Privacy Policy
Noma holds sensitive travel information. This policy explains what we collect, why we use it, who helps us process it, and the controls available to you.
1. Scope and who is responsible
This Privacy Policy applies to Noma's mobile applications, websites, support channels, and related travel-planning, passport, document, place-discovery, subscription, and AI features (collectively, the “Service”). Noma is responsible for deciding how personal data is used for the Service. A store, payment processor, or linked third-party service may separately control data it collects under its own privacy notice.
“You” means the account holder or visitor using the Service. This policy does not cover an airline, hotel, booking site, map provider, or other third party that you open from Noma.
2. Information you provide
- Account data such as your name, email address, authentication method, profile details, and support correspondence.
- Passport and place data such as countries, territories, regions, cities, restaurants, hotels, attractions, visited or wishlisted status, dates, notes, photos, and ratings.
- Trip data such as destinations, dates, travellers, preferences, budget, pace, constraints, itineraries, saved suggestions, and shared-trip participation.
- Booking and document data such as uploaded tickets, confirmations, PDFs, images, extracted fields, transport details, accommodation details, names, dates, addresses, booking references, and other content contained in files you choose to upload.
- Chat and memory data such as prompts, replies, edits, preferences, people you mention, and facts you ask Noma to remember.
Please upload only content you are entitled to use. Avoid adding unnecessary passport numbers, payment-card details, government IDs, health information, or information about another person. If you add another person's data, you are responsible for having a lawful basis to do so.
3. Information collected automatically
When you use Noma, we may receive device and app information such as platform, app version, language, time zone, device type, IP address, approximate region derived from the network, authentication and security events, feature interactions, crash information, and diagnostic logs. PostHog helps us measure product usage and diagnose failures, and may receive your account email as a profile identifier so we can find and support your account. Analytics events do not include trip names, destinations, document contents, chat messages, or other private travel content. Our website may use essential cookies or local storage to keep you signed in, preserve security state, and remember necessary preferences. Noma does not use private travel content for behavioural advertising.
4. Device permissions and precise location
Noma requests access to location, photos, camera, or files only when a feature needs it and your device asks for permission. Precise location may be used to centre a map, identify a place you choose to save, or support another location-based action you initiate. Photo, camera, and file access is used to import the specific content you select. You can revoke system permissions at any time in device settings, although the related feature may stop working.
When you use Google Maps or Places features, Google may receive map and place search terms, IP address, place identifiers, and latitude and longitude needed to return the requested result. Google processes this information under its Privacy Policy.
5. Payments and subscriptions
Apple, Google, Paddle, RevenueCat, or another disclosed commerce provider may process purchases depending on your platform and the checkout shown to you. RevenueCat may receive your account email as a customer attribute so we can find and support your subscription. Noma does not receive your full payment-card number. We may receive transaction identifiers, product and plan, purchase and renewal dates, currency, country, trial or promotional status, cancellation state, refund state, and current entitlement so we can unlock features, prevent fraud, provide support, and keep subscription records. Those providers process payment and tax data under their own privacy terms.
6. How and why we use information
- Provide, personalise, sync, and secure your account, passport, trips, documents, maps, suggestions, chats, memories, and subscription access.
- Extract structured itinerary information from files you deliberately upload and place it into the trip you selected.
- Respond to requests, investigate errors or abuse, recover accounts, enforce our Terms, and prevent fraud or security incidents.
- Maintain, debug, measure, and improve reliability and product experience using data that is aggregated or minimised where practical and excludes private travel content from analytics events.
- Meet accounting, tax, consumer-protection, legal, and regulatory obligations and establish or defend legal claims.
- Send essential service, security, purchase, and policy notices. Marketing messages, if introduced, will include the controls required by applicable law.
7. Legal bases
Where a legal basis is required, we process data to perform our contract with you; with your consent, including for optional device permissions; for our legitimate interests in securing, supporting, and improving the Service where those interests do not override your rights; and to comply with law. You may withdraw consent at any time, but withdrawal does not make earlier processing unlawful. The exact legal basis and rights available depend on where you live.
8. AI features and document extraction
When you ask Noma to plan, answer, extract, or remember something, the content needed for that request may be sent to a configured AI provider. This can include your prompt, relevant trip context, a selected document or image, and the minimum account or conversation context required to return and store the result. Do not submit highly sensitive information unless it is necessary for the feature. AI output can be incorrect; review important travel and booking details against the original source.
9. Service providers and disclosures
We disclose data only as needed to operate the Service, including to:
- Convex and authentication infrastructure for accounts, application data, file storage, server functions, and security.
- Apple and Google for sign-in, app distribution, device services, and purchases; RevenueCat for subscription entitlement management; and Paddle if a web checkout is offered.
- PostHog for privacy-minimised product analytics and diagnostics.
- Google Maps and Places, map and geographic-data providers, Unsplash, and travel-data providers such as LiteAPI when you use the relevant map, image, hotel, flight, or discovery feature.
- Configured AI model providers, currently including Google or providers accessed through OpenRouter, for prompts, planning, and document extraction you initiate.
- Professional advisers, auditors, authorities, courts, or counterparties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a financing, reorganisation, acquisition, or transfer of the Service subject to appropriate safeguards.
We do not sell personal data. We do not share private travel content with advertisers for cross-context behavioural advertising.
10. Sharing features
Content remains private unless you choose a sharing or collaboration feature. Anyone with access to a share link or invited trip may be able to view the content and changes described before you share it. Review a trip for documents, booking references, names, and other sensitive details before sharing. You can revoke sharing where the Service provides that control, but copies already made by recipients may remain outside Noma.
11. International processing
Noma and its providers may process information in India, the United States, the European Economic Area, the United Kingdom, and other countries where they operate. These countries may have different data-protection laws. Where required, transfers use recognised legal mechanisms and contractual, organisational, or technical safeguards.
12. Retention and deletion
We retain account and travel content while your account is active and as needed to provide features you use. When you delete individual content, it is removed from the active Service subject to normal synchronisation and backup cycles. Account deletion removes the account and associated saved travel data from active systems; limited security, fraud-prevention, transaction, tax, dispute, or legal records may be retained for the period required by law or reasonably needed to establish or defend claims. Backup copies are isolated and expire under routine retention schedules unless preservation is legally required.
13. Security
We use reasonable administrative, technical, and organisational safeguards designed to protect data in transit and at rest, restrict access, and detect misuse. No online service is perfectly secure. Protect your sign-in method, use a unique password where applicable, and contact us promptly if you believe your account or a share link has been compromised.
14. Your rights and choices
Depending on applicable law, you may request access, correction, export, deletion, restriction, objection, withdrawal of consent, or a copy of personal data; opt out of certain sale, sharing, profiling, or targeted-advertising uses; nominate another person where local law provides; and complain to a regulator. Noma does not discriminate against you for exercising a privacy right.
You can edit or delete much of your content in the app, manage device permissions in system settings, and permanently delete your account from Profile. For other requests, email hello@nomatravel.xyz from your account address. We may verify your identity, clarify the request, honour an authorised agent where legally required, or retain information when a lawful exception applies. You may appeal a declined request by replying with “Privacy appeal.”
15. Children
Noma is not directed to children under 13, or a higher minimum age where local law requires it, and we do not knowingly collect their personal data without legally valid parental authorisation. If you believe a child has provided data improperly, contact us so we can investigate and delete it where required.
16. Changes to this policy
We may update this policy as the Service, providers, or law changes. We will post the revised version with a new effective date and provide additional notice when a change is material or consent is required. Earlier versions may be requested from support.
17. Contact and grievances
Email privacy requests, questions, or grievances to hello@nomatravel.xyz with “Privacy” in the subject. Include enough detail to identify your account and request, but do not email passwords, full payment-card numbers, or unredacted identity documents. We will acknowledge and handle requests within the time required by applicable law. For an Indian consumer grievance, this email is also Noma's published grievance contact; we aim to acknowledge the complaint within 48 hours and resolve it within one month. You may also contact the data-protection or consumer authority available in your jurisdiction.