policy.
- Communications: account emails (confirmation, password reset, account and security notices) sent through our email provider (§4.2), and push notifications you've allowed. We do not currently send marketing email. If we ever add an opt-in digest, it will be clearly optional.
- Operate and secure the backend: prevent abuse, and debug and fix problems.
We do not sell your personal information, and we do not use your data for advertising.
2.1 Legal bases (Art. 6 GDPR)
| Processing | Legal basis |
|---|---|
| Your account, profile, matching, messaging, posts, stories, hails, groups, guides, trip diary, check-ins, maps, emergency contacts you add for yourself, and account emails | Performance of our contract with you, Art. 6(1)(b) |
| Location while the app is open | Art. 6(1)(b). Access to location on your device only with the iOS permission you grant (§ 25 TDDDG) |
| Route recording for a trip | Your consent, Art. 6(1)(a): you turn it on for a trip, and for recording while the app is closed you also allow the iOS "Always" location permission. You can withdraw it at any time by turning recording off or changing the permission in iOS Settings |
| Push notifications | Art. 6(1)(b). Only after you allow notifications in iOS (§ 25 TDDDG) |
| Age check from your date of birth | Art. 6(1)(b), and our legitimate interest in keeping minors off an adults-only app, Art. 6(1)(f) |
| Storing your emergency contacts' details | Legitimate interest (yours and your contact's) in your safety, Art. 6(1)(f) |
| Blocks, reports and the copy of reported content, rate limits, share-link view records, sign-in sessions and audit records, server logs | Legitimate interest in the safety of our users and the security of the service, Art. 6(1)(f) |
| Cover image suggestions from Unsplash when you tap "Suggest covers" while creating a group | Legitimate interest in making group creation easy, Art. 6(1)(f). Nothing is sent to Unsplash unless you ask, and you can pick your own photo instead |
| Keeping or disclosing data where the law requires it | Legal obligation, Art. 6(1)(c) |
Where we rely on legitimate interest, you can object (§8).
3. Location Data in Detail
Location is central to how Roamers works, so we describe what actually happens on our server, not just what the app shows.
3.1 How your location reaches us
- While the app is open with location permission granted, and your presence is not Hidden, your device sends your position to our server at most every few minutes, together with the name of your current town and country. We keep only your latest position on your profile, not a history. Depending on your settings, the app blurs the position on your device before it is sent.
- Route recording: if you turn on route recording for a trip, the app saves a point of your route about every 100 to 200 meters (fewer, town-level points if your iPhone only shares your approximate location). The points are stored on your device first and uploaded to our server with that trip when you're online. It records while the app is open and, only if you allow location access "Always", also while the app is closed; iOS then shows its location indicator. Recording stops when you end the trip, turn it off, sign out, or turn off location access. Only you can see your exact route. This is a history you choose to build, and it is kept until you delete the trip or your account.
- Check-ins and diary entries you tag with a location store that location with the entry.
- Live shares (§3.2) send your exact position while they are running.
To show town names, maps and place search results, the app uses Apple's location services, which receive coordinates or search terms from your device (§3.6).
3.2 What other users can see
Your presence setting (Settings → Privacy) controls who sees your town-level position in Nearby and the town and country on your profile:
- Pinned to town: signed-in travelers can see you in Nearby and see your town and country. They only ever receive your location coarsened to a grid cell of about 5.5 km. Our server computes that coarse point, and your exact coordinates are never sent to anyone else's app. Distances shown to others are also computed from the coarse point, in whole kilometers.
- Visible to connections: only travelers you're connected with see your town-level position and your town and country. This applies to accounts that haven't saved a choice yet. When you create your profile, you pick Pinned to town (preselected) or Hidden, and you can change it at any time.
- Hidden: you don't appear in Nearby, and no one else sees your town, country or past check-ins. Your app stops sending your current position to our server. Any open hails are closed, and you can't post new hails while Hidden.
What Hidden does not change:
- If route recording is on for a trip, it keeps recording your route for your own diary.
- Check-ins and diary entries you tag still store their location.
- A Live share you start still shows your exact position to the people who have the link, until it ends.
- Posts and stories you've already published keep their place label and area.
- Your last position stays on your profile, visible to no one else, until it is overwritten or your account is deleted.
In every mode:
- Live (time-limited): you can start a time-limited live location share and send the link to people you choose, for example family who don't use the app. This is the only situation in which your exact current location is shared: with anyone holding that link, for the duration you choose. You can end it at any time, and it also ends automatically. A Live share updates only while Roamers is open on your phone. When the app is closed it pauses, and people with the link see when your location was last updated.
- Blocked users never see your location, town or check-ins, in any mode.
- A location more than 72 hours old is treated as stale and isn't shown to anyone as "nearby".
- No other account can read your exact latitude and longitude, or your email address, through our API. Only you can read your own exact position, plus anyone holding an active Live share link until that share ends.
The location of a hail is snapped on our server to the same ~5.5 km grid before it is stored. Distances to hails are shown in whole kilometers.
3.3 "Follow my trip" links
You can create a "Follow my trip" web link that lets anyone who has it see your trip without the app. The link shows your route and current location only at town level (about 5 km), never your exact position. You choose what it includes: location only (the default), location plus your public and friends-visible diary entries, or everything, which adds your check-in names and notes and trip stats. Check-ins attached to a private diary entry are never shown. Every link expires: after 24 hours, 7 days (the default), 30 days, or 3 days after your trip ends (at most 30 days). You can revoke a link at any time, and it stops working immediately. If you widen what a link includes, we create a new link and the old one stops working. Links that no longer work, whether expired, revoked or replaced, all show the same message, so nobody can tell you stopped sharing with them. Once your trip ends, the page keeps showing your route and diary until the link expires, but no longer shows your current town or when you last updated. This is separate from the precise Live share in §3.2.
When someone opens a trip or live-location link, we record a keyed one-way hash of their IP address, their browser type and the time. This lets you see that the link was opened and helps us detect abuse. The hash and browser type are removed after 7 days. Trip-link view records are deleted after 30 days, and live-share view records after 7 days. The map on these pages is Apple MapKit JS (§4.3). When a page has a location to show, the viewer's browser loads the map and map images from Apple, which receives the viewer's IP address and the map area shown. Apart from Apple's map, the pages load no outside scripts, fonts or trackers.
3.4 Emergency / SOS
The SOS flow lets you call your local emergency number and start a live-location share with your saved emergency contacts. This is not monitored by Roamers. No one on our side sees or responds to an SOS action. It is a quicker way to reach the people and services you choose. See the Terms of Service §7 for the full safety disclaimer.
3.5 Trip diary and check-ins
If you tag a trip diary entry or check-in with a location, that coordinate is stored with the entry so it can be shown on your personal trip map. Other travelers never see the exact location, place names, notes, photos or times of your check-ins. Once a trip has ended, travelers who can see that trip may see the town, country and date of its check-ins, but never for check-ins from the last 24 hours. For public trips that is everyone; for friends-only trips, the people you're connected with. A connection starts when you accept someone's message request or they accept yours, and either of you can remove it at any time, which ends this access for both of you immediately. Check-ins that aren't part of a trip are only visible to you. None of this is shown if you are Hidden, if either of you has blocked the other, or if you are set to Visible to matches and haven't matched.
3.6 Apple's location and map services
The app uses Apple's built-in services on your iPhone to show maps, to turn your coordinates into a town and country name, and to search for places and cities when you check in or look at a place. To do this, iOS sends map areas, coordinates or your search text to Apple. Apple processes this under its own privacy policy; we don't receive anything from Apple about it beyond the result.
On-device AI place search (iOS 26 and later, where available) runs entirely on your iPhone and sends nothing to us or to Apple for that search.
4. Who We Share Information With
4.1 With other users
Depending on your privacy settings, other Roamers users may see your profile (name, photos, bio, interests, age), your town and country and town-level position (§3.2), your hails, and content you post (posts and stories with their place label and publishing day, group posts, comments, guides, reviews). Story authors see who viewed their story and on which day. You control this in Settings → Privacy.
Other travelers who can see your profile may also see summary statistics for trips that ended at least two days ago: number of trips, countries visited, and total distance rounded to the nearest 100 km. Profile lookups are rate-limited to prevent bulk collection.
4.2 Service providers who process data for us (processors, Art. 28 GDPR)
| Provider | Purpose | Data | Location and transfer safeguard | In use |
|---|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Hosts the server we run ourselves, with our database, authentication, file storage, live updates, server functions, server logs, and our website (legal pages and share pages) | All data described in §1 | Germany (EU) | Yes |
| Resend (Plus Five Five, Inc., San Francisco, USA) | Sending account emails: confirmation, password reset, account notices | Your email address, the content of the email (including one-time links), delivery metadata | Sent from Resend's EU region. The company is in the USA and may access data from there: EU-U.S. Data Privacy Framework certification and EU Standard Contractual Clauses | Yes |
We do not share data with any advertising network, data broker or analytics vendor.
4.3 Other companies that receive data when you use certain features
These companies decide for themselves how they process the data, under their own privacy policies (they are not our processors).
| Company | When | Data | Location | In use |
|---|---|---|---|---|
| Apple (Apple Distribution International Ltd., Ireland; Apple Inc., USA) | Sign in with Apple, if you use it | Your sign-in with Apple; we receive the account identifier and, if you share them, name and email | Apple Distribution International Ltd. (Ireland) is responsible for users in the EEA; Apple may process data in the USA under its own transfer safeguards | Yes, if you sign in with Apple |
| Apple, Apple Push Notification service | Push notifications you've allowed | Your device token and the notification's title, which names the person and the event (for example "Anna sent you a message"). Never message content | as above | Yes, if notifications are on |
| Apple, Maps, place search and location names (§3.6) | Showing maps, naming your town, searching places | Map areas, coordinates, search text, IP address | as above | Yes |
| Unsplash (Unsplash Inc.) | When you create a group and tap "Suggest covers" | The search term (group name and category), sent by our server, so the search doesn't give Unsplash your IP address. To prevent misuse we note that you searched (not what you searched for) and delete that note after 2 days. The suggested photos then load from Unsplash's servers, which gives Unsplash your IP address. When you pick one, our server tells Unsplash which photo was chosen, as Unsplash requires. If you keep the suggested cover, everyone who views the group loads it from Unsplash, which gives Unsplash their IP address | USA. See Unsplash's privacy policy | Yes, only when you ask for suggestions |
| Apple, MapKit JS | Map on "Follow my trip" and Live share web pages, when the page has a location to show | IP address and browser details of the person opening the page, and the map area shown (town level on trip links; the shared position during an active Live share) | as above | Yes, on share pages |
Links you tap: some screens link out, for example to a place's Wikivoyage article, a traveler's Instagram profile or Apple Maps. Opening them is an ordinary visit to that website or app, which then receives your IP address under its own privacy policy.
4.4 Built into the app but not switched on
We will update this policy before switching on any of these:
- Google sign-in (Google Ireland Ltd. / Google LLC): the sign-in library is part of the app, but the button isn't shown and the library isn't used. If we turn it on, Google will receive your Google sign-in, and we will receive your name and email address. Google's sign-in library may also collect device and usage data for Google's own purposes.
- In-app purchases (Apple App Store): there is no paid subscription today.
4.5 Legal requirements
We may disclose information when required by law: to respond to valid legal process, to protect our rights or the safety of our users, or to prevent fraud or an imminent risk to life.
4.6 Business transfers
If Roamers were ever acquired or its assets transferred, user data may transfer as part of that transaction. We would notify affected users of any such change.
5. Data Security
- Encryption in transit: all requests to our server use TLS (certificates from Let's Encrypt; no personal data goes to Let's Encrypt).
- Passwords: hashed by our authentication server, never stored or logged in plain text.
- Access control: our database uses row-level security, so a signed-in user can only read their own private data (exact location, email, date of birth). Other users receive only the coarsened or derived fields described above.
- Private conversations and live updates: in-app live updates (new messages, notifications, typing indicators) go over private channels that only the people in that conversation can join, never to someone you've blocked. Files in conversations are kept in private storage that only the two participants can open.
- Photo metadata: the app removes location and camera metadata from photos before uploading them.
- Infrastructure: our server runs on Hetzner in Germany. We do not currently keep separate off-server backups of the database. If that changes, we will update this section.
- Secrets: application credentials used by our server and app are rotated when we have reason to believe they were exposed, and are never checked into our source code repository.
5.1 Your security responsibilities
Use a strong, unique password; don't share your login credentials; sign out on shared devices; report suspicious activity to us.
5.2 Breach notification
If a data breach affects your personal information in a way that creates a risk to you, we will notify the relevant supervisory authority within the timeframes required by law (72 hours under GDPR). Where the risk to you is high, we will also notify you.
6. Data Retention
| Data type | Retention |
|---|---|
| Account and profile data | Until you delete your account |
| Current location and town | Overwritten on every update; not kept as a history. No longer shown as "nearby" after 72 hours without an update |
| Trip routes, diary and check-in locations | Until you delete the trip or entry, or your account. This is a history you build on purpose, unlike your current location |
| Live-location shares (including SOS shares) | Until they end (you choose the duration) or you stop them |
| "Follow my trip" links | Until they expire (24 hours, 7 days, 30 days, or 3 days after the trip ends, at most 30 days), or earlier if you revoke them or make the trip private |
| Fingerprints of links that no longer work (one-way hash of the link, not linked to you or your trip; link-open records store only this fingerprint) | 180 days, so old links can't be revived |
| Share-link view records (hashed IP, browser type, time) | Hash and browser type removed after 7 days; trip-link records deleted after 30 days, live-share records after 7 days |
| Messages, posts, stories, comments | Until you or we delete them, or until your account is deleted |
| Exact time of your posts and stories (visible only to you) | Deleted together with the post or story |
| Story views (who viewed, day) | Deleted together with the story or the viewer's account |
| In-app notifications (who did what, e.g. "Anna liked your post") | Deleted automatically 90 days after they were sent once you have read them, 180 days if unread, or earlier if you delete them or your account |
| Hails | Deleted automatically 7 days after they expire or are closed, or earlier if you delete them or your account |
| Rate-limit records (hail posting, notifications, profile lookups, photo lookups) | Deleted automatically after 2 hours to 8 days, depending on the record |
| Reports (including the copy of reported content) | Kept while the report is open or under review, and for 12 months after it has been resolved; then deleted automatically. This also applies after the reported content or either account has been deleted. A report is unlinked from a deleted reporter's account |
| Emergency contacts | Until you remove them or delete your account |
| Push notification tokens | Until the token stops working (we remove tokens that fail repeatedly) or you delete your account |
| Sign-in sessions (IP address, device type) | Until you sign out or the session expires, and at the latest when your account is deleted |
| Sign-in audit records (event, time, account email or identifier) | Deleted automatically after 90 days, and straight away when you delete your account (§7) |
| Server logs (time, requested address; IP addresses in authentication, storage and live-update logs) | Deleted automatically after 14 days |
| Deletion requests | Recorded with a timestamp for the period described in §7 |
7. Deleting Your Account
You can delete your account from within the app. Deleting your account:
- Permanently deletes your profile, content (messages, hails, posts, stories, comments, group posts, guides, reviews, check-ins, trip data, POI suggestions and photos), your connections and the conversations with them, story views, emergency contacts, notification preferences and privacy settings.
- Removes your uploaded files from every storage bucket we use: profile photos, trip photos, post and story images, group covers, guide images, POI photos and reviews, and all files in your conversations. Because the whole conversation is deleted, this includes files the other person sent in a conversation with you.
- Removes your authentication account and sign-in sessions.
- Does not delete safety reports. Reports you filed, and reports about you or your content, are unlinked from your account and kept, together with the copy of the reported content, for safety moderation until 12 months after the report was resolved (legitimate interest, Art. 6(1)(f), and Art. 17(3) GDPR).
- Deletes the sign-in audit records described in §1.6, including the record of the deletion itself. Entries in server logs are deleted automatically after 14 days (§6).
We aim to complete deletion within 30 days of a confirmed request, and immediately where technically possible. Once we run off-server backups (see §5), deleted data will age out of them on our normal backup rotation schedule.
Data export: self-service export in the app is not fully available yet. Until it is, email us at the privacy address in §14 and we will send you a copy of your data within 30 days.
8. Your Rights (GDPR and Others)
If you are in the European Union / EEA, you have the right to:
- Access: request a copy of your data.
- Rectification: correct inaccurate data (most fields can be edited directly in the app).
- Erasure: delete your account and data (§7).
- Restriction: ask us to limit processing in specific circumstances.
- Portability: receive your data in a portable format.
- Object: object to processing based on legitimate interest (§2.1).
- Withdraw consent: where processing is based on consent (e.g., route recording for a trip), withdraw it at any time by changing the permission in iOS Settings.
If you are in California or another place with a comparable law, you have similar rights (to know, to delete, and not to be discriminated against for using these rights). We do not sell personal information, so there is nothing to opt out of in that respect.
How to exercise your rights: use Settings → Privacy → Delete Account in the app, or email us at the address in §14. We will respond within 30 days, or sooner where required by law.
You also have the right to lodge a complaint with a data protection supervisory authority (§14).
9. Analytics and Crash Reporting
Roamers does not run any analytics or crash-reporting SDK. The only crash and usage data we see is what Apple provides through App Store Connect and TestFlight, and only if you have chosen in iOS Settings to share analytics with app developers (or, as a TestFlight tester, when you send feedback).
We plan to add:
- A privacy-first, EU-based analytics tool (planned: TelemetryDeck) for basic, non-tracking product usage metrics.
- A crash-reporting SDK (planned: Sentry) to catch and fix bugs faster.
- Apple's built-in MetricKit for on-device performance data.
None of these track you across apps or companies for advertising. We will update this policy and our App Store privacy label before any of them ships, not after.
10. Age Requirement
Roamers is for adults only. You must be 18 years of age or older to create an account. We ask for your date of birth at sign-up and enforce the minimum age there. We do not knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we will delete it. See the Terms of Service §1 for the full eligibility terms.
11. Wikivoyage and Third-Party Travel Content
Points of interest and guide content on the map (about 280,000 listings as of September 2026) include content from Wikivoyage, a community-maintained, freely licensed travel guide. This is public travel-guide content, not personal data. We import it to our own server, so browsing it sends nothing to Wikivoyage. Only if you tap a link to a Wikivoyage article does your device visit Wikivoyage's website.
Wikivoyage content is licensed under Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0). We credit Wikivoyage as the source and link to the article each listing comes from. We have adapted the content: listing fields are extracted from Wikivoyage articles and re-categorized, and a listing's country is filled in from its coordinates rather than taken from the article text. The Wikivoyage-derived text remains available under CC BY-SA 4.0.
Country boundary data comes from Natural Earth (public domain).
12. International Data Transfers
Our own infrastructure (database, authentication, file storage, logs, websites) runs on a server we operate in Germany, within the EU. Some companies listed in §4.2 and §4.3 are based in, or process data in, the USA:
| Company | Transfer safeguard |
|---|---|
| Resend (Plus Five Five, Inc.) | EU-U.S. Data Privacy Framework certification (EU adequacy decision, Art. 45 GDPR) and EU Standard Contractual Clauses (Art. 46 GDPR) |
| Apple | Apple Distribution International Ltd. (Ireland) is responsible for users in the EEA; Apple applies its own transfer safeguards, as described in Apple's privacy policy |
| Unsplash Inc. | Our server sends your cover search to Unsplash when you ask for suggestions, and your device loads the suggested photos from Unsplash. Unsplash states in its privacy policy that it complies with GDPR requirements for transfers from the EU |
The services in §4.4 are not in use. If we switch them on, we will name their transfer safeguards here first.
13. Changes to This Policy
We'll post material changes here with a new "Last Updated" date and a note under "What changed". Where a change meaningfully affects how your data is used, we'll tell you in the app before it takes effect.
14. Contact Us
Privacy questions: hallo@makeitnice.de
Mailing address: Make it Nice GmbH, An der Koppel 1, 53909 Zülpich, Germany (Amtsgericht Bonn, HRB 28837)
Data Protection Officer: none appointed (not required under § 38 BDSG).
Supervisory authority: if you're in the EU/EEA and unhappy with our response, you may contact the data protection authority in your country of residence, or the authority responsible for our registered office: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Applicable law: this policy is governed by German law, subject to the mandatory data protection law of your country of residence.
Summary of Key Points
| Topic | Key point |
|---|---|
| Location | Other users see at most a town-level (~5.5 km) position, depending on your presence setting. Exact location is only shared through a time-limited Live share you start. Hidden stops sharing your position, but not trips you track or Live shares you start. |
| Posts and stories | Others see the day, not the time. Place labels you add are visible to travelers who can see the post. |
| Infrastructure | Our own server at Hetzner in Germany; Resend for account emails. |
| Other companies | Apple (sign-in, push, maps, including the map on share pages), Unsplash (group cover suggestions). Google sign-in and purchases are built in but switched off. |
| Analytics | None today. Privacy-first analytics and crash reporting are planned, and this policy will be updated first. |
| Deletion | Deleting your account removes your data and files, including files in your conversations and your sign-in audit records. Safety reports are the exception (§7). |
| Age | 18+ only. |
| Selling data | We don't sell your personal information. |
This Privacy Policy describes the app as it is actually built. If you find something in the app that doesn't match what's written here, please tell us. We treat that as a bug in the app, the policy, or both.