Mikolaj Piech, operating Trailo (“we”), is the data controller for personal data processed through trailoapp.com and the Trailo apps. Contact: support@trailoapp.com.
What we collect
Depending on how you use Trailo, we may process:
- Account data: email, password hash, name, profile photo, language preference, optional onboarding answers
- Trip data: plans, messages, uploads, collaborators, tickets, and traveler details you add
- Group poll responses if you use a shared poll link without an account
- Payment status and purchase history (card details are handled by Stripe, not us)
- Booking details you submit when booking flights or hotels in the app
- Approximate location if you allow it, or inferred from IP during planning chat
- Session cookies, a locale cookie, device storage, server logs, and AI usage metadata
Why we use it
We use this data to provide and run the service, process payments, send account and invite emails, prevent abuse, and comply with law. Legal bases: contract (providing Trailo), legitimate interests (security and operations), and legal obligation where applicable. We do not sell your data or use advertising trackers.
AI features send your messages and relevant trip data to xAIfor planning and editing. When encrypted document analysis runs, the selected file is decrypted on your device and sent directly to our AI endpoint and xAI for analysis; the plaintext file is not written back to Supabase Storage. xAI's own data handling and retention terms apply. That provider may also use web search. See our Terms regarding AI output.
Document file protection
Ticket, wallet, and journal files use private cloud storage protected by sign-in and current trip membership. This lets authorized trip members open files automatically on any signed-in device. The files are encrypted in transit and at rest by our infrastructure, but Trailo's service and administrators can technically access them when needed to operate, secure, or support the service.
A small number of older files may still use Trailo's retired end-to-end encryption format. Those files require an authorized device or their recovery code once before they can be converted to the current storage format. If every recovery method was lost, Trailo cannot restore those legacy files. Trip members may retain copies they previously opened or downloaded, and removing a member cannot erase copies already in that person's possession.
Who we share it with
We use processors including:
- Supabase, hosting, auth, database, and ciphertext storage
- Stripe, payments
- xAI, AI features
- Google, sign-in, if you choose it
- LiteAPI, bookings, if you use them
- Map, geocoding, hosting, and infrastructure providers needed to run the app
Some providers are outside the EEA (including the US). Where required, transfers use appropriate safeguards such as Standard Contractual Clauses.
Retention
Account and trip data are kept until you delete them or your account. Payment records are kept as required for tax and disputes. You can permanently delete your account in the Trailo app (Account → Delete account) or on the web (account menu → Delete account). Deletion removes your account, profile data, and trips you alone belong to. App Store or Google Play subscriptions are not cancelled automatically – manage those in the store settings. You can also contact support@trailoapp.com.
Your rights
Under the GDPR you may request access, correction, deletion, restriction, portability, or object to certain processing. Contact support@trailoapp.com. You may also complain to the Polish data protection authority (UODO) at uodo.gov.pl.
Cookies
We use essential cookies for sign-in and language preference. We do not use analytics or advertising cookies.
Changes
We may update this page. The “Last updated” date shows the current version.

