Skip to content
Journew
  • Features
  • FAQ
DE Coming soon

Privacy Policy

In short: Your trips stay your business – they live on your device and, if you like, in your own iCloud; we cannot see them. When you sign in with Apple, all we receive is an identifier Apple assigns specifically for Journew: no name, no email address. Only what you deliberately send us reaches our servers – place ratings and photos. Photos are publicly visible after a review. We do not build a profile about you.

This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data in connection with the use of the Journew app (the “App”) and about your rights under the General Data Protection Regulation (GDPR). The App is designed to process as little personal data as possible: your trip data generally stays locally on your device or in your iCloud account, to which the developer has no access. Only for individual features is a limited amount of data transmitted to a server operated by the developer.

Table of contents

  1. Controller
  2. Scope and target audience
  3. Trip data: local storage, iCloud and sharing
  4. Map display and location
  5. Journew Pro (subscription)
  6. Loading of additional content
  7. Reporting of added places (“Popular places”)
  8. Signing in with Apple (“Sign in with Apple”)
  9. Place ratings
  10. Photos of places
  11. Device integrity check (Apple App Attest)
  12. Website and hosting
  13. Legal bases for processing
  14. Recipients and processors
  15. Transfer of data to third countries
  16. Storage period
  17. Your rights as a data subject
  18. Right to lodge a complaint with a supervisory authority

1. Controller

The controller within the meaning of the GDPR, hereinafter also the “developer”, is:

Tobias Klüver Rethelstr. 34 40237 Düsseldorf, Germany Email: [email protected]

If you contact the developer by email – for example with an enquiry, an objection or to exercise your rights – your email address and the content of your message are processed to handle the matter (Art. 6(1)(b) or (f) GDPR) and deleted once the matter has been dealt with conclusively and no statutory retention obligations stand in the way.


2. Scope and target audience

This Privacy Policy applies to the use of the Journew app on Apple devices and to visiting the website https://journew-app.com (see Section 12). It does not apply to third-party services (e.g. Apple/iCloud), for which their own privacy policies apply. The App is intended exclusively for adults aged 18 and over.


3. Trip data: local storage, iCloud and sharing

All trip data you create in the App is stored locally on your device and does not leave it as long as you do not enable iCloud synchronisation. If iCloud is enabled, the data is synchronised to a private database of your iCloud account (Apple infrastructure/CloudKit); only you have access to it, not the developer. Synchronisation can be disabled at any time in the device’s iCloud settings.

You can share individual trips with other people. In doing so, the trip and its associated activities, accommodations, fellow travellers and tickets are transferred to a shared iCloud database that the invited persons can access; here, too, the developer has no access. After sharing ends, residual data may, for technical reasons, remain on the devices of formerly invited persons (see the Terms of Use for details).

You can delete your data at any time via the App or the iCloud settings.


4. Map display and location

To display destinations and activities, the App shows map material via Apple frameworks (Apple Maps / MapKit); this processing is carried out by Apple. The App does not request your location and does not process any location data.


5. Journew Pro (subscription)

The paid features (“Journew Pro”) are offered as a subscription via the App Store; purchase and payment are handled exclusively by Apple, and the developer receives no payment data.

To unlock the features, the App transmits the Apple-signed purchase receipt (StoreKit transaction) to the developer’s server, which queries Apple as to whether the subscription is active. If it is active, the server issues a short-lived access token that contains, as an identifier, solely the transaction number of the subscription assigned by Apple. The purchase receipt is not stored permanently.


6. Loading of additional content

When using the App, additional content is loaded from a server operated by the developer, for example recommended activities and popular destinations.

In the process, general technical details (such as device type, operating system and App version) and the travel details required for the request (such as destination and travel period) are transmitted and stored anonymously – without any attribution to you. In addition, your IP address is processed in order to limit the number of requests per connection (protection against misuse); it is used solely for that purpose, is not linked with the other data, and is deleted no later than seven days after the last request.

Some of this content is in turn obtained by the server from further third-party providers. During this retrieval, no data about you is transmitted to those providers; only general, non-personal parameters (such as a country or calendar year) are queried.

Where loaded content is in a foreign language, it can, at your request, be translated using Apple’s translation framework – preferentially on your device; however, processing on Apple’s servers cannot be ruled out. In that case, Apple’s privacy policy applies in addition (see Section 14).

Legal bases: Where you actively invoke one of these features, the provision of the requested content serves to perform the App function you requested (Art. 6(1)(b) GDPR); transmitting the request (such as destination, country or year) is necessary for this. The processing of the IP address to limit requests, as well as the anonymously stored technical details used to improve recommendations, are based on the developer’s legitimate interest (Art. 6(1)(f) GDPR). You can disable the loading of additional content in the App settings.


7. Reporting of added places (“Popular places”)

If you add an activity or accommodation from the loaded place search to a trip, the App reports this to the developer’s server so that the App can show which places are added to trips particularly often.

Transmitted are the identifier of the place and a random identifier of the trip. The latter serves fraud prevention (detecting duplicate reports) and is stored solely as an irreversible check value (hash). Your IP address is processed – as described in Section 6 – solely to limit reports and is deleted within seven days.

No profiling takes place, and the information is not combined with other data. You can object to this processing at any time by disabling the report in the App under “Settings → Privacy”.


8. Signing in with Apple (“Sign in with Apple”)

Using the App requires signing in with “Sign in with Apple”. It is also what makes it possible to attribute your ratings (Section 9) and photos (Section 10) to you.

Your device transmits an identity token signed by Apple to the developer’s server. Only the app-specific user identifier that Apple assigns exclusively for Journew is stored from it; your name and email address are not requested and not transmitted. The identifier allows no conclusions about your Apple ID but qualifies as personal data under data protection law. It is stored in plain text.

After signing in, the server issues short-lived session tokens; server-side, only irreversible check values together with the associated timestamps are stored (for the duration, see Section 16). The tokens are stored on your device in the keychain; this storage is strictly necessary to provide the server-dependent features (Section 25(2) no. 2 TDDDG) and does not require consent.

When you sign in, your IP address is processed – as described in Section 6 – solely to limit requests and is deleted within seven days.

Signing out in the App revokes all refresh tokens. You can additionally revoke the App’s access in the settings of your Apple account; you delete your ratings and photos in the App (Sections 9 and 10).

If you revoke that access or delete your Apple account, Apple notifies us. We then revoke all sessions and delete your ratings, your subscription assignment and your upload blocks. Photos already published are retained, but lose any link to you (Section 10).

Legal basis: Performance of the user contract and of the features you have requested (Art. 6(1)(b) GDPR); the sign-in requirement also serves to protect published content against misuse (Art. 6(1)(f) GDPR). As part of signing in, your device communicates with Apple (see Section 14).


9. Place ratings

You can rate a place (such as a sight, activity or accommodation) against several criteria – such as recommendation, overall impression or atmosphere; some details are mandatory, the rest optional. The App transmits your rating to the developer’s server so that it can be aggregated per place into a summary for all users, and so that you can find, change and delete your own ratings across your devices. Individual ratings of other people are not displayed.

For each rating, the following are stored: your answers to the rating criteria, the time of the rating, and your pseudonymous user identifier from signing in with Apple (Section 8). This identifier is stored in plain text. It serves solely to attribute your own ratings to you across your devices (so that you can manage them) and to prevent duplicate or fraudulent ratings of the same place: per user identifier and place, at most one rating is possible; a new rating overwrites the previous one.

Every request that stores a rating is additionally secured by the device integrity check (Section 11). Your IP address is processed – as described in Section 6 – solely to limit requests, is not linked with the stored data, and is deleted within seven days.

Legal basis: The processing is based on the developer’s legitimate interest (Art. 6(1)(f) GDPR) in providing users with a community place-rating feature and protecting it against distortion by duplicate or fraudulent ratings (cf. Recital 47). Because the stored data relates solely to the respective rating, is not linked with other datasets and involves no profiling, the developer’s interests prevail. You can object to this processing at any time by not submitting a rating or by deleting a submitted rating in the App; the associated data is thereby completely removed.


10. Photos of places

You can upload your own photo for a place. It leaves your device and is stored on the developer’s server. Photos may also show other people; the uploading user is responsible for the lawfulness of the picture and its publication (see the Terms of Use). If you see yourself depicted in a photo, you can report it in the App or contact the address stated in Section 1; the developer reviews it and removes the photo in the event of a breach. After a successful review it is publicly retrievable: in the App at that place and via a public internet address to anyone who knows it. Your user identifier is not published.

Stored are: the image file and a thumbnail, the place, your user identifier from signing in with Apple (Section 8), the time, technical details about the image including a check value to detect duplicate uploads, and your IP address at the time of the upload. Unlike in Sections 6, 7 and 9, that IP address is retained for twelve months from the upload and serves to prevent misuse, in particular to enforce the upload blocks.

Review before publication: The image file is transmitted to OpenAI and automatically examined for prohibited content (Sections 14 and 15). If it is flagged, the photo is rejected and the image file deleted immediately; otherwise the developer reviews it manually before release.

History: For each photo, the key events are recorded (such as upload, review decisions and deletion) – in each case with the time and your user identifier. The history serves as a record of the moderation decisions and to prevent misuse.

Reports: If you report a photo, your user identifier, the reported photo, the time, your optional description, the processing status and the messages exchanged about it are stored. The reported user is not told who filed the report.

Upload blocks: If photos of yours are repeatedly rejected, the server blocks further photo uploads temporarily, and permanently if rejections continue. Stored are your user identifier and the type, reason and duration of the block. The block concerns photo uploads only; you can object to it at the address stated in Section 1.

Deletion: You can delete your photos at any time in the App under “Settings → My content”. For the storage period, see Section 16.

When your Apple account ends: If you delete your Apple account or revoke the App’s access, photos already published are retained; we merely remove your user identifier and the upload IP address, so that the photo is no longer attributable to you. The basis is the unlimited-in-time right of use granted on upload, which ends only when the individual photo is deleted (Terms of Use § 9 (3) and (8)). If you no longer want a photo to be published, delete it in the App before deleting your account — afterwards you can no longer remove it yourself and must contact the address given in Section 1.

Legal bases: Uploading, storing, publishing and managing your photos is carried out to perform the feature you have requested (Art. 6(1)(b) GDPR). The content review, the history, the upload IP address, duplicate detection and the upload blocks are based on the developer’s legitimate interest (Art. 6(1)(f) GDPR) in keeping unlawful content from being published and preventing misuse; without this review, photos could not be displayed publicly. Handling reports also serves the developer’s compliance with legal obligations (Art. 6(1)(c) GDPR).


11. Device integrity check (Apple App Attest)

To protect the developer’s servers against misuse (e.g. automated access by modified or cloned apps), the App proves, when making requests to the server, by means of Apple’s App Attest (DeviceCheck) procedure that it is running as an unmodified Journew app on a genuine Apple device.

Already when the App starts, a request is sent to the server for this purpose in order to keep a valid proof token ready for later requests – regardless of whether you use server-dependent features. This behaviour cannot currently be disabled.

Only technical attestation data is stored: an Apple-assigned key identifier together with the associated verification data and timestamps. This identifier is not directly attributable to a person and contains neither your name nor your Apple ID, device identifiers or trip content; it relates solely to the respective App installation, but under data protection law it qualifies as pseudonymous personal data. During the procedure, your device communicates with Apple (see Section 14).

The App additionally stores on your device the proofs and access tokens required for server access (see also Section 5). This storage is strictly necessary for providing the server-dependent features (Section 25(2) no. 2 of the German TDDDG) and therefore does not require consent.


12. Website and hosting

The website https://journew-app.com is hosted on a server operated by the developer at OVHcloud in Germany (Section 14). When it is accessed, technically necessary connection data (in particular IP address, time, page accessed, user agent) is processed in order to deliver the website and ensure the security of the service; it is deleted no later than seven days after the visit. The developer uses no cookies and no tracking or analytics services on the website.


13. Legal bases for processing

Where the developer processes personal data, this is done on the following legal bases:

  • Art. 6(1)(b) GDPR (performance of the requested function): for the core features of the App and the management of your trip data, signing in with Apple and session management (Section 8), uploading, publishing and managing your photos (Section 10), the verification of the Pro subscription (Section 5), and the provision of the additional content you actively invoke (Section 6).
  • Art. 6(1)(a) GDPR (consent): for iCloud synchronisation and the sharing of trips (Section 3). You may withdraw any consent given at any time with effect for the future by disabling synchronisation or ending sharing.
  • Art. 6(1)(f) GDPR (legitimate interests): for the map display (Section 4), limiting the number of requests per connection and the anonymously stored technical details used to improve recommendations (Section 6), the reporting of added places (Section 7), the place ratings (Section 9), the content review of photos, their history, the storage of the upload IP address and the upload blocks (Section 10), the device integrity check (Section 11), and the provision and protection of the website (Section 12). In these cases the developer’s interests prevail, because the data relates to individual requests, App installations or the uploaded content itself; no profiling takes place and the data is not combined with other datasets.
  • Art. 6(1)(c) GDPR (legal obligation): for handling and documenting reports about photos (Section 10), to the extent that the developer, as a provider, is subject to statutory duties regarding reported content.

Right to object: You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). You can object to the reporting of added places (Section 7) directly in the App under “Settings → Privacy”; you can object to your place ratings (Section 9) and your photos (Section 10) by deleting the respective rating or photo in the App; you cannot object to the content review separately, because without it publication is not possible. The device integrity check (Section 11) and the limitation of requests (Section 6) are indispensable technical prerequisites of every request to the server, cannot be disabled and are therefore based on compelling legitimate grounds within the meaning of Art. 21(1) GDPR; without them, the server-dependent features cannot be provided. Your trip data stored locally on the device and in iCloud remains unaffected and usable.

Automated decision-making producing legal effects concerning you or similarly significantly affecting you (Art. 22 GDPR) does not take place: the automatic rejection of a photo and the automatic upload block (Section 10) concern photo uploads only, and you can object to them at the address stated in Section 1 and request a review. No profiling takes place.


14. Recipients and processors

The developer has no access to your trip content; it remains locally on your device or in your iCloud account. The following recipients may be involved in connection with the described features:

  • Apple (iCloud, CloudKit, Apple Maps / MapKit, App Store, translation framework): with iCloud synchronisation enabled and when sharing trips (storage in your or a shared iCloud account), for the map display, for querying the Pro subscription status (Section 5), and – where not performed on the device – for translating foreign-language content (Section 6). For the device integrity check (Section 11) and signing in with Apple (Section 8), only your device communicates with Apple; the developer receives from Apple only the app-specific user identifier contained in the signed identity token. The provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA, or, for the EEA, Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Privacy policy: https://www.apple.com/legal/privacy/
  • Cloudflare (content delivery network / proxy): to deliver and secure the additional content (Section 6); processes the IP address for forwarding, delivery and security. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Privacy policy: https://www.cloudflare.com/privacypolicy/
  • OVHcloud (hosting of the developer’s server, the website and object storage for the photos): the developer’s server – through which the website (Section 12) is delivered, the additional content is loaded and the reporting of added places (Section 7), signing in (Section 8), the place ratings (Section 9) and the photos (Section 10) are processed and stored – is operated by OVH GmbH, Christophstraße 19, 50670 Cologne, Germany, exclusively on servers in Germany and on the basis of a data processing agreement (Art. 28 GDPR). Privacy policy: https://www.ovhcloud.com/de/personal-data-protection/
  • OpenAI (automated content review of photos): every uploaded photo is transmitted to OpenAI for review for prohibited content (Section 10). Only the image file is transmitted, not your user identifier or IP address. The provider is OpenAI OpCo, LLC, 1960 Bryant Street, San Francisco, CA 94110, USA; processing is carried out on the basis of a data processing agreement (Art. 28 GDPR), see also Section 15. Privacy policy: https://openai.com/policies/privacy-policy/

15. Transfer of data to third countries

The data stored by the developer on its server (Sections 6 to 10 and 12) is processed at OVHcloud exclusively on servers in Germany; no transfer to third countries takes place in this respect.

For the content review of photos (Section 10), the image file is transmitted to OpenAI; processing in the USA cannot be ruled out in this context. The data processing agreement concluded with OpenAI bases this transfer on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).

When using services of Apple (in particular iCloud and translation) and Cloudflare as well, data may be processed outside the EU, in particular in the USA. According to their own statements, these two providers are certified under the EU-US Data Privacy Framework, for which the European Commission issued an adequacy decision on 10 July 2023 (Art. 45 GDPR); in addition, they base transfers on standard contractual clauses (Art. 46 GDPR).


16. Storage period

  • Trip content: for as long as you keep it in the App or in iCloud; you determine the duration yourself by deleting (Section 3).
  • Pro subscription (Section 5): the purchase receipt is not stored permanently; the subscription status queried from Apple is cached for up to 24 hours.
  • Additional content (Section 6): technical details are stored without any personal reference (anonymised); translation results only locally on your device.
  • Popular places (Section 7): entries are anonymised after 14 days and fully deleted after 180 days.
  • Signing in with Apple (Section 8): the user identifier for as long as you use the App or ratings or photos are attributed to it. Access tokens expire after one hour. Refresh tokens expire after 90 days without use; expired and revoked entries are deleted 30 days after they end.
  • Place ratings (Section 9): for as long as the respective rating exists; deleting a rating completely removes all associated data (user identifier, time and answers). There is no fixed deletion period.
  • Photos (Section 10): published and pending photos for as long as you keep them in the App — including beyond the end of your Apple account, but then without any link to you (Section 10); deleting removes the image file without undue delay. The image file of a rejected photo is deleted immediately; its database entry and history are deleted 90 days after the rejection. The history of a deleted photo is retained as a record of the moderation decisions and to prevent misuse for a further 90 days from the deletion and is then deleted automatically.
  • Reports about photos (Section 10): until the report has been dealt with; closed reports, including their message history, are deleted automatically 12 months after they were closed.
  • Upload blocks (Section 10): expired and lifted blocks are retained for traceability for a further 12 months after they end and are then deleted automatically. Permanent blocks that have not been lifted remain in place for as long as they apply.
  • IP addresses (Sections 6 to 9, 11 and 12): no later than seven days after the last request. The IP address stored on photo upload (Section 10) is, by way of derogation, deleted no later than twelve months after the upload, or earlier if the photo is deleted.
  • Device integrity check (Section 11): deleted once the App installation has not used the service for 180 days.

17. Your rights as a data subject

Subject to the statutory requirements, you have the right to information (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and to withdraw any consent given with effect for the future (Art. 7(3) GDPR).

Since the developer has no access to your trip content stored locally or in iCloud, you can exercise many of these rights directly yourself – e.g. by viewing, changing or deleting the data in the App or in the iCloud settings. To exercise your rights vis-à-vis the controller, contact the details given in Section 1.


18. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for the controller is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Kavalleriestraße 2–4 40213 Düsseldorf, Germany Email: [email protected] Website: https://www.ldi.nrw.de


Last updated: 25 July 2026

Journew

Journew keeps your trips, tickets and budgets together. Right on your device, wherever you go.

Pages

  • Home
  • Features
  • FAQ
  • Journew Pro

Legal

  • Privacy Policy
  • Terms of Use
  • Legal Notice

Contact

  • [email protected]
© 2026 Journew. All rights reserved.