Privacy Policy
Voykit works without an account. If you sign in, we keep only what the features you use need, we never sell your data, and you can export or delete it at any time. Effective 30 September 2026.
Who we are
- Voykit (www.voykit.com) is a travel planning website. In this policy, "we" means the people who run Voykit, and "you" means anyone who uses the site.
- Questions or requests about your data: email privacy@voykit.com. We answer within 30 days.
Using Voykit without an account
- You can read every guide and use every tool without signing in.
- Trips, saved places, your profile, the journal, display settings and similar choices are stored in your own browser (localStorage, IndexedDB and the Cache API). They stay on your device until you clear the site's data. We cannot see them.
- The health card, medicine card and journal photos are stored only on your device and are never uploaded, even when you are signed in.
What we collect when you sign in
- Email sign-in: your email address. We send a one-time link and code to it; there is no password.
- Google sign-in: from your Google account we receive your name, email address and profile picture, and nothing else. We use them only to create and identify your Voykit account.
- Account data you choose to sync: your traveller profile (for example home city, passport country, currency, diet and pace), trips and their items, saved places, city alerts you follow and your notification settings.
- Shared trips: the people you invite and their role, comments on trip items, and files you attach to a trip (such as tickets or booking confirmations). Attached files are private to the members of that trip.
- Basic records needed to run the service: the time of sign-ins, daily counts of AI drafts (to enforce limits), and corrections or questions you send us.
How we use it
- To sign you in, keep your trips in sync across devices, let trip members work together, send the reminders and alerts you ask for, answer your messages and corrections, and keep the service secure and within its limits.
- We do not sell your personal information, we do not use it for advertising, and we do not build advertising profiles.
- "Most saved on Voykit" shows only pages saved by at least five different people, as a rounded count. It never shows who saved them.
Google user data
- Voykit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We request only the basic sign-in scopes (openid, email, profile). We do not access your Gmail, Calendar, Drive, contacts or any other Google data, and we do not use Google user data to train AI models.
AI trip drafts
- When a signed-in user asks for an AI draft, we send the trip request (cities, number of days, pace, interests, budget level, party size and mobility needs) and a list of places from Voykit's own guides to an AI model through OpenRouter. The current models are DeepSeek V4.1 Flash, with Qwen3.8 Flash and GLM 5.3 Flash as fallbacks.
- We do not send your name, email address, notes or files. We do not store the prompt or the answer; we log only the error type, timing and token counts.
- AI drafts can be wrong. Check times and bookings before you rely on them.
Services that receive data to make features work
- Supabase: accounts, synced data and trip files (database and file storage).
- Vercel: hosting. Like any web host, it receives your IP address and browser details when you load a page.
- OpenRouter and the AI model providers it routes to: AI trip drafts, as described above.
- Open-Meteo: weather forecasts. We send the coordinates of the city or place you are looking at.
- OpenStreetMap's Overpass API: the "near me" tools (toilets, pharmacies, vegetarian food, embassies, unusual places). Only when you tap to search, we send your approximate position as the center of that search. It is not stored by us.
- open.er-api.com: currency exchange rates. No personal data is sent.
- jsDelivr: the text-recognition files for the photo translate tool are downloaded from it. Your photos are processed on your device and are not uploaded.
- Wikimedia Commons: photos on guide pages load from its servers.
- Email delivery: sign-in emails and reminders are sent through our email provider to the address on your account.
Location
- Voykit asks for your location only when you tap a button that needs it (for example "Near me" or "Toilets near me"). The position is used for that search and kept on your device; we do not store it on our servers.
How long we keep data
- Account data is kept while your account exists. When you delete your account, your profile, trips, saved places, comments and trip files are deleted.
- Daily AI usage counters are kept for up to 30 days. Corrections you send are kept while they are useful for fixing the guides.
- Backups held by our providers are overwritten on their normal schedule.
Your choices and rights
- From your Account page you can download a copy of your data and delete your account.
- You can use Voykit without signing in at all, and you can turn cloud sync off at any time.
- Depending on where you live (for example the EU, UK, California, Canada or Australia), you may have rights to access, correct, delete or move your data, and to object to or restrict some uses. Email privacy@voykit.com and we will help. You can also complain to your local data protection authority.
Security
- Data in our database is protected by row-level security, so each account can reach only its own data and the trips it was invited to. Trip files are private and opened through links that expire after 60 seconds.
- No system is perfectly secure. If we learn of a breach that affects your data, we will tell you as the law requires.
Children
- Voykit is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.
International transfers
- Our providers may process data in countries other than yours, including the United States and countries in the Asia-Pacific region. We use providers that protect data under their own contracts and security standards.
Changes to this policy
- When we change this policy we update the date at the top. If a change is significant, we will say so on the site and, for signed-in users, by email before it takes effect.