← Back

Privacy Policy

Last updated: July 10, 2026

Who we are

MyIceland, operated by the Lovdu Technology Group ("we", "us", "our"), runs the website myiceland.is. This privacy policy explains how we collect, use, and protect your personal information when you use our platform.

What data we collect

When you create an account, we collect:

  • Email address (for passwordless sign-in and account-related notifications)
  • Username (chosen by you during onboarding)
  • Display name and bio (optional, set by you)
  • Profile picture (optional, uploaded by you)

When you use the platform, we collect:

  • Photos you upload (including GPS metadata if present in the image file)
  • Comments you post
  • Places you like, visit, and rate
  • Trips you create (including AI-generated trips)
  • AI trip generation prompts and the resulting itineraries
  • Feedback you submit

We automatically collect:

  • IP address (for rate limiting and abuse prevention)
  • Browser type and device information (for compatibility)
  • Page views and interaction data (for service improvement)
  • Analytics events and session recordings — the pages you visit, clicks, and navigation, plus anonymized recordings of how the site is used, to understand usage and diagnose issues. These are anonymous and never linked to your account, and any text you type into inputs (such as your email address) is masked and never recorded. You can opt out at any time via "Cookie preferences" in the footer, and we honor your browser's Do-Not-Track setting.

How we use your data

  • To provide and operate the platform
  • To authenticate your account
  • To display your profile, comments, and photos to other users
  • To send you notifications (likes, mentions, place approvals)
  • To generate AI-powered trip itineraries based on your prompts
  • To prevent abuse and enforce rate limits
  • To improve the platform and understand how it is used
  • To moderate content and ensure community guidelines are followed

We do not sell your personal data to third parties. We do not use your data for targeted advertising.

Third-party services

We use the following third-party services that may process your data:

  • Supabase — database hosting, authentication, and file storage
  • Vercel — website hosting and serverless functions
  • Cloudflare — image delivery via our photo CDN (myiceland.photos); it processes image requests to cache and serve photos quickly
  • Anthropic — AI trip generation (your prompts are sent to Anthropic's Claude API to generate itineraries)
  • Google — "Sign in with Google" (only if you choose it)
  • Apple — "Sign in with Apple" (only if you choose it) and Apple Maps (MapKit JS), used to display maps
  • PostHog — product analytics and session recording (usage events and masked recordings of site interactions, US hosted)

Some of these providers are based in the United States, so your data may be transferred to and processed there. These providers offer standard contractual clauses and other safeguards for such international transfers. Each service has its own privacy policy, and we encourage you to review them.

Photo data and GPS

When you upload a photo, we may extract GPS coordinates from the image metadata (EXIF data) to verify the photo was taken at the claimed location. This GPS data is stored in our database and is visible to platform administrators only — it is never displayed publicly.

If you do not want GPS data processed, you can strip EXIF metadata from your photos before uploading using your phone's settings or a third-party tool.

AI-generated content

When you use the "Plan with AI" feature, your prompt is sent to Anthropic's Claude API to generate a trip itinerary. We store your prompt, the generated itinerary, and usage metadata (model used, response time, token count) in our database. This data is used to improve the trip generation feature and monitor for abuse.

Anthropic may process your prompt according to their own privacy policy and API terms. We recommend reviewing Anthropic's privacy policy at anthropic.com/privacy for details on how they handle API inputs.

Admin access

Platform administrators may access user data for the purposes of content moderation (reviewing photos, comments, and flagged content), customer support, abuse prevention, and service improvement. Private trips are not visible to other users but may be accessed by administrators when necessary.

Admin access is limited to authorized personnel and is logged for accountability.

Public vs private content

By default, your profile is public. Other users can see your username, display name, bio, liked places, photos, and comments at /u/your-username. You can make your profile private in Settings — this hides your activity from other users.

Trips you create are private by default. You can choose to make them public, which makes them visible to everyone and listed in the community trips section.

Comments and photos you post on place pages are always public (visible to anyone browsing the place).

Security

We use industry-standard encryption (SSL/TLS), secure authentication via Supabase Auth, and server-side validation on all data. MyIceland is passwordless — you sign in with a secure one-time link sent to your email, or with Google or Apple — so we never create or store passwords at all. If you discover a security vulnerability, please contact security@myiceland.is.

Cookies

We use essential cookies to keep you signed in. We also use privacy-friendly product analytics (PostHog), which store a cookie and local-storage data to understand how the platform is used and to diagnose issues. This analytics is anonymous — it is never linked to your identity, used for advertising, or sold to anyone. PostHog only records activity on myiceland.is — it cannot and does not track you across other websites, and it never has access to anything you type into inputs (like your email).

Visitors in the EU, EEA, and UK are asked to consent before any analytics runs. Everyone, wherever you are, can opt out at any time via "Cookie preferences" in the footer, and we honor your browser's Do-Not-Track setting. We do not use advertising or third-party tracking cookies.

Data retention

Your data is retained as long as your account exists. When you delete your account:

  • Your profile, likes, visits, ratings, notifications, and trips are permanently deleted
  • Your comments are deleted
  • Your approved photos are anonymized (kept on the platform without attribution)
  • Unverified photos are deleted from storage
  • AI generation logs associated with your account are retained in anonymized form for service improvement

Your rights

Under GDPR and Icelandic data protection law, you have the right to:

  • Access your personal data
  • Correct inaccurate data (via Settings)
  • Delete your account and data (via Settings → Danger Zone)
  • Export your data (contact us)
  • Object to processing (contact us)
  • Withdraw consent for analytics at any time (via "Cookie preferences" in the footer)

Children

MyIceland is not intended for children under 13. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

Copyright and takedowns

If you believe content on our platform infringes your copyright, contact us at legal@myiceland.is with the URL of the content, proof of ownership, and a statement that the use is unauthorized. We will review and respond within 48 hours.

Changes to this policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the platform after changes constitutes acceptance.

Contact

For privacy-related questions or to exercise your rights, contact us at:

privacy@myiceland.is