Privacy
Pond Hopping · last updated 14 August 2026
Pond Hopping is a personal travel log. It holds what you put into it and shows it to you. There is no advertising, nothing is sold, and nothing is shared for marketing or tracked across other apps and sites.
Two things it is worth being blunt about, because they are the ones people would mind: the app records which screens you use, so we can tell what is broken or ignored; and to describe your photographs, an AI service has to be sent your photographs. Both are explained below.
What is stored
- Your email address, because signing in is a code sent to it. There is no password.
- What you write — trips, dates, journal entries, flights, wishlists and plans.
- What you spent, if you record costs: the description, amount and currency.
- Your runs, if you log them: distance, pace, elevation and — where your watch recorded it — your average and maximum heart rate.
- Booking emails you forward, including the original text of the message, so the itinerary can be re-read if the first attempt got it wrong.
- Email addresses of people you invite, so their invitation is waiting when they first sign in.
- Photos you upload, along with the date and, where the photo carries one, the location recorded by the camera that took it. Photos are resized on your device before they are uploaded.
- Places you stopped, but only if you switch that on. See below.
- A notification token for your device, if you allow notifications, so the app can tell you when something arrives.
- Which screens you opened and what you tapped, with a device identifier that is not your name or your email. This is how we find out that a button nobody presses is broken rather than unloved. It is ours alone — it is not sent to an advertising network and there is no third-party analytics service in the app.
- Crash and error reports, including what the app was doing at the time, so faults can be fixed without waiting for somebody to describe them.
Location
Recording places is off until you turn it on, and it can be turned off again at any time in Account. When it is on:
- What is recorded is where you stopped and roughly how long you stayed — not a continuous trail of your movements.
- It is visible only to you. It is not included in a trip you share with someone, and it is not included in a public or shopfront link.
- Background location is used so a day you never opened the app still gets recorded. That is the only reason it is requested.
- Turning it off stops the recording. Ask and everything recorded is deleted.
If you import a Google Timeline export, the file is read on your device. Only the trips you tick are ever sent anywhere; the rest of the file is never uploaded.
Who else is involved
| Service | What it sees |
|---|---|
| Supabase | Hosts the database and the photo storage. Everything above is held there. |
| Vercel | Hosts the website and the app's server functions. |
| CARTO / OpenStreetMap | Supplies the map images. Drawing a map asks them for the tiles covering the area being shown, which tells them roughly where on a map you are looking. |
| OpenAI | Your photographs, and things you wrote. Asking the app to write up a trip sends each of that trip's photographs to be looked at and described — that is how the feature works, and there is no version of it that does not. It also sees the text you type into the planner's chat, and any booking you paste in. If you would rather your photographs were not sent anywhere, do not run the story on a trip; everything else in the app works without it. |
| Google (Firebase) | Delivers push notifications, if you have allowed them. |
| Google (Gmail) | Only if you connect it. It is used to find booking confirmations, and only those. |
| Google (Calendar) | Only if you connect it, to put your trips in a calendar of the app's own. It is not used to read the rest of your diary. |
| Google (Photos) | Only if you connect it, and only to bring in photographs you have picked yourself. The permission asked for cannot list your library — Google shows you its own picker and tells us about the ones you chose and nothing else. The key that fetches a chosen file lasts about an hour. We also keep a longer-lived key, on our server and never in your browser, so that bringing photographs in a second time does not send you back through Google's consent screen every time. It can only ever reach photographs you pick in a picker; it cannot list or read your library. Disconnecting Google in Settings deletes it, and revoking access at myaccount.google.com/permissions stops it working. |
| CloudMailin | Your email address, to deliver sign-in codes and invitations. |
Sharing
A trip is private until you share it. You choose who: a named person, or a link you can revoke. Recorded locations, private notes and costs are excluded from shared views unless you explicitly include them. Revoking a link stops it working immediately.
Keeping and deleting
Your data is kept until you delete it. You can delete individual trips, entries and photos in the app, and switch off place recording at any time.
To delete your account and everything in it, see how to delete your account. There is no retention period afterwards and no archived copy; routine hosting backups are cycled out within 30 days.
Children
Pond Hopping is not intended for use by children under 13.
Changes
If this changes in a way that affects what is collected or who sees it, the date at the top of this page changes and the app will say so.