R'lyeh Technologies
Apps TravelBoop Contact
R'lyeh▸ TravelBoop▸ Privacy Policy

TravelBoop — Privacy Policy

Last updated: 14 June 2026 · Pre-release / internal testing

In short: TravelBoop has no servers and no account, and collects nothing for the developer. Your trips, notes, documents and photos stay encrypted on your device. The app reaches the network in only two situations, both explicit and opt-in: fetching public government travel-advisory and health information you ask for, and — only if you set it up — sending document text to an AI provider using your own API key. There are no ads, no analytics, and no third-party tracking. You can erase all of it at any time.

Who this applies to

This policy covers the TravelBoop Android app (com.rlyehtech.travelboop), a privacy-first, local-only travel companion for organising trips — itineraries, notes, photos and documents — entirely on your own device. TravelBoop is developed by R'lyeh Technologies. Note: the app is in internal testing and not yet publicly available; this policy is published in advance and will be kept current through release.

Information the app handles

TravelBoop is designed around a simple rule: collect nothing, hold nothing off-device. Everything below is created by you and stays on your device:

  • Trips & itinerariesThe trips you create — destinations, travel segments, events, dates and descriptions.
  • Notes & voice memosText notes and any audio you record. Voice memos are transcribed on-device; the audio is encrypted and never sent anywhere.
  • Documents & photosBooking PDFs and scans you add live in an encrypted vault. Photos are referenced from your device's own library, not copied off it.
  • Identity documentsPassports, IDs and vaccination cards you reuse across trips, held encrypted in the vault.
  • AI API key (optional)If you turn on cloud parsing, the API key you provide is stored in encrypted on-device storage and used only to reach the provider you chose.

The app has no user accounts of its own, and does not request or store payment-card numbers, your precise location in the background, contacts, messages, your date of birth, or your home address.

When the app uses the network

TravelBoop is offline-first. It makes no background network calls and contains no analytics. There are exactly two situations in which it reaches the internet, and you start both of them:

  1. 1
    Public government travel information

    When you add a destination or tap refresh, the app fetches travel advisories (U.S. State Department, optionally UK FCDO) and health and vaccination guidance (U.S. CDC) for that country, directly from those public government endpoints over HTTPS. No API key, no account, and no identifier about you is sent — only the country you're asking about. Results are cached on your device for offline use.

  2. 2
    Your own AI key (optional)

    If you turn on cloud parsing and paste your own API key (Anthropic, Google or OpenAI), document text you choose to parse is sent directly from your device to that provider, with a clear confirmation each time. The key and the content never pass through any R'lyeh server. Leave this off and the app uses only its built-in parser and, where supported, on-device AI.

Separately, if you buy the app, the purchase itself is handled by Google Play — Google processes the payment and the developer never receives your card details. That transaction is governed by Google's own terms and privacy policy, not by the app.

On-device document parsing & AI

When you import a booking, TravelBoop reads it through a tiered parser, and the highest available tier that runs entirely on your device is always preferred:

  • built-in heuristics and template matching, which run on every device;
  • on-device AI (Gemini Nano via Android AICore) on supported hardware, which never sends anything off the device; and
  • only if you have explicitly enabled it (see above), a cloud model reached with your own API key.

Whatever reads a document is surfaced honestly in the review screen (for example, "Parsed by Gemini Nano · on-device"), and you review and edit every result before anything is saved to your trip.

Where your information is stored

All of your information is stored locally on your device. Trip data, notes and OCR text live in a SQLCipher-encrypted database; each document and cached photo is encrypted with its own key (Tink). The keys are protected by a hardware-backed key in the Android Keystore, and a recovery code you establish at first run (or your own passphrase) is the backstop if the device ever loses its security key. An optional biometric / PIN app lock gates access to the vault. Your data is excluded from Android cloud backup and device-to-device transfer, so it stays on the one device where it was created.

Who your information is shared with

TravelBoop has no backend server. The developer never receives, stores, or has access to your trips, notes, documents, photos, or API key.

The app communicates directly and only with: public government data sources (such as the U.S. State Department and U.S. CDC) for the advisory and health information you request; and, only if you enable it, the AI provider you choose using your own API key. All such traffic uses encrypted HTTPS. The app contains no third-party advertising, analytics, or crash-reporting services, and does not sell or share your information with anyone.

Permissions

  • Photos / mediaTo attach photos to a trip through the system photo picker. The app stores references, not copies.
  • Camera (document scanner)Scanning a document runs in a secure Google system component, so the app captures pages without holding its own camera permission.
  • MicrophoneOnly while you record a voice memo in a note. Audio is encrypted and transcribed on-device.
  • BiometricFor the optional app lock that gates access to the vault.

Data security

  • All network traffic — the two cases above — uses encrypted HTTPS connections.
  • Trip data, documents, photos and voice memos are encrypted at rest on the device; keys are hardware-backed via the Android Keystore.
  • Your recovery code never leaves the device except when you record it; there is no server escrow.
  • Internal diagnostic logging is removed from release builds, so your trip details are not written to the device log.

How to delete your data

Because TravelBoop stores everything locally and keeps no server-side copy, you are always in full control of your data and can remove all of it at any time:

  • In the appDelete an individual trip (which cascades to its events, notes and documents), or use Settings → Clear all data to erase everything from the device.
  • Or uninstall the appRemoving TravelBoop from your device deletes all of its stored data.

Since the developer holds no copy of your information, there is nothing further to request — deleting it on your device deletes it completely.

Children's privacy

TravelBoop is a general-purpose trip-organising utility intended for adults managing their own travel. It is not directed to children and does not knowingly handle data from children.

Changes to this policy

The app is in active development, and this policy may be updated as features are finalized. The current version will always be posted at this page with a revised "Last updated" date.

Contact

Questions about this policy or your data can be sent to: travelboop@rlyehtech.com.

TravelBoop is an independent app developed by R'lyeh Technologies. Travel-advisory and health information is sourced from public government data (including the U.S. Department of State and the U.S. Centers for Disease Control and Prevention); those agencies do not endorse this app. Any AI provider you connect with your own API key is governed by that provider's own terms and privacy policy. "Google Play" and "Gemini" are trademarks of Google LLC. All trademarks are the property of their respective owners.
© 2026 R'lyeh Technologies · rlyehtech.com