OverlandSEA

Rail-first journey planning across Southeast Asia

Privacy

Overland SEA collects nothing about you. Here is what that means in each of the three places the name appears — the Android app, the iPhone app and the website — and where the edges of the claim are.

No accounts · No analytics · No cookies · No network access asked for, on either app

The short version

There is no account to make, no form that submits anywhere, and no server behind the planner to submit to. Where you are going, when, and which passport you carry are worked out on the device you typed them into. We do not know who you are and have not built anything capable of finding out.

The rest of this page is the long version, because "we value your privacy" is what every page says and the only useful form of the claim is the checkable one.

The Android app

It has no internet permission

Not "we choose not to send anything" — the app does not request android.permission.INTERNET, so Android will not let it open a network connection at all, including by accident and including if a future bug tried to. The rail network, the map, the photographs and the routing are all inside the installed package. That is also why it works in flight mode at a border with no signal, which is the point of it.

What it keeps on your phone: whether you chose the light or dark theme, whether you left the search panel folded, and the journey you last planned — the two stations and the trip settings beside them, so that closing the app and opening it again on a train with no signal returns you to what you were looking at rather than to the start. On the website only, it also remembers if you dismissed the strip offering the Android app, so that it does not ask twice.

All of it is written to local storage on the device, none of it is sent anywhere, and it goes when you uninstall the app or clear its data. A journey is two station names and your own routing preferences; it is not a record of where you went, because nothing here knows where you went.

What it does not have: any account or sign-in, your email address, your location, your contacts, an advertising identifier, an analytics library, or a crash-reporting library. Its only dependencies are two of Google's own AndroidX components, WebView and AppCompat. There is no third-party SDK in the build.

When you tap an operator's booking site or "open in maps", the app hands that address to whichever browser or maps app you have and stops being involved. From that moment you are on someone else's site under their policy.

One thing that is not ours to switch off: if you have left Google Play's automatic crash reporting on at the system level, Android may send Google a crash or ANR report for any app on your phone, this one included. We did not build that channel and cannot see into it. What reaches us is the aggregate view in the Play Console — stack traces and device models, with no identity attached to them.

The iPhone and iPad app

Same program, same bundled data, the same handful of settings kept on the device, same absence of accounts, analytics, advertising identifiers and third-party code. What differs is one sentence of the guarantee above, and it differs enough to be worth spelling out rather than quietly reusing.

iOS has no permission to withhold

Android lets an app decline the network outright, and the operating system then enforces it. iOS has no equivalent: an app either has network access or the platform assumes it might. So the promise here is one level down and narrower. The app makes no network calls of its own, and the web view it is built around runs under a WebKit content rule that refuses every load except from the app's own bundle — a tracking pixel or a remote font that somehow got into the page could not fetch, and neither could anything injected into it. That is enforced by WebKit rather than by the kernel. It is a good guarantee and it is not the same guarantee, and you should hold it as the weaker one.

Everything else reads across. Nothing is collected. Tapping an operator's booking site hands the address to Safari and the app stops being involved. And as on Android there is a channel that is not ours: if you have left Apple's analytics sharing on, iOS may send Apple crash reports for any app on the device. What we can see of that is aggregate stack traces in App Store Connect, with no identity attached.

The website

No analytics, no tag manager, no advertising pixel, no consent banner — because there is nothing to consent to. The site sets no cookies of any kind.

It stores the same theme and panel settings the app does, in your browser's local storage, plus a note of whether you dismissed the strip offering the Android app. It does not keep your last journey — the website holds that in the address bar, where your own history and bookmarks already keep it. Clearing site data for slowasia.com removes all of it.

Fonts and photographs are served from slowasia.com itself rather than from Google Fonts or a CDN, so opening a page here does not announce your visit to a third party as a side effect of loading the design.

The route you plan lives in the part of the address after the #. Browsers do not send that fragment to the server, so an itinerary link you share carries the journey and reaches only the person you send it to.

The site is hosted on Vercel, and like any web server its edge records requests as they arrive: IP address, time, the address requested, the browser's user-agent string. That is what serving a page and absorbing abuse requires. We do not build profiles from those logs, do not use them for advertising, and do not combine them with anything else. Vercel handles them as our hosting provider under its own privacy terms.

What you type into the planner

The origin and destination, the departure date, the passport nationality, the pace and the choice of beds are all read by code running on your own device and are used to pick which legs, which visa notes and which prices to show you. None of it is transmitted, because there is no endpoint to transmit it to — the planner is a static document. The passport field in particular exists only to decide which border notes apply to you, and never leaves the device.

Links to other people

Operator booking sites, Seat61 and Google Maps are ordinary links. Your browser tells those sites what it tells every site you visit; we pass them nothing about you.

Two links are affiliate links, marked as such in the page's own markup with rel="sponsored": accommodation search on Booking.com, and travel insurance from SafetyWing. If you follow one, that company can tell the referral came from Overland SEA, and if you go on to buy something they may pay us a commission. We are not told who you are, what you booked or what you paid — a commission report is a number, not a name. Nothing about the itinerary changes if you ignore them, and it costs you nothing either way.

Things we do not do

  • Sell, rent or share personal data. There is none to sell.
  • Build a profile of you, on this site or across others.
  • Show you advertising, or let anyone else show you advertising here.
  • Track you between the app and the website. They do not know about each other.
  • Email you. There is no mailing list and no box to join one.

Children

This is a travel planner, not directed at children. It collects nothing from anybody, which includes collecting nothing from them.

Your rights, and the honest version of them

Data protection law — the GDPR, the UK GDPR, the CCPA and their equivalents — gives you the right to ask what a company holds about you, to have it corrected, and to have it deleted. We hold nothing about you, so there is nothing for such a request to return. That is not a way of declining: it is what "collects nothing" means when you follow it to the end.

What is stored on your device is yours and is removed by uninstalling the app, clearing its data in Android's app settings, or clearing site data for slowasia.com in your browser.

Changes

If either app ever gains the ability to send something — neither has any plans to — this page changes before that release ships, and the date below changes with it. On Android you would also see it: the permission appears at install time. On iOS you would not, which is the practical consequence of the difference described above and another reason to state it here rather than leave it implied. There is no mailing list, so this page is the notice.

Last updated 31 July 2026.

Contact

Questions about any of this, including anything above you would like shown rather than asserted: doug@mukbangshow.ae.