← youlocal.app
Four things are worth knowing before the detail:
The data controller responsible for your personal data is YouLocal Eolas Limited, a company registered in Ireland (company registration number 822751), with its registered office at Suite 31, The Pottery, Bakers Point, Pottery Road, Dún Laoghaire, Dublin, A96 EV18, Ireland.
For any privacy question or to exercise your rights, contact us at support@youlocal.app.
We collect only what we need to provide the YouLocal travel-concierge service:
| Category | Examples | Why |
|---|---|---|
| Account & identity | Phone number (used for sign-in via one-time code), name, and any email you add | Create and secure your account; send you your itinerary or account emails |
| Traveller details (only if you provide them) | Date of birth, nationality, and travel-document type and number (passport, ID card or driving licence) | Only so we can complete a flight, stay or experience booking on your behalf, where the provider requires passenger identity details. You are never obliged to add these; without them we simply cannot book on your behalf |
| Travel companions | Names, whether each companion is an adult, child or infant, and — if you add them — dates of birth, document details, and any dietary, health, mobility or accessibility needs you tell us about | Plan a trip that works for everyone travelling, and complete bookings for the whole party. This is data about other people: please only add what is necessary, and see Section 12 |
| Location data | Precise device location, including in the background if you enable visit tracking | Answer your “what’s near me” questions, detect when you arrive at a planned stop, and send the alerts you switched on. Retention is short and specific — see Section 4 |
| Travel content | Trips, itineraries, saved places, conversations with the AI concierge, preferences, and preferences the concierge infers from what you tell it | Plan and adapt your trips and personalise suggestions |
| Payment data | A payment-provider customer reference. We never receive or store your card number — your card details go directly from your device to our payment provider | Process bookings of real-world experiences, stays and flights |
| Purchase & entitlement data | App Store / Google Play purchase events, your subscription status, credit balances | Know what you have paid for and unlock it |
| Device & technical | Push notification token, app version, device type, server logs | Send notifications you opt into; operate, secure and debug the service |
| Dictation (optional) | The text of what you dictated. We do not receive the audio — see below | Let you speak to the concierge instead of typing |
| Connected accounts (optional) | Authorisation tokens for third-party services you choose to link | Let you act on those services from within YouLocal |
| Website usage (with consent) | Pages viewed on youlocal.app, IP address, and a marketing-cookie identifier — only if you accept cookies | Measure the effectiveness of our advertising (see Section 7) |
We do not sell your personal data. We do not share it with data brokers, ad networks or audience-building platforms. The YouLocal app contains no advertising, analytics or attribution software at all. On our website, and only with your consent, we use a marketing cookie to measure our advertising campaigns (see Section 7); you can refuse or withdraw this at any time.
This is the part people care most about, so here it is in detail.
When location features are on, your device reports its position to us. We do not append those readings to a movement log. We keep one record per roughly 11-kilometre area you have recently been in, holding your latest position in that area — each new reading replaces the previous one rather than being added to a list. Every one of those records carries an expiry timestamp set to 48 hours after the last time we heard from you in that area. Our database enforces that expiry and removes the record without anyone doing anything.
Two honest qualifications, because the plain sentence is slightly too generous:
We are not going to pretend that everything location-related disappears in 48 hours. The raw coordinate is short-lived; some conclusions drawn from it are kept, because they are what make the service work at all:
| What | Kept for | Why |
|---|---|---|
| Your precise position (latitude/longitude) | Expires 48h after the last report, then deleted automatically | Answer “what’s near me”, detect arrival at a planned stop, trigger the alerts you enabled |
| A coarse area key, rounded to roughly 11 km | Alongside the record above, and expires with it | Group your session by rough area (city-scale) instead of by exact point |
| Visit records: which planned stop you reached, when, and roughly how long you stayed | Until you delete your account. There is no automatic expiry on these today | Learn what you actually liked so suggestions improve, and stop reminding you about places you already visited |
| Alerts we generated for you about a place or area | Until you delete your account, capped at a recent number per location | So you can re-read a notification you missed |
We think this asymmetry is defensible, and we would rather state it than bury it: the raw coordinate is disposable; what we learned about your taste is the product. If you do not want the second half, turn off visit tracking under Settings → Visit tracking, or delete your account and it goes with it.
To answer a location question we have to ask other services, and those services receive the coordinate. When we do this we send the coordinate and the query — not your name, phone number or account identifier. But we want to be exact rather than reassuring: a precise coordinate is itself identifying, and once we have sent it to a provider our 48-hour expiry has no effect on their copy. Their retention is governed by their own policies. The providers concerned are named in Section 6: Google (turning coordinates into place names, and place search), the OpenStreetMap Foundation’s Nominatim service (the same, as a fallback), AccuWeather and Stormglass (weather and sea conditions where you are), and Mapbox (which receives your device’s IP address and the map area shown, because map tiles are requested by your phone directly).
We use location data only to answer your own here-and-now requests and to run the monitoring and alerts you switched on for your own trips. We do not aggregate it into analytics, dashboards, footfall reports or audience segments; we do not sell or license it; and we do not use it to build any product that is not your own trip. This is a written internal constraint, not just an intention, and it comes with a rule attached: if we ever want to use location data for anything else, this policy has to change first, before the code does.
Some apps promise that their staff can never see your data. We are not going to make that promise, because for us — and for essentially any hosted service — it would not be true. Our databases are administered by people, and administrator credentials that can read them exist. They are held by a small number of named individuals who need them to run, deploy and troubleshoot the service, and access is granted on a least-privilege basis.
What we can commit to is behaviour, so that is what we commit to:
Since 30 August 2026, in the environment that serves the live app, there is a technical audit trail behind those commitments, and here is exactly what it does and does not cover. Direct access to the two databases that hold your location — the store of where you currently are, and the record of places you visited — is logged in AWS CloudTrail, reads as well as writes, with log-file validation, and those logs are kept for 365 days. Reads are the point: an administrator opening your coordinates is a read, and that is now recorded.
What it does not cover, so that you are not left to assume: it covers those two databases, not every place a location-derived record can end up, and it cannot distinguish one user's data from another's when our own service reads it, because the service reads with a single identity. There is also no automatic alarm on it yet — it is a record you can be shown, not a tripwire. We will say so here when that changes.
We share data with service providers that process it on our behalf under contract. This is every provider that receives your personal data as of 31 August 2026 — not a sample. When it changes, this list changes. If you think one is missing, tell us at support@youlocal.app and we will add it.
| Provider | Purpose | Data it receives |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, cache, sign-in (Cognito), file storage, and the AI models behind the concierge (Bedrock / AgentCore) | All categories in Section 2. Stored in the EU — Frankfurt, Germany, for the live service and for our development environment alike. (The only thing hosted elsewhere is this marketing website's own static files, in Ireland; they contain no personal data.) See the note on AI processing below |
| Stripe | Payment processing for real-world bookings | Payment details, entered on your device and sent to Stripe directly; we hold only a customer reference |
| RevenueCat | Managing App Store / Google Play subscriptions and credit packs | Your YouLocal user identifier and your purchase and subscription events |
| Google Firebase Cloud Messaging | Delivering push notifications | Your device push token and the content of the notification |
| Twilio Verify | Sending and checking the one-time code you sign in with | Your phone number, at every sign-in. Twilio generates, stores and verifies the code. Processed in the United States |
| Twilio (WhatsApp) | Only if you choose to send an itinerary to yourself on WhatsApp | Your phone number and a private link to the itinerary file |
| Airlines, hotels and global distribution systems | Actually holding a flight or stay you book — they receive the booking from Duffel, not from us | The traveller details required for that booking. Airline reservations are distributed through industry systems that operate worldwide |
| Third-party ticketing and booking sites | Only if you ask us to book something that has no direct integration — we complete the form on the site for you | The details you gave us for that booking, entered on that site |
| Twilio SendGrid | Sending transactional email (your itinerary, account email) | Your email address, your name, and the content of the message |
| Google Maps Platform (Geocoding, Places) | Turning coordinates into place names, and searching for places | Coordinates — including your live position — and place search text. No name, phone number or account identifier |
| OpenStreetMap Foundation (Nominatim) | Turning coordinates into place names, as a fallback | Coordinates, including your live position |
| Mapbox | Map tiles and static map images, requested by your device directly | Your device’s IP address and the map area being displayed |
| AccuWeather | Weather forecasts where you are or where you are going | Coordinates |
| Stormglass | Sea state and marine conditions for coastal advice | Coordinates |
| FlightAware | Live status of flights you add to a trip | Flight number and date |
| Duffel | Flight and stay search and booking | For bookings only: passenger names, dates of birth (including children’s), travel-document details and contact details |
| Amadeus | Finding the airports nearest a departure or destination point | A coordinate pair for that point. No name or account identifier |
| Perplexity | Live web lookups the concierge performs to answer your question | The search query derived from your request, which may include a place and dates |
| Google Fonts | The app downloads its typefaces from Google’s font servers | Your device’s IP address, when the app fetches a font |
| Apple / Google speech recognition | Converting your dictation to text, on your own device or their servers | Your voice input, handled by your operating system under Apple’s or Google’s policy. It does not pass through us |
| Local experts (“Ask a Local”) | Answering a question you choose to send to a real person in the destination | Only if you use the feature: your question, your first name, and a short trip summary (dates, who is travelling, any needs you told us about). These are individuals under contract, not a company |
This is about our own processing. Some of the third-party services listed above are outside the EU/EEA — notably Twilio, which sends your sign-in code from the United States — and an airline booking is distributed through industry systems that operate worldwide. Where processing occurs outside the EU/EEA we rely on the transfer mechanisms in those providers’ published data processing terms, including EU Standard Contractual Clauses where offered. One provider — the OpenStreetMap Foundation’s public Nominatim service — is a free public endpoint with which we have no processing contract; we are replacing that dependency, and in the meantime the only thing sent to it is a coordinate pair. You can ask us for a copy of the transfer safeguards we rely on by emailing support@youlocal.app.
Separately, if you consent to marketing cookies on our website, Meta also receives limited data as an independent recipient — see Section 7.
The YouLocal mobile app uses no advertising cookies, trackers, analytics or attribution software of any kind. On our website (youlocal.app) we use cookies and similar technologies, grouped by purpose:
| Category | Purpose | Consent |
|---|---|---|
| Strictly necessary | Make the site work and remember your cookie choice | Always on — no consent needed |
| Marketing & analytics | Measure our advertising and understand how visitors reach and use the site | Only with your consent |
Our marketing cookies currently come from the Meta Pixel,
provided by Meta Platforms Ireland Ltd. When enabled it may
transmit your IP address and on-site actions (such as page views) to Meta
and set the _fbp cookie, so we can measure our campaigns. Meta
then processes that data for its own purposes under the
Meta Privacy Policy,
over which we have no control.
| What | How long |
|---|---|
| Your precise location | Expires 48 hours after the last time we hear from you, then deleted automatically (see Section 4) |
| Visit records — which planned stops you reached | Until you delete your account. No automatic expiry today |
| Account and profile data | As long as your account exists |
| Trips, itineraries and saved places | Until you delete them, or until you delete your account. You can set automatic archiving of old itineraries under Settings |
| Concierge conversations, and the preferences the concierge has learned | Until you delete your account |
| Push notification token | Until you turn notifications off or delete your account |
| Server logs | Short-lived operational retention (currently a matter of weeks), then discarded automatically |
| Website marketing cookie | Set by Meta under its own lifetime; clear your browser’s site data to remove it |
When you delete your account we erase your personal data from the systems listed in Section 10, and that section also says plainly what our automated erasure does not yet reach.
Under GDPR you have the right to:
You can delete your account at any time from Profile → Delete account in the app. It happens immediately, you are signed out, and what is deleted cannot be recovered.
Deletion removes: your profile and inferred preferences; your trips, itineraries, saved places and travel spaces; the companion details you added; your conversations with the concierge, including archived copies; your visit records and your current location record; your device push tokens; your payment-provider reference; the credentials for any third-party account you connected; the blocks you had set (on both sides, so nobody is left permanently blocked by an account that no longer exists); and your sign-in identity.
Deletion also runs across several separate storage systems. If one of them fails, the others still complete and the failure is recorded on our side so the job can be finished. If you want confirmation that everything was removed, ask us and we will check and reply.
Note that a subscription bought through the App Store or Google Play is managed by Apple or Google, not by us: deleting your YouLocal account does not cancel it. Cancel it in your Apple or Google account settings.
If you have uninstalled the app or cannot sign in, see Delete your account for the request route.
The concierge is an AI system, and it forms a picture of your travel preferences from what you tell it, what you save and which suggested places you actually visit. It uses that picture to choose what to suggest and how to write to you. It does not make decisions with a legal or similarly significant effect on you: it does not price you differently, does not decide your eligibility for anything, and does not profile you for advertising. You can see and correct your profile in the app, and you can object to this profiling by writing to us.
YouLocal accounts are for adults. You must be at least 16 to hold one, and we do not knowingly let children create accounts. We do not verify age at sign-up — we sign you in with a phone number and a one-time code — so this rests on your declaration.
We must be straightforward about a related point, because a blanket “we do not collect children’s data” would be false. If you are planning a family trip, you can tell us who is coming, including children and infants, and we will hold what you give us: a name, whether they are an adult, child or infant, and — only if you add them — a date of birth, travel-document details for a booking, and any dietary, health, mobility or accessibility needs. Where a flight or stay requires it, passenger details including a child’s date of birth are passed to the booking provider.
That data is used only to plan and book that trip. It is deleted when you remove the companion or delete your account. Please add only what is actually needed, and only for people you are entitled to act for. If you believe a child has created an account, or that data about a child is held here that should not be, contact us and we will delete it.
This section exists because the honest description is more than “we learn your travel preferences”, and you are entitled to the specific version.
From your conversations, what you save and which suggested places you actually visit, an automated system estimates five broad personality traits — openness, conscientiousness, extraversion, agreeableness and emotional sensitivity. These are inferences, not facts: nobody asked you these questions and you never answered them.
What they are used for: ordering what you see — which suggestions appear near the top of your list. They are also given to the concierge as context so its tone and suggestions fit you. They are not used to set prices, to decide what you are allowed to do, to assess you for any benefit, or for advertising — and they are never shared.
Nothing here decides anything about you in a legal or contractual sense; it changes the order of travel suggestions. If you would rather it did not:
In the app, Profile → Your travel style shows what the concierge believes about you in plain language, and what it is still unsure of. That screen is deliberately written in everyday words rather than trait scores — the scores are what this section is for.
Traffic between the app and our servers travels over encrypted connections (HTTPS/TLS). Our databases and our cache are encrypted at rest, and the cache is also encrypted in transit inside our network. Credentials for third-party services you link are held in a dedicated secrets manager, not in our database. Access to production systems is on a least-privilege basis. No system is perfectly secure, but we work continuously to safeguard your information.
Fixed since the last version of this page. Until 31 August 2026 this section disclosed that the final internal hop — from our content-delivery network to the server that answers — was unencrypted. It is now encrypted (TLS 1.2), and that server no longer accepts requests that did not come through our network. We said we would update this page the day it shipped rather than before, so we are.
One exception remains, and we would rather tell you than let “all data is encrypted in transit” stand as a claim that is not fully true. The call we make to our weather provider to look up conditions for a coordinate is made over an unencrypted connection. It carries a coordinate pair only — no name, phone number or account identifier. We are moving it.
We may update this policy. We will revise the “Last updated” date above and, for material changes, notify you in the app. Where a change would widen how we use location data, we will publish the change before we make it, not after.
Questions or requests:
support@youlocal.app
YouLocal Eolas Limited, Suite 31, The Pottery, Bakers Point, Pottery Road,
Dún Laoghaire, Dublin, A96 EV18, Ireland.