Privacy Policy
Last updated: 16 August 2026
This policy explains what personal data Adventurelist collects, why we collect it, and the rights you have over it under the General Data Protection Regulation (GDPR).
1. Who we are
The data controller responsible for your personal data is Björn Höglund. For any privacy questions or to exercise your rights, contact us at admin@adventurelist.eu.
2. What we collect
- Account details — your email address (also your sign-in identifier), a display name, your preferred language, and the date your account was created.
- Password — stored only as a salted cryptographic hash. We never store or can see your actual password.
- Your activity — the experiences you mark as completed (with the date and any personal notes you add), whether you would recommend them, the experiences you add to your wishlist, and any lists you create.
- Security metadata — limited data used to protect your account, such as failed sign-in counts, temporary lockout status, and password-reset request timestamps.
- Cookies — a small number of strictly-necessary cookies (see section 6).
We do not collect special-category data, we do not use advertising or analytics trackers, and we do not build behavioural profiles or sell your data.
3. Why we use it (legal basis)
- Performance of a contract — creating your account and providing the features you signed up for (tracking progress, notes, wishlist, lists, and your dashboard).
- Legitimate interests — keeping the service secure and functioning (authentication, password resets), and understanding overall use of the site. Any community figures we show (for example "85% recommend this") and the statistics available to our administrators are aggregated and anonymous — they are counts only and cannot identify you.
4. Where your data is stored
Your account and activity data is stored on Microsoft Azure in the EU (Sweden). Some third-party content shown on the site is loaded directly by your browser from providers that may be outside the EU (see section 5); those requests expose your IP address but no account data.
5. Who your data reaches
Processors we use to run the service (your account data is never sold or shared for marketing):
- Microsoft Azure — hosting, database storage (Azure Cosmos DB), and image storage (Azure Blob Storage). Your account and activity data is stored here.
- Our email provider — used only to deliver transactional emails such as password-reset links, using your email address.
- Anthropic (Claude) — generates the informational descriptions on experience pages. Only the experience name and category name are sent; no user personal data is sent.
Third-party content loaded in your browser. Some pages include content served directly from other providers. Your browser contacts them to fetch it, which means they receive your IP address (and standard request information). We do not share your account or activity data with them:
- Unsplash — illustrative photos on pages without a curated image.
- MapTiler — map tiles on pages that show a location map.
- unpkg and Cloudflare — content delivery networks that serve the map library and the icon font used across the site.
Where a provider processes data outside the EU, transfers rely on that provider's standard contractual clauses and safeguards.
6. Cookies
Adventurelist uses only strictly-necessary cookies. Because each is essential to a service you actively use, no consent banner is required, and we use no analytics, advertising, or third-party tracking cookies.
- Authentication — keeps you signed in.
- Language — remembers your chosen language.
- Security — an anti-forgery token that protects forms from cross-site request forgery.
7. How long we keep it
We keep your account and activity data for as long as your account exists. When you delete your account, your personal data is removed without undue delay.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, object to, and port your personal data.
Two of these you can exercise yourself, at any time, from your dashboard:
- Download my data — get a copy of your data (account, completions, wishlist, and lists) in a portable JSON file (access & portability).
- Delete my account — permanently erase your account and all associated data (erasure).
For anything else — correcting your details, or restricting or objecting to processing — email admin@adventurelist.eu. You also have the right to lodge a complaint with the Swedish data protection authority, Integritetsskyddsmyndigheten (IMY).
9. Who can access your data
Access is limited to what is needed to run the service. Authorised administrators can view account details (such as name, email, and account status) and manage accounts for support, moderation, and security purposes. Administrators cannot see your password.
10. Children
Adventurelist is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date at the top of this page.