Privacy Policy
Last updated 30 July 2026
This notice explains what Going Somewhere does with your personal information, and what rights you have over it. It covers our website at https://goingsomewhere.app and the Going Somewhere app on mobile, tablet and desktop.
Going Somewhere is a shared packing checklist. You create a trip, invite the people coming with you, and organise what needs packing into groups. Each item has a status (to buy, ready to pack, packed), can be assigned to someone, and can carry a note and a storage location. Everything on a trip is visible to everyone on that trip — that is the point of the app.
Questions? Email us at help@goingsomewhere.app.
SUMMARY OF KEY POINTS
What do we collect? Your email address, the display name you choose, and the trips, groups and items you create. Nothing else.
Do we track you? No. There is no analytics, no advertising, no tracking pixels, and no third-party cookies. We set exactly one cookie, to keep you signed in.
Do we sell or share your information? We never sell it, and we do not share it for advertising. We use a small number of suppliers to run the service — an email provider, an AI provider, a host and a database — listed in full in section 4.
Do we use AI? Yes, for one optional feature. When you tap "Forgotten anything?", the trip and the item names on it are sent to Anthropic to check for gaps. Your name and email address are never sent, and neither are your item notes or storage locations.
Can you delete everything? Yes, from the app, without asking us. See section 6.
Who is this for? Adults. We do not knowingly collect information from anyone under 18.
CONTENTS
- What information we collect
- How we use it
- Our legal bases for using it
- Who else sees it
- Cookies
- How long we keep it
- How we protect it
- Children
- Your rights
- US state residents
- Changes to this notice
- How to contact us
1. WHAT INFORMATION WE COLLECT
In Short: An email address, a display name, and whatever you put on your packing lists.
Everything below is information you give us. We do not buy information about you, receive it from data brokers, or collect it from third parties.
Your account
- Your email address. This is how you sign in and how we reach you.
- The display name you choose. It is shown to the other people on your trips.
- The date and time you last signed in.
Signing in
Going Somewhere has no passwords. When you ask to sign in we email you a six-digit code and store a one-way cryptographic hash of it — never the code itself — along with its expiry time and a count of failed attempts.
Your trips
- Trip names, and optionally a destination and travel dates.
- The groups you create and the items in them: name, quantity, status, and optionally a storage location and a note.
- Who added each item, who it is assigned to, and who packed it and when.
- Which trips you belong to, your role on each, and the colour used for your avatar.
Invitations
When you invite someone to a trip by email address, we store that address so we can add them to the trip when they sign in. We hold it only while the invitation is open: it is deleted as soon as the invitation is answered, and automatically after three days if it is not. See section 6.
What we do not collect
We do not collect or store your location, device identifiers, advertising identifiers, contacts, photos, browsing history, payment details, or any of the categories of information that laws describe as sensitive or special — your health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometrics or genetics. We do not use analytics or tracking technology of any kind. We do not send push notifications, and we do not offer sign-in through Google, Apple, Facebook or any other social account.
Note that item notes and storage locations are free text: we do not inspect them, but whatever you type into them is stored. Please do not put anything in a packing list that you would not want the other people on that trip to read.
2. HOW WE USE IT
In Short: To run the app, to sign you in, and — only when you ask for it — to check a list for gaps.
We use your information to:
- Create your account and keep you signed in.
- Email you a sign-in code when you ask for one.
- Store your trips and show them to you and to the other people on those trips.
- Show your display name and avatar colour to the other members of a trip, so they can see who added, was assigned, or packed an item.
- Check a list for gaps when you tap "Forgotten anything?" — see section 4.
- Keep the service working and secure, and respond to you when you contact us.
We do not use your information to profile you, to advertise to you, or to train any AI model. We do not make any decision about you by automated means that would have a legal or similarly significant effect.
3. OUR LEGAL BASES FOR USING IT
In Short: Mostly because you asked us to provide the service.
If you are in the UK or the EEA, the UK GDPR and GDPR require us to have a lawful basis for each use of your information. Ours are:
- Performance of a contract. Creating and maintaining your account, storing your trips, sharing them with the people you invite, emailing your sign-in code, and running the "Forgotten anything?" check when you ask for it. These are the service you signed up for.
- Legitimate interests. Keeping the service secure and preventing abuse — for example expiring sign-in codes and invalidating one after repeated wrong guesses. We consider this proportionate because it involves no profiling and no information beyond what is described in section 1.
- Legal obligations. Complying with the law where we are required to, such as responding to a lawful request from an authority.
If you are in Canada, we rely on your express or implied consent, which you may withdraw at any time by deleting your account or contacting us.
4. WHO ELSE SEES IT
In Short: The people on your trips, and four suppliers who help us run the service.
Other people on your trips. Everything on a trip — items, statuses, assignments, notes, and the display names of everyone involved — is visible to every member of that trip. Anyone holding a trip's share link can join it and see the same. Treat a share link as you would a key.
Our suppliers. We use the following companies to run Going Somewhere. Each processes your information only on our instructions, under contract, and none of them are permitted to use it for their own purposes.
| Supplier | What they receive | When |
|---|---|---|
| Anthropic (AI) | The trip name, destination, dates, number of travellers, and the name, quantity and status of each item on the list | Only when you tap "Forgotten anything?" |
| Resend (email) | Your email address and the sign-in code | Each time you request a sign-in code |
| Vercel (hosting) | All traffic to the app; their server logs may include your IP address | Every request |
| Neon (database, through Vercel) | Everything described in section 1 | Continuously, as our database |
What Anthropic receives is deliberately narrow: your name and email address are never sent, and neither are your items' notes or storage locations. Under Anthropic’s commercial terms, information sent to their API is not used to train their models.
Nothing else is loaded from anywhere else. Our website and app carry no third-party scripts, embeds or fonts — the typefaces are served from our own domain rather than from Google Fonts, so no request leaves for anyone else before you have done anything.
Nobody else. We do not sell your personal information, we do not share it for advertising or any other cross-context behavioural purpose, and we have not disclosed it to any third party other than the suppliers named above. We may have to disclose information if the law requires it, or transfer it as part of a merger or sale of the business — if that ever happens we will say so here first.
5. COOKIES
In Short: One cookie, so you stay signed in. Nothing else.
We set a single cookie, named session. It holds a signed token identifying your account, lasts 30 days, and cannot be read by JavaScript. It exists only to keep you signed in — without it you would have to enter a code on every page.
We do not use analytics cookies, advertising cookies, tracking pixels, web beacons, or any third-party tracking technology, so there is nothing here to opt out of and no cookie banner to dismiss. Because we do not track you across sites, "Do Not Track" browser signals make no difference to what we do.
Clearing the cookie signs you out.
6. HOW LONG WE KEEP IT
In Short: Until you delete it. You can do that yourself, in the app.
- Your account and trips are kept until you delete your account.
- Sign-in codes expire ten minutes after they are issued, are erased as soon as they are used, and are invalidated after five wrong attempts.
- Invitations are deleted the moment they are answered — accepting or declining one erases the address rather than filing it away. An invitation nobody answers is deleted automatically after three days, so an address we were never given permission to hold is not kept indefinitely. Sending a fresh invitation to the same person starts that three days again.
- Your session expires 30 days after you sign in.
Deleting your account. Open your profile in the app and choose to delete your account. This happens immediately and does not require asking us. When you do:
- Trips where you were the only member are deleted entirely.
- Trips shared with other people remain, because they are theirs too. Items you added are deleted with your account. Items that other people added, which you were merely assigned or had packed, remain on the list with those fields cleared.
- Your account, email address and display name are removed.
One thing worth knowing: if you are removed from a shared trip but keep your account, we keep the record of your membership so that "added by" stays accurate on items you contributed. That record links your account to that trip. Deleting your account removes it.
7. HOW WE PROTECT IT
In Short: Encrypted in transit, no passwords to steal, sign-in codes never stored in readable form.
All traffic is over HTTPS. Sign-in codes are stored as a keyed hash rather than as codes, so a copy of our database could not be used to sign in as you, and they are compared in constant time. Session cookies are signed, marked HttpOnly and Secure, and restricted with SameSite=Lax.
No system is perfectly secure, and we cannot guarantee that information sent over the internet is safe from interception. If we ever suffer a breach affecting your personal information, we will tell you and the relevant authority as the law requires.
8. CHILDREN
In Short: The service is for adults.
Going Somewhere is not directed at children, and we do not knowingly collect information from anyone under 18. We do not ask your age, so we rely on you: by using the service you confirm you are 18 or older, or that a parent or guardian consents. If you believe a child has given us their information, email help@goingsomewhere.app and we will delete the account.
9. YOUR RIGHTS
In Short: You can see it, correct it, take it with you, or delete it.
Wherever you live, you can change your display name in the app and delete your account and its contents at any time.
If you are in the UK, the EEA or Switzerland, you also have the right to: ask what we hold and get a copy of it; have inaccurate information corrected; have your information erased; restrict or object to our use of it; receive it in a portable format; and, where we rely on consent, withdraw that consent. Exercising any of these rights is free and will not lead to worse treatment.
To exercise any of them, email help@goingsomewhere.app. We will respond within one month.
If you are unhappy with how we have handled your information, please tell us first so we can put it right — we will acknowledge your complaint within 30 days, investigate promptly, and explain the outcome.
You can also complain to a regulator:
- UK: the Information Commissioner's Office — ico.org.uk/make-a-complaint, 0303 123 1113, or Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
- EEA: your national data protection authority.
- Switzerland: the Federal Data Protection and Information Commissioner.
10. US STATE RESIDENTS
In Short: The same rights, and we have nothing to opt out of.
If you live in a US state with a comprehensive privacy law — including California, Colorado, Connecticut, Texas, Virginia and others — you have the right to know what we hold, to get a copy of it, to correct it, and to delete it. Email help@goingsomewhere.app, or delete your account in the app.
In the terms California uses, the only category of personal information we collect is identifiers — your name and email address — together with the content you create in the app. We do not collect protected classification characteristics, commercial information, biometric information, internet or network activity, geolocation data, audio or visual information, professional or employment information, education information, inferences or profiles, or sensitive personal information.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling. There is therefore no opt-out to offer you. We have not disclosed personal information to any third party in the past twelve months other than the suppliers listed in section 4.
You may use an authorised agent to make a request, with written proof of their authority. We will need to verify your identity before acting on a request, using only the information you have already given us where possible. If we refuse a request you may appeal by replying to our response; if we refuse the appeal you may complain to your state attorney general.
11. CHANGES TO THIS NOTICE
We will update this notice when what we do changes. The date at the top always reflects the current version. If we make a material change — a new supplier, a new use of your information — we will tell you in the app before it takes effect.
12. HOW TO CONTACT US
Email: help@goingsomewhere.app
Going Somewhere is the controller of the personal information described in this notice.