← Vagort
Privacy policy
Last updated: 24 August 2026
The short version
Your trips live on your device. An account is a separate thing from a subscription, and
this page is only about the account: it exists so your trips can be backed up and opened on
another phone. Vagort has no ad trackers and does not sell personal data. You can delete your
account, and everything in it, from inside the app at any time.
What we store, and where
- Trips and preferences (itineraries, notes, checklists, language, theme)
are stored locally on your device. Deleting the app deletes them.
- Your account, if you create one. Signing in is by emailed code, or with
Apple, Google or Facebook. We store your email address, an optional travel persona, and
the profile you filled in: your display name, your handle, your two sharing switches, and
the code behind your profile link if you made one. That copy is what puts your profile
back when you sign in on a second phone, and it is readable only by your own account.
We do not receive your password from any of those providers.
- Your date of birth, if you fill it in, stays on this device. It is
written to this phone's storage and nowhere else. It is not copied to your account, it is
never shown on your public profile, and it is not sent to us. It is the one profile field
we deliberately do not back up, because a full date of birth is permanent in a way an
email address is not, and nothing in the app needs it anywhere but on the phone you typed
it on. If you change phones you type it again, and that is the trade on purpose.
- Trips and memories you sync, once signed in, are copied to our database
so they survive a lost phone. Memory photos you attach are stored with them. They are
readable only by your own account.
- Community content, if you post it: your handle, display name, bio,
avatar, published routes, follows, reactions and reports. This part is public by
intention, which is what publishing means.
- Trip export codes are created only when you tap export, and go only where
you paste them.
Deleting your account
Sign in, open the account screen, and choose Delete account. This is immediate and
permanent: your account, trips, memories, uploaded photos, community posts, follows and
reactions are erased. It is a deletion, not a deactivation, and there is no recovery
afterwards. Trips kept only on your device are erased from it at the same time. You do not
need to email anyone to do this.
What leaves your device
- Place data and routing requests may be sent to mapping providers (e.g.
Google Places / Routes) and to OpenStreetMap Overpass to search cities and compute travel
times. These requests carry query content, not your identity as a Vagort user.
- Booking links open partner sites (hotels, flights). Once you're on a
partner's site, their privacy policy applies. Links may carry an affiliate tag so partners
know the visit came from Vagort, the tag identifies us, not you.
Location
Vagort can ask where you are in two places, and they are different enough to be worth
describing separately: inside the app, and on a shared plan page opened in a web browser.
Neither is ever asked on first launch, neither is background location, and nothing here is
ever asked before you have tapped something that says what it is for.
Everything works if you decline both.
Inside the app. We ask only while you are using the app, and
only when you tap something that needs it, such as "Find places near here".
- What we read: a single approximate coordinate at the moment you tap. We do
not track you, we do not record a location history, and we do not store a trail of where you
have been.
- Where it goes: the coordinate is sent as a search bias to our own server
and to the mapping providers above, so that results are the ones near you rather than near
somewhere else. It is used for that request and nothing keeps it afterwards.
- Turning it off: decline the permission, or withdraw it later in your
device settings. Vagort keeps working; you pick a city by name instead.
On a shared plan page, in your browser. If somebody sends you a link to a
Vagort plan, that page can offer you a button that says you are starting from where you are, so
the plan can begin with you. You do not need the app, an account, or anything installed. This
is the one place where a coordinate is stored rather than only passed along, so it is
set out in full.
- Only if you press the button. Your browser asks your permission before it
answers, and it only reaches that point after you have pressed something that says what it is
for. Ignore the button and nothing is read. The page is complete without it.
- What is stored: one latitude and longitude, rounded to about eleven
metres, and the time you sent it, filed against the plan you were looking at. No name, no
email address, no account and no device identifier is stored with it. Pressing the button
does not sign you up for anything and does not tell us who you are.
- How long: 24 hours, then it is deleted automatically and we cannot get it
back. A starting point is a fact about right now rather than a record worth keeping: if the
trip is further off, press the button again nearer the time.
- One per plan, and only the latest. A plan holds a single starting point.
Pressing the button again replaces what was there instead of adding to it, so no trail can
build up even if you press it every day.
- Changing your mind: because it is deleted within a day on its own, the
simplest answer is to wait. If you would rather it went now, mail
hello@vagort.app with the link you opened.
Usage data
We record how the app is used so we can tell which parts work. This is our own
server, not an advertising network, and there is no ad SDK in the app.
- What we record: events such as opening a screen, starting a plan, viewing
the subscription screen, and completing a purchase. Each event carries the event name, a
timestamp, the app version, the platform, your plan (free, trial or Pro) and the city you are
planning in.
- Crash reports, to our own server. When a screen fails to draw, we record
the error message along with the same event details above, so we can find the fault and fix
it. The message is cleaned before it is sent: email addresses, access tokens and anything in
a web address are replaced before it leaves your phone. There is no third-party crash
reporting service in this app, and there has not been one since August 2026.
- How you found us. One short label, worked out the first time you open the
app and never changed afterwards: a referral code if a friend sent you, a campaign name if
you arrived from a link we published, and otherwise the word "organic". It tells us which
efforts brought people here. It says nothing about you.
- How it is keyed: to a random identifier generated by the app on first
launch, plus a session identifier. It is not your device's advertising ID and
not Apple's IDFV. Deleting the app and reinstalling generates a new one.
- The city field is derived location. We are naming it here rather than
hiding it under "usage": knowing which city you are planning in is coarse location
information, and you should be told that plainly.
- Search terms are not stored. What you type in the ask box is matched on
your device or sent as a one-off search. We keep no history of your queries.
This website
Everything above is about the Vagort app. This site, vagort.app, is a separate thing with a
small set of records of its own, and until 24 August 2026 this policy did not describe them.
It does now. None of this uses cookies. Everything below is kept in your
browser's own local storage, which no other website can read, and all of it is erased if you
clear site data for vagort.app.
What this site keeps in your browser. The complete list, not a sample. Most
visitors have the first two and nothing else.
- vagort.webvid is a random visitor identifier, made inside your browser on
your first page here. Its only job is to tell us that two page views were one visit rather
than two people. It contains nothing about you and is not derived from anything about you or
your device. It lasts until you clear site data.
- vagort.webtok.v1 is a token our own server issues, which lets it tell an
ordinary browser apart from a flood of automated requests. It is what stops the site's
measurements being swamped, and it identifies a browser to a rate limiter rather than a
person to anybody. It lasts until you clear site data.
- vagort.ref.v1 is stored by the front page, and
vagort.ref by the referral page, but only if you arrived through a link
carrying a referral or campaign code. They hold that code, nothing else, so that a friend or
a partner still gets credit if you install the app minutes or weeks later. They are set only
when such a link is used, and they last until you clear site data.
- vagort.affiliate.session exists only if you are one of our partners and
have signed in to the affiliate portal. It is a sign-in credential, so it is
worth being blunt about it: anyone with access to your browser profile has access to your
partner account, exactly as with any signed-in site. It is removed the moment you sign out,
and removed automatically the first time the server refuses it. The server stops accepting
it 30 days after you sign in. Ordinary visitors never have it.
What this site sends, and where. When a page here loads, we record that a
page view happened.
- What the record carries: the path of the page you are on, the time,
whether you arrived from another site at all as a plain yes or no, and the first two
identifiers above. It goes to our own server, which runs on Cloudflare. It is the same
server the app talks to.
- What is deliberately left out: not the query string of the address, so a
campaign tag or a referral code sitting in the link is dropped before anything is sent. Not
the address of the page you came from, only whether there was one. Not your name, your email
address, or anything you have typed. There are no advertising trackers on this site, none of
this reaches an ad network, and it is not joined up with your Vagort account if you have
one.
- Turning it off: any browser setting or extension that blocks scripts or
local storage stops all of it, and every page here is built to work anyway. Nothing on this
site is withheld from a reader who blocks it. The one thing that needs storage to work at
all is the partner sign-in, because a sign-in is what it is.
What we don't do
- No selling or renting of personal data.
- No advertising SDKs or cross-app tracking.
- No account required to READ a plan. Signing in is about backup and sharing, not about
paying; what a subscription covers is set out in the Terms.
Payments
Subscriptions are processed by the app stores (Apple / Google). RevenueCat is the billing
partner that tells us whether a subscription is active; it receives the store's purchase
identifiers, never your card details, which we never see either.
Who else handles your data
- Supabase hosts the account and everything saved to it: the email address
you sign in with, your trips, and any plan you have shared. Signing in emails you a one-time
code through Supabase; there is no password to store.
- Cloudflare runs the service our app talks to, and stores the affiliate
programme's records. If you apply to be an affiliate, the email address you apply with is
held there together with your application and your sign-in codes. Ordinary app use does not
put you in that store.
Both act only on our instructions, and neither is paid for your data or given it to sell.
Children
Vagort is a general-audience travel tool and is not directed at children under 13.
Who operates Vagort
Vagort is operated by Wermom Technologies Inc, which is also the
copyright holder named on the App Store listing. Everything, including legal notices,
reaches us at hello@vagort.app. One address on
purpose: a second one published here would be a second mailbox somebody has to watch,
and a legal contact that nobody reads is worse than not having published one.
Changes & contact
If this policy changes materially, the "last updated" date above changes with it. Questions:
hello@vagort.app.