GYAVO Privacy Policy
1. Who we are and how to reach us
GYAVO is operated by CANTRUST LTD, a company registered in Israel (company no. 516410487), Derech A-Sultani 24, Tira 4491500, Israel (“GYAVO”, “we”, “us”).
For any question about this policy or about your information, write to privacy@gyavo.com. For help with the app, write to support@gyavo.com.
2. What this policy covers
This policy describes what the GYAVO mobile app (Android and iOS), the website gyavo.com and our e-mail addresses do with information. It is based on the app’s and the service’s verified behaviour as of the version date above.
Some capabilities are built but not active in every version. This policy describes them all, so that it does not have to change on the day one of them is switched on; where a capability is off in your version, nothing described for it happens. The capabilities concerned are: the guest session (section 5.3), the service’s usage-event and spending-ledger records (section 7), partner referral references (section 11.2) and place photos (section 6). Which of them are active depends on the build you use: in the build distributed through Google Play’s internal-testing track, the guest session and the usage-event and spending-ledger records are active (that build talks to our staging service); in every other build at the version date all four are inactive. The app shows which build you are using under Settings → Help & about.
If you use GYAVO as an invited pilot participant, the Pilot Privacy Notice you received supplements this policy for the pilot period; it adds the pilot’s conditions and takes nothing away from what this policy promises.
3. In short
- Your trips, documents, contacts and preferences stay on your device. GYAVO has no user accounts, no sync and no cloud backup of your data.
- The app sends information to GYAVO’s planning service only when you tap “Propose a plan” or “Search”, and only after you have agreed to that under Privacy & security. The request goes to our service on Cloudflare and from there to Google (place search and travel times) and Anthropic (arranging the results). Names, documents, contacts and nationality are never sent.
- Your location is used on your device, in real time, to show where you are and for the emergency screen. It is sent to the planning service only if you choose “Near my location” or “Use my location as the start point”. There is no background tracking, and GYAVO keeps no location history.
- The planning service keeps usage counters and operational records without request content, and Cloudflare keeps server logs for a limited time. Google and Anthropic process requests under their own terms.
- Partner links open the partner’s own website in your browser; the booking, the payment and the partner’s data practices happen there.
- The website gyavo.com sets no cookies and runs no analytics.
- Every retention period in this policy is a maximum: we delete earlier when the information is no longer needed.
- You can switch request sending off at any time, remove documents and contacts on their screens, and delete everything by uninstalling the app.
4. Information stored on your device
The app stores the following in its private storage on your device:
- Your trips — itinerary, activities, bookings you entered, notes and budget lines; the list of your trips and which trip you last opened.
- Documents you attach — for example tickets, visas, passports or insurance, as files copied into the app’s private storage.
- Trip contacts you add, nationality choices you confirm for consular assistance, and the emergency country you confirm.
- Places you save in a trip — a place you add to your itinerary carries that place’s coordinates; a location you deliberately save as part of a trip stays with that trip until you delete the trip or the app’s data. Your own position (point, time, accuracy and a place label) is held only in the app’s memory while the app runs, replaced by each new reading, and is not written to storage.
- Preferences — language, archived trips, text size and your planning-service decision.
- Emergency and consular data — a bundled copy plus any update fetched later (section 10).
- Guest session key — only in versions where the guest session is active (section 5.3), kept in the device’s secure storage (Android Keystore / iOS Keychain), never in your trip files.
If a newer version of the app has written a trip file that your installed version cannot read, the app keeps a byte-for-byte copy of that file aside so that nothing is lost; the copy contains the same data as the trip it copies.
None of this is uploaded to GYAVO. There is no GYAVO account, no synchronisation between devices and no GYAVO cloud backup. The files are protected by your operating system’s app-file protection and are not separately encrypted by the app. Your operating system’s own backup (Android backup, iOS device backup) may include the app’s files according to your device settings; the guest session key is excluded from Android backup.
5. When the app sends information to GYAVO’s planning service
5.1 Only on your action, only after your consent
The app makes requests to GYAVO’s planning service (operated by us on Cloudflare Workers) in two cases only: when you tap “Propose a plan” and when you tap “Search” in Add activity. The first time, the app asks for your agreement; you can agree or decline, and you can change your decision at any time under Settings → Privacy & security. If you decline or switch it off, the app sends nothing and everything else keeps working.
5.2 What a request contains
A plan request contains: the destination area (its name, country and centre coordinates); the two dates being planned and the day’s start and end hours; the number of adults and the ages of children; your transport, pace and budget choices; dietary preferences you ticked; interests you typed; a start and end point if you filled them (including your device coordinates if you chose “Use my location as the start point”); the locked or booked activities of the two planned days (title, time, duration and location), so that the proposal fits around them; the destination time zone; and the interface language.
A search request contains: the category, the text you typed, dietary preferences, the search area (or your device coordinates if you tapped “Near my location”), and the interface language.
Every request carries an application key that identifies the GYAVO app build — not you — and, in versions with the guest session active, the session credential described in 5.3.
Never sent: your name, documents, contacts, nationality choices, notes, bookings, the activities of other days, or your location when it is only displayed on the device.
5.3 Guest session (built; active only in the builds named in section 2)
When active, the first planning or search request after your consent asks the planning service for a guest session: a random session identifier and key that the app keeps in your device’s secure storage and presents with later requests. It identifies this installation of the app towards the service — not you and not your trips. The service stores only a one-way hash of the key, the session’s creation, last-use and expiry times, the first characters of the application key and the network address the session was created from, to limit abuse. A session expires after 90 days without use and at the latest 365 days after creation, and you can end it at any time with “Reset session” under Settings → Privacy & security.
6. Service providers that receive parts of a request
To answer a request, the planning service passes parts of it to the following providers, each of which receives only what it needs:
| Provider | What it receives | Purpose |
|---|---|---|
| Cloudflare (Workers, D1) | every request to the planning service, as the infrastructure it runs on | hosting the service; server logs (section 7) |
| Google Places (Google Maps Platform) | the search text or category, dietary preference and the search area or coordinates | finding places |
| Google Routes (Google Maps Platform) | the coordinates of consecutive stops | travel times between stops |
| Anthropic | the places retrieved for the request and your planning preferences (dates, hours, traveller counts and children’s ages, transport, pace, budget, dietary preferences, interests, locked activities, language) | arranging the retrieved places into the proposed days and writing the short explanations shown with them |
Place photos are not requested in the current version. These providers process the data under their own terms. What their terms say about how long they keep it: Google Maps Platform states no single fixed retention period for these services, and this policy states none. Anthropic’s published terms for its commercial API provide that request inputs and outputs are kept for up to 30 days by default, unless a contractual, legal or safety exception applies; GYAVO relies on that default and claims no shorter period and no zero-data-retention arrangement.
7. Records kept by the planning service
The planning service keeps operational records, all without request content:
- Usage counters — how many provider requests were made per day, by kind (search, photo, route, AI), and a running total of tokens reported by Anthropic. Numbers only.
- Usage events, spending ledger and safety switches (the service’s cost and abuse control; active only in the builds named in section 2) — an opaque request identifier, the time, the feature used, the outcome, the response time, provider call counts and estimated cost and, in versions with the guest session, the internal session identifier. These records contain no request text, coordinates, network address, key or credential.
- Operator audit trail (same status) — which safety switch was changed, when, by which operator handle and why. No request content, no traveller data.
- Duplicate-request protection (same status) — a fingerprint of a request and, for a completed request, its answer (the proposed places and explanations, including the titles of the activities you locked for that plan and the start or end point you gave, if any), so that a retry by your device can be answered without a new provider call. Kept for at most 15 minutes by default and never more than 24 hours, then deleted automatically.
- Session records — as described in section 5.3, in versions with the guest session active.
- Rate limiting — the service limits how many requests a caller may make per minute, using the session identifier or, without a session, the application key together with the requesting network address; this is held in memory for that purpose only and is not stored.
- Server logs — Cloudflare’s Workers observability records request metadata and error messages for the service. Our own code writes no request content to logs. Our ceiling for these operational and security logs is 30 days (section 15); the retention that Cloudflare’s own logging applies for our account plan is being confirmed.
The app contains no analytics or crash-reporting component and sends no usage statistics to anyone.
8. Location
With your permission — asked only when you tap refresh, “Near my location”, “Use my location as the start point” or “Show my location” — the app reads your precise device location while the app is in use and uses it in real time on the device: to show where you are, to mark the map, to label your position with a place name (the coordinates are passed to your device’s own geocoding service for that label) and to suggest the country for the emergency screen, which you confirm explicitly. Your location is sent to the planning service only in the two cases named in section 5.2; the service keeps no record of it, apart from the short-lived copy of an answer held for duplicate-request protection (section 7: at most 15 minutes by default, never more than 24 hours), and our code writes no coordinates to logs. GYAVO keeps no location history: the app holds only your latest position, in memory, while it runs, replaced by each new reading and gone when the app closes. A location you deliberately save as part of a trip — for example a place you add to your itinerary — stays with that trip until you delete the trip or the app’s data. There is no background location tracking. Location permission is managed in your device settings.
9. Maps
The map tab uses the Google Maps SDK on your device with a GYAVO API key. Google receives the map requests needed to draw the map, under Google’s terms. When you enable “Show my location”, your position is drawn on the device. Opening a place in an external maps app hands that place to the app you choose.
10. Emergency and consular information
Emergency numbers, diplomatic missions and useful apps come from data files bundled in the app. The app may fetch a signed public update of these files from the planning service; that request carries no personal details. Calling a number opens your phone’s dialler only after your confirmation; the app never dials on its own.
11. Partner links and referrals
11.1 What happens when you continue to a partner
GYAVO shows links to travel partners’ websites (for example places to stay). When you tap one, the partner’s website opens in your device browser. The link is built on your device and may carry what the partner needs to show the right page: the destination, check-in and check-out dates, the number of adults, children’s ages, the number of rooms and the currency. It never carries your name, e-mail, phone number, documents, notes, contacts or any credential.
From that moment you are on the partner’s website: the search, booking, payment, changes and support happen there, under the partner’s own terms and privacy policy. GYAVO does not sell or process bookings and does not see what you do on the partner’s site.
11.2 Referral references (built, not active at the version date)
When GYAVO has an approved referral relationship with a partner, the app tells you so with a short disclosure line next to that partner’s links: “GYAVO may earn a commission from eligible bookings made through partner links. This does not increase your price.” In that case the app asks GYAVO’s service to build the partner link; the request contains the same fields listed in 11.1 and the interface language, and the link may additionally carry a partner identifier and a random reference number, so that the partner can tell us that a booking resulted from a GYAVO referral. The record we keep for such a reference contains the reference number, the partner, the category and screen the link came from, the destination country, the currency, the interface language and the time — and, in versions with the guest session, the internal session identifier. It contains no destination text, dates, traveller counts, name or contact detail, and our ceiling for it is 90 days (section 15). If a partner later reports a booking against a reference, we keep the partner’s booking reference, the booking and commission amounts and their status as accounting records, for the period accounting law requires (being confirmed with counsel). GYAVO shows no partner prices or availability.
12. Website
gyavo.com consists of static pages. It sets no cookies, runs no analytics or third-party scripts and has no forms. Cloudflare, which serves the site, processes the requests needed to deliver it and keeps its own server logs under its terms; our ceiling for those logs is 30 days (section 15), and the retention that Cloudflare’s own logging applies is being confirmed.
13. E-mail
When you write to any of our addresses at gyavo.com — privacy@, support@, security@, partners@, business@, legal@, billing@ or press@gyavo.com — we receive your message and your address in our company mailbox, which is hosted by Google Workspace, and we use them to answer you. Support and privacy correspondence is kept for no longer than 12 months after the matter is closed; partner and business correspondence for no longer than 24 months after the matter is closed; correspondence with our other addresses for no longer than 24 months after the matter is closed. In every case we delete earlier when the correspondence is no longer needed.
14. Your choices and controls
- Planning service: agree, decline or switch off request sending under Settings → Privacy & security. Declined or off means nothing is sent.
- Location: grant or revoke the permission in your device settings; the app asks only when you use a location feature.
- Delete on your device: remove documents, contacts and nationality choices on their screens; archive or restore trips; uninstalling the app deletes all app data on the device.
- Guest session: “Reset session” under Settings → Privacy & security (in versions where the session is active) ends the current session; the service keeps only the hashed, expired record described in 5.3, and removes it as described in section 15.
- Requests: for anything else, including questions about records the planning service holds, write to privacy@gyavo.com. Because GYAVO keeps no account and no name, the service cannot link its records to a person; a request about a guest session needs the session identifier shown in the app. Deletion requests are carried out promptly in our active systems; backup copies then age out through normal backup rotation (section 15).
15. Retention
Every period below is a maximum. We keep nothing for the full period just because the period allows it: information is deleted earlier when it is no longer needed for the purpose it was kept for. Where a period is described as our ceiling, the scheduled removal that enforces it is not yet in operation or the underlying fact is still being confirmed; the text says which.
| Data | Kept for no longer than |
|---|---|
| Everything stored on your device (section 4) | until you delete it or uninstall the app |
| Guest session (5.3) | until you reset it, 90 days after its last use, or 365 days after creation, whichever comes first; the service’s hashed record of an expired or revoked session: our ceiling is 30 days, together with the operational and security records below — the scheduled removal that enforces it is not yet in operation |
| Usage counters, usage events, the spending ledger and the operator audit trail (7) | our ceiling is 90 days — the scheduled removal that enforces it is not yet in operation; until it runs, these records are kept |
| Referral references (11.2) | not active — no such record exists today; our ceiling is 90 days (the scheduled removal is not yet in operation) |
| Partner booking reports and commission records (11.2) | no such record exists today; accounting records, kept for the period accounting law requires — being confirmed with counsel |
| Duplicate-request protection (7) | 15 minutes by default, never more than 24 hours |
| Operational and security logs, including the server logs of the planning service and of the website (7, 12) | our ceiling is 30 days; the retention that Cloudflare’s own logging applies for our account plan is being confirmed |
| Requests processed by Google and Anthropic (6) | Google Maps Platform: under Google’s terms, no fixed period stated. Anthropic: up to 30 days by default under Anthropic’s published terms, unless a contractual, legal or safety exception applies; no zero-data-retention arrangement is claimed |
| Support and privacy correspondence (13) | 12 months after the matter is closed |
| Partner and business correspondence (13) | 24 months after the matter is closed |
| Correspondence with our other addresses — security, legal, billing, press (13) | 24 months after the matter is closed |
| Deletion and backup copies | deletion requests are carried out promptly in our active systems; backup copies then age out through normal backup rotation — our target is within 30 days after the deletion, unless a legal or security obligation requires a longer period; the rotation periods of the service’s database and of the mailbox are being confirmed |
16. Security
Data on your device is kept in the app’s private storage under your operating system’s protection; the guest session key is kept in the device’s secure storage. Connections to the planning service and to the website use HTTPS; a plain-http request to the website is redirected to HTTPS. The planning service stores session keys only as one-way hashes, keeps no request content in its records or logs, and limits requests per caller. No system is perfectly secure; if you believe your information has been affected, write to security@gyavo.com or privacy@gyavo.com.
17. Children
The app asks only for the number of children travelling and their ages, to plan for them; it does not collect children’s names or create profiles for them. During GYAVO’s controlled pilot, participation is limited to invited testers aged 18 or over (Pilot Privacy Notice); that is a condition of the pilot, not the app’s general age rule, which is being settled with counsel.
18. Where data is processed
CANTRUST LTD is established in Israel. The planning service and the website run on Cloudflare’s global network, and the providers in section 6 (Google, Anthropic) process requests on their own infrastructure, which may be outside Israel.
19. Legal basis and your rights
20. Changes to this policy
We update this policy when the app’s, the website’s or the service’s behaviour changes, and when the points marked above as being completed are completed; the version and date are shown at the top.