Check The App
Privacy
Last updated 9 September 2026
The short version
- There is no sign-up, no username and no password. The app never asks who you are in a way that leaves our hands.
- We collect no analytics, show no adverts and track nobody.
- Nothing is sent to your phone unless you ask for it, and then only to say the trip has changed.
- If you switch location on, your phone works out where it is while the app is open — but that stays on the phone, and it is only ever sent anywhere when you press the button that needs it.
- Which person you picked and how you like the app set up are kept on your phone, not on a server.
- Delete the app and everything it kept on your phone goes with it.
- A photo you add to the trip is seen by everybody with the app, and it is protected by nothing stronger than having the app. Do not put anything private in it.
- The two people who can edit the itinerary have a tool that sends it to Anthropic's Claude to work out what changed. Nothing you do sends anything there.
Who this is
Check The App is a private holiday app made by TMDigital Studio Ltd for one family and their friends. It is handed out through TestFlight to people we know. It is not on the App Store and it is not for sale.
TMDigital Studio Ltd is the data controller for the purposes of UK data protection law. You can reach us at admin@tmdigitalstudio.co.uk.
No account, no sign-up
You never make an account. When the app first opens it quietly signs itself in to our database with an anonymous ID — a random string of characters with no name, no email address and no phone number attached to it. Its only job is to prove to the database that the request came from the app, so that the itinerary is not readable by the open internet.
That ID belongs to the installation, not to you. Delete the app and it is gone for good; reinstall and you get a different one.
What the app keeps on your phone
These are kept on the handset itself and never sent to us:
- which person in the group you picked as yourself;
- your settings — light or dark, which map app you prefer, whether location is switched on, and your notification switches;
- the moment you last read the "what has changed" screen, so it does not show you the same changes twice;
- which trip you were last looking at, and the last time the app managed to reach the internet, so it can tell you when what is on screen is a saved copy;
- a copy of the itinerary, so the app still works with no signal.
Deleting the app deletes all of it.
What is in the itinerary
The itinerary itself is written by the trip organiser and stored in our database. It holds the plan for the trip: what is happening and when, the first names of people in the group, the places we are staying and their addresses, booking references and a phone number or two.
Only somebody with the app can read it, and only the organiser can change it. None of it is public, and none of it is shared with anyone outside the group.
Where you are
The app can work out how long it would take you to get to the next thing. That is the only reason it ever asks for your location, and none of it happens until you turn the setting on. It is off to begin with.
Once it is on, there are two different things to be clear about, because they are not the same and only one of them involves us at all.
Your phone works out where it is while the app is open. It does this when the app is opened, when you come back to it, and about every five minutes while it is on your screen — so that the app can show you where you are without making you wait for it each time. This stops when the app is not in front of you: it is not able to follow you in the background, and it does not try.
Nothing about that leaves your phone. The position stays on the handset, it is not sent to us, it is not written down anywhere, and it is forgotten the moment you turn the setting off. The only thing that ever sends it is the button — Calculate from my location on a particular card — and it takes a fresh reading when you press it rather than using anything kept from before.
When you do press it, this is exactly what happens:
- your phone works out where it is, to about street accuracy rather than house accuracy — the app deliberately asks for the coarser of the two;
- that position is sent to our own small server in London, which asks Google how long the journey takes by foot, by car and by public transport, and what the area you are in is called;
- the times come back and appear on the card.
Your position is not stored against you, and it is not stored at all in the form your phone gave it. What is stored is a shared answer, so that seven people asking the same question on the same morning do not cost seven lookups: the travel times, the name of the area you set off from — "Trastevere, Rome", never a street or a house — and a scrambled label made from your rounded position that cannot be turned back into a place. It carries no ID of any kind, so it cannot be traced to a person or a phone, and it is treated as out of date after fifteen minutes.
Google receives the position in order to answer the question, and handles it under its own privacy policy. We send it nothing else about you, because we have nothing else to send.
You can turn the setting off at any time on the account screen, or refuse the permission in your phone's own settings. The rest of the app works exactly as before — you lose the travel times and nothing else.
Notifications
There are three switches on the account screen, all off until you turn them on, and they do not work the same way.
The two reminder switches — before you leave, and before something starts — are worked out by your own phone from the itinerary it has already downloaded. Nothing is sent to it and nothing leaves it. They work with no signal at all.
The third, when the plan changes, has to be sent, because your phone cannot warn you about a change it has not been given yet. If you turn it on, your phone registers with Apple and with Google's messaging service so it can receive those messages, and it joins a group named after the trip. When the itinerary changes, a message goes to that group saying what changed.
There are two of those groups per trip, one for each setting under Language on the account screen, because the message has to be written out before it is sent and the two write dates and times differently. Your phone is in one of them, and it moves to the other if you change that setting. The group name is the only thing that says which — it is not a record of you, and nothing about it is stored anywhere by us.
We do not keep a list of who has it on, and we could not send a message to one person if we wanted to — the message goes to the trip, not to anybody in particular. Turning the switch off leaves the groups immediately. Apple and Google handle the delivery under their own privacy policies, the same way they do for every app on your phone.
Photos you add to the trip
You can add up to three photos to anything on the itinerary — the meal, the museum, the walk. This is the one part of the app where something you make goes to everybody else, so it is worth reading properly.
Everyone with the app sees everybody's photos. A photo you add is not private to you and is not private to the activity. It is uploaded to Google Cloud Storage in London, and it appears on the activity's card and in the Photos tab for everybody on the trip, with the name you picked on the account screen printed under it.
Please do not add anything you would mind the group seeing, or anything of anyone who has not agreed to it. That is the whole rule. It is a shared album for a family holiday, and it should be treated like one.
The app asks for the camera the first time you take a photo rather than choose one, and it asks separately — a different permission — the first time you save a photo from the trip back into your own camera roll. Choosing an existing photo hands over that one photo only; the app is never given your photo library.
You can remove any photo you added, and the trip organiser can remove any photo at all. Removing takes it off everybody's app and deletes the file; it cannot be undone, and there is no copy kept.
Photos are not sent to Anthropic, not analysed, not scanned, and not used for anything except being shown to the group. The editing tool described below is a separate thing that only the organiser can reach.
How well they are protected, said plainly. Reading a photo requires the app to have signed in, and that sign-in is anonymous and automatic — the app does it for you, using a key that is built into every copy of it. So the honest description is not "only the group can see these". It is: anybody who has the app, or who extracts that key from it, can read them. That is the same protection the itinerary itself has, it is the ordinary arrangement for an app that asks nobody to type a password, and it is the reason for the rule two paragraphs up. The app is given out privately, to a known group, and that is a reason to expect privacy in practice rather than a guarantee of it.
If you are one of the two people who can edit
The trip organiser signs in with an email address and a password to change the itinerary. That email address is stored by Firebase Authentication so the sign-in works, and is used for nothing else. This applies to two people and to nobody else using the app.
The editor has a second way of working, where the organiser describes a change in ordinary words instead of filling in a form. When she does, the whole itinerary and what she typed are sent to Anthropic's Claude, which reads them and suggests changes. Nothing is changed by that on its own — every suggestion appears on a card and only takes effect when she accepts it.
She can also attach something to that message: a document, a PDF, or a photo — a booking confirmation, a screenshot, a note somebody wrote. What she attaches is sent to Claude in the same way, and the app will ask for the camera the first time she chooses to take a photo rather than pick an existing one. Choosing an existing photo hands over that one photo only; the app is never given your photo library.
Working out where a place is happens the same way for her as it does for everyone else's directions. When she looks a place up — by typing a few words into the editor, or by accepting a suggestion that names one — those words are sent to Google so it can say which place is meant and give back the address. Google is told the words and, to help it pick the right answer, roughly where on the trip to look — that comes from the itinerary and never from anybody's phone. It is a search for a place and carries nothing about a person, Google is not told who asked, and we store none of it.
We keep none of it. Anthropic processes it to answer and does not train on it; their handling is covered by their own privacy policy at anthropic.com/legal/privacy. This applies only to the two people who can edit. Using the app to look at the trip sends nothing to Claude, ever.
The itinerary carries the names and plans of everybody on the trip, so that is what goes with it. If you would rather your name were not in the itinerary at all, say so and it comes out.
What we do not do
- No analytics, no crash reporting, no usage tracking of any kind.
- No advertising, and no advertising identifiers.
- No selling or sharing of anything with anybody, ever.
- No profiling, and no automated decisions about you. The editor's suggestions are read and accepted by a person before anything changes.
- No contacts, no microphone, no health data, no calendar. The app never asks for them.
- Nothing is done with your photos beyond showing them to the group. They are not analysed, not scanned and not sent to Anthropic.
Where it is kept, and for how long
The itinerary, the photos and the anonymous sign-ins are held on Google's Firebase platform, in Google's London data centres. The travel-time server runs in London too.
The itinerary is kept for as long as the trip is useful to look back on, and can be deleted on request. The cached travel times fall out of use after fifteen minutes and carry nothing personal in the first place.
Deleting your data
Delete the app. Everything it kept on your phone goes at the same moment, and the anonymous ID it used stops meaning anything.
If you want your name taken out of the shared itinerary, or you want to know what it holds about you, email admin@tmdigitalstudio.co.uk and we will sort it out. Under UK data protection law you can also ask for a copy of your data, ask for it to be corrected, or complain to the Information Commissioner's Office at ico.org.uk.
Children
Children in the group use the app the same way everyone else does, with a parent's say-so. It collects nothing that identifies them: no account, no contact details, no tracking. Their first name appears in the itinerary only because the trip organiser wrote it there.
If this changes
If the app starts doing something this page does not describe, this page changes first, and the date at the top changes with it.