Loxaway Privacy

Loxaway

Privacy Policy

Last updated: 13 August 2026

Loxaway is a trip planner that keeps your trip on your phone. That is not a marketing line, it is the architecture, and it is the reason this policy is short: most of what other apps have to disclose, this one never receives.

The short version

Your itinerary is stored on your phone and, if you use sync or share a trip, on our servers. Travel document expiry dates never leave your phone at all. We do not sell anything about you, and there are no advertising or tracking SDKs in the app. In this version of the app there is no sign-up yet — see section 2, which also says what changes when accounts arrive.

1. Who we are

Loxaway is made by MediaBoxEnt Digital Studio LLC, a product of MediaBoxEnt Technologies. We are the data controller for the information described here.

Questions, requests or complaints: hello@loxaway.com.

2. How Loxaway knows who you are

Today, in this version of the app: there is no sign-up. When you first open Loxaway, your phone generates a random identifier for itself — we call it a participant id. That identifier is what lets the server tell one collaborator from another inside a shared trip. It is not linked to your name, your email, your phone number or your device's advertising id, because at this stage we do not receive any of those.

The practical consequence, stated plainly: with no account there is nothing to log back into. If you uninstall the app without having shared the trip, the trip on that phone is gone.

Accounts are coming, and this is why. Loxaway is being built so that the same trip opens on your phone and in your browser — the web version is a mirror of the app, not a separate product. A per-device identity cannot do that: your phone and your laptop would be two different strangers. So Loxaway will add a profile you sign in to, on both.

When that ships, we will hold an email address for you, and we will update this page before it does — with what is stored, for how long, and how to delete it. The plan is a sign-in code sent by email rather than a password, so there is no password for us to store or for you to lose. Nothing in this section will be changed quietly: the date at the top moves and the release notes say so.

3. What is stored, and where

WhatWhere it livesWhy
Your itinerary: days, stops, times, notes, costs, expenses, packing list Your phone. Also on our servers (Cloudflare, EU/US) once the trip syncs or is shared with someone. So the trip opens instantly with no signal, and so collaborators see the same plan.
Photos you add to a trip, and files you attach to a stop Your phone, and our file storage once uploaded. So they are on the trip for everyone in it, and available offline.
Travel document reminders: document type, expiry date, optional issuing country, vaccination dates Your phone only. Never uploaded, never synced, not included in exports, not visible to people you share a trip with. To warn you that a passport expires too close to your return date.
Booking confirmations you forward by email Our servers: the parsed booking until your app collects it, and the original message and its attachments in file storage. So the confirmation lands on the right day of the trip by itself.
Who is in a shared trip and with what role Our database: the participant id, the display name you chose, and the role. So the owner can invite, demote and remove people.
Aggregate usage counts Our database. See section 7. To know whether the app is being used at all.

What we deliberately do not collect

4. Permissions the app asks for

PermissionWhenWhat happens to it
Photos When you pick a cover photo or add photos to a trip. Through Android's photo picker, so the app only ever sees the pictures you chose — not your gallery.
Camera When you photograph a receipt while adding an expense. The picture is attached to that expense. Nothing else uses the camera.
Notifications For reminders: a booking deadline, a check-in, a passport expiring. Reminders are worked out on your phone and fire from your phone. There is no notification server and no push token.
Location (approximate, foreground) Only on the Explore screen, only for "weekend trips near me". Read once, used to sort a list, never stored and never in the background. Say no and Explore simply drops that one section.

5. Sharing a trip, and publishing a guide

A trip is private until you decide otherwise. Two things can change that, and both are your action:

A limitation worth knowing

Links to photos and attachments are long and unguessable, but they are not individually access-controlled: someone you send such a link to can open it without being in the trip. Treat a shared file link as public. We consider this a rough edge, not a design goal, and it is on the list to fix.

6. Who processes data for us

These are the only third parties involved, and none of them receives a list of users, because no such list exists.

Our servers run on Cloudflare's global network, which means data may be processed outside your country. We do not sell personal data, and we do not share it for advertising.

7. Usage measurement

We count four things, all of them as daily totals: how many devices opened a trip, how many trips were active, how well the booking reader is doing at understanding confirmations, and which partner links were tapped. No names, no email addresses and no trip content ever go into those counters.

Two details we would rather state than bury. The device counter stores the random participant id from section 2 against a date, so that "how many people came back the following week" can be answered — that is a device identifier, retained, and Google Play's Data safety form declares it as one. Tapped-link counts record which link and from where, never who.

This website separately uses Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors.

8. Partner links

Some links in Loxaway — a hotel, a tour, a car — may be affiliate links: if you book through one, we may earn a commission at no extra cost to you. Published guides mark those links as sponsored. Tapping one goes through our server so the click can be counted; the count records the link and the origin, not you.

9. Children

Loxaway is not directed at children under 13, and we do not knowingly collect information from them.

10. Keeping and deleting

Trip data is kept while the trip exists. When the owner deletes a trip, we delete the document, every photo and attachment belonging to it, its public directory entry, its inbox, its members and invites, its questions, and its counters — in one pass, not marked as hidden.

A forwarded booking is deleted from our side as soon as your app collects it. Usage counters are aggregates and are kept as history.

While there is no account, "delete my data" is: delete the trips you own, and uninstall the app. If you want anything else removed, or a copy of what is held for a trip you own, write to hello@loxaway.com and tell us the trip. Once profiles exist, deleting the profile will delete what is attached to it.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict how we use it, and to complain to your data protection authority. Write to hello@loxaway.com. Until profiles exist we will need enough information to identify the trip in question: with no account to look you up by, the trip is the only handle we have.

12. Changes

If this policy changes in a way that affects what we collect, we will change the date at the top and say what changed in the app's release notes. The version you are reading always lives at loxaway.com/privacy.