— Legal
Privacy Policy
Last updated: 7 July 2026
Roamium (“Roamium”, “we”, “us”) is an AI-powered travel planning service. This policy explains what personal data we collect, why we collect it, who we share it with, and the choices you have. By using Roamium you agree to this policy.
1. Information we collect
Account information
When you sign up we collect your name and email address. If you register with email and password, your password is stored in hashed form and is never visible to us. If you sign in with Google, we receive your name, email, profile image, and OAuth tokens from Google. You may optionally provide your gender, which is used only to power safety-focused recommendations (for example, solo-female travel guidance).
Technical and session data
To keep your account secure we store session records including your IP address and browser user-agent. We use a session cookie to keep you signed in.
Trip and planning data
When you create a trip we collect the details you provide: destination, travel dates, group size, interests, travel pace, and budget. If you use Yearly Roam or the Budget Advisor, we also store the budget profile you enter — home city, travel budget, income bracket, annual income, and group composition — and your advisor chat history.
Social feed data
If you create a post, we store the image you upload, any caption, and location data. Uploaded photos may contain GPS coordinates embedded in the image (EXIF data), which we read to verify and display where the photo was taken. We derive and store the city and country from those coordinates. Your posts, likes, and saves are associated with your account.
Booking and payment data
If you book a hotel, we collect the guest name, check-in/check-out dates, and number of guests. Payments are processed by Razorpay. We do not store your card, UPI, or bank details — Razorpay handles those. We retain payment references (order and payment IDs) and booking amounts for your booking history and support.
2. How we use your data
- To create and manage your account and keep you signed in.
- To generate AI itineraries, suggestions, and budget advice tailored to you.
- To look up real venues, weather, and crowd forecasts for your trips.
- To process hotel bookings and payments.
- To operate the social feed and verify post locations.
- To send you trip-related alerts (for example, weather warnings during an active trip).
- To secure the service, prevent abuse, and comply with legal obligations.
3. Third-party services (data processors)
We share the minimum data necessary with the following providers so the service can function:
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | AI itineraries, suggestions, advisor | Trip details, budget profile, chat messages |
| Maps, Places, Weather, Google sign-in | Destinations, locations, account info (on login) | |
| BestTime | Venue crowd forecasts | Venue names and locations |
| Hotelbeds | Hotel search and booking | Guest name, dates, guest count |
| Razorpay | Payment processing | Payment amount and contact (handled by Razorpay) |
| Amazon Web Services (S3) | Image storage | Photos you upload |
| Neon | Database hosting | All stored data (at rest) |
| Railway | Application hosting | All processed data (in transit) |
We do not sell your personal data. We do not share it for third-party advertising.
4. Data retention
We keep your data for as long as your account is active. Cached venue, weather, and crowd data expire automatically on a rolling basis. When you delete your account, we delete your associated personal data, except where we are required to retain records (for example, transaction records for tax or legal compliance).
5. Your rights
You can access, correct, or delete your data. You may delete individual trips and posts from within the app. To delete your account or request a copy of your data, email us at privacy@roamium.ai. If you signed in with Google, you can also revoke Roamium’s access from your Google account settings.
6. Security
Data is transmitted over HTTPS and stored in a managed, access-controlled database. Passwords are hashed. No system is perfectly secure, but we take reasonable measures to protect your data.
7. Children
Roamium is not intended for anyone under 18. We do not knowingly collect data from children.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above. Continued use of Roamium after an update means you accept the revised policy.
9. Contact
For any privacy question or request, email privacy@roamium.ai.