1. Controller (Art. 4 GDPR)
MY YACHTWEEK SL
Paseo del Borne 14
07012 Palma de Mallorca
Islas Baleares, Spain
E-Mail: privacy@hellokiwi.app
Represented by the Director: Pierre Schorb
2. Purposes
- Trip planning, packing lists, tasks, expenses and destination management – at first entirely local on your device.
- Optional account with sign-in via Apple, Google, an email code or a passkey, to sync your trips between devices and share them with other people.
- Optional AI support (packing list assistant, country and flight information).
- Place, map, weather, flight and currency information as well as offers (including Google, Apple, OpenStreetMap, Open-Meteo, AeroDataBox, Wikipedia, Wikidata, Viator).
- Notifications and reminders for appointments, tasks and trips (local on the device).
- Operation, security and troubleshooting of our servers (server logs) and – only with your consent – usage statistics (Matomo).
3. Account & sign-in (optional)
You can use HelloKiwi without an account; all data then stays on your device. To sync via the HelloKiwi server and to share trips, you sign in in the settings. There are four ways to do so; there is no separate password:
- Google: We receive a sign-in token from Google and store the unique Google identifier, your email address, your display name and – if available – your profile picture.
- Apple: We receive a sign-in token from Apple and store the unique Apple identifier as well as your email address and name, if Apple provides them. If you choose “Hide My Email”, we only receive a relay address from Apple. We also store a token issued by Apple in encrypted form so that we can revoke the connection to your Apple ID when you delete your account. On Android, Sign in with Apple runs via a web page from Apple; the sign-in result is kept on our server for at most 10 minutes until the app collects it.
- Email code: We send a six-digit code to your email address. We store the address; the code is stored only as a hash, is valid for 10 minutes and is deleted after one day at the latest. To prevent abuse, the number of codes per address and per IP address is limited.
- Passkey: You can add a passkey to your account and sign in with Face ID, fingerprint or device passcode. We only store the public key, an identifier of the passkey, a usage counter and the name you give it. Biometric data never leaves your device.
In addition, there is technical session data (timestamps, expiry; sign-in tokens only as a hash). We never see the passwords of your Apple or Google accounts. Different sign-in methods result in separate accounts.
You can sign out at any time. You can permanently delete your account and all server data in the settings with “Delete account and server data” (see the section “Storage & retention”).
4. Synchronisation via the HelloKiwi server
When you sign in, HelloKiwi syncs your data with our server so that you have it on several devices and can share it with others. All content of your trips is synced: titles, periods, destinations, accommodations, flights, trains, cruises, activities, tasks, participants (names, email addresses and other details you enter yourself), expenses, packing lists, notes, results of the packing list assistant, saved places, cover images and attachments (photos, documents) as well as your profile and settings (e.g. language).
The server is located in a data centre in the European Union (Spain). Transmission is encrypted (TLS), attachments are stored encrypted on the server, and backups are encrypted.
Synchronisation is voluntary. It ends when you sign out; your data stays on the device (if you wish, you can have it removed from the device when signing out). Data that has already been synced stays on the server until it is deleted (see “Storage & retention”).
On iOS, while it is working, the packing list assistant stores a device identifier assigned by the app vendor (identifierForVendor) on the trip so that two devices do not create the same list at the same time. It is synced with the trip and is therefore also stored for the trip’s members; it serves no other purpose.
If you enter names, email addresses or other data of your travel companions, please make sure you are entitled to do so.
5. Earlier iCloud data (iOS)
Earlier versions of the iOS app synced your data between your devices via iCloud (Apple CloudKit) and offered sharing trips via iCloud. Neither exists any more: sync and sharing now run via the HelloKiwi server (see above).
So that nothing is lost, the app takes over the data in your private iCloud storage once, on the first start of the new version, and stores it on your device. After that, the app no longer reads from or writes to iCloud. Shares from other people received via iCloud are not taken over and are no longer shown.
We have no access to your iCloud data. It stays in your iCloud storage until you delete it: in the iOS settings under your name → iCloud → Manage Storage → HelloKiwi.
6. Sharing trips with others (HelloKiwi sharing)
You can share a trip with other HelloKiwi users. To do so you create an invitation (“Invite someone”), optionally with the name and email address of the invited person, and send them the invitation code, a link or a QR code. An invitation is valid for one person and for 14 days.
The invited person signs in and sends a request. As the owner of the trip you see their name and email address and decide whether to approve them. Only after your approval do they get access.
All members of a shared trip can see its content (including attachments) and edit it, but cannot delete the trip. All members see the names and email addresses of the other members. The owner can remove members at any time, and members can leave the trip at any time (“Leave trip”). What a member has already entered stays in the trip.
If the owner deletes their account, the trip passes to the member who has been involved the longest; if there is none, it is deleted.
Please do not pass on third-party data without their consent. Check the name and email address of the requesting person before every approval.
7. Legal bases
- Contract (Art. 6(1)(b) GDPR): providing the app, the account, synchronisation and sharing.
- Legitimate interest (Art. 6(1)(f) GDPR): operation and security of the servers (server logs, rate limiting, backups).
- Consent (Art. 6(1)(a) GDPR): optional permissions (calendar, notifications), the optional AI feature and usage statistics (for storing the identifier on your device additionally Section 25(1) TDDDG); can be withdrawn at any time.
8. Recipients and third-party services
We only pass on data where this is necessary to provide the functions:
- Hosting provider (data centres in Spain and Germany, EU): operation of our servers (processor).
- Google: sign-in with your Google account, place search, nearby places and place photos (Google Places: search text, coordinates of the destination), map links (Google Maps).
- OpenAI: optional packing list assistant, country information and flight information (see below).
- Open-Meteo (Android): weather forecast for destinations (coordinates, period).
- OpenStreetMap (Android): map tiles when choosing a location and – via Nominatim – the address for coordinates (map section, coordinates).
- Wikipedia: short descriptions of destinations (city, country, possibly coordinates).
- AeroDataBox (via RapidAPI): flight information (flight number, date, airport code).
- Viator: offers and activities for destinations (coordinates, destination, period, currency) and their images.
- Wikimedia (Wikidata): currencies of destinations (country codes, language).
- Esri (ArcGIS) (Android): satellite map when choosing a location (map tiles).
- Apple: Sign in with Apple; on iOS also weather (WeatherKit: coordinates of the destination), maps and place search (MapKit: search text, coordinates), push services, the check for app updates in the App Store and the one-time takeover of earlier iCloud data (see “Earlier iCloud data”).
- Microsoft (Microsoft 365, processor): sending sign-in codes by email (email address, code). Sent messages are not stored in our mailbox.
- Frankfurter / European Central Bank: exchange rates for expenses in other currencies. Our server retrieves the rates; no data about you is transmitted.
- Other members of shared trips (see “Sharing trips with others”).
Requests to OpenAI, Google Places, Open-Meteo, OpenStreetMap, AeroDataBox and Viator go through our relay server (api.hellokiwi.app): the providers receive the request, but not your IP address. Sign-in with Google and Apple, queries to Wikipedia and Wikidata, the Apple services on iOS and loading map tiles and Viator images are made directly from your device – your IP address is then visible to the provider. If you open a map link, Google Maps or your browser is opened.
AI features (OpenAI): For the optional packing list assistant we send OpenAI the trip title, the period, the number of participants, the destinations (city, country code), the selected trip themes and means of transport, existing packing list items and the app language. For country information we send the country and coordinates of the destination, for flight information the airline, flight number, airports and flight date. Names of people, email addresses, addresses or account data are not transmitted; because the trip title is free text, please do not enter personal data there. The content is used only to create the respective suggestions; the results are saved in the trip and are visible to its members. According to the provider, the transmitted content is not used to train models, but may be stored briefly to detect misuse. You can report AI content to support@hellokiwi.app with “Report content”.
9. Server logs (log files)
Technical logs are created when our servers are accessed. They contain the time, the requested path, the response code and a shortened IP address (for IPv4 without the last byte); on the relay server (api.hellokiwi.app) also the identifier of the app version (user agent). Error and security logs (server errors, firewall, login attempts on the server) may contain the full IP address. All logs are deleted after 7 days at the latest. The hosting provider may keep its own logs.
The purposes are operation, troubleshooting and defence against attacks (legitimate interest). To limit requests, the IP address is used briefly in memory. These legal texts are served without an access log.
10. Storage & retention
We store data only for as long as it is necessary for the respective purpose.
- On your device: trips, photos, notes and settings are in the app database on your device and are removed on uninstallation. When you sign out you can have them deleted from the device; when switching to another account the app asks.
- On the HelloKiwi server: as long as your account exists. If you delete a trip, its content and attachments are removed immediately; an empty deletion marker remains for 90 days so that your other devices also apply the deletion. If you delete individual entries, attachments are removed immediately and the remaining content after 90 days at the latest.
- Deleting your account: with “Delete account and server data” your account, your profile, your sign-in data, your trips without other members including content and attachments, and your invitations on the server are permanently deleted; we revoke any connection to your Apple ID with Apple. Trips with other members pass to the member who has been involved the longest; what you entered there is kept for the others. If others have entered you as a participant in their trips, these details remain there. Without the app, you can request deletion via legal.hellokiwi.app/account-deletion.
- Backups: the server is backed up daily in encrypted form (14 days on the server, a further encrypted copy for up to 60 days). Deleted data can therefore remain in backups for up to 60 days and is then removed completely.
- Invitations: are valid for 14 days and remain stored with the trip until the trip or account is deleted.
- Server logs: 7 days.
- Usage statistics: raw data for at most 13 months, then deleted automatically.
- Sign-in codes by email: at most 1 day (including the IP address used for rate limiting); results of Sign in with Apple on Android at most 10 minutes.
- Operating system backups (e.g. iCloud on iOS) are subject to the providers’ policies. The Android app does not take part in automatic Google backup.
11. Your Rights
- Access, rectification, erasure, restriction
- Data portability
- Objection
- Withdrawal of consent
- Complaint to a supervisory authority (AEPD, Spain)
How to exercise your rights: In the app’s Settings you can download your data with “Export my data” (on Android as a ZIP with a readable overview, a machine-readable JSON file and all attachments; on iOS as a machine-readable JSON file) and delete your account with “Delete account and server data”. You can also contact privacy@hellokiwi.app – even if the app is no longer installed.
12. Third countries
Our servers are located in the EU (Spain, Germany). Some third-party services may process data outside the EU, in particular in the USA (e.g. OpenAI, Google, Microsoft, Wikimedia, Esri). Such transfers take place only on the basis of recognised safeguards, such as an adequacy decision of the European Commission (EU-US Data Privacy Framework) or the EU Standard Contractual Clauses.
13. Security
- Encrypted transmission (TLS) between the app and the servers.
- Attachments are stored encrypted on the server (AES-256); backups are encrypted with a key that is not stored on the server.
- Sign-in tokens are stored on the server only as a checksum; access to trips is possible only for members and is checked on every request.
- Hardened servers (firewall, access by key only, rate limiting, automatic security updates); access only for the operator.
- Nobody can promise absolute security: protect your device (screen lock) and give invitations only to people you know.
14. Usage statistics (Matomo)
If you agree, we use the open-source software Matomo to record how the app is used, so that we can improve it where it matters. The app asks you on its second start with two equal buttons (“No thanks” and “Sure”); nothing is preselected. Without your consent nothing is recorded. Your decision applies to the respective device and is not synced with your account.
Matomo runs exclusively on our own server (track.hellokiwi.app) in a data centre in the EU. There is no disclosure to third parties and no transfer to third countries.
What is recorded:
- which screens and features are used (e.g. “trip created”, “packing list exported”) and when (date, time, local time);
- app version, platform (iOS/Android), app language, sign-in method (e.g. Apple, Google, not signed in), device model, operating system version, screen resolution and device language;
- a random identifier that the app creates and stores on your device when you consent, plus the time and number of previous visits. This only serves to recognise returning use; the identifier is not linked to your account;
- your IP address: it is used to determine your country; it is only stored in shortened form (the last two bytes are removed).
What is not recorded: no content such as trip titles, names, email addresses, places, amounts, notes or packing list items, no account ID and no advertising ID. There is no cross-app or cross-platform tracking.
Legal basis: your consent (Art. 6(1)(a) GDPR; for storing the identifier on your device Section 25(1) TDDDG).
Withdrawal: You can withdraw your consent at any time in the settings under “Privacy → Usage statistics”. The app then stops sending, and the identifier and any unsent data are deleted from your device.
Retention: Raw data is deleted automatically after 13 months. Aggregated statistics without reference to individual users may be kept longer.
Older iOS versions (up to 1.4.x) send anonymous usage analytics without a stored identifier. This data is stored separately and is also deleted after 13 months.
15. Obligation to provide data
You do not have to provide us with any data to use the app locally. An account, sync and sharing require sign-in (Apple, Google, email code or passkey); without it, these features are not available. Usage statistics are voluntary. Some features also need certain information or permissions (e.g. reminders without notification permission, flight information without a flight number).
16. Device access
The app may request the following permissions – only when you use the function; you can revoke them at any time in the system settings:
- Calendar: add and check trip and appointment events (local; only with your consent).
- Notifications and – on Android – exact alarms and start after the device restarts: showing reminders for trips, tasks and appointments reliably (local).
- Camera / photos / files: take or select images and documents (via the system picker; only the files you choose are used). If you are signed in, attachments and cover images are synced with the trip (see “Synchronisation”); on iOS the camera also reads the QR codes of invitations.
- Contacts: when adding participants you can choose a contact via the system picker. The app receives only the chosen contact and takes over its name and email address as a participant; there is no access to your address book.
- QR code scanner (Android): scanning invitation codes. Scanning is done by the Google scanner of Google Play services on your device; the app receives only the scanned code, no camera image.
- Internet: for synchronisation, sharing and the online services.
17. No tracking (advertising & profiles)
The app uses no advertising tracking SDKs, no advertising profiling, no advertising networks and no cross-app or cross-site tracking.
The usage statistics (section “Usage statistics (Matomo)”) only run with your consent on our own server and are not combined with data from other providers.
18. Changes
Adjustments are made when services or legal requirements change. See the header for the latest update.
Contact
Version 2.3 • Document ID: HK-PRIV-2026-10-01-EN