← Back to Roamr

Privacy Policy

Last updated: 25 July 2026

Roamr is a travel assistant that personalizes results using a context graph built from your stated preferences and the booking decisions you record. This policy explains exactly what is stored, where it lives, and how to remove it.

What we collect

Roamr stores only what it needs to personalize your results:

We do not collect payment details, government identifiers, precise location, contacts, browsing history, or any data from outside your Roamr session. Roamr has no advertising integrations and no third-party analytics or tracking scripts.

How your data is used

Your context graph exists for one purpose: to rank travel results for you. When you search, Roamr scores each candidate against your stored preferences and returns the reasons for the score. When you record a decision, the graph updates so later searches reflect it.

Your data is never sold, rented, or shared with third parties, and is not used to train machine-learning models.

Connecting Roamr to an AI assistant

When you connect Roamr to ChatGPT, Claude, or any other client, you authorize it through a standard OAuth 2.1 flow. You enter your password on a Roamr page — the assistant never sees it. The assistant receives a scoped access token that expires after one hour, and can request only the permissions shown on the consent screen.

Note that the content of your conversation is handled by that assistant under its provider's privacy policy, not this one. Roamr only ever receives the tool calls the assistant makes.

Where your data is stored

Data is held in a SQLite database on the server operating this Roamr instance. If you self-host Roamr, that server is yours and no data reaches us at all.

Retention

Your context graph is kept until you delete it. Decision history is capped at the most recent 1,000 entries per account; older entries are discarded automatically. Authorization codes expire within one minute, access tokens within one hour, and refresh tokens within thirty days.

Your rights

Security

Passwords are hashed with scrypt and verified in constant time. Access and refresh tokens are stored as SHA-256 hashes, so a database copy yields no usable credentials. All authorization flows require PKCE. Roamr should always be served over HTTPS in production.

Children

Roamr is not directed at children under 13 and we do not knowingly collect their data.

Changes

Material changes to this policy will be reflected in the date above and announced in the project repository.

Contact

Questions or deletion requests: privacy@roamr.app