Core Privacy Commitment: Roamabout does not sell, rent, or monetise your personal data. We do not run third-party advertising SDKs, tracking pixels, or data brokers. Your financial records and travel receipts belong solely to you and your travel group.
1. Information We Collect and How We Use It
Roamabout is designed with an offline-first architecture. The information processed by the app includes:
- Trip & Expense Information: Expense titles, amounts, foreign currencies, exchange rates, categories, and split ratios that you create. This data is saved locally on your device via SwiftData and synced securely to Cloud Firestore when sharing trips with group members.
- Receipt Scanning & AI Vision (Guidelines 5.1.1(i) & 5.1.2(i)):
- Local On-Device Processing: By default, receipt photos scanned using the camera or photo picker are analysed directly on your device using Apple's Vision framework (OCR). Text extraction runs entirely on your iPhone's Neural Engine without internet transmission.
- Third-Party AI Service (Google Cloud Gemini API): For complex, crumpled, or multi-item handwritten receipts, you may explicitly opt to use Cloud AI enhancement.
- What Data is Sent: The receipt photo or document image you select/capture, including visible text such as merchant name, date, item descriptions, and prices.
- How It is Collected: Captured or picked directly by the user within the expense creation screen.
- Who It is Sent To: Google LLC (Google Cloud Gemini API servers).
- All Uses of That Data: Exclusively for optical character recognition and parsing structured expense line items into your app form. Never used for user profiling, advertising, or marketing.
- User Permission & Control: Transmitted only after you grant explicit in-app consent via our AI transparency prompt. You can revoke this permission at any time in App Settings > Receipt AI Assistance.
- Third-Party Protection Guarantee: In accordance with Guideline 5.1.2(i), we confirm that Google LLC provides equal or greater protection of user data, operating under strict SOC 2, ISO 27001, and GDPR enterprise standards. Under Google Cloud API terms, receipt data is encrypted in transit via TLS 1.3, processed ephemerally in volatile memory, never stored on disk, and never used to train Google's artificial intelligence or machine learning models.
- Location Data (Optional): If you grant location access, Roamabout records the GPS coordinate (latitude and longitude) of an expense solely to display it on your personal travel map. Location is never tracked continuously in the background and is never shared with third parties.
- Contacts (Optional): If you use the native iOS contact picker to invite friends or autofill payment details, the contact data is accessed purely on-device at the moment of selection. We never upload or scrape your address book.
2. Cloud Synchronisation & Multi-User Sharing
When you share a trip via a 6-character code or secret invite link:
- Trip and expense records are encrypted in transit and stored in Google Firebase Cloud Firestore.
- Authentication uses anonymous cryptographic tokens. We do not require or demand your real name, email, or password to join or view a shared trip.
- Only members with your trip’s cryptographic link or explicit host approval can read or modify shared trip expenses.
3. In-App Purchases & Subscriptions
All in-app purchases and subscriptions (Roamabout Pro) are handled securely through Apple's StoreKit 2 and App Store infrastructure. We do not collect or store your credit card numbers, billing addresses, or banking credentials.
4. Third-Party Services & Data Protection Standards
Roamabout utilises minimal, strictly audited third-party infrastructure. We confirm that all third parties provide the same or equal protection of user personal data:
- Apple Inc.: App Store distribution, StoreKit transaction validation, and on-device Vision OCR framework.
- Google Firebase: Cloud Firestore for encrypted real-time group synchronisation and Firebase Anonymous Authentication.
- Google Cloud (Gemini API): Zero-retention, ephemeral multi-modal artificial intelligence for receipt parsing. All data is processed under enterprise data protection commitments ensuring zero storage and zero model training.
- Exchange Rate APIs: Open-access foreign currency lookup for foreign exchange conversion. No personal user data is ever transmitted.
5. Data Retention & Deletion
You maintain full control over your data:
- Deleting a trip inside the app permanently deletes all associated local expenses and debt settlements.
- If you are the trip owner, deleting a shared trip purges the trip records and cloud subcollections from Firestore.
- You can reset or wipe all app data at any time by uninstalling the application.
6. Children's Privacy
Roamabout is not intended for or directed towards children under the age of 13. We do not knowingly collect personal information from children.
7. Contact & Inquiries
If you have any questions or feedback regarding this Privacy Policy or your data, please contact us at:
Entity: JLam Solutions (ABN: 55 450 695 789)
Email: support@jlamsolutions.com.au