PRIVACY POLICY

Last Updated: March 25, 2026

Effective Date: March 25, 2026

View Version History →

At a Glance ✨

  • Data We Collect: Account info, trip details, user content, real-time location (for navigation), phone number (for SMS verification), and gamification data (points, coins, leaderboard rankings).
  • AI Usage: We use Google Gemini to generate itinerary suggestions.
  • Agencies: If you join an Agency trip, they can see your location & profile during that trip.
  • Privacy Controls: Use "Ghost Mode" to pause location sharing anytime. iOS users can limit tracking via ATT.
  • Security: Direct messages are E2E encrypted. Group chat metadata is not encrypted. We auto-purge deleted messages.
  • No Selling: We do not sell your personal data to third parties.

Polyhistor Inc ("Company," "we," "us," or "our"), a corporation organized under the laws of the State of Delaware, is committed to protecting your privacy. This Privacy Policy describes how we collect, process, and safeguard your information when you use the Polyhistor mobile application and associated services (collectively, the "Service").

By creating an account or using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

We collect data to provide accurate navigation, AI-driven recommendations, social connectivity, and gamification features.

A. Information You Provide

  • Account Registration: When you create an account, we collect your username, email address, phone number (for SMS verification), and password (hashed for security).
  • Profile Information: You may provide a display name, bio, date of birth, gender, hometown, language, and timezone settings.
  • Trip & Itinerary Data: We collect trip details including destination, budget, start/end dates, and itinerary items (flights, hotels, activities).
  • User Content: This includes messages, photos (profile pictures, trip covers), comments on itineraries, and votes.
  • Gamification Data: We collect and track your points, coin balances, leaderboard rankings, referral codes, and achievement badges earned through app engagement.

B. Information Collected Automatically

  • Real-Time Location & Navigation History: To provide routing and "Live Tracking," we collect your precise latitude, longitude, speed, and heading. We store Navigation Sessions (origin, destination, waypoints) and Location History timestamps.
  • Device & Usage Data: We use analytics tools (PostHog and Sentry) to collect device models, IP addresses, operating systems, crash logs, and interaction metrics to improve App stability.
  • Media Metadata: When you upload images, we may process metadata associated with the file.

2. Artificial Intelligence (AI) & Automated Processing

We use advanced AI to personalize your travel experience.

  • Generative AI (Google Gemini): We utilize Google's Gemini models to generate itinerary suggestions and travel advice. Anonymized query data is sent to our AI partners to generate responses.
  • Vector Embeddings: We process your travel preferences and historical trip data to create "embeddings" (mathematical vector representations). These are stored in our database to help our AI "understand" your travel style and find semantically similar locations.

3. How We Use Your Information

  • Navigation: To calculate routes, provide lane guidance, and estimate arrival times using Mapbox and Google Places.
  • Social Connectivity: To facilitate Friend requests, Group chats, and location sharing between connected users.
  • Agency Integration: If you accept an invite from a Travel Agency, we link your account to that Agency to facilitate professional trip planning.
  • Communication: To send push notifications (via Firebase) and emails (via Resend) regarding trip updates, friend requests, or security alerts. We may also send SMS messages for verification purposes.
  • Gamification: To track your points, coin balances, leaderboard rankings, and referral activity. This data is used to display your progress and enable social competition features.
  • Safety & Moderation: We employ automated and manual moderation to detect hate speech, harassment, or unsafe content in compliance with our community standards.

4. Data Sharing and Third Parties

We do not sell your personal data. We share data only with the specific infrastructure providers necessary to run the Service:

  • Cloud Infrastructure & Storage: AWS S3 for secure file storage (images, media) and Supabase for database hosting and real-time data synchronization.
  • Maps & Location: Mapbox, Google Places, and OpenMeteo (weather data) to provide map interfaces and environmental context.
  • Analytics & Stability: PostHog (analytics) and Sentry (error tracking).
  • Travel Agencies: Important: If you join a trip organized by an Agency or link your account to an Agency, that Agency's staff will have access to your name, profile, real-time location during the trip, and itinerary details.

5. Messaging and Encryption

  • End-to-End Encryption (E2E) for Direct Messages: Your one-on-one direct messages are protected with end-to-end encryption. Messages are stored with an Initialization Vector (IV) and Auth Tag, ensuring that only you and the recipient can read the content.
  • Group Chat Encryption: Group chat messages are encrypted in transit and at rest, but group chat metadata (participant lists, group names, timestamps) is not end-to-end encrypted and may be accessible to Polyhistor for moderation and service operation purposes.
  • Retention: We implement an auto-purge policy for deleted messages. While a message is removed from the user interface immediately upon deletion, a backup may be retained for up to 90 days for safety and moderation auditing before being permanently erased.

6. Control Over Your Data

  • Ghost Mode: You can toggle "Ghost Mode" within the application to pause real-time location sharing with friends and groups.
  • Privacy Settings: You can manage notification preferences (Push/Email/SMS) and friend request settings in your User Settings.
  • Blocking: You have the right to block other users. Blocked users cannot see your location or send you messages.
  • Apple App Tracking Transparency (ATT): iOS users will see an ATT modal requesting permission to track. You can choose to limit tracking, which affects personalized advertising and analytics data collection. See Section 11 for details.

7. Data Retention

We retain your personal data only as long as necessary:

  • Account Data: Retained until you request deletion.
  • Navigation History: Retained to provide your personal travel history logs. You may delete specific trips from your history.
  • Gamification Data: Points, coins, and leaderboard data are retained as long as your account is active. Upon account deletion, this data is permanently removed.
  • Inactive Accounts: We reserve the right to delete accounts that have been inactive for an extended period.

8. Security

We use industry-standard security measures, including HTTPS encryption in transit and database encryption at rest. However, no method of transmission over the Internet is 100% secure. You are responsible for maintaining the secrecy of your unique password and account information.

9. Children's Privacy

The Service is intended for general audiences and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete such information from our files.

10. Jurisdiction and International Transfers

Polyhistor Inc is a Delaware corporation. Your information may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those from your jurisdiction.

11. Apple App Tracking Transparency (ATT)

For iOS users, Apple requires apps to request your permission before tracking your activity across other companies' apps and websites. When you first launch Polyhistor on iOS, you will see an App Tracking Transparency (ATT) modal asking for your consent.

  • If You Allow Tracking: We may collect data about your app usage for personalized advertising and analytics purposes. This helps us improve the app and show you more relevant content.
  • If You Request App Not to Track: We will not collect tracking data for advertising purposes. You will still receive a fully functional app experience, but ads and recommendations may be less personalized.
  • Changing Your Choice: You can change your ATT preference at any time in your iOS device Settings > Privacy > Tracking.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Polyhistor Inc
Email: naveengali@thepolyhistor.com