Last updated 26 July 2026
Privacy
Path collects what it needs to show your travels to the people you choose, and nothing else. There is no advertising, no tracking across other apps or sites, and no analytics SDK in the app.
What you give us
- An email address and a username. The email verifies your account and is how a password reset reaches you; it is never shown on your profile.
- A password, stored only as a scrypt hash. Nobody at Path can read it, which is also why we cannot tell you what it was.
- The home towns and college town you enter, which appear on your profile.
- Anything you post: folder names, place names, ratings, notes, tags, dates, and photos you upload.
- Messages you send to other travelers.
What we work out from that
When you name a place, we look up its approximate coordinates so it can be shown on a map. That lookup is based on the text you typed, not on your device — Path never asks for or receives your location, and there is no background location collection of any kind.
We also count things in order to rank content: how many people have bucket-listed a folder, how many places you have rated, and how many saves your travels have received. Those counts drive what appears on the discover and search pages and which accreditation badge you hold.
What we keep for operating the service
- A session record for each device you sign in on, so you stay signed in. It stores a hash of the session token, never the token.
- A log of transactional emails we attempted to send — the address, the subject, and whether it succeeded. The links inside are not kept.
- Short-lived counters used for rate limiting, keyed on a username or account id, so one client cannot brute-force a password or flood reports.
- Reports you file and blocks you set, which we need in order to act on them.
Who else touches your data
Path is not in the business of selling or sharing your data, and does not do either. Three infrastructure providers necessarily process it on our behalf: a managed Postgres host stores the database, an S3-compatible object store with a CDN in front of it stores and serves uploaded images, and Resend delivers verification and password-reset email. Each is used only for that purpose.
There are no advertising networks, no data brokers, and no analytics or attribution SDKs involved.
Who can see what you post
You decide this, and the controls are in the app rather than here. Your account can be public or private; each folder is either public or followers-only; your bucket list has its own setting. A private account forces every folder followers-only. Plans are the one thing with no setting at all — they are visible to you and to nobody else, ever, and adding somebody's place to a plan tells them nothing.
Deleting it
Settings has a delete option that removes the account outright, not a deactivation that keeps everything on file. It takes your folders, places, photos, ratings, plans, messages, follows, and saves with it. Uploaded images are removed from storage as part of the same operation.
Two things survive by design. Reports you filed against other people remain, with your name detached from them, because a moderation record has to outlive the reporter. And messages you sent still exist in the recipient's copy of the conversation, in the same way a sent text message does.
Children
Path is not intended for anyone under 13, and we do not knowingly keep accounts for children under 13. If you believe one exists, tell us and we will remove it.
Asking us about any of this
Write to support@pathtravelapp.com for a copy of your data, a correction, or a deletion you would rather we handled. We answer within 30 days.