Private trips stay private.
RoamTab is designed to keep shared travel expenses private and simple. This policy explains what the app handles and when data leaves your device. RoamTab stores the name you enter, participant names, trips, expenses, settlements and optional receipt attachments in the app’s private local container. An optional Apple account restores Trip Pass access, not trip data. RoamTab does not show ads, use behavioral analytics or track people across apps or websites. Standard Apple Ads attribution is used only to measure RoamTab’s own App Store campaigns. If you choose Sign in with Apple, our Chibigiant backend stores your Apple account identifier, the email Apple provides (which may be a private relay address), device session identifiers and an encrypted Apple token needed to revoke access. Account session tokens stay in the iPhone’s device-only Keychain and are not synchronized through iCloud. Account information is used for authentication, security and restoring access, not advertising or behavioral analytics. Local profile and participant names are not uploaded as part of signing in. When you link a Trip Pass, or buy one while signed in, signed purchase proof is sent over HTTPS to Chibigiant and verified with Apple. We retain the account association, transaction identifiers, purchase and expiry dates, purchase environment and refund status to restore access on another device. Raw signed proof is not stored. Signed-in scanning requests include an account session token to check access; this token and account details are not forwarded to Google Gemini. The account does not synchronize trips or receipt attachments; use Backup & Restore to transfer local data. Only when you choose to scan a receipt, RoamTab sends the selected image over an encrypted connection to the RoamTab receipt-processing service and Google Gemini API. The image is used to extract the merchant, date, currency, line items and total. RoamTab’s proxy processes the image in memory and does not save the image or extracted content. Google may retain the prompt, receipt image and generated response for up to 55 days for abuse monitoring, service security and required legal or regulatory disclosures. When used as a paid service, Google states that this content is not used to improve its products. To protect the scanning service from abuse, RoamTab creates a random installation identifier and uses Apple’s App Attest service on supported devices. The proxy retains a one-way hash of that identifier, the attested public key, assertion counter and scan-quota counters. This information is used only for app functionality, fraud prevention and rate limiting. It is not associated with the name or expense data stored in RoamTab. When you use a reference rate for a foreign-currency expense, RoamTab sends the two currency codes and expense calendar date to Chibigiant over an encrypted connection. Chibigiant requests a rate from Frankfurter and caches the public quote. Expense amounts, receipt images, participant names, purchase identifiers and installation identifiers are not included in that rate request. The rate provider receives the request from Chibigiant, not directly from your phone. Manual rates and actual charged amounts are calculated locally and can be entered without an internet connection. Confirmed original amounts, conversion rates and trip-currency amounts are stored with the expense on your device and included in your exported backups. Fetching later reference rates does not change saved expenses. Camera access is used only when you photograph a receipt. Photo library access is used only for the image you select. RoamTab does not browse or upload the rest of your photo library. RoamTab uses RevenueCat to present, process, validate and restore Trip Pass purchases made through Apple. RoamTab stores a random purchase identifier in Keychain so access can survive a reinstall or device restoration when Keychain data is preserved. RevenueCat receives that anonymous identifier, purchase history and limited app or device technical information needed to provide the purchase service. RoamTab does not send RevenueCat your name, participant names, trips, expenses, balances or receipt images. Purchase data is also used to measure whether an Apple Ads campaign resulted in a Trip Pass purchase. The receipt-processing proxy sends the anonymous RevenueCat app user identifier to RevenueCat when it needs to validate Trip Pass access. The proxy stores only a one-way hash of that identifier in a short-lived access cache, not the raw identifier. RoamTab uses Apple’s AdServices framework and RevenueCat’s Apple Ads integration to measure its own advertising in the App Store. The app sends a short-lived Apple attribution token to RevenueCat. RevenueCat exchanges it with Apple and may store campaign, ad group, keyword, creative and attribution details on the anonymous purchase profile. RoamTab uses standard Apple Ads attribution only. It does not request IDFA, show an App Tracking Transparency prompt or use this information to track you across other companies’ apps or websites. RoamTab does not sell personal data, show advertising or track you across apps or websites. Receipt data is shared only with the processing service and Google Gemini API needed to perform a scan. Purchase data is shared only with Apple and RevenueCat to provide in-app purchases, restore access and measure RoamTab’s own Apple Ads campaigns, subject to protections consistent with this policy. Local data remains on your device until you delete the related expense, use Data & Backup → Delete All RoamTab Data, or remove the app. Deleting an expense removes its saved receipt attachment. You can export a portable backup before erasing the app. RoamTab’s proxy discards receipt images and extracted content after completing the request. Google may retain the prompt, image and response for up to 55 days for abuse monitoring, service security and legal compliance. Quota records are removed after 31 days and App Attest keys are removed after 180 days without a receipt scan. RevenueCat retains purchase records as described in its privacy policy and as required to provide purchase restoration and comply with law. You may contact us to request deletion of developer-controlled purchase metadata where applicable; Apple transaction records may be subject to Apple’s own retention obligations. Use Plan & Purchases → Delete RoamTab Account to request deletion. Account sessions are blocked immediately. Chibigiant revokes the Apple token, then removes the account, provider credential and linked purchase associations. If Apple is unavailable, revocation is retried and the disabled account and encrypted credential remain until it succeeds. Contact us if deletion is delayed. Local trips are not erased; use Data & Backup to erase them separately. Account deletion does not refund purchases or remove Apple’s or RevenueCat’s own records. Account information and linked purchases otherwise remain while the account exists. If RoamTab’s data practices change, this policy and the App Store privacy disclosure will be updated before the changed behavior is released. For privacy questions or deletion requests, email hi@zeitflow.de.Data stored on your device
Optional Apple account and purchase recovery
Receipt scanning
Exchange rates
Camera and photo library
Purchases
Apple Ads attribution
Sharing and tracking
Retention and deletion
Account deletion
Changes
Contact