Privacy

Pond Hopping · last updated 14 August 2026

Pond Hopping is a personal travel log. It holds what you put into it and shows it to you. There is no advertising, nothing is sold, and nothing is shared for marketing or tracked across other apps and sites.

Two things it is worth being blunt about, because they are the ones people would mind: the app records which screens you use, so we can tell what is broken or ignored; and to describe your photographs, an AI service has to be sent your photographs. Both are explained below.

What is stored

Location

Recording places is off until you turn it on, and it can be turned off again at any time in Account. When it is on:

If you import a Google Timeline export, the file is read on your device. Only the trips you tick are ever sent anywhere; the rest of the file is never uploaded.

Who else is involved

ServiceWhat it sees
Supabase Hosts the database and the photo storage. Everything above is held there.
Vercel Hosts the website and the app's server functions.
CARTO / OpenStreetMap Supplies the map images. Drawing a map asks them for the tiles covering the area being shown, which tells them roughly where on a map you are looking.
OpenAI Your photographs, and things you wrote. Asking the app to write up a trip sends each of that trip's photographs to be looked at and described — that is how the feature works, and there is no version of it that does not. It also sees the text you type into the planner's chat, and any booking you paste in. If you would rather your photographs were not sent anywhere, do not run the story on a trip; everything else in the app works without it.
Google (Firebase) Delivers push notifications, if you have allowed them.
Google (Gmail) Only if you connect it. It is used to find booking confirmations, and only those.
Google (Calendar) Only if you connect it, to put your trips in a calendar of the app's own. It is not used to read the rest of your diary.
Google (Photos) Only if you connect it, and only to bring in photographs you have picked yourself. The permission asked for cannot list your library — Google shows you its own picker and tells us about the ones you chose and nothing else. The key that fetches a chosen file lasts about an hour. We also keep a longer-lived key, on our server and never in your browser, so that bringing photographs in a second time does not send you back through Google's consent screen every time. It can only ever reach photographs you pick in a picker; it cannot list or read your library. Disconnecting Google in Settings deletes it, and revoking access at myaccount.google.com/permissions stops it working.
CloudMailin Your email address, to deliver sign-in codes and invitations.

Sharing

A trip is private until you share it. You choose who: a named person, or a link you can revoke. Recorded locations, private notes and costs are excluded from shared views unless you explicitly include them. Revoking a link stops it working immediately.

Keeping and deleting

Your data is kept until you delete it. You can delete individual trips, entries and photos in the app, and switch off place recording at any time.

To delete your account and everything in it, see how to delete your account. There is no retention period afterwards and no archived copy; routine hosting backups are cycled out within 30 days.

Children

Pond Hopping is not intended for use by children under 13.

Changes

If this changes in a way that affects what is collected or who sees it, the date at the top of this page changes and the app will say so.