Legal

Privacy Policy

Last updated: August 29, 2026

This Privacy Policy explains how Solvago collects, uses, stores, shares, and protects information when you use the Solvago mobile application, the solvago.app website, trip organization and budgeting tools, booking-email processing, flight price discovery, shared trip memories, and related services (together, the “Service”).

1. Who we are

The Service is operated by SOLVAGO sp. z o.o. (“Solvago”, “we”, “us”, or “our”), a limited liability company registered in Poland. For the purposes of the EU General Data Protection Regulation (GDPR / RODO) and other applicable data protection laws, SOLVAGO sp. z o.o. is the controller of personal data processed in connection with Solvago, except where a third party such as Apple or Google acts as an independent controller for its own services.

SOLVAGO spółka z ograniczoną odpowiedzialnością
Legal formLimited liability company under Polish law (spółka z ograniczoną odpowiedzialnością, sp. z o.o.)
Addressul. Leśna 36A lok. 8, 81-549 Gdynia, woj. pomorskie, Poland
KRS0001260682
Registry courtDistrict Court Gdańsk-Północ in Gdańsk, 8th Commercial Division of the National Court Register
NIP5862433691
REGON54548476300000

2. Information we collect

We collect the following categories of information, depending on how you use the Service.

Account and authentication data

Your email address, display name, a Solvago user ID, and authentication identifiers. If you sign in with Sign in with Apple or Sign in with Google, we receive an identifier and (where you allow it) your email and name from that provider. If you use email and password, we store a secure hash of your password — never the password itself. We also store your account settings and the date and version of the Terms and Privacy Policy accepted when your account was created.

Trip content

The trips, itineraries and day-by-day timelines you build; bookings extracted from your emails (flights, stays, car rentals and other reservations); notes; photos and other media you add to memories; trip cover images; and budget entries, including amounts, currencies, categories and how costs are split between travelers.

Booking emails you forward or connect

When you forward a confirmation to your personal Solvago forwarding address (at the in.solvago.app domain), or add a verified sender, we receive and process the email — sender, subject, body and information about any attachments — to extract booking details. See section 3.

Discover (flight discovery) inputs

When you use Discover, we process the direction or destinations, budget, dates and similar preferences you provide, in order to search for and monitor flight offers.

Collaboration data

When you invite co-travelers to a trip or a shared budget, we process the email addresses you invite and the shared trip, itinerary and budget data, so invited people can view or edit according to the role you assign.

Device, usage and diagnostic data

Device type, operating system, app version, language and region, feature interactions, and technical logs such as server logs, error logs and security logs. Requests to our servers include metadata such as IP address and user agent. Where you enable notifications, we store a push notification token (an Expo push token).

Product analytics

To understand how Solvago is used and to improve it, we record a small set of product-analytics events on our servers — for example that an account was created, the app was opened, a trip was created, a Discover search was run, or a booking email was processed. These events are generated on our servers, not by tracking code inside the app: Solvago contains no analytics SDK, no autocapture and no session replay. Each event is tied to a pseudonymous user identifier — never your email address — and records only that an action happened, together with non-identifying details such as a count or a feature name. We do not include the content of your emails, trips, messages or photos. This analytics is processed by PostHog and hosted in the European Union (see section 8).

Communications

Support requests, feedback and other messages you send us.

3. How we use AI to read your booking emails

Extracting bookings from your emails is the core of Solvago and relies on artificial intelligence, so we describe it in detail here. This section also serves as our AI transparency notice.

When AI is used

You receive a personal forwarding address on the in.solvago.app domain. When you forward a confirmation email to that address — or when a sender you have verified sends one — the message is received through Cloudflare Email Routing and passed to our servers. We then send the email content to an AI model to extract structured booking details, such as airline, flight numbers, times, hotel name, dates, confirmation numbers and prices, which are saved to your trip. AI is used in the same way to interpret the free-text request you type in Discover (for example “somewhere warm in March under 2000 zł”).

Which AI service and models we use

AI processing runs on Amazon Bedrock, Amazon Web Services’ managed AI platform. The models are Anthropic’s Claude — currently Claude Haiku 4.5 for most emails, with Claude Sonnet 4.6 used for messages that are harder to read reliably. We access these models only through Amazon Bedrock; we do not send your data to Anthropic directly, and Anthropic does not receive it through Bedrock.

Where processing happens (EU data residency)

We run Amazon Bedrock in an EU region (currently eu-central-1, Frankfurt) using EU-resident model endpoints, so that AI inference on your data stays within the European Union.

What we send to the model

For booking extraction, we send the content of the email you forwarded — its sender, subject and body text — so the model can find the booking details. For Discover, we send the search text you type. We do not add your name, account identifiers or unrelated data to these requests beyond what the email or query already contains, and we do not send your photos to the model.

No training, no sharing, no long-term storage by the AI service

Amazon Bedrock does not use your prompts or the model’s responses to train any AI models, and does not share them with the model provider or other third parties. Bedrock does not retain your prompts or the outputs after your request has been processed. Separately, we do not use the content of your emails, trips or photos to train AI models (see also section 7).

Human oversight and accuracy

AI extraction is a convenience feature, not an automated decision that produces legal or similarly significant effects on you. Extracted bookings are presented for you to review, confirm and edit before you rely on them, and AI output can be incomplete or wrong — always verify important details against the original confirmation and the provider. You remain in control of what ends up in your trip.

Retention of the original email

The original forwarded email is retained only as long as needed to run extraction and let you verify the result, then deleted from our servers. You are responsible for only forwarding emails you are entitled to process.

4. Device permissions

Solvago requests only the device permissions it needs, and only when a feature uses them:

  • Photo library & camera — so you can attach photos to trip memories. Solvago accesses only the photos you select.
  • Notifications — so we can send the alerts you ask for, such as Discover price drops and trip reminders.

Solvago does not request location or calendar access. You can review and change these permissions at any time in your device settings.

5. How we use information

We use information to:

  • create, authenticate, secure and manage your account;
  • provide the Service — build your trip timelines, extract bookings from the emails you forward, track budgets, run Discover flight searches and price alerts, and generate and share trip memories;
  • enable collaboration with the co-travelers you invite;
  • send service messages, support responses and the notifications you enable;
  • debug errors, monitor performance, maintain security and prevent abuse;
  • improve the product using aggregated or de-identified information;
  • comply with legal obligations, respond to lawful requests, enforce our Terms and resolve disputes.

6. Legal bases for processing

Where the GDPR or a similar law applies, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to create and manage your account and provide the core features, including booking extraction, trip timelines, budgets, Discover, memories and collaboration.
  • Consent (Art. 6(1)(a)) — for optional device permissions such as photo library and notifications, and for any optional marketing messages you choose to receive. You can withdraw device permissions in your device settings and withdraw other consents by contacting hello@solvago.app.
  • Legitimate interests (Art. 6(1)(f)) — to keep the Service secure, prevent fraud and abuse, debug errors, and improve product quality in a privacy-conscious way.
  • Legal obligations (Art. 6(1)(c)) — to meet accounting, tax, consumer-protection and other legal requirements.

7. No sale, no tracking ads, no AI training on your content

We do not sell your personal data. We do not use third-party advertising or cross-app tracking SDKs. Our product analytics runs on our servers with no tracking code inside the app, is tied to a pseudonymous identifier rather than your email, and is never used for advertising or shared with advertisers (see section 2). We do not use the content of your booking emails, trips, budgets or photos to train AI models. We may use aggregated or de-identified information to improve reliability and quality. If any of this changes materially, we will update this Policy and obtain any consent required by law.

8. Service providers and sharing

We share information with service providers (processors) only as needed to operate, secure, support and improve the Service, to comply with law, or to provide features you request. The main providers are:

  • Cloudflare — hosting, database, media storage, inbound email routing, queues and content delivery.
  • Amazon Web Services (Amazon Bedrock) — the EU-hosted AI platform on which booking extraction and Discover text understanding run. The models are Anthropic’s Claude; your data is not used to train models and is not shared with the model provider (see section 3).
  • Duffel — flight search and price data used by Discover.
  • Pexels — stock photo search used when you choose a trip cover image.
  • Expo — delivery of push notifications (via Apple and Google notification services).
  • PostHog — privacy-conscious product analytics, hosted in the European Union. It receives only server-side usage events tied to a pseudonymous user ID (never your email) and no message, trip or photo content (see section 2).
  • Apple — Sign in with Apple and App Store distribution.
  • Google — Sign in with Google and Google Play distribution.

These providers are bound by contracts (including data-processing agreements) that require them to protect your information and use it only to provide their service to us. We may also disclose information where required to comply with law, enforce our Terms, protect rights, investigate abuse, or in connection with a business transfer such as a merger, acquisition or sale of assets.

9. Public or shared content

When you share a trip memory via a link, anyone with that link can view the shared content — the route, places, stays and photos you included — until you revoke the link. When you invite co-travelers to a trip or budget, the people you invite can view or edit it according to the role you assign. Recipients may copy, save, screenshot or re-share content outside Solvago, so only share what you are comfortable making visible. You can revoke a memory link or remove a collaborator at any time.

10. Retention and deletion

We keep personal data only as long as reasonably necessary for the purposes in this Policy, unless a longer period is required or permitted by law. As a general rule:

  • account data, trips, bookings, budgets, photos and memories are retained while your account is active and until deletion is completed;
  • original forwarded booking emails are retained only as long as needed for extraction and troubleshooting, then deleted;
  • diagnostic, error and security logs are normally retained for up to 90 days, unless needed longer for security, debugging, legal or dispute purposes;
  • support communications are normally retained for up to 24 months;
  • backups may persist for up to 90 days before being overwritten;
  • records required for accounting or tax purposes are kept for the period required by law.

You can delete your account in the app under Settings → Privacy → Delete account, or by contacting hello@solvago.app. When you request deletion, your account enters a short grace period (currently 30 days) during which you can cancel; after that, your personal data is permanently deleted or de-identified, except where we must retain limited information for legal compliance, security, fraud prevention or dispute resolution. For content shared with co-travelers, you will be able to choose whether to transfer or delete it.

11. Your choices and rights

Under the GDPR and similar laws you may request access to your personal data, and its correction, deletion, export (portability), restriction of processing, objection to processing, and withdrawal of consent where processing is based on consent. To exercise these rights, contact hello@solvago.app. We may need to verify your identity, and we respond within the period required by law (in the EEA, generally within one month).

You also have the right to lodge a complaint with a data protection authority. In Poland, the competent authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa.

12. International transfers

AI processing of your booking emails and Discover queries takes place on Amazon Bedrock within the EU (see section 3). Some other providers may process limited information outside the European Economic Area, including in the United States (for example Duffel, Expo, Apple and Google). Where required, we rely on appropriate safeguards such as European Commission adequacy decisions, the EU–U.S. Data Privacy Framework where applicable, or Standard Contractual Clauses, together with data-processing agreements.

13. Security

Data is encrypted in transit and at rest. We use access controls, authentication and operational safeguards, and limit access to personnel who need it to operate the Service. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your account credentials safe.

14. Children

Solvago is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact hello@solvago.app and we will delete it.

15. Cookies and the website

The Solvago mobile app does not use advertising cookies. The solvago.app website uses only what is strictly necessary to serve the pages; it does not run third-party advertising or cross-site tracking. If we add optional analytics in the future, we will request consent where required and update this Policy.

16. Changes to this Policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you — for example by updating the date above or posting a notice in the app. Your continued use of the Service after the updated Policy takes effect means you acknowledge it.

17. Contact

For privacy questions or requests, email us at hello@solvago.app.

See also our Terms of Service and Data Deletion page.