dani.go

Privacy policy

Last updated · 2026-08-25

What we collect

To make dani.go work, we store:

  • Your account email address (for sign-in).
  • Your trip data — events, places, notes, imports, bookings. This needs to sync across your devices and your travel companions.
  • Basic app analytics — which screens you visit, which features you use, how often. Aggregated and anonymized; never tied to your identity in any report.
  • Crash logs when the app crashes, so we can fix it.

What we don't collect

We don't track you across the web. We don't fingerprint your device. We don't read your journal — by design we can't, because it's encrypted on your device before it leaves.

Journal encryption

Every memory you write into dani.go is encrypted on your device with a key derived from your account password. The server sees only ciphertext. If someone breached our servers, they would see nothing — not photos, not notes, not titles. If we received a subpoena for your journal, we would have nothing to hand over.

This is real end-to-end encryption, not a marketing term. It also means: if you forget your password, nobody can recover your journal for you. We don't have the key. That tradeoff is the point.

Who we share data with

Nobody, unless you explicitly ask us to. Specifically:

  • Airlines and hotels — when you book through dani.go, we send the minimum booking info required (name, dates, passport if legally required). We don't send them your travel history, your other plans, or your companions.
  • Your travel companions — people you invite onto a trip see the parts of that trip you share with them, based on their role. They never see your journal or other trips.
  • Law enforcement — only with a valid legal order and only for the specific data requested. We publish a transparency report annually.

We do not share data with advertisers, data brokers, or third parties for marketing.

Google Photos

If you choose to attach a photo from Google Photos, dani.go requests the photospicker.mediaitems.readonly scope from your Google Account. This scope only lets us open Google's own photo picker and receive the specific items you select there. dani.go cannot read, list, search, or browse your Google Photos library — the picker runs inside Google, and nothing is returned to us except the photos you pick.

The photos you select are downloaded and stored with the trip event or journal entry you attached them to, so they still appear when you are offline and so your invited travel companions can see them on that trip. They are never shown to anyone outside that trip, never sold, and never given to advertisers or data brokers. You can delete an attached photo from the event at any time, and you can revoke dani.go's access to Google Photos entirely at myaccount.google.com/permissions.

Limited Use disclosure. dani.go's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your rights

You can export every trip, every memory, and every file associated with your account at any time from Settings → Export. You can delete your account at any time — doing so permanently destroys your journal key, making all encrypted content irrecoverable, and queues the rest of your data for deletion within 30 days.

Contact

Questions, concerns, or data requests: privacy@dani.go. We respond within 7 business days.