RoamzyCreate a free trip
Built for trust

Your trip data is secure — here's exactly how

Travel documents contain passport names, addresses, and booking references. We treat security as a feature, not an afterthought. This page explains, in plain language, how your data is protected at every layer.

Authenticated access only

Every trip lives behind sign-in. There are no public, guessable links to your data — you must be a signed-in, invited member to see anything.

Row-Level Security on every table

Access rules are enforced in the database itself, not just the app. The database refuses to return a row unless you're the owner or an invited member of that exact trip.

Membership-based permissions

Each trip has owners, editors and viewers. The database checks your role on every read and write, so a viewer can never edit and an outsider can never read.

Encrypted storage & transfer

Your documents are stored in private, access-controlled storage. All traffic is encrypted in transit with HTTPS/TLS.

Sensitive work stays server-side

Document processing and admin actions run on protected servers with verified credentials, never exposing keys or secrets to the browser.

No public indexing

Nothing about your trip is public, indexed by search engines, or shared with advertisers.

Delete anytime

You can delete any trip, document or your entire account at any time. Deletion is permanent and covers both the database and file storage.

What this means for you, in plain words

Only you — and the exact people you invite — can ever open your trip. The rules that decide who sees what aren't enforced by hopeful front-end code; they're enforced deep inside the database, so even a bug in the app cannot hand your data to a stranger. When you share a trip, you choose whether each person can edit or only view, and you can change or remove their access at any time. Nothing about your trip is public, indexed, or shared with advertisers.

Questions about security?

Reach out via the contact info in our Impressum.

Create a free trip