Privacy

Last updated: 2 October 2026

Short version: we keep almost nothing about you personally. No name, no email, no password, no payment data. The AI and booking features use an anonymous account that isn't tied to who you are, and we keep anonymous product analytics so we can tell which features are useful. We don't sell anything because there isn't anything to sell. This policy applies to Icebreaker, the free Iceland travel app, and to the website icebreakerapp.is, including tours booked through its Book buttons.

1 · Who we are

Icebreaker ehf. is a private limited company registered in Reykjavík, Iceland. We make the Icebreaker app ("Icebreaker", "the app") and are the controller of the data described here. You can reach us at hello@icebreakerapp.is.

2 · What we collect

Your location, if you grant the permission

When you grant the iOS or Android location permission, the app reads your latitude and longitude to show you what's nearby (cafés, bars, events, activities). Our own servers never receive your coordinates. Two outside services do: the app sends them to Open-Meteo to get the weather where you are, and Mapbox receives location data when it draws the map (see §4). On Android, location is provided through Google Play Services.

Your IP address, at our servers

Like any web server, our servers see the IP address of each request, because that is where the answer goes.

  • Our API server does not write it to its request log: that log holds only a request id, the method, the path and the status code.
  • Our AI and booking functions (on Supabase) never store your raw IP address. They turn it into a one-way hash, used only for the usage limits described below. We call this pseudonymised rather than anonymous: it is not your IP address, but it is still derived from it, so we treat it as personal data.
  • Supabase, which runs those functions and the anonymous accounts, records IP addresses in its own request and sign-in logs, which are kept for a short time (see §5).

An anonymous account, for the AI and booking features

There is no sign-up and no login screen. The first time you use Hulli, the trip planner or book a tour in the app, the app quietly creates an anonymous account with our backend provider, Supabase. It has no name, email, phone number or password, and it isn't linked to your identity or to the analytics install ID. The app keeps the account's session on your device and uses it to show our functions that requests come from the app, and to count usage per account.

  • What Supabase stores with it: a random account id, when it was created and last used, and, for the active session, the IP address and device type (user agent) it signed in from.
  • Deleted automatically: an anonymous account that hasn't been used for 30 days is deleted, together with its sessions. If you come back later, the app simply creates a new one. Nothing is lost, because your chat history and saved plans live on your device.
  • A random chat ID is still sent alongside it. It is created by the app, separate from the analytics install ID, and kept in the iOS Keychain, so it survives deleting and reinstalling the app. On Android and older versions of the app, which don't use the anonymous account yet, it takes the account's place for usage limits.

Usage limits

To stop abuse and keep costs under control, every request to Hulli, the trip planner, stop swaps and in-app bookings is counted before it is handled. We count per anonymous account (or random chat ID), per hashed IP address, and in total for everyone. Each counter is stored in our database with an expiry: hourly counters expire at the end of the hour and daily ones at the end of the day (UTC), and expired counters are deleted.

What you send to Hulli and the trip planner (sent to Anthropic)

Hulli, the AI chat, and the trip planner are built on Anthropic's Claude. Before your first chat message, the app asks for your agreement, and nothing you write to Hulli is sent until you give it. If you say no, the rest of the app works as normal.

  • Hulli chat: the recent conversation (at most the last 20 messages) goes to our chat function, which looks up places in our own venue database and forwards the conversation to Anthropic to write the reply. Please don't put personal or sensitive information in the chat.
  • Trip planner: your interests, the regions you picked, the number of days and any wishes you typed are sent to our itinerary function and on to Anthropic, which picks places from our database. This includes the suggested itinerary the app builds from your onboarding answers. The trip planner doesn't ask for agreement first, because these choices don't identify you: they are only used to build the plan you asked for.
  • Swapping a stop: the stop being replaced, its region and type, a short summary of that day and any wishes you typed are sent the same way.
  • Not sent to Anthropic: your location, your travel dates, your party size, your anonymous account, your chat ID, your install ID or anything else about you. For tours in a plan, the app checks availability for your trip days with TourDesk (see §4).
  • Chat history and saved plans are stored only on your device. Chat can be wiped with “Clear chat”, and plans can be deleted in the app. We keep no copy of either on any server, and the requests themselves are not stored.
  • Function logs record timing, token counts, cost and a request id per request, not the text of your messages. If something goes wrong, the error log can include the raw reply the model wrote.

Anonymous product analytics, inside the app (PostHog)

We use PostHog inside the app to understand how it is used in aggregate: which features people open, how long the app is in the foreground, which screens get touched, and whether common flows fail. PostHog stores:

  • Anonymous events (the screen you opened, the button you tapped, whether you agreed to AI use, etc.).
  • When you start a booking, the tour, the date you pick, the number of guests and the price; when you choose a venue, which one; when you generate a plan, the interests, regions, trip dates and party size you picked.
  • Device-level metadata (OS version, app version, screen size, language, country at IP-level).
  • A randomly-generated install ID, a UUID created the first time you open the app. It is not tied to your name, email, phone number, your anonymous account or your chat ID.

We do not enable PostHog session replay, do not capture form input, do not send the text of your chat messages, and do not attach your name, email, or any contact information to events. Icebreaker has none of those to attach. PostHog data is hosted in PostHog Cloud's EU region.

Anonymous product analytics, on icebreakerapp.is (PostHog)

The website also uses PostHog to understand how the trip planner, chat and itinerary pages are used in aggregate: which features get opened, where people drop off, and whether common flows fail. PostHog stores:

  • The page you visited, when, and how long you stayed.
  • Anonymous product events, such as picking a place, answering a question in the chat, editing or saving an itinerary, or clicking a Book link. These carry ids and counts, never the text you typed or a place's name.
  • Device and browser type, screen size, language, country at IP-level.
  • A randomly-generated browser id, so a single visitor isn't counted as many.

If you sign in to save a chat or itinerary, this id is not linked to your account: PostHog on the website never receives your email, name or account id, even signed in. Same as in the app: no session replay, no form input capture, no chat message text. PostHog loads with consent denied by default and is controlled by the same banner as Google Analytics below: click "No thanks" and it records nothing about you. PostHog data is hosted in PostHog Cloud's EU region.

Anonymous web analytics, on icebreakerapp.is (Google Analytics 4)

The website at icebreakerapp.is uses Google Analytics 4 to count pageviews and to attribute visits to the QR codes, print ads, and referrers that brought them in. GA4 stores:

  • The page you visited, when, and how long you stayed.
  • Device and browser type, screen size, language, country at IP-level (Google truncates the IP before storage).
  • UTM tags from the URL, the tracking labels on our own QR codes and campaign links, so we can tell which channel a visit came from.
  • A randomly-generated client ID cookie, so a single visit isn't counted as many.

Google Analytics loads with consent set to denied by default. Google Tag Manager, the script that loads it, is fetched on every page before you choose, so Google receives your IP address. Until you click “OK, count me” on the consent banner, GA4 sets no cookies and records no visit, although Google's Consent Mode may send cookieless pings while consent is denied. Click “No thanks” and the site works exactly the same. You can change your mind by clearing cookies for icebreakerapp.is, or by opening browser dev-tools and running localStorage.removeItem('icebreaker-consent'). The app itself is unaffected either way: it does not use Google Analytics.

Advertising measurement, on icebreakerapp.is (Meta Pixel)

The website also loads the Meta Pixel so we can tell which of our own ads and posts actually bring people here, and so Meta can show Icebreaker ads to people who look likely to want it. The pixel sends Meta:

  • The page you visited and when, as a PageView event.
  • Which outbound links you click: the App Store or Google Play buttons, a “Book here” button, or our email address. We send Meta the name of the thing you clicked, so we can tell which ads lead to downloads and bookings rather than just visits. Not who you are, and never the content of anything you type.
  • Some clicks we did not ask for. Once you agree, Meta's pixel may also record button clicks on its own, without us configuring them, as an automatic SubscribedButtonClick event. We do not choose which ones. We are listing it because it happens, not because we wanted it.
  • Your IP address and browser user-agent, which Meta uses to match the visit to a Facebook or Instagram account if you have one.
  • An _fbp cookie in your browser: a randomly-generated browser ID that lets Meta recognise the same browser on later visits.

This one is different from GA4, and we would rather say so plainly: it is advertising data, not an anonymous headcount. Meta can link it to your Facebook or Instagram profile.

The pixel does not load at all until you click “OK, count me”. That one button turns on both the headcount above and this pixel. Click “No thanks” and the script is never fetched, no _fbp cookie is set, and Meta is never told you were here. Same opt-out as above: clear cookies for icebreakerapp.is, or run localStorage.removeItem('icebreaker-consent').

The app itself contains no Meta SDK and no advertising tracker of any kind.

The website itself (hosting, listings, booking)

icebreakerapp.is is hosted by Netlify, which receives your IP address with every page request and uses Netlify's performance measurement (RUM) to record how fast pages load. The site's fonts are served from icebreakerapp.is itself, not from Google Fonts. The home page's opening animation loads its player from cdnjs, so cdnjs also sees your IP address.

The listings on the site (places, events, fun facts, phrases, road signs and the rest) are read by your browser straight from our Supabase database, using its public, publishable key. So Supabase sees your IP address and browser type when you open those pages, as it does for the app. Nothing you do on the site is written to that database.

Some pages load data from elsewhere, and each of those services sees your IP address too: the aurora and road-condition pages ask our own API server on Fly.io; the fuel prices page reads the Gasvaktin price feed from GitHub; and event and venue photos load from wherever they are stored, which is our Supabase storage or the server of the site they were listed on, such as the venue, the organiser or the ticket seller.

The Book buttons open a booking sheet on the page. It asks TourDesk for the tour, its dates and its prices through our API server, and sends the booking details (the tour, time slot, number of guests and pickup) the same way; the tour's photos load straight from TourDesk's servers. Your browser then moves to TourDesk's own checkout page, where you enter your name, email and card details. Those go to TourDesk and its payment provider, never to us.

QR code scans, counted on our server

Our printed QR codes point at short addresses on icebreakerapp.is (/s, /p, /f and /g). When you scan one, our API server counts the scan and sends you on to the download page. Older codes that point straight at the front page are counted the same way, once per browser tab, when the page opens. Each count holds the code (or, for the older codes, the campaign tags), the time, and whether the phone is an iPhone, an Android or something else, read from the browser's user agent. No IP address, cookie or ID is stored with it, so a count cannot be traced to a person, and it works whether or not you answer the consent banner.

3 · What we don't collect

  • Your identity. No name, email address, phone number, password, sign-in or social login. The only account is the anonymous one described in §2, which isn't tied to who you are.
  • Your payment details. The app doesn't take payments itself. When you book a tour or activity, the app sends the booking details (the tour, time slot, number of guests and pickup place) through our booking function to TourDesk, and TourDesk's own secure checkout page opens inside the app. Your name, email and card details are entered there and go to TourDesk and its payment provider, never to us. On icebreakerapp.is it works the same way, through our API server, and the checkout opens in your browser.
  • Advertising IDs, in the app. We do not read your IDFA / GAID, and the app contains no advertising SDK. We never sell data to data brokers. The website is the exception, and we would rather flag it than bury it: icebreakerapp.is loads the Meta Pixel if you opt in on the consent banner (see §2). That is the one place where advertising data leaves us.
  • Session recordings, form input, or content of your typing for analytics. PostHog session replay is disabled. The only typing that leaves your device is what you send to Hulli or the trip planner, and only to produce the answer.
  • Children's data. Icebreaker is not designed for users under 13. We don't knowingly collect data from anyone we have reason to believe is a child.

4 · Who we share data with

We do not sell your data. The only third parties that ever see any of it:

  • Anthropic (Claude): receives your chat messages to Hulli and your trip planner requests, as described in §2, and returns the reply. Processed under Anthropic's commercial API terms, which do not allow Anthropic to train its models on that data. Governed by Anthropic's Privacy Policy.
  • Supabase: hosts our venue database, the anonymous accounts, the usage counters and the functions that run Hulli, the trip planner and in-app bookings, so those requests pass through Supabase's infrastructure. The website reads its listings from the same database, so Supabase also sees website visitors' IP addresses. Operates as a data processor on our behalf.
  • TourDesk: when you book a tour or activity, the booking details (tour, time slot, guests, pickup) go to TourDesk, from the app through our booking function and from icebreakerapp.is through our API server, along with the details you enter at checkout. The app also asks TourDesk which tours are available on the days of your plan. TourDesk handles the payment under its own privacy policy.
  • Mapbox: draws the map. Mapbox receives your IP address, device data and the map area you are looking at, and, if you have granted location permission, location telemetry.
  • Google (Firebase Cloud Messaging): if you allow notifications, your device is registered with Google's Firebase Cloud Messaging so we can send them. Google receives a push token for your device, your device model, operating system version and IP address. Your device is subscribed to a notification topic, and we keep no list of devices or tokens ourselves. No name or contact details are attached. Governed by Google's Privacy Policy.
  • OneSignal (older versions of the app): if you allowed notifications in an earlier version, a push token for your device was registered with OneSignal, which also received your device model, language, timezone and IP address. We still send some notifications to older Android versions through OneSignal and plan to close that account in 2027. So that your notifications keep working, the push tokens of iOS users who had allowed them were copied from OneSignal to Google's Firebase Cloud Messaging; you don't need to do anything.
  • Apple and Google: if you install Icebreaker through the App Store or Google Play. On Android the app also uses Google Play Services for location. Their handling is governed by their respective privacy policies.
  • Google (Tag Manager and Analytics): every page on icebreakerapp.is loads Google Tag Manager, so Google sees your IP address. If you have opted in via the consent banner, GA4 also receives the anonymous pageview + UTM data described in §2. Governed by Google's Privacy Policy. The app never sends anything to Google Analytics.
  • Meta (Facebook / Instagram): when you browse icebreakerapp.is and have opted in on the consent banner, the Meta Pixel sends the pageview described in §2, together with your IP address and user-agent. Meta may match this to your Facebook or Instagram account and use it to target ads. Governed by Meta's Privacy Policy. The app never loads the pixel.
  • Fly.io: hosts our API server in the EU region. The website calls it too, for the aurora forecast, the road conditions, the booking sheet and the QR scan counts described in §2. Operates as a data processor on our behalf.
  • PostHog: receives the anonymous product analytics described in §2, from the app always and from the website once you consent. Neither is linked to your name, email or account. Hosted in PostHog Cloud's EU region. Their handling is governed by their Privacy Policy.
  • Netlify and cdnjs: Netlify hosts icebreakerapp.is and measures page-load performance (RUM); cdnjs serves a script on the home page. Both see your IP address.
  • GitHub and image hosts, on the website: the fuel prices page reads the Gasvaktin feed from GitHub, and some event and venue photos load from the venue's, organiser's or ticket seller's own servers. Each sees your IP address and nothing else from us.
  • Weather, currency and aurora data: the app asks Open-Meteo for weather, sending the coordinates it needs weather for, and Frankfurter for currency rates. Both requests go straight from your device, so these services also see your IP address. Aurora data comes from NOAA through our own API server, so NOAA never sees you.

5 · How long we keep things

  • Anonymous accounts: deleted automatically after 30 days without use, together with their sessions (including the IP address and device type recorded with them).
  • Usage counters (anonymous account or chat ID, hashed IP): hourly counters expire at the end of the hour and daily ones at the end of the day (UTC); expired counters are deleted.
  • Chat history and saved plans: only on your device, until you clear or delete them, or delete the app.
  • Chat and trip planner requests: we keep no copy. Anthropic's own retention is governed by its API terms.
  • Supabase request, function and sign-in logs: kept by Supabase for at most 7 days, then deleted.
  • Notifications: Google keeps the push token for your device for as long as it is in use; it stops when you uninstall the app or turn notifications off, and we keep no copy. OneSignal keeps the data described in §4 until we close our account there.
  • Rate-limit / abuse counters on our API server: in-memory. Rate-limit window resets each hour; abuse cooldown lasts up to 30 minutes. Everything is lost on server restart and is never written to disk.
  • API server access logs: a request id, method, request path and status code. No IP address, message bodies or coordinates. Retained at most 7 days, then deleted.
  • QR scan counts: the code or campaign tags, the time and the phone type, kept for as long as we use the counts. Nothing in them points to a person.

6 · Where data is processed

Our API server runs in Fly.io's Amsterdam region (EU). PostHog analytics events stay in PostHog Cloud's EU region. Our venue database, the anonymous accounts, the usage counters and the chat, trip planner and booking functions run on Supabase in Ireland. Chat messages and trip planner requests are processed by Anthropic on its own infrastructure, which is primarily in the United States, and push notifications are delivered through Google's Firebase Cloud Messaging, which runs on Google's global infrastructure. Where data leaves the EU / EEA, it is protected by the safeguards in the provider's data processing terms, such as the EU Standard Contractual Clauses.

7 · Why we're allowed to use it (legal bases)

  • Your consent: sending your chat messages to Anthropic, notifications, location, and analytics and advertising cookies on the website. You can withdraw it at any time: stop using Hulli, turn off notifications or location in your phone's settings, or clear the consent on the website as described in §2. Withdrawing doesn't affect what was already done.
  • Providing the service you ask for: showing places, weather and maps, building your plan with Anthropic's Claude, and handling a booking you start.
  • Our legitimate interests: the anonymous account, usage limits and hashed IP addresses, to keep the service secure and stop abuse and runaway costs; server logs, to keep things running; and anonymous in-app analytics, to learn which features are useful. We keep these to the minimum described above, and you can object (see §8).

8 · Your rights under GDPR

Because Icebreaker is built by an Icelandic company and EU / EEA visitors use the app, the GDPR applies to us regardless of where you live. Your rights:

  • Right of access: ask what we hold about you. (In almost every case the honest answer is "nothing tied to your identity".)
  • Right to erasure: ask us to delete whatever we do hold. The quickest route is on your own device: “Clear chat”, delete your saved plans, or delete the app. The anonymous account is then deleted automatically after 30 days.
  • Right to object to processing based on our legitimate interests.
  • Right to withdraw consent at any time, as described in §7.
  • Right to data portability, where it applies.
  • Right to lodge a complaint with the Icelandic Data Protection Authority, Persónuvernd, or with the supervisory authority of your own EU / EEA country.

Because we don't know who you are, we may not be able to find your data from a request alone. If you want us to act on a specific anonymous account or chat ID, tell us and we'll explain how to find it. To exercise any of these rights, email hello@icebreakerapp.is. We respond within 30 days.

9 · Children's privacy

Icebreaker is intended for adults visiting Iceland and is not directed to children under 13. We do not knowingly collect personal information from children. If you are a parent or guardian and you believe your child has provided us with personal information, contact us and we'll address it.

10 · Security

Our API server and our Supabase functions are served exclusively over HTTPS. Standard transport security applies to every request your device makes to us and to the weather and currency APIs. The anonymous account's session is kept in your device's secure storage. No system is perfectly secure, but the absence of named accounts and payment data, and the fact that your chat history and plans live only on your device, means there is very little to leak in the first place.

11 · Changes to this policy

When something material changes, we update this page and bump the "Last updated" date at the top. If a change meaningfully expands what we collect, we'll surface a notice in the app the next time you open it.

12 · Contact

Icebreaker ehf.
Reykjavík, Iceland
hello@icebreakerapp.is

← Back to Icebreaker