Privacy Policy
Last updated: 2026-09-06
Camp Roostly ("the App") is an RV trip planner. This policy explains what data we collect, how we use it, and the controls you have. We designed Camp Roostly to collect as little personal information as possible.
What we collect
- Account info: your email address, used to sign you in (magic link or Google sign-in) and to send you transactional messages (sign-in codes, booking-window reminders for trips you've added, referral-reward notices, account/billing notifications). We do not send marketing email.
- Profile: optional display name, optional home address. The home address is geocoded to compute drive times for your trips.
- Trip data you create: trips, stops, dates, confirmation numbers, costs, notes, photos, favorites, dismissed warnings, scheduled booking-window reminders.
- Stay ratings and visit history: when you tap "Rate this stay" we store the campground, the date you stayed, your star rating, and any note you add. Unlike the rest of your trip data, a star rating contributes to a public average — see What other travelers can see.
- Rig profile: optional dimensions and capacity for your RV. Used to filter campsites that fit your rig and to compute truck-safe routes.
-
Forwarded itineraries: only when you forward a
confirmation email to our intake address (e.g.
intake@camproostly.app). We extract trip details (campground name, dates, confirmation #) via an AI parsing step and attach them to your account. The original email body and any attachments are deleted after parsing. - Subscription & billing: if you start a Premium trial or subscribe, we store your subscription status (active / trialing / cancelled) and the platform identifier (Google Play purchase token or Stripe customer ID). Payment card details are handled entirely by Google Play or Stripe — we never see or store them.
- Referral program: if you use the invite-a-friend feature, we store your referral code and a record of the referrals you send or receive — who invited whom and whether the free-month reward has been earned — so we can grant the months you and your friend earn.
- Diagnostics: anonymous error reports (Sentry) and product analytics (PostHog) when those features are enabled. No personally identifying information is sent to either service by default; crash reports are stripped of user content before upload.
- Location: only when you tap "Use my location" on the map, or when you use in-app navigation. During turn-by-turn navigation we use your device's live location to follow your route and keep you on a rig-safe path, and we send your current position to our routing provider (HERE) to compute and, if you leave the route, recompute directions. Navigation runs only while the screen is open — we never track your location in the background.
- Contacts: only when you tap "From contacts" on an address field. We read the single contact you select; we do not upload your contact list to our servers.
- Google Calendar (only if you connect it): an optional Premium feature. When you connect your work calendar, we read only your free/busy times via Google's read-only Calendar API — the start/end times of when you're busy, never event titles, descriptions, attendees, locations, or attachments. We never create or modify calendar events.
What we do with it
- Show you the campsites + routes you ask for.
- Pass coordinates to HERE (driving directions, including your live position during in-app navigation), OpenStreetMap (map tiles), and Google Maps (geocoding + place autocomplete) when needed to compute trip details. These are stateless lookups; we don't share identifying information with these providers.
- Pass forwarded itinerary text to Anthropic Claude for structured extraction. The text is sent without your account identifier and is not used by Anthropic to train models (per their zero-data- retention API terms).
- Send transactional email via Resend (sign-in, booking-window reminders). Resend retains delivery logs for 30 days for deliverability troubleshooting.
- Look up state-level diesel prices from the U.S. Energy Information Administration (EIA) once a week and cache the results. No request to EIA contains user information.
- Use your connected Google Calendar's free/busy times only to warn you when a travel day or campsite stay collides with a meeting-heavy workday. The busy intervals are cached on our server to power these warnings and are used for nothing else.
- Persist your trips so they're available across your devices.
- Aggregate anonymous usage (page views, button clicks) via PostHog to understand which features are useful. You can opt out in your OS-level settings.
- Verify Premium-subscription receipts with Google Play or Stripe to confirm entitlement. We store only the receipt identifier, not any payment details.
- Run the referral program: when a referral qualifies, we grant both people a free month of Premium and notify each of you by email and push. The person who sent the invite is shown the display name of the friend who joined (or, if no display name is set, the part of their email before the @) so they know who accepted — we don't share any other account details between you.
What other travelers can see
Your trips, stops, dates, notes, costs and confirmation numbers are private to you. There are exactly three things you can do that put information in front of other people, and each one is something you choose to do:
- Sharing a trip link: when you turn on "Public link" for a trip, anyone with that link can see that trip. You can turn the link off again at any time.
- Rating a stay: when you rate a campground, your star rating is folded into that campground's community average, which is shown to other travelers (and on our public campground pages). We publish only the average, the number of ratings, and the date of the most recent stay — never your name, your account, your dates, or which particular rating was yours. Rate a place only if you're comfortable contributing to its public average.
- Rating a stay at a place that isn't in our catalog: if you rate a stop you typed in by hand, we first try to match it to a campground we already know about. If there's no match and the stop has coordinates, we create a new catalog entry for that place — its name and location, badged "unverified" — so other travelers can find it and so your rating can count. Your identity is not attached to the entry. Because this publishes a location, don't rate a stay at a private address — a friend's driveway, a host's property, or your own home. Your trip stop itself always stays private either way; it's the rating that creates the entry. If a place was published this way in error, email us and we'll remove it.
We may also, in the future, use stays at verified public campgrounds to power anonymous recommendations ("travelers who stayed here also stayed there"). This is off unless you turn it on, under Profile → Privacy. If you turn it on: only stays at verified public campgrounds are ever counted (never a place you typed in by hand, never an unverified entry); no dates, names, accounts, rigs, routes or notes are included; and a pattern is shown only once at least five different travelers share it, so nothing traceable to one person can surface. Turning the setting off stops your stays counting from that point on.
What we don't do
- We don't sell or rent your data.
- We don't show your trips, stops, dates, notes or costs to other users. The only exceptions are the ones you choose — see What other travelers can see.
- We don't track you across other apps.
- We don't run third-party advertising.
Your controls
- Export your data: every trip can be exported as an iCalendar (.ics) file for import into Google/Apple/Outlook Calendar.
- Contribute anonymous stay patterns: open the app → Profile → Privacy. Off by default. See What other travelers can see for exactly what is and isn't included when it's on.
- Delete your account: open the app → Profile → Danger zone → Delete account. This permanently removes your profile, rig, all trips and stops, favorites, visit history, forwarded itineraries, and scheduled reminders. Cascade deletes are atomic — there are no orphan records. Your stay ratings go with it, so they stop counting toward any community average. One thing does survive: if you added a campground to the catalog by rating a stay somewhere we didn't know about, that campground entry stays — it's part of the shared catalog other travelers now rely on — but the link back to your account is erased. Email us if you want such an entry removed as well. Full details and an email path for users who can't sign in are at camproostly.com/delete-account.
- Cancel a Premium subscription: cancel via Google Play (Play Store → Subscriptions → Camp Roostly) or via Profile → Manage subscription on the web. Cancellation is separate from account deletion — cancel first if you want to stop billing before deleting.
- Revoke a shared trip link: in any trip's Share sheet, toggle "Public link" off. The recipient sees a "no longer shared" message. We retain the token so a future re-enable restores the same link.
- Cancel a booking-window reminder: open the trip and tap × on the booking-window chip for that stop. The reminder is marked cancelled and no email is sent.
- Disconnect Google Calendar: open the app → Profile → Work calendar → Disconnect. This immediately stops all calendar access and deletes the cached busy times. You can also revoke access from your Google Account at myaccount.google.com/permissions.
- Revoke permissions: contacts, location, and notifications can be turned off any time in Android Settings → Apps → Camp Roostly → Permissions.
Google Calendar data
Connecting your Google Calendar is optional. When connected, Camp
Roostly accesses only your free/busy information through the read-only
calendar.readonly scope — the start and end times of when
you are busy, with no access to event titles, descriptions, attendees,
locations, or attachments, and no ability to create or modify events.
We use this data for the single purpose of warning you when your travel
days overlap your work meetings. The busy times are cached only to
provide these warnings and are deleted when you disconnect.
Camp Roostly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, do not use it for advertising, and do not transfer it to others except as needed to provide this feature.
AI and automated processing
Camp Roostly uses one third-party AI provider, Anthropic (Claude), accessed through Anthropic's API. We do not train or operate our own AI model.
Claude is used for a single, narrow purpose: when you voluntarily
forward a booking-confirmation email to our intake address (e.g.
intake@camproostly.app), Claude extracts structured trip
details — campground name, dates, confirmation number — from that
email text so we can add the trip to your account. The text is sent
without your account identifier, is not used by Anthropic to train
models (per their API terms), and the original email is deleted after
parsing.
Your Google Calendar data is never sent to any AI model or
provider. The free/busy times we read through the read-only
calendar.readonly scope are used only to warn you about
schedule collisions, are stored under strict per-user access control,
and are never processed by Claude or any other AI service.
How we protect your data
We apply technical and organizational safeguards to protect your personal information, with extra care for sensitive data such as your Google Calendar connection.
- Encryption in transit: all traffic between the app, our servers, and every third-party provider (Google, Supabase, HERE, Anthropic, Resend, Stripe) is encrypted with TLS/HTTPS. We never transmit your data over an unencrypted connection.
- Encryption at rest: our database and backups are hosted on Supabase, where stored data is encrypted at rest with AES-256.
- Per-user access control: every table is protected by row-level security, so each account can read only its own data. Your trips, location history, contacts, and calendar data are never visible to other users. The community rating average is the one place we read across accounts, and it is computed by a restricted server-side function that can return only the average, the count, and the last-stay date — it has no way to return who rated what. Your calendar data is excluded from this and every other cross-account calculation.
- Sensitive credentials are server-side only: your Google Calendar OAuth tokens (including the long-lived refresh token) are stored under strict owner-only access control and are never sent to the app or exposed to the client. They are read only by our trusted server-side functions to fetch your free/busy times.
- Data minimization for sensitive scopes: from your Google Calendar we request and store only coarse free/busy intervals — never event titles, descriptions, attendees, locations, or attachments. Less sensitive data collected means less to protect.
- Least-privilege access: access to production data is limited to the operators who maintain the service, used only to run and support the App, and protected by authenticated, access-controlled administrative tooling.
- Prompt deletion: when you disconnect Google Calendar we immediately delete the stored tokens and cached free/busy times; when you delete your account we remove your data as described below.
No method of transmission or storage is ever completely secure, but these measures are designed to protect your information against unauthorized access, disclosure, alteration, and loss. If we ever become aware of a breach affecting your data, we will notify you as required by applicable law.
Data retention
Your data lives in our database for as long as you have an account. When you delete your account, we delete it within 24 hours from our live database. Backups (point-in-time-recovery snapshots) age out after 7 days.
Where data lives
Camp Roostly runs on Supabase (Postgres) hosted in the United States. Static web assets and the image proxy run on Cloudflare Workers. We use OpenStreetMap, Recreation.gov (RIDB), and other public catalog sources for campsite data — none of those sources receive your personal information.
Third-party services we use
- Supabase — auth + Postgres database (US).
- Cloudflare Workers — web hosting + image proxy.
- Google Cloud (Places, Maps, OAuth, Calendar) — geocoding, autocomplete, sign-in, and optional read-only work-calendar free/busy.
- HERE Technologies — rig-safe truck driving directions (honors vehicle dimensions).
- OpenStreetMap — map tiles.
- Anthropic Claude — itinerary email parsing (zero-data-retention API).
- Resend — transactional email delivery.
- U.S. Energy Information Administration (EIA) — weekly state fuel prices.
- Google Play Billing — Android subscription payments.
- Stripe — web subscription payments.
- Sentry — anonymous crash reporting (when enabled).
- PostHog — anonymous product analytics (when enabled).
Children
Camp Roostly is not directed at children under 13. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
Changes to this policy
Material changes to this policy will be announced in the app and take effect 30 days after notice.
Contact
Questions about this policy or your data: email privacy@camproostly.com.