Who is behind the app
The Viharo app for iOS and iPadOS is operated by Ing. Vladimír Srnec, Company ID (IČO) 87174634 (“we”). For anything privacy-related, contact us at support@viharo.app.
What data we collect
None. The app requires no account or sign-in, contains no third-party analytics or advertising tools, and sends us no information about you or how you use it. We have no access to the contents of your lists, trips, circles, or settings. The only things that pass through our server are the encrypted sharing data and the notification delivery messages described below, and the server keeps nothing from either.
Where your data lives
Everything you create in the app (trips, lists, items, templates, notes, attachments, gear, Memories) is stored on your device. If you have iCloud turned on, your data syncs between your devices through your private iCloud database (CloudKit). Only you can access it, through your Apple Account; we cannot see into it. Processing is handled by Apple under Apple’s privacy terms.
Destination weather
If you enter a destination for a trip, the app converts the place name you typed into coordinates (Apple MapKit) and requests a forecast for them (Apple WeatherKit). The app does not use your device’s location; it works solely with the text you type. The request is processed by Apple and is not linked to your identity by us.
Add from a list (photo or clipboard)
When you let Viharo read a list from a photo or from text on the clipboard, text recognition and typo correction happen entirely on your device (Apple Vision and the system spell checker). Neither the photo nor the text is sent anywhere, and the app does not keep the photo; only the items you confirm in the preview remain. The app asks for camera access only to photograph a list, or your room before you leave.
Memories and photos
When you have the app build a Memory after a trip, it reads photos from your device’s library matched to the trip dates and picks the best shots right on the device (Apple PhotoKit and Vision). Photos and photo data are never sent to us; the app keeps only the identifiers of the chosen photos and your choices (hidden days, chosen cover). To fill in the weather for the days of a Memory, it may use the places where your photos were taken (coordinates from the photo metadata) and request historical weather for them (Apple WeatherKit); as with forecasts, Apple processes this request and we do not link it to you.
Only you share a Memory. When you share one to a circle, a finished view (an image with the trip’s facts) goes into the circle’s iCloud, where the other members can see it; the photos themselves are not uploaded to the circle. Cards, stickers, or PDFs made from a Memory go only where you send them through the system Share sheet.
Notifications
Departure reminders and loan due dates are local notifications scheduled directly on your device; they pass through no server.
Circle notifications (a request to borrow and its reply, an item handed over or returned, a Looking for post, a group trip, a new Memory, a circle handover) are sent by the app of the member who took the action, through our server (a Cloudflare Worker), to the Apple Push Notification service, which delivers them to your device. The server is only a courier: it hands Apple a message carrying the kind of event and a few words for the sentence (such as an item’s name and a name from a card), and it stores and logs nothing from it, device addresses included. The server’s storage holds only rate-limit counters and hashes of device addresses that Apple has reported as invalid, so they are not retried for 30 days.
Your devices’ delivery addresses (at most 5) are part of your card in a circle, so they live in the circle founder’s iCloud; the other members’ apps can see them, we cannot. When you mute someone, that is stored there too, and their app then delivers your notifications quietly. You can turn system notifications off at any time in iOS Settings.
Shared lists and sent copies
When you share a list with a read-only link, or send it as a new list (a copy), the app encrypts the content on your device, and only the encrypted form is stored on our server (Cloudflare). The decryption key is part of the link (the portion after the # sign) and is never sent to the server, so neither we nor anyone without the link can read the content. A link expires 30 days after it was last sent, and you can revoke it instantly at any time in the app. Shared pages are not indexed by search engines and contain no tracking.
What is never in a link: bag lock codes and purchase records. Trip notes are never included in a read-only link; they go into a sent copy only if you explicitly switch them on when sending.
Packing together (collaboration)
When you invite travel companions to pack together, the shared trip syncs between participants through iCloud (Apple CloudKit), Apple’s infrastructure rather than our servers; we cannot see into it here either. Participants can see the trip’s content (items, notes, purchases, tasks, bag names, who checked off what), each other’s Apple Account names, and each other’s cards if filled in. Bag lock codes are shown to companions only if the bag’s owner explicitly allows it for that trip; attachments only if their author marks them for sharing. The green dot (“in the list right now”) is visible only to the trip’s participants and can be turned off. You can end the collaboration at any time: as the owner for everyone, as a companion for yourself.
Circles
A circle lives in the iCloud of the member who founded it (a shared CloudKit database). When you join a circle, your app reads from and writes to that database; we cannot see into it. The founder can hand the circle over to another member, and it then moves to that member’s iCloud.
What the other members can see: your card (the name you choose, an optional photo, and a color), your gear from only the categories you pick for that circle, loans and Looking for posts with their status, group trips (emoji, name, destination, dates) and your In/Out replies, the Memories you share to the circle, and the templates you offer it. Your card also carries the technical details for delivering notifications described above. Someone waiting to be approved sees only the circle’s name.
A circle invitation is a link (viharo.app/k/…) or a QR code. The app encrypts its content on your device; only the encrypted form sits on our server, for at most 30 days since it was last refreshed, and the key travels in the link after the # sign, so it never reaches us. A new invite link invalidates the old ones. The invitation page shown to people without the app contains no tracking.
You can leave a circle at any time from its settings; the founder can dissolve it, which ends it for everyone.
Attachments and Save to Viharo
Trip attachments (PDFs, images) are stored on your device and sync through your iCloud like the rest of your data. The Save to Viharo extension in the Share sheet hands a file from Mail, Photos, or Safari directly to the app; nothing leaves your device. Companions see an attachment only if you mark it for sharing.
Data backup
The backup file is created on your device, and you save it yourself wherever you choose (Files, iCloud Drive, and so on). It is never sent to us. It contains your trips, lists, templates, gear, and preferences; circles and Memories, which live in iCloud, are not included. Handling the file is in your hands: anyone who has it can read it.
Purchases
Viharo PRO subscriptions and one-time purchases are processed by Apple through the App Store. We have no access to your payment details. You manage or cancel a subscription in your Apple Account.
Your rights
Because we do not collect your data, it is fully in your hands. To remove it permanently, delete content in the app, use Erase all data in the app’s Settings → Data (it clears the device, iCloud, and any shared links or collaborations), or delete the app and its iCloud data (Settings → Apple Account → iCloud → Manage Storage). You leave circles from a circle’s settings; as a founder you can dissolve them. For any privacy question, write to support@viharo.app.
Changes to this policy
If the way the app handles data changes in the future (for example with new features), we will update this page and the effective date above.