Privacy Policy

YouLocal · Last updated: 1 September 2026 · Effective: 1 September 2026

This policy explains what personal data the YouLocal app and website (“YouLocal”, “we”, “us”) collect, why, how we use it, who we share it with, and the rights you have. We are committed to processing your data lawfully and transparently under the EU General Data Protection Regulation (GDPR) and applicable data-protection law.

We have written it to be checkable. Where we make a promise, we say what it does and does not cover, and we say plainly where we fall short. A privacy policy you cannot verify is worth nothing.

The short version

Four things are worth knowing before the detail:

1. Who we are (Data Controller)

The data controller responsible for your personal data is YouLocal Eolas Limited, a company registered in Ireland (company registration number 822751), with its registered office at Suite 31, The Pottery, Bakers Point, Pottery Road, Dún Laoghaire, Dublin, A96 EV18, Ireland.

For any privacy question or to exercise your rights, contact us at support@youlocal.app.

2. Data we collect

We collect only what we need to provide the YouLocal travel-concierge service:

CategoryExamplesWhy
Account & identityPhone number (used for sign-in via one-time code), name, and any email you addCreate and secure your account; send you your itinerary or account emails
Traveller details (only if you provide them)Date of birth, nationality, and travel-document type and number (passport, ID card or driving licence)Only so we can complete a flight, stay or experience booking on your behalf, where the provider requires passenger identity details. You are never obliged to add these; without them we simply cannot book on your behalf
Travel companionsNames, whether each companion is an adult, child or infant, and — if you add them — dates of birth, document details, and any dietary, health, mobility or accessibility needs you tell us aboutPlan a trip that works for everyone travelling, and complete bookings for the whole party. This is data about other people: please only add what is necessary, and see Section 12
Location dataPrecise device location, including in the background if you enable visit trackingAnswer your “what’s near me” questions, detect when you arrive at a planned stop, and send the alerts you switched on. Retention is short and specific — see Section 4
Travel contentTrips, itineraries, saved places, conversations with the AI concierge, preferences, and preferences the concierge infers from what you tell itPlan and adapt your trips and personalise suggestions
Payment dataA payment-provider customer reference. We never receive or store your card number — your card details go directly from your device to our payment providerProcess bookings of real-world experiences, stays and flights
Purchase & entitlement dataApp Store / Google Play purchase events, your subscription status, credit balancesKnow what you have paid for and unlock it
Device & technicalPush notification token, app version, device type, server logsSend notifications you opt into; operate, secure and debug the service
Dictation (optional)The text of what you dictated. We do not receive the audio — see belowLet you speak to the concierge instead of typing
Connected accounts (optional)Authorisation tokens for third-party services you choose to linkLet you act on those services from within YouLocal
Website usage (with consent)Pages viewed on youlocal.app, IP address, and a marketing-cookie identifier — only if you accept cookiesMeasure the effectiveness of our advertising (see Section 7)
About dictation. When you tap the microphone, the speech recognition is performed by your phone’s own operating system — Apple’s speech framework on iOS, Google’s recogniser on Android. Depending on your device and settings, that recognition may happen on the device or on Apple’s or Google’s servers, under their privacy policies. Your audio recording is never uploaded to YouLocal; we receive only the transcribed text, exactly as if you had typed it.

3. How we use your data & legal bases

We do not sell your personal data. We do not share it with data brokers, ad networks or audience-building platforms. The YouLocal app contains no advertising, analytics or attribution software at all. On our website, and only with your consent, we use a marketing cookie to measure our advertising campaigns (see Section 7); you can refuse or withdraw this at any time.

4. Location data — what we actually do

This is the part people care most about, so here it is in detail.

Your precise position is deleted automatically

When location features are on, your device reports its position to us. We do not append those readings to a movement log. We keep one record per roughly 11-kilometre area you have recently been in, holding your latest position in that area — each new reading replaces the previous one rather than being added to a list. Every one of those records carries an expiry timestamp set to 48 hours after the last time we heard from you in that area. Our database enforces that expiry and removes the record without anyone doing anything.

Two honest qualifications, because the plain sentence is slightly too generous:

What we keep longer, and why

We are not going to pretend that everything location-related disappears in 48 hours. The raw coordinate is short-lived; some conclusions drawn from it are kept, because they are what make the service work at all:

WhatKept forWhy
Your precise position (latitude/longitude)Expires 48h after the last report, then deleted automaticallyAnswer “what’s near me”, detect arrival at a planned stop, trigger the alerts you enabled
A coarse area key, rounded to roughly 11 kmAlongside the record above, and expires with itGroup your session by rough area (city-scale) instead of by exact point
Visit records: which planned stop you reached, when, and roughly how long you stayedUntil you delete your account. There is no automatic expiry on these todayLearn what you actually liked so suggestions improve, and stop reminding you about places you already visited
Alerts we generated for you about a place or areaUntil you delete your account, capped at a recent number per locationSo you can re-read a notification you missed

We think this asymmetry is defensible, and we would rather state it than bury it: the raw coordinate is disposable; what we learned about your taste is the product. If you do not want the second half, turn off visit tracking under Settings → Visit tracking, or delete your account and it goes with it.

Who your coordinates are sent to

To answer a location question we have to ask other services, and those services receive the coordinate. When we do this we send the coordinate and the query — not your name, phone number or account identifier. But we want to be exact rather than reassuring: a precise coordinate is itself identifying, and once we have sent it to a provider our 48-hour expiry has no effect on their copy. Their retention is governed by their own policies. The providers concerned are named in Section 6: Google (turning coordinates into place names, and place search), the OpenStreetMap Foundation’s Nominatim service (the same, as a fallback), AccuWeather and Stormglass (weather and sea conditions where you are), and Mapbox (which receives your device’s IP address and the map area shown, because map tiles are requested by your phone directly).

What we do not do with it

We use location data only to answer your own here-and-now requests and to run the monitoring and alerts you switched on for your own trips. We do not aggregate it into analytics, dashboards, footfall reports or audience segments; we do not sell or license it; and we do not use it to build any product that is not your own trip. This is a written internal constraint, not just an intention, and it comes with a rule attached: if we ever want to use location data for anything else, this policy has to change first, before the code does.

5. Who inside YouLocal can access your data

Some apps promise that their staff can never see your data. We are not going to make that promise, because for us — and for essentially any hosted service — it would not be true. Our databases are administered by people, and administrator credentials that can read them exist. They are held by a small number of named individuals who need them to run, deploy and troubleshoot the service, and access is granted on a least-privilege basis.

What we can commit to is behaviour, so that is what we commit to:

Since 30 August 2026, in the environment that serves the live app, there is a technical audit trail behind those commitments, and here is exactly what it does and does not cover. Direct access to the two databases that hold your location — the store of where you currently are, and the record of places you visited — is logged in AWS CloudTrail, reads as well as writes, with log-file validation, and those logs are kept for 365 days. Reads are the point: an administrator opening your coordinates is a read, and that is now recorded.

What it does not cover, so that you are not left to assume: it covers those two databases, not every place a location-derived record can end up, and it cannot distinguish one user's data from another's when our own service reads it, because the service reads with a single identity. There is also no automatic alarm on it yet — it is a record you can be shown, not a tripwire. We will say so here when that changes.

6. Who we share data with

We share data with service providers that process it on our behalf under contract. This is every provider that receives your personal data as of 31 August 2026 — not a sample. When it changes, this list changes. If you think one is missing, tell us at support@youlocal.app and we will add it.

ProviderPurposeData it receives
Amazon Web Services (AWS)Cloud hosting, database, cache, sign-in (Cognito), file storage, and the AI models behind the concierge (Bedrock / AgentCore)All categories in Section 2. Stored in the EU — Frankfurt, Germany, for the live service and for our development environment alike. (The only thing hosted elsewhere is this marketing website's own static files, in Ireland; they contain no personal data.) See the note on AI processing below
StripePayment processing for real-world bookingsPayment details, entered on your device and sent to Stripe directly; we hold only a customer reference
RevenueCatManaging App Store / Google Play subscriptions and credit packsYour YouLocal user identifier and your purchase and subscription events
Google Firebase Cloud MessagingDelivering push notificationsYour device push token and the content of the notification
Twilio VerifySending and checking the one-time code you sign in withYour phone number, at every sign-in. Twilio generates, stores and verifies the code. Processed in the United States
Twilio (WhatsApp)Only if you choose to send an itinerary to yourself on WhatsAppYour phone number and a private link to the itinerary file
Airlines, hotels and global distribution systemsActually holding a flight or stay you book — they receive the booking from Duffel, not from usThe traveller details required for that booking. Airline reservations are distributed through industry systems that operate worldwide
Third-party ticketing and booking sitesOnly if you ask us to book something that has no direct integration — we complete the form on the site for youThe details you gave us for that booking, entered on that site
Twilio SendGridSending transactional email (your itinerary, account email)Your email address, your name, and the content of the message
Google Maps Platform (Geocoding, Places)Turning coordinates into place names, and searching for placesCoordinates — including your live position — and place search text. No name, phone number or account identifier
OpenStreetMap Foundation (Nominatim)Turning coordinates into place names, as a fallbackCoordinates, including your live position
MapboxMap tiles and static map images, requested by your device directlyYour device’s IP address and the map area being displayed
AccuWeatherWeather forecasts where you are or where you are goingCoordinates
StormglassSea state and marine conditions for coastal adviceCoordinates
FlightAwareLive status of flights you add to a tripFlight number and date
DuffelFlight and stay search and bookingFor bookings only: passenger names, dates of birth (including children’s), travel-document details and contact details
AmadeusFinding the airports nearest a departure or destination pointA coordinate pair for that point. No name or account identifier
PerplexityLive web lookups the concierge performs to answer your questionThe search query derived from your request, which may include a place and dates
Google FontsThe app downloads its typefaces from Google’s font serversYour device’s IP address, when the app fetches a font
Apple / Google speech recognitionConverting your dictation to text, on your own device or their serversYour voice input, handled by your operating system under Apple’s or Google’s policy. It does not pass through us
Local experts (“Ask a Local”)Answering a question you choose to send to a real person in the destinationOnly if you use the feature: your question, your first name, and a short trip summary (dates, who is travelling, any needs you told us about). These are individuals under contract, not a company
Where the AI processing happens. The concierge runs on AI models hosted inside AWS Bedrock, in the EU. Under our AWS terms, prompts and outputs are not used to train those models and are not shared with the model developer. Every model we invoke for the concierge uses an EU-only Bedrock inference profile, so a request is served from an AWS region inside the EU — it is not routed to whichever region happens to have capacity. The browser component that can fill in a booking form for you also runs in the EU (Frankfurt).

This is about our own processing. Some of the third-party services listed above are outside the EU/EEA — notably Twilio, which sends your sign-in code from the United States — and an airline booking is distributed through industry systems that operate worldwide. Where processing occurs outside the EU/EEA we rely on the transfer mechanisms in those providers’ published data processing terms, including EU Standard Contractual Clauses where offered. One provider — the OpenStreetMap Foundation’s public Nominatim service — is a free public endpoint with which we have no processing contract; we are replacing that dependency, and in the meantime the only thing sent to it is a coordinate pair. You can ask us for a copy of the transfer safeguards we rely on by emailing support@youlocal.app.

Separately, if you consent to marketing cookies on our website, Meta also receives limited data as an independent recipient — see Section 7.

7. Cookies and similar technologies (website)

The YouLocal mobile app uses no advertising cookies, trackers, analytics or attribution software of any kind. On our website (youlocal.app) we use cookies and similar technologies, grouped by purpose:

CategoryPurposeConsent
Strictly necessaryMake the site work and remember your cookie choiceAlways on — no consent needed
Marketing & analyticsMeasure our advertising and understand how visitors reach and use the siteOnly with your consent

Our marketing cookies currently come from the Meta Pixel, provided by Meta Platforms Ireland Ltd. When enabled it may transmit your IP address and on-site actions (such as page views) to Meta and set the _fbp cookie, so we can measure our campaigns. Meta then processes that data for its own purposes under the Meta Privacy Policy, over which we have no control.

We load no marketing cookie and send nothing to Meta until you choose “Accept” on our cookie banner. The pixel script is not present on the page at all before then. Refusing (“Reject”) is just as easy, and no marketing cookie is set if you take no action. You can withdraw consent at any time by clearing this site’s cookies / site data in your browser, which brings the banner back. Legal basis: your consent (Art. 6(1)(a) GDPR and the ePrivacy rules).

8. How long we keep it

WhatHow long
Your precise locationExpires 48 hours after the last time we hear from you, then deleted automatically (see Section 4)
Visit records — which planned stops you reachedUntil you delete your account. No automatic expiry today
Account and profile dataAs long as your account exists
Trips, itineraries and saved placesUntil you delete them, or until you delete your account. You can set automatic archiving of old itineraries under Settings
Concierge conversations, and the preferences the concierge has learnedUntil you delete your account
Push notification tokenUntil you turn notifications off or delete your account
Server logsShort-lived operational retention (currently a matter of weeks), then discarded automatically
Website marketing cookieSet by Meta under its own lifetime; clear your browser’s site data to remove it

When you delete your account we erase your personal data from the systems listed in Section 10, and that section also says plainly what our automated erasure does not yet reach.

9. Your rights

Under GDPR you have the right to:

10. Deleting your account

You can delete your account at any time from Profile → Delete account in the app. It happens immediately, you are signed out, and what is deleted cannot be recovered.

Deletion removes: your profile and inferred preferences; your trips, itineraries, saved places and travel spaces; the companion details you added; your conversations with the concierge, including archived copies; your visit records and your current location record; your device push tokens; your payment-provider reference; the credentials for any third-party account you connected; the blocks you had set (on both sides, so nobody is left permanently blocked by an account that no longer exists); and your sign-in identity.

What our automated deletion does not yet reach. We are telling you this because you could otherwise discover it yourself, and because a promise we cannot keep is worse than an admission. A small set of records linked to your account is not yet covered by the automatic purge: your subscription and credit balances, your referral code, links to itineraries you shared with other people, questions you sent to a local expert, some itinerary records, alerts we had generated for you about a place, any content reports you filed, and the long-term memory the concierge builds from your conversations. We are extending the automatic purge to cover all of them. In the meantime, email support@youlocal.app after deleting your account and we will remove them by hand and confirm.

Deletion also runs across several separate storage systems. If one of them fails, the others still complete and the failure is recorded on our side so the job can be finished. If you want confirmation that everything was removed, ask us and we will check and reply.

Note that a subscription bought through the App Store or Google Play is managed by Apple or Google, not by us: deleting your YouLocal account does not cancel it. Cancel it in your Apple or Google account settings.

If you have uninstalled the app or cannot sign in, see Delete your account for the request route.

11. Automated processing

The concierge is an AI system, and it forms a picture of your travel preferences from what you tell it, what you save and which suggested places you actually visit. It uses that picture to choose what to suggest and how to write to you. It does not make decisions with a legal or similarly significant effect on you: it does not price you differently, does not decide your eligibility for anything, and does not profile you for advertising. You can see and correct your profile in the app, and you can object to this profiling by writing to us.

12. Children, and children who travel with you

YouLocal accounts are for adults. You must be at least 16 to hold one, and we do not knowingly let children create accounts. We do not verify age at sign-up — we sign you in with a phone number and a one-time code — so this rests on your declaration.

We must be straightforward about a related point, because a blanket “we do not collect children’s data” would be false. If you are planning a family trip, you can tell us who is coming, including children and infants, and we will hold what you give us: a name, whether they are an adult, child or infant, and — only if you add them — a date of birth, travel-document details for a booking, and any dietary, health, mobility or accessibility needs. Where a flight or stay requires it, passenger details including a child’s date of birth are passed to the booking provider.

That data is used only to plan and book that trip. It is deleted when you remove the companion or delete your account. Please add only what is actually needed, and only for people you are entitled to act for. If you believe a child has created an account, or that data about a child is held here that should not be, contact us and we will delete it.

12b. How the concierge forms a picture of you — including personality traits

This section exists because the honest description is more than “we learn your travel preferences”, and you are entitled to the specific version.

From your conversations, what you save and which suggested places you actually visit, an automated system estimates five broad personality traits — openness, conscientiousness, extraversion, agreeableness and emotional sensitivity. These are inferences, not facts: nobody asked you these questions and you never answered them.

What they are used for: ordering what you see — which suggestions appear near the top of your list. They are also given to the concierge as context so its tone and suggestions fit you. They are not used to set prices, to decide what you are allowed to do, to assess you for any benefit, or for advertising — and they are never shared.

Nothing here decides anything about you in a legal or contractual sense; it changes the order of travel suggestions. If you would rather it did not:

In the app, Profile → Your travel style shows what the concierge believes about you in plain language, and what it is still unsure of. That screen is deliberately written in everyday words rather than trait scores — the scores are what this section is for.

13. Security

Traffic between the app and our servers travels over encrypted connections (HTTPS/TLS). Our databases and our cache are encrypted at rest, and the cache is also encrypted in transit inside our network. Credentials for third-party services you link are held in a dedicated secrets manager, not in our database. Access to production systems is on a least-privilege basis. No system is perfectly secure, but we work continuously to safeguard your information.

Fixed since the last version of this page. Until 31 August 2026 this section disclosed that the final internal hop — from our content-delivery network to the server that answers — was unencrypted. It is now encrypted (TLS 1.2), and that server no longer accepts requests that did not come through our network. We said we would update this page the day it shipped rather than before, so we are.

One exception remains, and we would rather tell you than let “all data is encrypted in transit” stand as a claim that is not fully true. The call we make to our weather provider to look up conditions for a coordinate is made over an unencrypted connection. It carries a coordinate pair only — no name, phone number or account identifier. We are moving it.

14. Changes to this policy

We may update this policy. We will revise the “Last updated” date above and, for material changes, notify you in the app. Where a change would widen how we use location data, we will publish the change before we make it, not after.

15. Contact

Questions or requests: support@youlocal.app
YouLocal Eolas Limited, Suite 31, The Pottery, Bakers Point, Pottery Road, Dún Laoghaire, Dublin, A96 EV18, Ireland.