Check The App

Privacy

Last updated 9 September 2026

The short version

Who this is

Check The App is a private holiday app made by TMDigital Studio Ltd for one family and their friends. It is handed out through TestFlight to people we know. It is not on the App Store and it is not for sale.

TMDigital Studio Ltd is the data controller for the purposes of UK data protection law. You can reach us at admin@tmdigitalstudio.co.uk.

No account, no sign-up

You never make an account. When the app first opens it quietly signs itself in to our database with an anonymous ID — a random string of characters with no name, no email address and no phone number attached to it. Its only job is to prove to the database that the request came from the app, so that the itinerary is not readable by the open internet.

That ID belongs to the installation, not to you. Delete the app and it is gone for good; reinstall and you get a different one.

What the app keeps on your phone

These are kept on the handset itself and never sent to us:

Deleting the app deletes all of it.

What is in the itinerary

The itinerary itself is written by the trip organiser and stored in our database. It holds the plan for the trip: what is happening and when, the first names of people in the group, the places we are staying and their addresses, booking references and a phone number or two.

Only somebody with the app can read it, and only the organiser can change it. None of it is public, and none of it is shared with anyone outside the group.

Where you are

The app can work out how long it would take you to get to the next thing. That is the only reason it ever asks for your location, and none of it happens until you turn the setting on. It is off to begin with.

Once it is on, there are two different things to be clear about, because they are not the same and only one of them involves us at all.

Your phone works out where it is while the app is open. It does this when the app is opened, when you come back to it, and about every five minutes while it is on your screen — so that the app can show you where you are without making you wait for it each time. This stops when the app is not in front of you: it is not able to follow you in the background, and it does not try.

Nothing about that leaves your phone. The position stays on the handset, it is not sent to us, it is not written down anywhere, and it is forgotten the moment you turn the setting off. The only thing that ever sends it is the button — Calculate from my location on a particular card — and it takes a fresh reading when you press it rather than using anything kept from before.

When you do press it, this is exactly what happens:

Your position is not stored against you, and it is not stored at all in the form your phone gave it. What is stored is a shared answer, so that seven people asking the same question on the same morning do not cost seven lookups: the travel times, the name of the area you set off from — "Trastevere, Rome", never a street or a house — and a scrambled label made from your rounded position that cannot be turned back into a place. It carries no ID of any kind, so it cannot be traced to a person or a phone, and it is treated as out of date after fifteen minutes.

Google receives the position in order to answer the question, and handles it under its own privacy policy. We send it nothing else about you, because we have nothing else to send.

You can turn the setting off at any time on the account screen, or refuse the permission in your phone's own settings. The rest of the app works exactly as before — you lose the travel times and nothing else.

Notifications

There are three switches on the account screen, all off until you turn them on, and they do not work the same way.

The two reminder switches — before you leave, and before something starts — are worked out by your own phone from the itinerary it has already downloaded. Nothing is sent to it and nothing leaves it. They work with no signal at all.

The third, when the plan changes, has to be sent, because your phone cannot warn you about a change it has not been given yet. If you turn it on, your phone registers with Apple and with Google's messaging service so it can receive those messages, and it joins a group named after the trip. When the itinerary changes, a message goes to that group saying what changed.

There are two of those groups per trip, one for each setting under Language on the account screen, because the message has to be written out before it is sent and the two write dates and times differently. Your phone is in one of them, and it moves to the other if you change that setting. The group name is the only thing that says which — it is not a record of you, and nothing about it is stored anywhere by us.

We do not keep a list of who has it on, and we could not send a message to one person if we wanted to — the message goes to the trip, not to anybody in particular. Turning the switch off leaves the groups immediately. Apple and Google handle the delivery under their own privacy policies, the same way they do for every app on your phone.

Photos you add to the trip

You can add up to three photos to anything on the itinerary — the meal, the museum, the walk. This is the one part of the app where something you make goes to everybody else, so it is worth reading properly.

Everyone with the app sees everybody's photos. A photo you add is not private to you and is not private to the activity. It is uploaded to Google Cloud Storage in London, and it appears on the activity's card and in the Photos tab for everybody on the trip, with the name you picked on the account screen printed under it.

Please do not add anything you would mind the group seeing, or anything of anyone who has not agreed to it. That is the whole rule. It is a shared album for a family holiday, and it should be treated like one.

The app asks for the camera the first time you take a photo rather than choose one, and it asks separately — a different permission — the first time you save a photo from the trip back into your own camera roll. Choosing an existing photo hands over that one photo only; the app is never given your photo library.

You can remove any photo you added, and the trip organiser can remove any photo at all. Removing takes it off everybody's app and deletes the file; it cannot be undone, and there is no copy kept.

Photos are not sent to Anthropic, not analysed, not scanned, and not used for anything except being shown to the group. The editing tool described below is a separate thing that only the organiser can reach.

How well they are protected, said plainly. Reading a photo requires the app to have signed in, and that sign-in is anonymous and automatic — the app does it for you, using a key that is built into every copy of it. So the honest description is not "only the group can see these". It is: anybody who has the app, or who extracts that key from it, can read them. That is the same protection the itinerary itself has, it is the ordinary arrangement for an app that asks nobody to type a password, and it is the reason for the rule two paragraphs up. The app is given out privately, to a known group, and that is a reason to expect privacy in practice rather than a guarantee of it.

If you are one of the two people who can edit

The trip organiser signs in with an email address and a password to change the itinerary. That email address is stored by Firebase Authentication so the sign-in works, and is used for nothing else. This applies to two people and to nobody else using the app.

The editor has a second way of working, where the organiser describes a change in ordinary words instead of filling in a form. When she does, the whole itinerary and what she typed are sent to Anthropic's Claude, which reads them and suggests changes. Nothing is changed by that on its own — every suggestion appears on a card and only takes effect when she accepts it.

She can also attach something to that message: a document, a PDF, or a photo — a booking confirmation, a screenshot, a note somebody wrote. What she attaches is sent to Claude in the same way, and the app will ask for the camera the first time she chooses to take a photo rather than pick an existing one. Choosing an existing photo hands over that one photo only; the app is never given your photo library.

Working out where a place is happens the same way for her as it does for everyone else's directions. When she looks a place up — by typing a few words into the editor, or by accepting a suggestion that names one — those words are sent to Google so it can say which place is meant and give back the address. Google is told the words and, to help it pick the right answer, roughly where on the trip to look — that comes from the itinerary and never from anybody's phone. It is a search for a place and carries nothing about a person, Google is not told who asked, and we store none of it.

We keep none of it. Anthropic processes it to answer and does not train on it; their handling is covered by their own privacy policy at anthropic.com/legal/privacy. This applies only to the two people who can edit. Using the app to look at the trip sends nothing to Claude, ever.

The itinerary carries the names and plans of everybody on the trip, so that is what goes with it. If you would rather your name were not in the itinerary at all, say so and it comes out.

What we do not do

Where it is kept, and for how long

The itinerary, the photos and the anonymous sign-ins are held on Google's Firebase platform, in Google's London data centres. The travel-time server runs in London too.

The itinerary is kept for as long as the trip is useful to look back on, and can be deleted on request. The cached travel times fall out of use after fifteen minutes and carry nothing personal in the first place.

Deleting your data

Delete the app. Everything it kept on your phone goes at the same moment, and the anonymous ID it used stops meaning anything.

If you want your name taken out of the shared itinerary, or you want to know what it holds about you, email admin@tmdigitalstudio.co.uk and we will sort it out. Under UK data protection law you can also ask for a copy of your data, ask for it to be corrected, or complain to the Information Commissioner's Office at ico.org.uk.

Children

Children in the group use the app the same way everyone else does, with a parent's say-so. It collects nothing that identifies them: no account, no contact details, no tracking. Their first name appears in the itinerary only because the trip organiser wrote it there.

If this changes

If the app starts doing something this page does not describe, this page changes first, and the date at the top changes with it.