Souvenir
Sign in

Privacy

Your trip is yours

Last updated 25 August 2026.

In one paragraph

Everything your group writes on a trip — calls, comments, verdicts, bills, the name, the phrasebook — is locked on your phone before it is sent, with a key that only the people on the trip have. We store the locked copies, keep them in order and count them. We cannot read them, and neither can anyone who copies our database, restores a backup of it, or asks us for it. Below is how that works in plain words, what we can see, and how to check us.

Who is responsible

The app is operated by an individual in India, who is the data fiduciary (DPDP Act, 2023) and data controller (GDPR) for it. For anything on this page, write to pungoyal+souvenir@gmail.com.

Your keys, in plain words

  • The trip's key is made on the phone that opens the trip and reaches your friends inside the invite link — in the part of the address after #, which browsers never send to any server. That is why the link should go to the group and nobody else.
  • New phone, or lost one? Anyone on the trip sends you the key again in one tap from the table page; the link works only for you, signed in as you, for half an hour. If your passkey supports it (iCloud Keychain and Google Password Manager do; most password managers not yet), it also keeps a sealed backup of your keys, so signing in on a new device brings them back by itself. We store that backup and cannot open it.
  • Lost every passkey? An organiser can give you your seat back with a recovery link, after checking it is really you; the key then comes the ordinary way. Nobody at our end can do either — there is no reset button here, on purpose.
  • Somebody leaves? The organiser turns the key. Everyone still on the trip gets the new one, sealed to a key their own phone announced; the person who left keeps what was written until then and reads nothing after.

What we can see

  • Your name and the lingo you chose — so your friends know who called what and the app can talk to you the way you asked.
  • An email address, only if you sign in with Google. We take the address and your name from Google and nothing else — not your picture, not your contacts.
  • Passkeys: a credential id, a public key, and a counter. Nothing that identifies your device or its make. The private key never leaves your device.
  • A picture, only if you upload one. Otherwise a monogram is drawn from your initials.
  • The shape of a trip: that it exists, its destination, dates, currencies and cap; who is on it and with what role; and, for each sealed entry, who wrote it, when, and how large it is — not what it says. The name, the phrasebook and every bill are sealed with the rest.
  • A verdict card, only when a member taps share on a resolved prediction: their phone publishes the question, the outcome, first names and stamps as a public page for the group chat. Anyone on the trip can take it down.
  • Server logs with request metadata, kept for a short period for security and debugging.

What we do not keep

The interpreter keeps nothing: no audio, no transcript, no turn. A conversation lives in the browser tab and ends with it. Speech recognition happens on your device, through your browser's own recogniser; translation text is sent to a language-model provider for the duration of the request and is not retained by us. We run no third-party analytics, set no advertising cookies, and use only the cookies the app needs to sign you in.

How to check us

The one thing you do have to trust is the code we send to your phone, since that is what handles the key. So we make it checkable: every build comes from one commit through an automated pipeline, carries that commit's name — this page was served by build 72c5864 (it is in the footer too) — and is signed with an attestation that ties the running image to the commit. Want to see it? Write to pungoyal+souvenir@gmail.com naming the build, and we send you the source for that commit and the attestation to check it against.

Who can see it

Members of a trip who hold its key see everything on that trip. Nobody outside it sees anything, with the one exception above: a verdict card a member chose to share. Providers who host the database process sealed records on our instructions only; language-model and voice providers see the text of a request and nothing that identifies you.

Lawful basis

Performing the service you asked for (the game, the bills, the interpreter); your consent for anything optional (a picture, a kept phrase, the lingo, a shared card); and our legitimate interest in keeping the service secure and the record honest.

How long

As long as you have an account. When you delete it, your name, email, picture, passkeys, shared cards and key backups are removed immediately. Your sealed entries stay in each trip's record, attributed to "Departed member", because the record is append-only and removing a call would change other members' numbers. That residue carries no identifier — and, being sealed, nothing we could read anyway.

Your rights

Access, correction, erasure (above), portability, and the right to complain to the Data Protection Board of India or your local supervisory authority. You can exercise every one of them from your account page or by writing to us; we answer within 30 days. Access to the content of a trip is something only its members can give — we hold nothing readable to hand over.

Children

The app is for people 18 and over. We do not knowingly hold data about anyone younger, and delete an account when we learn otherwise.

Where the data lives

On servers we operate, currently in India, with backups in the same region. Language model and voice providers may process requests outside India; we send them the text of a request and nothing that identifies you.