GYAVO Privacy Policy

Version 0.2, revision 3 — interim publication of 19 September 2026

1. Who we are and how to reach us

GYAVO is operated by CANTRUST LTD, a company registered in Israel (company no. 516410487), Derech A-Sultani 24, Tira 4491500, Israel (“GYAVO”, “we”, “us”).

For any question about this policy or about your information, write to privacy@gyavo.com. For help with the app, write to support@gyavo.com.

2. What this policy covers

This policy describes what the GYAVO mobile app (Android and iOS), the website gyavo.com and our e-mail addresses do with information. It is based on the app’s and the service’s verified behaviour as of the version date above.

Some capabilities are built but not active in every version. This policy describes them all, so that it does not have to change on the day one of them is switched on; where a capability is off in your version, nothing described for it happens. The capabilities concerned are: the guest session (section 5.3), the service’s usage-event and spending-ledger records (section 7), partner referral references (section 11.2) and place photos (section 6). Which of them are active depends on the build you use: in the build distributed through Google Play’s internal-testing track, the guest session and the usage-event and spending-ledger records are active (that build talks to our staging service); in every other build at the version date all four are inactive. The app shows which build you are using under Settings → Help & about.

If you use GYAVO as an invited pilot participant, the Pilot Privacy Notice you received supplements this policy for the pilot period; it adds the pilot’s conditions and takes nothing away from what this policy promises.

3. In short

4. Information stored on your device

The app stores the following in its private storage on your device:

If a newer version of the app has written a trip file that your installed version cannot read, the app keeps a byte-for-byte copy of that file aside so that nothing is lost; the copy contains the same data as the trip it copies.

None of this is uploaded to GYAVO. There is no GYAVO account, no synchronisation between devices and no GYAVO cloud backup. The files are protected by your operating system’s app-file protection and are not separately encrypted by the app. Your operating system’s own backup (Android backup, iOS device backup) may include the app’s files according to your device settings; the guest session key is excluded from Android backup.

5. When the app sends information to GYAVO’s planning service

5.1 Only on your action, only after your consent

The app makes requests to GYAVO’s planning service (operated by us on Cloudflare Workers) in two cases only: when you tap “Propose a plan” and when you tap “Search” in Add activity. The first time, the app asks for your agreement; you can agree or decline, and you can change your decision at any time under Settings → Privacy & security. If you decline or switch it off, the app sends nothing and everything else keeps working.

5.2 What a request contains

A plan request contains: the destination area (its name, country and centre coordinates); the two dates being planned and the day’s start and end hours; the number of adults and the ages of children; your transport, pace and budget choices; dietary preferences you ticked; interests you typed; a start and end point if you filled them (including your device coordinates if you chose “Use my location as the start point”); the locked or booked activities of the two planned days (title, time, duration and location), so that the proposal fits around them; the destination time zone; and the interface language.

A search request contains: the category, the text you typed, dietary preferences, the search area (or your device coordinates if you tapped “Near my location”), and the interface language.

Every request carries an application key that identifies the GYAVO app build — not you — and, in versions with the guest session active, the session credential described in 5.3.

Never sent: your name, documents, contacts, nationality choices, notes, bookings, the activities of other days, or your location when it is only displayed on the device.

5.3 Guest session (built; active only in the builds named in section 2)

When active, the first planning or search request after your consent asks the planning service for a guest session: a random session identifier and key that the app keeps in your device’s secure storage and presents with later requests. It identifies this installation of the app towards the service — not you and not your trips. The service stores only a one-way hash of the key, the session’s creation, last-use and expiry times, the first characters of the application key and the network address the session was created from, to limit abuse. A session expires after 90 days without use and at the latest 365 days after creation, and you can end it at any time with “Reset session” under Settings → Privacy & security.

6. Service providers that receive parts of a request

To answer a request, the planning service passes parts of it to the following providers, each of which receives only what it needs:

ProviderWhat it receivesPurpose
Cloudflare (Workers, D1)every request to the planning service, as the infrastructure it runs onhosting the service; server logs (section 7)
Google Places (Google Maps Platform)the search text or category, dietary preference and the search area or coordinatesfinding places
Google Routes (Google Maps Platform)the coordinates of consecutive stopstravel times between stops
Anthropicthe places retrieved for the request and your planning preferences (dates, hours, traveller counts and children’s ages, transport, pace, budget, dietary preferences, interests, locked activities, language)arranging the retrieved places into the proposed days and writing the short explanations shown with them

Place photos are not requested in the current version. These providers process the data under their own terms. What their terms say about how long they keep it: Google Maps Platform states no single fixed retention period for these services, and this policy states none. Anthropic’s published terms for its commercial API provide that request inputs and outputs are kept for up to 30 days by default, unless a contractual, legal or safety exception applies; GYAVO relies on that default and claims no shorter period and no zero-data-retention arrangement.

7. Records kept by the planning service

The planning service keeps operational records, all without request content:

The app contains no analytics or crash-reporting component and sends no usage statistics to anyone.

8. Location

With your permission — asked only when you tap refresh, “Near my location”, “Use my location as the start point” or “Show my location” — the app reads your precise device location while the app is in use and uses it in real time on the device: to show where you are, to mark the map, to label your position with a place name (the coordinates are passed to your device’s own geocoding service for that label) and to suggest the country for the emergency screen, which you confirm explicitly. Your location is sent to the planning service only in the two cases named in section 5.2; the service keeps no record of it, apart from the short-lived copy of an answer held for duplicate-request protection (section 7: at most 15 minutes by default, never more than 24 hours), and our code writes no coordinates to logs. GYAVO keeps no location history: the app holds only your latest position, in memory, while it runs, replaced by each new reading and gone when the app closes. A location you deliberately save as part of a trip — for example a place you add to your itinerary — stays with that trip until you delete the trip or the app’s data. There is no background location tracking. Location permission is managed in your device settings.

9. Maps

The map tab uses the Google Maps SDK on your device with a GYAVO API key. Google receives the map requests needed to draw the map, under Google’s terms. When you enable “Show my location”, your position is drawn on the device. Opening a place in an external maps app hands that place to the app you choose.

10. Emergency and consular information

Emergency numbers, diplomatic missions and useful apps come from data files bundled in the app. The app may fetch a signed public update of these files from the planning service; that request carries no personal details. Calling a number opens your phone’s dialler only after your confirmation; the app never dials on its own.

11. Partner links and referrals

11.1 What happens when you continue to a partner

GYAVO shows links to travel partners’ websites (for example places to stay). When you tap one, the partner’s website opens in your device browser. The link is built on your device and may carry what the partner needs to show the right page: the destination, check-in and check-out dates, the number of adults, children’s ages, the number of rooms and the currency. It never carries your name, e-mail, phone number, documents, notes, contacts or any credential.

From that moment you are on the partner’s website: the search, booking, payment, changes and support happen there, under the partner’s own terms and privacy policy. GYAVO does not sell or process bookings and does not see what you do on the partner’s site.

11.2 Referral references (built, not active at the version date)

When GYAVO has an approved referral relationship with a partner, the app tells you so with a short disclosure line next to that partner’s links: “GYAVO may earn a commission from eligible bookings made through partner links. This does not increase your price.” In that case the app asks GYAVO’s service to build the partner link; the request contains the same fields listed in 11.1 and the interface language, and the link may additionally carry a partner identifier and a random reference number, so that the partner can tell us that a booking resulted from a GYAVO referral. The record we keep for such a reference contains the reference number, the partner, the category and screen the link came from, the destination country, the currency, the interface language and the time — and, in versions with the guest session, the internal session identifier. It contains no destination text, dates, traveller counts, name or contact detail, and our ceiling for it is 90 days (section 15). If a partner later reports a booking against a reference, we keep the partner’s booking reference, the booking and commission amounts and their status as accounting records, for the period accounting law requires (being confirmed with counsel). GYAVO shows no partner prices or availability.

12. Website

gyavo.com consists of static pages. It sets no cookies, runs no analytics or third-party scripts and has no forms. Cloudflare, which serves the site, processes the requests needed to deliver it and keeps its own server logs under its terms; our ceiling for those logs is 30 days (section 15), and the retention that Cloudflare’s own logging applies is being confirmed.

13. E-mail

When you write to any of our addresses at gyavo.com — privacy@, support@, security@, partners@, business@, legal@, billing@ or press@gyavo.com — we receive your message and your address in our company mailbox, which is hosted by Google Workspace, and we use them to answer you. Support and privacy correspondence is kept for no longer than 12 months after the matter is closed; partner and business correspondence for no longer than 24 months after the matter is closed; correspondence with our other addresses for no longer than 24 months after the matter is closed. In every case we delete earlier when the correspondence is no longer needed.

14. Your choices and controls

15. Retention

Every period below is a maximum. We keep nothing for the full period just because the period allows it: information is deleted earlier when it is no longer needed for the purpose it was kept for. Where a period is described as our ceiling, the scheduled removal that enforces it is not yet in operation or the underlying fact is still being confirmed; the text says which.

DataKept for no longer than
Everything stored on your device (section 4)until you delete it or uninstall the app
Guest session (5.3)until you reset it, 90 days after its last use, or 365 days after creation, whichever comes first; the service’s hashed record of an expired or revoked session: our ceiling is 30 days, together with the operational and security records below — the scheduled removal that enforces it is not yet in operation
Usage counters, usage events, the spending ledger and the operator audit trail (7)our ceiling is 90 days — the scheduled removal that enforces it is not yet in operation; until it runs, these records are kept
Referral references (11.2)not active — no such record exists today; our ceiling is 90 days (the scheduled removal is not yet in operation)
Partner booking reports and commission records (11.2)no such record exists today; accounting records, kept for the period accounting law requires — being confirmed with counsel
Duplicate-request protection (7)15 minutes by default, never more than 24 hours
Operational and security logs, including the server logs of the planning service and of the website (7, 12)our ceiling is 30 days; the retention that Cloudflare’s own logging applies for our account plan is being confirmed
Requests processed by Google and Anthropic (6)Google Maps Platform: under Google’s terms, no fixed period stated. Anthropic: up to 30 days by default under Anthropic’s published terms, unless a contractual, legal or safety exception applies; no zero-data-retention arrangement is claimed
Support and privacy correspondence (13)12 months after the matter is closed
Partner and business correspondence (13)24 months after the matter is closed
Correspondence with our other addresses — security, legal, billing, press (13)24 months after the matter is closed
Deletion and backup copiesdeletion requests are carried out promptly in our active systems; backup copies then age out through normal backup rotation — our target is within 30 days after the deletion, unless a legal or security obligation requires a longer period; the rotation periods of the service’s database and of the mailbox are being confirmed

16. Security

Data on your device is kept in the app’s private storage under your operating system’s protection; the guest session key is kept in the device’s secure storage. Connections to the planning service and to the website use HTTPS; a plain-http request to the website is redirected to HTTPS. The planning service stores session keys only as one-way hashes, keeps no request content in its records or logs, and limits requests per caller. No system is perfectly secure; if you believe your information has been affected, write to security@gyavo.com or privacy@gyavo.com.

17. Children

The app asks only for the number of children travelling and their ages, to plan for them; it does not collect children’s names or create profiles for them. During GYAVO’s controlled pilot, participation is limited to invited testers aged 18 or over (Pilot Privacy Notice); that is a condition of the pilot, not the app’s general age rule, which is being settled with counsel.

18. Where data is processed

CANTRUST LTD is established in Israel. The planning service and the website run on Cloudflare’s global network, and the providers in section 6 (Google, Anthropic) process requests on their own infrastructure, which may be outside Israel.

19. Legal basis and your rights

20. Changes to this policy

We update this policy when the app’s, the website’s or the service’s behaviour changes, and when the points marked above as being completed are completed; the version and date are shown at the top.