Privacy Policy

Simple, human explanations of how we handle your travel memories.

Last updated: June 9, 2026

Our promise

We keep your data private by default, explain things clearly, and give you control without legalese.

Who we are

  • WhereHaveIBeen (WHIB) is an independent project created to help travelers preserve their memories.
  • For any questions regarding your personal data, contact us at: support@whib.app
  • We are based in the European Union and comply with GDPR regulations.

What we collect

  • Account details you share with us (email, username, profile picture).
  • Your travel content: countries visited, memories, photos, achievements, and friendships you create.
  • Authentication data from third-party providers if you sign in with Google, GitHub, or Discord.
  • Aggregate audience measurement through Umami Cloud: the page visited, the referring page, your browser, operating system, device type and country, the last two being derived from your IP address.
  • Umami sets no cookie and reads nothing from your device, so we show you no cookie banner. It derives a pseudonymous session identifier from your IP address and browser characteristics; the raw IP address is not exposed in the statistics we can see, and Umami states that visitors cannot be identified and are never tracked across websites.

Legal basis for processing

  • Contract: to provide the service you signed up for (storing your memories, showing your map).
  • Legitimate interest: to improve the app, fix bugs, and prevent abuse.
  • Consent: for optional features like sharing your map with friends, and for marketing emails if you ticked that box when signing up.
  • Audience measurement: we rely on the French CNIL exemption for audience-measurement tools, given how Umami is configured here (this site only, aggregate reporting, no cookie, no cross-site identifier). Umami is not on the CNIL list of solutions formally recognised as exempt, and we claim no such certification.

Why we use it

  • To run the app: authenticate you, display your map, save your memories, and track achievements.
  • To enable sharing: show your countries and stories to friends you explicitly add.
  • To keep things safe: fix bugs, prevent abuse, and provide support when you need it.

Where your data is stored

  • All data is stored in Supabase's EU region (Frankfurt, Germany) with HTTPS in transit and encryption at rest.
  • Photos are renamed with a random UUID to protect original filenames and stored in private buckets.
  • Audience-measurement data is processed separately by Umami Cloud, whose servers are located in the EU and the United States. It contains no memory content and no account identifier.
  • Transactional emails are sent through Resend (United States); contact-form messages are received through Netlify Forms (United States).

Third-party services (sub-processors)

  • Supabase (Supabase Pte. Ltd., Singapore) - database, authentication and file storage. Your data is hosted in Supabase's EU region (Frankfurt, Germany). Any transfer outside the EU is covered by the European Commission's Standard Contractual Clauses set out in Supabase's data processing agreement.
  • Netlify, Inc. (United States) - hosting of the site, content delivery network, and Netlify Forms for the contact form. Netlify is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), and its data processing agreement falls back to the Standard Contractual Clauses if that certification lapses.
  • Stripe (payments) - Stripe Technology Company, Limited (Ireland) is Stripe's main establishment in Europe; processing also involves Stripe, Inc. (United States), which is certified under the EU-U.S. Data Privacy Framework and additionally relies on the Standard Contractual Clauses. Your card number is entered on Stripe's side: we never see it and never store it.
  • Cloudflare, Inc. (United States) - Turnstile anti-bot verification on the sign-up and sign-in forms. Cloudflare is certified under the EU-U.S. Data Privacy Framework and relies on the Standard Contractual Clauses for international transfers.
  • Umami Software, Inc. (United States; Umami Cloud servers are located in the EU and the United States) - cookie-free audience measurement. The transfer is covered by the data processing agreement we entered into with Umami.
  • Resend (Plus Five Five, Inc., United States) - transactional emails only: memory reminders, subscription renewal notices and cancellation confirmations. Resend states that it complies with the EU-U.S. Data Privacy Framework and that transfers out of the EEA are also made under the EU Standard Contractual Clauses.
  • CARTO (map tiles, basemaps.cartocdn.com) - your browser fetches the base map directly, so CARTO receives your IP address and the area of the map you are looking at. It never receives your memories.
  • OpenStreetMap Foundation (United Kingdom, a country covered by an EU adequacy decision) - the Nominatim service turns the coordinates of a pin into a place and country name. It receives those coordinates and your IP address.
  • Apple (iTunes Search API, United States) - only when you look for a song to attach to a memory. Apple receives your search term and your IP address.
  • Google, GitHub (Microsoft) and Discord - only if you choose to sign in with one of these providers. They then pass us your email address and, when available, your name and profile picture.
  • We never sell your data to advertisers or data brokers, and we never use it for advertising or profiling.

How long we keep your data

  • Active accounts: your data is kept as long as you use the service.
  • Deleted memories: permanently removed within 24 hours, including associated photos.
  • Deleted accounts: deletion runs immediately when you confirm it. Your uploaded files are erased from storage first, then your account and every related row (profile, memories, trips, friendships, achievements) are deleted from the database. There is no soft delete and no recovery window, so make an export first if you want to keep a copy.
  • Proof of consent: the date you accepted the terms, the version you accepted and your marketing choice are kept for the lifetime of the account, as evidence that we were allowed to process your data.
  • Server logs: kept for up to 90 days for security and debugging purposes.
  • Billing records: invoices held by Stripe are kept for the period required by French accounting and tax law, even after you delete your account.

Your rights (GDPR)

  • Access: view all your personal data in your profile settings at any time.
  • Rectification: update or correct your information directly in the app.
  • Portability: go to Settings > Profile and use "Export my data". The file downloads immediately as a single JSON document (whib-export-YYYY-MM-DD.json) containing your profile, memories, trips, friends, achievements and subscription status, plus download links for your photos and audio recordings. Those media links stay valid for 7 days; run a new export to refresh them.
  • Erasure: delete individual memories, or use Settings > Profile > "Delete account" to erase everything. Your stored files are deleted from storage first, then the account and all related database rows. The deletion is immediate and cannot be undone.
  • Object: contact us to object to specific processing activities.
  • Complaint: you have the right to lodge a complaint with your local data protection authority.

Age requirement

  • You must be at least 15 years old (the age of digital consent in France) to use WhereHaveIBeen.
  • When you create an account you have to tick a box confirming that you are 15 or older and that you accept these terms. We take that declaration at face value: we do not ask for an identity document and we cannot verify your age.
  • We do not knowingly collect data from anyone under 15. If you believe a child under 15 has created an account, tell us through the contact form and we will delete it.
  • Signing in with Google, GitHub or Discord goes through those providers directly, so the same box is shown once, right after your first sign-in, before you can use the app.

Contact

Questions about privacy? Reach us through the contact form or at

Policy Updates

If we make significant changes to this policy, we will notify you via email or in-app notification. The updated version will be posted here with a new date.