01Summary
Rouve is an AI-powered travel packing list app for iOS. To generate a packing list, it sends your trip details to our backend server, which then calls Anthropic's Claude API on your behalf. Your trip data is not stored on our servers — only your account information and usage counters are.
We don't sell data. We don't run ads. We don't build profiles.
Your trips live on your device. Our server only sees them for the seconds it takes to generate your list.
02Data controller
The data controller for all personal data processed through Rouve is:
- Name: Lorenzo Simonelli
- Address: Aversa (CE), Italy
- Email: [email protected]
As the data controller, Lorenzo Simonelli is responsible for determining the purposes and means of processing your personal data in accordance with the EU General Data Protection Regulation (GDPR), the Italian Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018), and any other applicable data protection legislation.
03What we collect
Rouve processes the following categories of personal and non-personal data:
Account data
- Apple ID (hashed) — when you sign in with Apple, we receive a unique, anonymised identifier from Apple. We never receive your real Apple ID, email address, or name unless you explicitly choose to share them. This identifier is stored in our database to associate your account with your usage.
- Email address (optional) — if you choose to share your email through Sign in with Apple, we store it solely for account-related communications. You may use Apple's email relay feature to keep your real address private.
- Premium status — a boolean flag indicating whether you have completed the one-time in-app purchase unlock.
- Generation counter — the number of AI packing lists you have generated, used to enforce free-tier limits and display your remaining quota in-app.
Trip data (transient)
- Destination — the city, region, or country you enter.
- Travel dates — your departure and return dates.
- Trip type — the category or categories you select (e.g. beach, business, ski).
- Traveller details — age and gender if you choose to provide them, used only to personalise item suggestions.
- Extras — optional flags such as carry-on only, medicines, photography gear.
- Baggage type — the luggage option you select.
Trip data is transmitted to our server solely to generate your packing list. It is not stored in our database and is discarded immediately after the AI response is returned to your device.
Device and technical data
- App locale — the language setting of your device (Italian or English), used to generate the packing list in the correct language.
- Purchase receipt — provided by the App Store to verify your in-app purchase. Processed by RevenueCat on our behalf.
- Crash and diagnostic reports — when the app encounters an error or crash, technical diagnostic data (such as the error, device model, OS version, and a stack trace) is sent to Sentry to help us fix bugs. These reports are linked to your anonymised account identifier so we can correlate issues affecting the same user. They never contain your trip details.
- Anonymous usage analytics — to understand how features are used and improve the app, we send anonymous, aggregated event data (for example, that a trip was created or a list was generated) to TelemetryDeck. This data is anonymised at the source and not used to identify you.
- HTTP request metadata — standard server logs (IP address, timestamp, HTTP method, response code) retained for up to 30 days for security and abuse-prevention purposes, then automatically deleted.
Rouve does not collect your device location, contacts, photos, or microphone input. The usage analytics we collect are anonymous and aggregated; we do not track individual behaviour or build advertising profiles.
04Legal basis for processing
Under the GDPR, we process your data on the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR) — processing your account data and trip details is necessary to provide the Rouve service you have requested.
- Legitimate interests (Art. 6(1)(f) GDPR) — retaining server logs for up to 30 days to detect abuse, prevent fraud, and maintain the security and integrity of our infrastructure; and processing anonymous usage analytics and crash diagnostics to fix bugs, improve stability, and develop the app.
- Compliance with legal obligations (Art. 6(1)(c) GDPR) — retaining transaction records as required by applicable Italian and EU tax and accounting regulations.
- Consent (Art. 6(1)(a) GDPR) — where you voluntarily provide optional data such as your email address or traveller details. You may withdraw consent at any time without affecting the lawfulness of prior processing.
05How we use your data
We use your data exclusively for the following purposes:
- Providing the service — authenticating your account, enforcing generation limits, and returning AI-generated packing lists.
- Processing payments — verifying and restoring your one-time in-app purchase via RevenueCat and Apple.
- Security and abuse prevention — detecting automated abuse, enforcing rate limits, and protecting the integrity of the Claude API pipeline.
- Improving the app — using anonymous usage analytics and crash diagnostics to understand which features are used, fix bugs, and improve stability and performance.
- Service communications — responding to support requests or feedback you send us via email.
- Legal compliance — meeting our obligations under Italian and EU law.
We do not use your data for advertising, profiling, automated decision-making with legal effects, or to train any AI model.
06AI generation and data flow
When you tap Generate list, the following sequence occurs:
- Your device sends the trip details (destination, dates, trip type, and optional traveller data) to Rouve's backend server, hosted on Railway (infrastructure located in the EU).
- Our backend validates the request, checks your generation quota, and forwards the trip details to Anthropic's Claude API over an encrypted TLS connection.
- Anthropic processes the request and returns a structured packing list to our server.
- Our server returns the list to your device and increments your generation counter.
- The trip details are discarded from server memory. Only the generation counter is updated in our database.
Anthropic processes your trip details as a sub-processor acting on our instructions. Under Anthropic's commercial API Data Processing Agreement, your inputs and outputs are not used to train models and are retained only briefly for trust-and-safety monitoring before deletion. Anthropic's privacy policy is available at anthropic.com/privacy.
Packing lists are AI-generated suggestions. Rouve does not guarantee their completeness or accuracy. Always verify critical items — documents, medicines, and safety equipment — independently.
07Storage, retention, and infrastructure
On your device
Your trips, packing lists, and checked items are stored locally using SwiftData. If you have iCloud enabled, they sync to your private iCloud container via CloudKit. We have no access to your iCloud container.
On our servers
Our backend runs on Railway (EU region). Our database is PostgreSQL, also hosted on Railway. We store:
- Your hashed Apple identifier
- Your optional email address
- Your premium status flag
- Your generation counter
- Standard HTTP server logs (retained 30 days)
Retention periods
- Account data — retained for as long as your account exists. If you delete your account, all account data is permanently deleted within 30 days.
- Server logs — automatically deleted after 30 days.
- Trip data — never persisted on our servers. Discarded after generation.
- Transaction records — retained for 10 years as required by Italian accounting law (D.P.R. 600/1973).
09International data transfers
Our primary infrastructure is located within the European Union. However, some sub-processors — including Anthropic (United States) and RevenueCat (United States) — process data outside the EU/EEA.
Where data is transferred to the United States, we rely on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) approved by the European Commission under Art. 46(2)(c) GDPR, incorporated into our data processing agreements with relevant sub-processors.
- EU-US Data Privacy Framework where the sub-processor is certified.
You may request a copy of the applicable transfer safeguards by contacting us at [email protected].
10Your rights
Under the GDPR and applicable Italian law, you have the following rights with respect to your personal data:
- Right of access (Art. 15) — request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17) — request deletion of your data ('right to be forgotten'), subject to legal retention obligations.
- Right to restriction (Art. 18) — request that we limit processing of your data in certain circumstances.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
- Right to lodge a complaint — file a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garante.it), or the supervisory authority of your EU member state.
To exercise any of these rights, email [email protected] with the subject line 'Data Request'. We will respond within 30 days. We may ask you to verify your identity before processing the request.
Because most of your trip data is stored locally on your device, you can exercise many of these rights directly within the app — by editing, deleting, or exporting your trips — without contacting us.
11Security
We implement the following technical and organisational measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher.
- Our backend enforces authentication on all protected endpoints via JWT tokens.
- The Claude API is called server-side only — your API credentials are never exposed to client devices.
- Database access is restricted to our backend service with least-privilege credentials.
- Server logs are automatically purged after 30 days.
- Our domain (rouve.app) is on the HSTS preload list, enforcing HTTPS for all connections.
No method of transmission over the internet or electronic storage is 100% secure. In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you and the Garante within 72 hours of becoming aware of it, as required by Art. 33-34 GDPR.
12Children
Rouve is not directed at children under 13 years of age (or under 16 in EU member states that have set a higher age of digital consent). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided data through the app, contact us at [email protected] and we will delete it promptly.
13Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will increment the version number at the top of this page and update the effective date. For material changes — changes that affect the nature of data collected, the purposes of processing, or your rights — we will notify you in-app the next time you open Rouve, and provide at least 30 days' notice before the changes take effect.
Continued use of Rouve after the effective date of a revised policy constitutes acceptance of the updated terms.
14Contact
For privacy questions, data requests, or any concerns about this policy, contact us at:
Get in touch
Rouve · Aversa, Italy