Codonic
← All privacy policies

Privacy policy

Souvenir

For iOS, Android

Last updated 13 August 2026

In short

  • Without an optional Souvenir Account or AI connector, your journal is not readable by Codonic: it stays on your device, in your private iCloud, or inside an end-to-end-encrypted shared trip.
  • A Souvenir Account is optional. It stores identity and recovery metadata so the same trip member can move between devices; the recovery code itself never reaches us.
  • Claude and ChatGPT access is a second, separate opt-in. It gives our integration service and the provider a limited, server-readable trip projection, never notes, precise GPS, card identifiers, photos, receipts or other media.
  • Deleting a trip, deleting the app and deleting a Souvenir Account are different actions. The sections below explain exactly what each removes.

Who is responsible

Souvenir is made by Codonic. If you have a question about anything on this page, write to dev@codonic.dev. For help with the app itself, support@codonic.dev is the faster address.

This policy covers these store listings:

  • Souvenir for iOS — App Store
  • Souvenir for Android — Google Play

Ordinary use without an account or AI connector

Creating a Souvenir Account and connecting Claude or ChatGPT are both optional and off by default. Without either opt-in, Codonic does not receive a readable copy of your journal or build a profile of you.

Your trips, expenses and amounts, photos and receipts, recorded places, travel-companion names, and the nicknames and last four digits you give payment cards are stored in the app’s database on your device. Personal iCloud and end-to-end-encrypted sharing are described separately below.

Currency exchange rates

Souvenir fetches currency exchange rates from frankfurter.dev. The iPhone app can use additional public fallback sources when needed; the current Android app uses Frankfurter. Other network features are described separately below.

Those requests contain only currency codes and dates — for example, “the euro-to-baht rate on 14 July”. They carry no personal data and no identifier of you or your device. Rates are cached on the device and stored with each expense as you save it, so the app keeps working offline.

Maps and optional intelligence downloads

Map views need an internet connection to load public OpenStreetMap map tiles. On Android, the map component also loads its display library from a public content-delivery network. These requests necessarily receive ordinary connection information such as your IP address, under the respective provider’s privacy terms; Souvenir sends no Codonic-assigned user identifier or advertising identifier with them.

On iPhone, if you explicitly choose to download an optional on-device intelligence model, the model file is fetched from Hugging Face. The model then runs on the device; your receipts, photos and journal content are not uploaded to that provider for analysis.

Automatic capture Android only

Souvenir on Android has an optional feature called Automatic capture. It is off by default and does nothing until you turn it on and explicitly grant Android’s notification-access permission.

When enabled, it reads notifications on the device in order to spot payment alerts — a Google Pay tap, a bank charge notice — and offer to turn them into expenses. Only notifications that contain a monetary amount are used, and only while one of your trips is ongoing.

All of this happens on the device. Notification content is never transmitted anywhere, is not retained beyond the expense entry it creates, and is never shared with anyone. You can turn the feature off at any time, either in the app or in your Android system settings.

Capturing Apple Pay purchases iOS only

On iOS, capturing an Apple Pay purchase works through a Shortcuts automation that you create yourself. Souvenir never accesses Wallet, your payment credentials or your transaction history. It only receives whatever your own automation chooses to hand it.

Location

Location is used at the moment you add an expense: a single one-shot fix suggests the local currency and, if you keep it, pins the expense to a place. It is stored with that expense like the rest of your journal. On an optional shared trip it is included only inside the end-to-end-encrypted trip data described below, which we cannot read. Souvenir does not track you in the background, and you can decline the permission — you then pick the currency yourself.

Photos and camera

Photos and receipt images you attach are stored on your device, inside the app’s own database. They are never sent to us.

On a shared trip, photos sync to the group the same encrypted way as everything else. A small thumbnail travels with the trip so everyone can browse it; the full-size image is uploaded encrypted and kept in the shared cloud storage for 30 days after the trip ends, and the thumbnail for about a year, after which they are removed to free up space. Anyone in the group who opens a photo while it is available keeps their own copy for good — expiry frees the cloud storage, never your device. A single “Download shared photos” setting lets you fetch full-size images automatically rather than on demand.

Personal sync and backup iOS only

On iPhone, Souvenir can keep your journal in sync across your own devices and backed up, using your personal iCloud account. This is your own private iCloud database: the data is stored under your Apple Account, we have no access to it and receive no copy, and it is governed by Apple’s terms. If you are signed out of iCloud or turn sync off, Souvenir simply keeps everything on the device.

This personal sync is separate from sharing a trip with other people, described next.

Optional Souvenir Account Separate opt-in

You can create a Souvenir Account to keep the same participant identity when you move between devices and to recover your trip bindings. An account is not required to use the app, personal iCloud or shared trips. We do not ask for an email address, phone number or password.

The account service stores a random account ID, public account and device signing keys, device status and timestamps, random per-trip aliases, the trip member ID each alias represents, and encrypted recovery envelopes for your bindings. A recovery envelope can contain a shared-trip key and account-authority key, but it is encrypted from your recovery code before upload and the service cannot decrypt it. The recovery code and its root secret stay on your device unless you choose to copy them elsewhere.

Account records are stored in locked record types in Apple CloudKit’s public database and can be accessed only by the dedicated Codonic integration service. Sensitive record bodies are encrypted at rest by that service. The operational lookup fields named above are pseudonymous but linkable metadata, not anonymous data. Cloudflare processes account API requests at the edge; Apple stores the records. Neither service changes the underlying trips or turns an account into a separate copy of your journal.

Anyone who has your recovery code can recover the account. Keep it private. Because there is no email, SMS or password reset, Codonic support cannot retrieve or replace a lost recovery code.

Optional Claude and ChatGPT connectors Separate opt-in

AI access is disabled until you explicitly enable it and approve an OAuth connection. Approval is account-wide: the connector can use every current or future trip for which that account has a valid participant binding and AI grant. Claude or ChatGPT may still ask you to approve individual tool actions under the provider’s own controls.

For this feature, the Codonic integration service receives a limited, server-readable projection containing trip names, dates, budgets and home currency; member IDs and names; and permitted expense fields such as title, amount, currency, date, category, city or place name, payer and split participants. It deliberately excludes free-form notes, exact coordinates, card identifiers, card nicknames and last four digits, attachments, photos, receipts and all other media.

AI access is account-wide across every current and future bound shared Bridge trip, not a per-trip picker. Its limited projection includes other participants’ display names and shared expenses even when those people did not create a Souvenir Account or enable a connector themselves. The participant who opts in should have authority to share that ledger with the selected provider and notify the group when appropriate.

Local and private-iCloud trips are not exposed because they do not have an always-on server canonical source. For a granted shared trip, the service stores the Bridge key encrypted at rest plus an expiring, revocable AI delegate key. It verifies and decrypts the exact canonical Bridge history for every tool call and commits attributed AI writes through the same Bridge gate. No phone acts as a relay or must remain online. This opt-in path is not end-to-end encrypted from Codonic or the selected provider.

Every connector write is recorded as an action by the exact participant bound to the account in that trip. The expense payer is a separate ledger field and may be another current trip member. OAuth clients, hashed authorization credentials, limited projections, grants and action records are stored in the locked account service described above. Terminal action records may be retained for up to 30 days; refresh credentials can last for up to 90 days unless revoked sooner.

Claude or ChatGPT receives the tool results you request and may copy them into a conversation or other provider storage. That copy is governed by the provider’s terms and privacy controls, and Codonic cannot delete it for you. Read the provider’s confirmation screen and policy before connecting.

Sharing a trip with your travel companions

You can share a trip with the people you travel with on supported devices. Sharing requires Android 13 or later; iPhone participation becomes publicly available when the iPhone app is released. Sharing is optional and off until you create an invite link and hand it to someone. Once you do, that trip’s expenses, photos, places and members sync between everyone in the group, so you all work from the same ledger.

The shared data travels as an end-to-end-encrypted log: every change is encrypted on your device before it leaves, using a key that exists only on the participants’ devices and inside the invite link itself. The encrypted changes are held in the app’s shared cloud storage (Apple’s CloudKit public database) and passed along by a small relay we run at codonic.dev. The relay used for ordinary shared-trip transport is stateless — it stores nothing of its own and, because everything reaching it is already encrypted with a key it never sees, it cannot read your trip. The key rides in the part of the invite link after the “#”, which by design is never sent to that relay or to CloudKit. The optional account and AI services are separate and are described above.

The invite link is like a key to the trip: anyone who holds it can view the trip and add to it. Treat it as private — share it only with the people you want in the trip, and prefer a direct message over a public post. You do not need to be signed in to iCloud to share a trip.

You stay in control. As the trip’s owner you can refresh the invite link at any time, which revokes the old one so anyone still holding it loses access; you can hand ownership to someone else; and you can delete the trip for everyone. Any member can leave a shared trip; when they do, the expenses they already logged stay with the group, and their device stops syncing.

Without shared-trip AI opt-in, we cannot read the contents of a shared trip. The account overlay alone stores only identity-and-recovery metadata and does not make the trip log readable. Enabling AI explicitly sends the shared-trip key and an expiring delegate credential encrypted at rest to the integration service, which can then decrypt the canonical log and expose only the limited fields described above.

Deleting your data

Deleting a trip that you have not shared removes it from your device, along with its copy in your personal iCloud if sync is on.

For a shared trip: if you are the owner, deleting it purges the trip’s records — every change and every stored photo — from the shared cloud storage, so it is removed for the whole group. If you are a member rather than the owner, leaving the trip removes it from your device, while the expenses you logged stay with the group. Because the relay keeps nothing of its own, no separate copy is left on our systems once the shared records are gone.

Signing out of a Souvenir Account revokes that device but does not delete the account. Turning off AI access immediately invalidates existing provider access and revokes reachable per-trip delegates; encrypted account-side grant and projection records may remain until they are replaced or the account is deleted.

Deleting a Souvenir Account is a separate in-app action. Before the service purge, the app removes the account authority from every reachable shared trip while keeping the device’s access and trip data. The service then freezes the account and deletes its devices, credentials, recovery envelopes, identity mappings, OAuth grants, AI grants, projections and actions in bounded batches. The app waits for a signed completion receipt before removing its account secrets. Pseudonymous public-key and alias history can remain in an append-only shared-trip security log, but the deleted mapping can no longer link it to the account.

Deleting the app deletes what it held on that device, but does not by itself delete a Souvenir Account, another device’s data, shared-trip history, personal-iCloud data or copies already retained by Claude or ChatGPT. Delete the account and disconnect providers before removing the last signed-in device if you want the remote account overlay purged.

Device backups

Your device’s own backup system — Apple’s on iOS, Google’s on Android — may include Souvenir’s data, under the backup mechanism and encryption those companies provide. That arrangement is between you and them, and is governed by their terms, not ours.

Children

Souvenir is not directed at children. We do not knowingly create accounts for children or collect their information through the optional account and connector services. A traveller may enter another person’s display name in a trip for group-expense splitting; that information follows the storage and sharing choices described above.

Your rights

Privacy law in the European Economic Area, the United Kingdom, California and elsewhere may give you rights to access, correct, erase, restrict or object to our processing of personal data, receive portable data, and complain to a regulator. We do not sell or share personal information for cross-context behavioural advertising.

Most journal data remains under your direct control in the app, personal iCloud or a shared trip. For an optional Souvenir Account, the fastest erasure method is Delete Account in Souvenir: the app performs the trip-safety steps described above and waits for a signed purge receipt. You can also turn off AI access at any time to revoke the connector.

For a privacy request, write to dev@codonic.dev. Because accounts deliberately have no email address or other support identity, we may need a signed-in app or recovery proof to avoid disclosing or deleting someone else’s account. We cannot recover your recovery code or erase data that Claude, ChatGPT, Apple, another trip participant or a device keeps under its own control.

Changes to this policy

If this policy changes, the new version will be posted at this same address with a new “last updated” date above. The address does not change.

Contact

Codonic
dev@codonic.dev

Related: Souvenir · account & AI connector guide · all privacy policies · support