Last updated: 27 August 2026
Vifo is operated by Youli Global Limited, registered in Hong Kong, which is also the controller of your personal data under this policy; the product is built and maintained by one person. This policy describes how this service actually handles your data — it is not a template. Every category below maps to a specific field in the code.
All of it comes from what you hand over: the photos and videos you (or your AI agent) upload, the words you write, and the small amount of technical record-keeping an account needs. We buy no data and enrich your profile from no third party.
Your email address, used to sign you in and send you a six-digit code. You can also sign in with Google; in that case we additionally keep the stable id Google gives us for that account, alongside the email address it returns, after checking that Google has verified it. That stable id is what makes the same Google account land in the same Vifo account, even if the email on it later changes. We keep no Google access token or refresh token, and we make no other call to any Google API. Session credentials and the API keys you issue on the Connect page are stored only as hashes, never in the clear — we cannot read your key back either. When the account is created we also note two things about how you arrived, once, and never update them: the domain name of the site that linked you here, if any (kept for seven days in a small cookie until you sign up; the domain only, never the full address), and which agent, if any, sent you to connect. We use them to learn where new people come from.
The original photo and video files, the descriptions and keywords written for them, the words you said yourself — the message box on the upload page, and anything you asked the agent to write down — kept as "remarks": stored verbatim, source recorded, never rewritten by anyone. Also the body of every timeline block, and each trip's title, summary and ending. This is your work; we only keep and present it. Remarks are working material addressed to your agent: it can read them, and must quote them exactly when placing them on a page. Remarks feed the site's search; they are not displayed on any page by themselves, and they never travel with a share link — the only way your words reach a public page is by being quoted, verbatim, into the timeline.
This is the most sensitive thing we hold, so it gets its own section: if your photo carries GPS, that pair of coordinates is stored. Years of photo coordinates, joined up, are enough to reconstruct where someone has been and where they live. We are aware of that.
Three places coordinates go, stated one by one. First, at filing time (confirm_upload) they are echoed straight back to the agent that made the call, because that call is where they came from; no other tool returns coordinates — listing media, searching, reading a timeline and looking at pictures all come back with place names only. Second, your own signed-in web pages receive them, to work out how far a trip went; share links do not — public pages carry no coordinates, and that is an explicit step in the code. Third, to turn coordinates into a place name they are sent to OpenStreetMap's public geocoding service — see the next section; that is the one place coordinates leave this site.
Each photo's capture instant (epoch milliseconds UTC) and the timezone offset at that moment. On its own it is unremarkable; together with coordinates it is a complete trace of a journey — so we treat it with the same care as the coordinates.
The administrative levels a coordinate resolves to — neighbourhood, city, country — plus the raw response from the geocoding service. The place name you write yourself (a restaurant, a landmark) is a separate field, filled in by you or your agent; we do not guess it.
The metadata that comes with your photos and videos, read out by your browser or your agent and handed to us, is kept as a whole. Our upload interface does not restrict which fields it may contain, so what follows is what it usually contains, not a closed list. For photos, typically: capture time and timezone, orientation, the make and model of the camera or phone, the software, the lens, and shutter, aperture, ISO, focal length, exposure compensation and flash. For videos, typically: creation time, the raw coordinate string of where it was recorded, make and model, software, and duration. Make, model and software can point back at a device, and that recording-location string is a set of coordinates in its own right — which is why each is listed here rather than swept under "file metadata". We also store a SHA-256 digest of the file's bytes (to recognise re-uploads) and its size (for quota).
Speech-to-text on video is off by default and happens only when you explicitly ask for it through your agent. That is deliberate: a travel video's audio often catches other people talking, and keeping the video is not the same thing as turning what they said into a searchable written record. When you ask, the video's audio track is sent to Cloudflare's Workers AI (the Whisper model) for recognition; the result is stored on that item and returned to your agent. Listing media only tells you whether a transcript exists, never its text; and a share link cannot reach the transcript either, for the same reason as the coordinates — other people's voices may be in it.
Once you subscribe we keep one subscription row against your account: Paddle's customer id and subscription id, the subscription status, the plan, when the current billing period ends, whether you have set it to stop or pause renewing (and which), whether a chargeback has ever been raised and how many chargebacks there have been, and the time and sequence number of the last Paddle event we received (used to tell which event is newer, so an old one cannot overwrite a newer state). We store no card number, no expiry date and no payment credential of any kind — those live only at Paddle, start to finish. At your first checkout your email address is passed to Paddle as the billing email, to open a customer record and send receipts; after that we go by the customer id Paddle gives back and do not send it again.
You can open an upload link and send it to the people you travelled with; anyone holding it can add photos, videos or a line of text to that trip without an account. This section is written for them: the files you pick are read in your own browser for capture time, timezone, GPS coordinates, and the make, model and software of the camera or phone, and all of that is sent along with the file; anything you write is kept verbatim. It all lands in the trip belonging to whoever opened the link — they keep it, and they decide whether to share it — and we handle it exactly as the rest of this policy describes. If you would rather not hand over one of these, the most reliable way is to strip the photo's location on your own device before picking the file. An upload link can be revoked at any time, and once it is, nothing more can be sent through it. The link you were given carries your name; the photos and notes you send are credited to it — the trip owner and their agent see it when organising, and so does the public page. Show links (/show/…) that your agent creates to let you look at a few of your own items: we store the link token and its hash, and the record is deleted when the link expires — at most 72 hours later.
Every account, trip, item, timeline block and upload link has an internal id (u_ / t_ / m_ / b_ / ul_ followed by twelve hex characters). They appear in tool results because later calls need them to name things. They contain nothing personal, but they are identifiers that tie your records together, so they are disclosed here.
When you ask for a login code, and when anyone opens a share link, we count requests against the IP address, to stop anyone hammering those endpoints. That counter exists only for rate limiting; a scheduled job deletes it once its window has passed, so it is not retained long term. Cloudflare, as the host, also produces ordinary request logs. The login form also runs Cloudflare Turnstile, a bot check from the same host: it loads a Cloudflare script on that page and sends Cloudflare a one-time token plus your IP address so the server can confirm a person asked for the code. Turnstile does not do cross-site tracking. When someone opens a share link we count the visit: we take a one-way, salted hash of the visitor's IP address and browser identifier together with the date and the id of that trip, use it only to avoid counting the same visitor twice in one day, and delete it after 30 days. Because the trip's own id goes into the hash, the same visitor gets a different value on every trip, so those records cannot be joined up into one person's browsing. We do not store the IP address itself and set no cookie for this. The public marketing pages — the landing page, the guides, the connect guide and the sample notebooks — load Cloudflare Web Analytics, a page-view counter from the same host: it sets no cookie, stores no persistent identifier and does no cross-site tracking; it reports the page seen, the referrer, the country and load timing. Signed-in pages and shared trip pages carry no analytics at all. When your agent talks to Vifo we also keep a call log: which account, which connection, which tool was called, whether it succeeded and how long it took — the names only, never the contents of the call. It exists so we can see where a new connection gets stuck, and it is deleted after 90 days. Beyond that we run no analytics script, no advertising pixel and no cross-site tracker.
Apart from the table below, we hand your content to no one. We do not sell data and we do not trade it for advertising.
| Who | What they receive |
|---|---|
| Cloudflare | Hosting, database, file storage, image and video resizing, video transcription and search-vector computation (Workers AI), and the vector index. Most of the time, your content lives here. |
| OpenStreetMap / Nominatim | The GPS coordinates of your photos. Coordinates only — no picture, no description, no identifier that points back at you. |
| Paddle | Paddle.com, our reseller and Merchant of Record: subscription and payment, your email address at first checkout (as the billing email), and the country and postcode you enter at checkout (Paddle uses them to work out tax). Checkout and the customer portal are hosted by Paddle; we never touch your card number. Paddle's own privacy policy covers what it does with this. |
| Cloudflare Email Sending | Your email address, to deliver the login code and the reminder email if you go inactive for a long time. |
| Google LLC, and only if you choose to sign in with Google. We receive your email address, whether Google has verified it, and the stable id of your Google account. We ask for nothing else — no name, no profile picture — and we make no other call to any Google API. The redirect to Google happens only after you press "Continue with Google"; this site loads no Google script. | |
| Your own AI agent | The part of your content you authorised it to read and write — including the pictures themselves when you ask it to look at them. |
One more word about the geocoding service, because it is worth spelling out: you probably would not think that "I uploaded a photo" means "my coordinates were sent to a third-party place-name service". But that is what happens — the server takes your photo's coordinates to OpenStreetMap's public Nominatim to look up a name. The same location is queried once for the whole site, and the answer is cached against a grid of roughly one hundred and ten metres (that cache holds only "which grid cell maps to which name", with no user identifier). This is a real cross-border transfer of data, which is why it gets its own row and its own paragraph.
About your own agent: this service is built for AI agents, so the Claude, ChatGPT or local agent you connect will receive your trips, descriptions, place names and times through tool calls, plus the image bytes whenever you ask it to look at a picture. That content then falls under that provider's own privacy policy, which is outside our control. To take it back, disconnect it on the Connect page — effective immediately.
After you cancel, not one item is deleted. You return to the free tier's capabilities: your ten most recent trips open, edit and share as normal; older ones are locked — the card stays, opening one offers to renew, but share links you already sent keep working, because those links live in other people's chat histories and have nothing to do with them.
Long inactivity: signing in on the web, an agent call, someone using an upload link, or a subscription payment going through — any activity resets the clock. After 12 months with no activity at all, we send a reminder email with a one-click "keep it" button. If there is still no answer, the material is degraded once: photos keep only their display size, and a video that already has a transcript keeps only its cover frame and that transcript — a video with no transcript is left exactly as it is, because degrading it would leave neither picture nor sound, which is deletion rather than degradation. The text, the timeline and the share links are all kept exactly as they were. Degradation is where it stops; nothing is deleted automatically.
Both of the above are current policy, not a permanent promise. If they change, we will tell you in advance. We do not write "we will never delete" — a permanent promise is a permanent constraint, and it is more honest to say plainly that this is how it works now and that changes get announced.
Two exceptions, stated plainly: the place-name cache keyed by coordinate grid is shared site-wide, contains no user identifier, and is not cleared when an account is deleted; Cloudflare's ordinary request logs are retained on its own schedule and we cannot delete individual entries.
This service is not aimed at children under 13 and we do not knowingly collect their information. If we find any, we delete it.
Changes update the date at the top of this page. For material changes to how data is used or who receives it, we will email you before they take effect.
For anything privacy-related — export, account removal, questions, complaints — write to privacy@vifo.app. A real person reads that mailbox, usually replying within a few days.