Legal information

Privacy Policy

Last updated: March 31, 2026

This page explains what data the TripVaria mobile app collects, why we use it, who may receive it and what choices you have. The text reflects the active flows currently implemented in the app and backend API.

1. Scope

This policy applies to the TripVaria mobile app and the related backend services used for authentication, trip planning, place discovery, community content, subscriptions and AI-powered features.

It covers the data processed when you use the app, create an account, save content, purchase premium access or contact us for support.

2. Data we may collect

  • Account and authentication data: Firebase UID, display name, email address, profile photo and the sign-in provider you choose, such as Google, Apple, email/password or anonymous session.
  • Profile data: display name, bio, phone number, home city, interests, user role, subscription plan, trial status, referral status, badges and relevant progress data used in the app experience.
  • Trip and usage data: origin, destination, intermediate stops, search filters, favorites, history, saved itineraries, collections, journals and packing lists.
  • Location data: precise or approximate device location only when you grant the required permission and use current-location or route-based features.
  • User-generated content: reviews, ratings, photos uploaded with reviews, pro tips, questions, answers, content reports and business or explorer contributions.
  • Commercial and subscription data: purchased product, active plan, entitlement dates, store transaction or purchase identifiers, referral redemption status and trial status.
  • AI feature inputs when you choose to use them: selected places, route details, weather context, locale, prompts and generated outputs for itinerary, journal and packing flows.
  • Minimum technical data required to operate the service: authentication tokens, request metadata and information needed for security, debugging and abuse prevention.

3. How we use data

  • To create and manage your account and authenticate you securely.
  • To sync your profile, favorites, history, itineraries, journals, collections and other preferences across sessions and devices.
  • To calculate routes, search places, display maps, photos, place details and weather relevant to your trip.
  • To process community and business features, including reviews, uploaded images, questions, answers, moderation and place claims.
  • To activate subscriptions, trials, premium entitlements and validate in-app purchases handled through Google Play or the App Store.
  • To generate AI outputs only when you explicitly invoke an AI feature in the app.
  • To protect the service, prevent fraud, enforce community rules, resolve incidents and improve reliability.

4. What may become public

Some information may become visible to other users when you choose to publish it. Examples include public itineraries, reviews, ratings, review photos, pro tips, questions, answers and business or explorer submissions.

Favorites, history, extended profile data, private journals and packing lists are treated as private by default unless you explicitly publish or share a specific item.

5. Who may receive data

We do not sell your personal data to data brokers.

  • Identity and sign-in providers such as Firebase Authentication, Google Sign-In and Sign in with Apple.
  • Map and place providers such as Google Maps, Google Places, geocoding and routing services when you use search, maps or place details.
  • Weather providers when we request weather data for a selected place or route.
  • AI providers used through our backend when you use AI itinerary, AI journal or AI packing features.
  • App stores and payment infrastructure for in-app purchase processing and validation. We do not store full payment card details.
  • Hosting, media storage and technical infrastructure providers used to run the API and serve user-uploaded content.
  • Authorities or relevant third parties when we are legally required to do so or when it is necessary to protect rights, safety and service integrity.

6. Legal bases and controls

  • Performance of the service you request: authentication, profile sync, routing, favorites, history, itineraries, journals and saved content.
  • Your consent: location access, photo uploads, optional profile fields and AI features or public content that you choose to submit.
  • Legitimate interests: security, abuse prevention, moderation, operational stability and protection of our rights.
  • Legal obligations: retaining certain records needed for compliance, accounting, dispute resolution or valid legal requests.

7. Retention

We keep personal data for as long as your account remains active or as long as needed to provide the services you request. You can delete certain items directly in the app, and you can request full account deletion from the dedicated flow in Profile.

When you request account deletion, we aim to delete or anonymize account-linked data, except where retention is required for legal obligations, security, fraud prevention or dispute handling.

8. Your rights and choices

  • You can access and update certain profile data directly in the app.
  • You can revoke location permission from your device settings.
  • You can edit or delete certain content that you create where the feature provides those controls.
  • You can request account deletion from Profile > Delete Account.
  • You can contact support@tripvaria.com for privacy questions, rectification requests or help exercising your rights.

9. Security and transfers

We use reasonable technical and organizational measures to protect data against unauthorized access, loss or misuse. No transmission or storage method is completely guaranteed, but we actively work to reduce security and operational risk.

Some service providers may process data outside your country of residence. When this happens, the processing is performed through the infrastructure and contractual terms of the providers used to operate the service.

10. Policy changes

We may update this policy when features, providers or data flows change. We will update the date shown at the top of this page and should publish the same updated version on the official TripVaria website.