1. Who this applies to
You if you use the iPhone app, visit waymora.app, write to us, or buy Waymora Pro through the App Store. The public site is a landing page and research pages. The Journey, Documents, Copilot, and Atlas calculators run on iPhone.
2. What we do not send to a hosted model
A Privacy Firewall classifies text by origin and schema before any hosted DeepSeek call. Unmatched typed text is not treated as public. The hosted model does not receive raw passports, names, emails, dates of birth, exact addresses, case numbers, child data, document contents, or personally attributable immigration status. If a safe public prompt cannot be built, Copilot returns official Source Cards or a block message and the model is not called.
Source retrieval may send only that generic public prompt to Workers AI for embeddings. Questions that are not public questions use lexical ranking only. That path is separate from DeepSeek.
3. Data that stays on your iPhone
These records live in on-device storage unless you share them yourself:
- Journey profile: origin, destination, purpose, case type, and planned timing.
- Journey progress, appointment notes, and destination notes you type.
- Document Vault metadata and files. Vault bytes are encrypted on the device. Readiness checks log a document id, not the file.
- Family Window phase, stamps, and an optional “I’m safe” time. The share payload has no coordinates.
- Scam evidence you save (URLs, notes). Export is something you start.
- A random device subject identifier used only to count daily AI quota.
- Change-alert preference and similar settings.
Deleting the app removes this on-device data. We cannot read your Vault from our servers.
4. Data that reaches Waymora servers
The API runs on Cloudflare. When you use a networked feature we may process:
- Copilot questions, destination-scaffold or customize text, and travel-money explanations. That text reaches Waymora first. A rule classifier runs before any hosted DeepSeek call. A match stops the model. Allowed prompts are treated as public. Travel-money prompts carry origin, destination, spend kind, and card product names from the on-device table. They do not carry card numbers.
- The device subject identifier, Pro status used for quota, model name, whether the call was blocked, token counts, and a timestamp. Usage rows do not store passport numbers or Vault files.
- Daily quota counters (Copilot: 0 free / 300 Pro; destination generation: 0 free / 600 Pro, per UTC day). Safety classification is not counted.
- An optional Sign in with Apple bind. It attaches an Apple user id to the existing device subject. It does not replace that subject.
- Technical request data Cloudflare needs to serve the API and the public site (IP address, user agent, timestamps, error traces).
The app can also fetch public official-portal lists, Source Cards, and Atlas figures. Those requests carry ordinary network metadata, not your Vault.
5. Purchases
Waymora Pro is sold through Apple In-App Purchase (StoreKit 2). RevenueCat tells the app whether Waymora Pro is active. Apple processes the payment. We receive subscription status, product identifier, renewal state, and expiration. We do not receive your full card number.
Safety tools stay usable without a subscription: emergency contacts, official portals, Official Portal Guard, and critical scam warnings.
6. What we do not collect today
- Advertising identifiers or cross-app tracking.
- Precise or coarse location.
- Contacts, photos library, microphone, or camera photo rolls.
- A required Waymora account or email login.
- Crash or analytics SDKs from a third-party product-analytics vendor.
- Payment card numbers.
If a later release adds a category, we will update this policy and the App Store privacy labels before that data is collected.
7. How we use data
- Run the Journey, Copilot, quota, and official-source features you ask for.
- Recognize Waymora Pro and restore purchases.
- Stop abusive or oversized AI use.
- Keep the API and public site up, and diagnose failures.
- Respond when you write to us.
We do not use this data to advertise other products to you.
8. Who else processes data
- Apple. App Store, StoreKit, and on-device system services. Apple’s privacy rules apply to purchases and anything you share through the system share sheet.
- RevenueCat. Subscription status. See RevenueCat’s privacy policy.
- Cloudflare. Hosts waymora.app and the API (Workers, D1, KV, R2, Queues, Durable Objects, Analytics Engine, AI Gateway). See Cloudflare’s privacy policy.
- DeepSeek. Hosted generative model for Copilot and destination generation after the Privacy Firewall. DeepSeek’s own policy says its services are not intended for sensitive personal data including citizenship and immigration status. That is why prohibited classes never leave as model input. See DeepSeek’s privacy policy.
We may disclose information if required by law, to protect a person from serious harm, or to defend a legal claim. We do not sell personal information and we do not share it for cross-context behavioral advertising.
9. Family Window and sharing
Family Window is a read-only progress view you create. Recipients see phase, stamps, and an optional “I’m safe” time. They do not get a map pin or street address from Waymora. If you use the iOS share sheet, Apple and the app you pick apply their own terms.
10. Public website
waymora.app is a static landing and research site. Pages may be crawled by search engines. We do not run advertising cookies. Host logs on Cloudflare may include IP address and user agent for security and delivery. Contact forms are not on the site; you write to the addresses below.
11. Retention
- On-device Journey, Vault, and Family Window data: until you delete it or delete the app.
- Daily AI quota counters: the current UTC day, then they reset.
- Server usage rows (subject id, model, privacy class, time): kept to operate quota, debug failures, and review abuse. Write to [email protected] if you want those rows deleted.
- Purchase records: retained by Apple and RevenueCat under their policies.
- Support and correction emails: kept long enough to resolve the request.
12. Security
Transport uses HTTPS. Vault files are encrypted on the device. Hosted model calls are blocked when the Privacy Firewall finds a prohibited class. No method is perfect. Do not put a live passport image into Copilot. The product is built so you do not need to.
13. Your choices
- Use the free safety tools without buying Pro or calling Copilot.
- Leave personal details out of Copilot. The firewall will also refuse many of them.
- Revoke a Family Window session in the app.
- Restore, change, or cancel Waymora Pro in your Apple ID subscriptions.
- Delete the app to wipe on-device data.
- Email [email protected] to ask what server-side quota or usage records we hold for a device subject identifier, or to ask us to delete them.
Depending on where you live, you may also have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to complain to a data-protection authority. Waymora does not create a required cloud account. Journey, Vault, and Family Window records stay on the phone unless you export or share them. Copilot and destination text still leave the phone to Waymora first. We will not discriminate against you for exercising a privacy right.
14. Children
Waymora is built for adults planning a move. It is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child submitted personal data to us, write to [email protected] and we will delete what we hold.
15. International processing
Cloudflare and DeepSeek may process allowed data in countries other than yours. Purchase data is processed by Apple and RevenueCat where they operate. If you use Copilot, you are asking us to send a firewall-cleared public prompt through that path.
16. Changes
If we change what we collect or who processes it, we will update this page and the effective date. Material changes will also be reflected in the App Store privacy labels when those labels require it.