Kumo Travel
← Kumo

Privacy Policy

Effective date: 1 July 2026  ·  Last updated: 1 July 2026

Kumo ("we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable privacy laws.

1. Data Controller

Kumo is the data controller for personal data collected through the Kumo mobile application. For enquiries about this policy or your data rights, contact us at privacy@kumo.travel.

2. Data We Collect

Account data

Trip and travel data

Usage data

We do not run third-party analytics or advertising SDKs. Standard server logs (IP address, request timestamps) are retained by our infrastructure provider (Supabase) for up to 30 days for security purposes.

Launch waitlist (marketing website)

If you sign up for launch updates on our marketing website (kumo.travel), we store only the email address you provide, based on your consent, solely to send a one-time email when Kumo launches. We keep it until you unsubscribe (a link is included with that email, and available anytime on the website) or the launch email has been sent, whichever comes first. This address is never sold, shared with third parties, or used for anything other than that one message.

3. Legal Basis for Processing (GDPR)

4. How We Use Your Data

5. Data Sharing & Sub-processors

We do not sell your data. We share data only with the following sub-processors to operate the service:

6. International Transfers

Kumo operates globally, so your data may be accessed or processed from a country other than your own. Supabase stores your data in the EU (Frankfurt). Anthropic's servers are in the United States. Transfers out of the EU/UK rely on Standard Contractual Clauses (SCCs) adopted by the European Commission; transfers from other jurisdictions (including India, Brazil, Japan, and Canada) rely on your consent to this Privacy Policy, together with SCCs or an equivalent contractual safeguard with each sub-processor, and the same EU-hosted infrastructure — we do not maintain a separate copy of your data in any other country.

7. Data Retention

Your data is retained for as long as your account is active. When you delete your account, all personal data — including itineraries, expenses, packing lists, messages, and ratings — is permanently deleted within 30 days. Aggregated, anonymised statistics may be retained indefinitely. If you forward a trip-related email (e.g. a flight confirmation) to your trip's Kumo email alias, we keep a metadata-only record (sender address, subject line, forward count — never the message body) for up to 90 days to support delivery troubleshooting, then delete it automatically.

8. Your Rights, by Region

Kumo operates globally. Regardless of where you live, you can always access, correct, or remove your own data via Profile → Privacy, or by contacting privacy@kumo.travel. The rights below reflect the specific laws that apply depending on your location; contact us if you are unsure which applies to you.

European Economic Area & United Kingdom (GDPR / UK GDPR)

You also have the right to lodge a complaint with your national data protection authority.

United States (CCPA/CPRA, VCDPA, CPA, and similar state laws)

We honor the Global Privacy Control (GPC) signal, where legally required, as a valid request to opt out of sale/sharing. Since we do not sell or share personal data in the first place, GPC has no practical effect on how your data is processed today, but we detect it and this applies automatically if that ever changes.

India (Digital Personal Data Protection Act, 2023)

Grievance Officer: Privacy Team, privacy@kumo.travel.

Brazil (Lei Geral de Proteção de Dados — LGPD)

Encarregado (Data Protection Officer): Privacy Team, privacy@kumo.travel.

Japan (Act on the Protection of Personal Information — APPI)

Contact privacy@kumo.travel to exercise these rights.

Canada (PIPEDA, and provincial laws including Quebec's Law 25)

Privacy Officer: Privacy Team, privacy@kumo.travel.

To exercise any right listed above, contact privacy@kumo.travel. We will verify your identity before acting on a request and respond within the timeframe required by the applicable law (typically 30–45 days).

9. Discoverability & Visibility

Your display name is visible to other users only within trips you are a member of. You can disable discoverability in Profile → Privacy Settings so your name does not appear in invite searches. Public itineraries you choose to share are visible to all users in the Discover feed.

10. Security

We use HTTPS for all data in transit. Authentication tokens are stored in the platform secure keychain (iOS Keychain / Android Keystore). Row-Level Security (RLS) policies on our database ensure users can only access data they own or have been invited to.

11. Children

Kumo requires every account holder to be 18 or older, enforced at signup and re-checked on every write to our database — not just requested. We do not knowingly collect personal data from anyone under 18. If you believe a minor has an account, contact privacy@kumo.travel.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via an in-app notice or email before the change takes effect. Continued use after the effective date constitutes acceptance.

13. Contact

Kumo Privacy
privacy@kumo.travel