Privacy Policy of Xdestination
Last Updated: February 11, 2026
Effective Date: February 11, 2026
SOCIALMEDIAHOUSE srl
Piazza Aquileia 9, Sesto al Reghena 33079 (PN), Italy
VAT: IT01onal924660931
Email: info@xdestination.io
Your privacy is important to us. This Privacy Policy explains how SOCIALMEDIAHOUSE srl ("we", "us", "Company") collects, uses, protects, and shares your personal information when you use Xdestination ("App"), in compliance with the General Data Protection Regulation (GDPR - EU 2016/679), the Italian Privacy Code (D.Lgs. 196/2003), and the EU AI Act (EU 2024/1689).
1. Age Requirements
Xdestination is intended for users aged 16 years or older. We do not knowingly collect personal information from children under 16. If you are under 16, please do not use this App or provide any personal information.
If we learn that we have collected personal information from a child under 16, we will promptly delete that information. If you believe we might have information from or about a child under 16, please contact us at info@xdestination.io.
2. Types of Data We Collect
2.1 Data You Provide Directly
- Account Information: Name, email address, username, password, profile photo
- Payment Information: Payment details processed by third-party payment providers (we do not store full card numbers)
- Profile Information: Bio, interests, travel preferences
- Communications: Messages you send to other users or to our support team
2.2 Data Collected Automatically
- Device Information: Device type, operating system, unique device identifiers, app version
- Usage Data: Session duration, screens visited, features used, actions taken within the App
- Log Data: IP address, access times, crash reports, performance data
2.3 Location Data
- Precise Location: GPS coordinates when you enable location services (required for core features)
- Coarse Location: Approximate location based on IP address
- Location History: Places you've visited, check-ins, travel routes (stored in your personal vault)
You can disable location tracking at any time through your device settings or within the App. Some features require location access to function.
2.4 User-Generated Content
- Media: Photos, videos you upload
- Memories: Travel experiences you create and share
- Moments: Time-limited content shared with friends or community
- Metadata: EXIF data from photos (date, location, camera settings) - you can strip this before upload
2.5 Social and Community Data
- Friend Connections: Your friend list, friend requests, blocked users
- Interactions: Likes, comments, shares, tags
- Visibility Preferences: Who can see your location, content, profile
3. Artificial Intelligence and Automated Processing
Xdestination uses artificial intelligence systems to enhance your experience. We are committed to transparency about how AI is used.
3.1 Magic Search (AI-Powered Discovery)
Our "Magic Search" feature uses large language models (LLMs) provided by third-party AI services (Anthropic Claude, OpenAI) to:
- Understand your natural language search queries
- Discover points of interest based on your descriptions
- Provide personalized recommendations
Data processed: Your search queries, location context, and preferences are sent to AI service providers to generate results. These providers process data under strict data processing agreements.
Cost: Magic Search uses Xcoins (1 coin per search). Results are saved to your personal vault.
3.2 Behavioral Analysis and Profiling
The App analyzes your usage patterns to create a "Lifestyle Profile" across 8 dimensions:
- Evolve, Explore, Connect, Enjoy, Learn, Contribute, Create, Dream
This profiling is used to:
- Personalize your experience and recommendations
- Award points and achievements in the gamification system
- Suggest relevant content and connections
3.3 Your Rights Regarding Automated Decisions (GDPR Art. 22)
You have the right to:
- Opt-out of profiling: Disable lifestyle profiling in Settings > Privacy > Profiling
- Request human review: Contest any automated decision that significantly affects you
- Obtain explanation: Understand the logic behind automated recommendations
- Access your profile: View and export your lifestyle profile data
4. Legal Basis for Processing (GDPR Art. 6)
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Account creation and management | Contract (Art. 6.1.b) | Necessary to provide the service |
| Location-based features | Consent (Art. 6.1.a) | You explicitly enable location access |
| AI-powered search | Consent (Art. 6.1.a) | You initiate each AI search |
| Lifestyle profiling | Consent (Art. 6.1.a) | Opt-in feature, can be disabled |
| Marketing communications | Consent (Art. 6.1.a) | Only with your explicit opt-in |
| Analytics and improvement | Legitimate Interest (Art. 6.1.f) | To improve the App; you can opt-out |
| Security and fraud prevention | Legitimate Interest (Art. 6.1.f) | To protect you and our services |
| Legal compliance | Legal Obligation (Art. 6.1.c) | When required by law |
5. How We Use Your Data
- Service Delivery: Provide, maintain, and improve App functionality
- Personalization: Customize your experience based on preferences and location
- Gamification: Manage points, levels, achievements, and rewards
- Community Features: Enable friend connections, content sharing, messaging
- Safety and Content Moderation: Detect and prevent fraud, abuse, and violations of our Community Guidelines, including automated content filtering, processing user reports, and enforcing our Terms of Service
- Communications: Send service updates, respond to support requests
- Marketing: Send promotional content (only with your consent)
- Analytics: Understand usage patterns to improve the App
- Legal Compliance: Meet our legal obligations
6. Content Moderation and User Safety Data
To maintain a safe community and comply with applicable regulations (including Apple App Store Guidelines), we collect and process the following data related to content moderation:
6.1 Data Collected for Moderation
- User Reports: When you report content or a user, we collect the report details, the reported content, and identifiers of both the reporting and reported users
- Block Records: When you block a user, we record the block action to enforce the restriction and to review the blocked user's activity for potential violations
- Content Filtering Logs: Our automated content filtering systems log flagged content and the reasons for flagging
- Moderation Actions: Records of warnings issued, content removed, accounts suspended or terminated, and appeal outcomes
6.2 How We Use Moderation Data
- To review and act on reported content and users within 24 hours
- To enforce our Terms of Service and Community Guidelines
- To improve our automated content filtering systems
- To notify developers and the moderation team of abusive behavior
- To maintain records for legal compliance and law enforcement cooperation
- To protect the safety of all users on the platform
6.3 Retention of Moderation Data
| Data Type | Retention Period |
|---|---|
| User reports | 2 years after resolution |
| Block records | Duration of the block + 1 year |
| Content filtering logs | 6 months |
| Moderation actions (warnings, suspensions) | Duration of account + 3 years |
| Terminated account records | 5 years (to prevent re-registration) |
7. Data Storage and Security
7.1 Where Your Data is Stored
Your personal data is stored on:
- Microsoft Azure: Cloud infrastructure located in the European Union (West Europe region)
- Personal Vault: Each user has a dedicated Azure Blob storage container for their media and experiences
7.2 International Transfers
Some of our service providers are located outside the European Economic Area (EEA):
| Provider | Location | Safeguard |
|---|---|---|
| Anthropic (AI) | USA | Standard Contractual Clauses (SCCs) |
| OpenAI (AI) | USA | Standard Contractual Clauses (SCCs) |
| Google Analytics | USA | EU-US Data Privacy Framework |
All international transfers are protected by appropriate safeguards as required by GDPR Chapter V.
7.3 Security Measures
- End-to-end encryption for data in transit (HTTPS/TLS 1.3)
- Encryption at rest for stored data
- Access controls and authentication
- Regular security audits and penetration testing
- Employee training on data protection
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion |
| User-generated content | Until you delete it or your account |
| Location history | Until you delete it or your account |
| Messages | Until deleted by sender/recipient or account deletion |
| AI search history | 90 days (anonymized after 30 days) |
| Analytics data | 26 months (anonymized) |
| Support tickets | 3 years after resolution |
| Legal/compliance records | As required by law (typically 10 years) |
9. Data Sharing
We do not sell your personal data. We may share data with:
9.1 Service Providers
- Microsoft Azure: Cloud hosting and storage
- Anthropic/OpenAI: AI processing for Magic Search
- Mapbox: Maps and geocoding services
- Payment processors: Secure payment handling
- Analytics providers: Usage analysis (Google Analytics)
All service providers are bound by data processing agreements (DPAs) that comply with GDPR requirements.
9.2 Other Users
Based on your privacy settings, other users may see:
- Your public profile information
- Content you share publicly or with friends
- Your location (if you enable location sharing)
9.3 Legal Requirements
We may disclose data when required by law, court order, or to protect our legal rights.
10. Your Rights (GDPR Articles 15-22)
You have the following rights regarding your personal data:
| Right | Description | How to Exercise |
|---|---|---|
| Access (Art. 15) | Obtain a copy of your personal data | Settings > Privacy > Download My Data |
| Rectification (Art. 16) | Correct inaccurate data | Edit your profile in the App |
| Erasure (Art. 17) | Delete your data ("right to be forgotten") | Settings > Account > Delete Account |
| Restriction (Art. 18) | Limit how we process your data | Contact info@xdestination.io |
| Portability (Art. 20) | Receive your data in a portable format | Settings > Privacy > Export Data (JSON) |
| Object (Art. 21) | Object to processing based on legitimate interests | Contact info@xdestination.io |
| Withdraw Consent | Withdraw previously given consent | Settings > Privacy or contact us |
To exercise any right, contact us at info@xdestination.io. We will respond within 30 days.
11. Cookies and Tracking Technologies
We use cookies and similar technologies. For detailed information, please see our Cookie Policy.
12. Marketing and Communications
12.1 Opt-In Marketing
We only send marketing communications if you have explicitly opted in. You can manage your preferences in Settings > Notifications.
12.2 How to Unsubscribe
- Click "Unsubscribe" in any marketing email
- Go to Settings > Notifications in the App
- Contact info@xdestination.io
Note: You will still receive essential service communications (security alerts, account updates).
13. Data Breach Notification
In the event of a personal data breach that poses a high risk to your rights and freedoms, we will:
- Notify the Italian Data Protection Authority (Garante) within 72 hours
- Notify affected users without undue delay
- Provide information about the breach and steps to protect yourself
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will:
- Post the updated policy with a new "Last Updated" date
- Notify you of material changes via email or in-app notification
- Provide at least 30 days notice before changes take effect
Continued use of the App after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
For questions, requests, or complaints about this Privacy Policy or our data practices:
SOCIALMEDIAHOUSE srl
Piazza Aquileia 9, Sesto al Reghena 33079 (PN), Italy
Email: info@xdestination.io
Website: https://xdestination.io
Support: https://xdestination.io/support
16. Supervisory Authority
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with a supervisory authority:
Piazza Venezia 11, 00187 Roma, Italy
Website: www.garanteprivacy.it
Email: protocollo@gpdp.it