Privacy
Last updated 3 September 2026
Who can see it
A trip is visible to the people in it, and to nobody else. This is enforced in the database itself with row-level security, not just in the app: a request for a trip you are not a member of returns nothing, no matter who makes it. Photos and covers live in private storage and are served through short-lived signed links that only trip members can get.
Your profile — name, username, bio and picture — is visible to people you share a trip with, and to anyone who looks you up by username if you have set your profile to public. You control that in the app.
What we store
Your account
An email address, a display name, and a username. Optionally a short bio and a profile picture. If you sign in with Apple and choose to hide your email, we only ever see the relay address Apple gives us — we never receive your real one.
Your trips
Trip names, destinations and dates; the itinerary you build; the polls you open and the votes cast in them; the messages in a trip’s discussion; the photos you add to a trip album, including the cover photograph; and receipt photos you attach to an expense.
Finding friends
If you choose to look up people you already know, At Last reads names, emails and phone numbers from your address book on the phone. Only the emails leave the device: they are sent to our server to see who already has an account. Names and numbers stay on the phone, so you can text or email an invite yourself. We do not keep your address book.
Photos and the camera
Album photos and trip covers come from your photo library. The camera is for snapping a receipt onto an expense. Both kinds of photo are stored with the trip and shown only to members, through the same short-lived signed links.
At Last Pro
Planning, voting, the album and the passport work without paying. At Last Pro is optional — extra storage, offline photo queue, recap cards without our mark, and a gold ring on your avatar. If you buy it, Apple handles the payment. RevenueCat keeps the purchase in sync with your account so the app knows whether Pro is active. We do not see your card number.
What we don’t store
No location data, no device identifiers for advertising, no browsing history, and no behavioural analytics. At Last has no advertising or analytics SDK in it at all. We do not build a profile of you and we do not track you across other apps or websites.
Who else is involved
- Supabase hosts the database, authentication and file storage. They process this data on our behalf and do not use it for anything else.
- Apple, if you use Sign in with Apple, tells us only the identifier and the email address (or relay address) you agreed to share. If you buy Pro, Apple also processes the payment.
- RevenueCat processes Pro purchases and customer info so the app can tell whether Pro is active. They do not get your trips, photos or contacts.
- Resend sends the password-reset email if you forget your password. They do not get your trips, photos or contacts.
How long we keep it
Your account and its content stay until you delete them. Cancelled trips are kept for a short recovery window and then purged. Deleting your account removes your profile, your photos and the files behind them immediately.
One exception, and it is deliberate: if you created a trip that other people are still on, deleting your account hands that trip to another member rather than deleting it out from under them. Your messages and the photos you uploaded still go.
Your choices
- See it. Everything we hold about you is visible in the app.
- Correct it. Profile → Edit.
- Delete it. Profile → Settings → Delete account. No email, no waiting, no support ticket.
- Ask us. If you are in the UK, the EU or a state with its own privacy law and want a copy of your data or a deletion confirmation in writing, email hello@atlast.travel and you will get one.
Children
At Last is not intended for children under 13, and we do not knowingly collect their information. If you believe a child has created an account, email hello@atlast.travel and we will remove it.
Security
Everything travels over HTTPS and is encrypted at rest. Passwords are hashed and never stored in a form we can read. Access to trip data is checked by the database on every single request.
Changes
If this policy changes in a way that matters, we will say so in the app before it takes effect, not just quietly edit this page.
Contact
Questions about privacy? Email hello@atlast.travel.