Privacy Policy

Last updated: July 2026

1. Introduction

Mystigo ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Mystigo mobile application and related services.

This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

The data controller responsible for your personal data is Mystigo. For privacy-related inquiries, contact us at privacy@mystigo.world.

3. Information We Collect

3.1 Information You Provide

3.2 Information Collected Automatically

4. How We Use Your Information

We use your information to:

5. Legal Basis for Processing (GDPR)

6. Location Data

Location data is core to Mystigo's functionality. We collect:

You can revoke location permissions at any time in your device settings. Background location can be disabled independently in the App settings without affecting other features.

Your precise location coordinates are never sold to third parties and are not used for advertising purposes.

7. Data Sharing

We do not sell your personal data. We may share your information with:

8. AI-Assisted Features

Some optional features rely on a third-party artificial-intelligence service to generate or process content. When you use AI-assisted itinerary creation, the natural-language description you type is transmitted to Anthropic PBC (operator of the Claude API, based in the United States), which generates the resulting itinerary. Heritage and point-of-interest descriptions presented in the App may likewise be generated or translated using this service.

Only the text required to fulfil the request is sent to the AI provider — we do not transmit your account identifiers, email address, or precise location coordinates. Anthropic acts as a sub-processor under its commercial API terms; it does not use this data to train its models and does not use it for advertising. Because this involves a transfer of data outside the European Economic Area, the safeguards described in section 13 apply.

These features are optional. If you do not use AI-assisted creation, no content is sent to the AI provider on your behalf.

9. Data Retention

We retain your personal data for as long as your account is active. You may delete your account at any time — see how to delete your account. After account deletion:

10. Your Rights (GDPR)

Under the GDPR, you have the right to:

To exercise these rights, contact us at privacy@mystigo.world. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

11. Security

We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS), bcrypt password hashing, JWT-based authentication, and regular security reviews. However, no method of transmission over the internet is 100% secure.

12. Children's Privacy

The App is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us to have it deleted.

13. International Transfers

Your data may be processed in countries outside the European Economic Area. When such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the App or by email. The "last updated" date at the top of this page indicates when it was last revised.

15. Contact

For privacy-related questions or to exercise your rights, contact us at privacy@mystigo.world.