1. Introduction
PlanToTrip (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains what information the PlanToTrip iOS application (the “App”) collects, how that information is used, and what choices you have. By using the App, you agree to the practices described in this policy.
2. Information We Collect
Trip content you create or import:
- Trip titles, dates, and itineraries
- Stages, tasks, and schedules
- Bookings (flights, hotels, transfers, rentals) — including dates, prices, confirmation numbers, addresses
- Routes and points of interest
- Activities (with addresses and times)
- Documents you scan or attach (passports, tickets, vouchers, reservations)
- Personal documents you add about yourself and travel companions (citizenship, document type and number, names)
- Free-form chat messages you send to the AI
Onboarding information:
- Country and city of residence (to localize defaults and suggestions)
- Display name (optional; shown to people you invite to a shared trip — see Section 5b)
- Preferred app language
Device and permission-gated data:
- Apple Calendar events (read-only; see Section 6)
- Photos or PDFs you explicitly select to scan as a document or attach to a booking
- Notification permissions (to deliver scheduling reminders)
Automatically collected information:
- Device type and iOS version
- App version
- Crash logs and aggregated performance data
- Subscription state (active / inactive) via Apple’s App Store
- Product-analytics events — which screens you view and actions you take (for example: trip created, plan generated, paywall viewed), recorded as metadata only. We never attach trip content (destinations, names, chat text, booking details) to these events. Events are associated with an anonymous app-generated identifier, not your name or email.
We do NOT collect:
- Your email address, phone number, or contacts (unless you email us)
- Background or real-time location
- Health, financial, or biometric data
- Advertising identifiers (IDFA) — the App contains no ad SDKs and performs no cross-app or cross-site tracking
3. How We Use Your Information
We use the information described above to:
- Generate personalized trip plans, day-by-day schedules, and AI suggestions
- Extract structured fields (dates, addresses, prices) from documents you scan
- Schedule tasks around your existing calendar events
- Deliver local and push notifications for upcoming or rescheduled tasks
- Process your in-app purchase through Apple’s App Store
- Diagnose crashes and improve App performance
- Understand aggregate product usage (which features are used, where users drop off) to improve the App
4. Data Storage
- Trip content, bookings, documents, personal documents, and preferences are stored locally on your device using Apple’s SwiftData framework. The App does not sync via iCloud at this time.
- Exception — trips you choose to share with other people. If (and only if) you invite someone to collaborate on a trip (see Section 5), a copy of that trip is stored on our servers so both of you can sync it. That copy is encrypted at rest under envelope encryption: the trip document is encrypted with AES-256-GCM using a per-write data key, and that key is itself wrapped by a master key held in Google Cloud KMS. A trip you never share is never uploaded.
- Attached and scanned files (images, PDFs) are transmitted to our backend over TLS solely for real-time AI recognition. The file itself is never stored on our servers — recognition happens in memory during the request, and both the original file and the extracted fields are saved only on your device, protected by iOS file encryption.
- AI planning requests, scan-document requests, and chat messages are transmitted over TLS-encrypted HTTPS to our backend hosted on Google Cloud Platform (US region).
- The text of an AI planning or chat request is processed in real time to produce the response and is not retained beyond the duration of the request, except where the message itself is part of a trip’s chat history that you choose to keep.
- We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Sharing a Trip
The App offers two separate, independent ways to share a trip. Neither happens unless you start it.
5a. Public share links (read-only web page)
The App lets you publish a trip as a read-only web page (“share link”) that anyone holding the link can view.
- What is published: trip title, dates, destination, stages, day-by-day items, activity and route-stop names with public photos, task/booking statuses, and — if you enable “Include bookings” — booking routes, times, flight numbers and hotel names/addresses.
- What is never published: booking references (PNRs), prices, passenger names, seat/baggage details, scanned documents, and document photos. These are excluded structurally on the device and rejected by the server schema.
- Links use unguessable 128-bit tokens, are excluded from search-engine indexing, and can be set to expire automatically.
- You can update the published content or revoke a link at any time in the App (Share → Stop sharing); revocation is immediate and permanent for that link.
- Treat a share link like any private URL: anyone you forward it to can view the page and forward it further.
5b. In-app collaboration (inviting people to a trip)
You can invite other PlanToTrip users to a trip so you can plan it together. This is the only case in which trip content is stored on our servers (see Section 4).
- How invites work: you create an invite link (optionally shown as a QR code) and send it to whoever you choose. Holding the link is what grants access — treat it like a password. Invite links expire after 7 days, and you can remove any member at any time.
- What members can see: the trip itself — title, dates, destination, stages, tasks, activities, routes, and the free-text notes you write on those items. Bookings are shared only as route, times, flight number and hotel name/address.
- What is never shared with members: booking references (PNRs), ticket prices, passenger names, seat and baggage details, check-in and room information, scanned documents, document photos, and any personal documents such as passports. These stay on the device of whoever added the booking. The exclusion is structural — the fields are not part of the sync document at all, and our servers reject any attempt to send them.
- Your display name — the name you set in the App — is shown to the people you invite so they can tell who shared the trip and who changed what. We do not ask for, or share, your email address.
- Members’ own documents stay private: anything an invited member scans or attaches themselves is stored only on their device and is never synced to you.
- Leaving and removing: the trip owner can remove a member or stop sharing entirely; a member can leave. In every case access ends immediately, and the App removes the shared trip from that person’s device the next time it runs. Two honest limits: the removal is done by the App, so it only happens once that person’s App next connects — an app left offline, or an older version, may hold the copy longer — and anything they already saw, they may have kept by other means. Treat inviting someone as giving them a copy.
- Encryption: the shared trip is encrypted at rest as described in Section 4 and travels over TLS.
6. Apple Calendar Access
If you grant calendar permission, the App reads events from your selected Apple Calendars solely to detect scheduling conflicts and place tasks in free time. The App never adds, edits, or deletes calendar events. You can revoke access at any time in iOS Settings → Privacy & Security → Calendars.
7. Third-Party Services
- Apple App Store / StoreKit — payment processing and subscription state.
- Apple EventKit — calendar event read access (with your permission).
- Google Cloud Platform (Cloud Run, Cloud Tasks, Firestore, Cloud Storage, Cloud KMS) — backend hosting, file storage, and the key-management service that holds the master key protecting shared trips (see Sections 4 and 5b), all in the United States.
- Google Vertex AI (Gemini) — the AI models used to generate trip plans, route suggestions, chat responses, and document text extraction. Processing happens inside our own Google Cloud project under Google Cloud’s data-processing terms: only the content of your prompt and the structured trip context required to answer it are sent, and your data is never used to train AI models.
- Google Places API — address autocomplete when you add a route point or activity. Lookups are made server-side; we do not send your device identifier.
- RevenueCat — subscription management. RevenueCat processes your App Store transaction and subscription status to unlock paid features. See https://www.revenuecat.com/privacy.
- Amplitude — first-party product analytics. We send behavioral events (screen and action names plus non-identifying metadata) to understand how the App is used and improve it. No advertising identifier (IDFA) is used, no cross-app tracking is performed, and IP-based geolocation is disabled. Events are tied to an anonymous app-user identifier. See https://amplitude.com/privacy. You can opt out at any time — see Section 9.
The App contains no advertising SDKs.
8. AI Data Processing
When you create or modify a trip, the following data may be sent to our AI services for plan generation, refinement, or chat:
- Trip title, dates, destination, and stage information
- Free-form messages you send in trip chat
- Document fields extracted from scans you submit
- The minimum schedule context needed (existing event times — not titles — when scheduling tasks)
AI processing is performed by Google’s Gemini models via Vertex AI within our own Google Cloud project. Plan, route, and chat responses are generated in real time. Neither we nor Google use your prompts or your trip content to train AI models.
On a trip you share with other people (Section 5b), an AI request made by any member carries that trip’s shared context — the same content every member can already see. The fields excluded from sharing (booking references, ticket prices, passenger names, documents) are not part of that context.
9. Your Rights and Choices
- Access: Your trip data is on your device and visible inside the App. Trips you share with other people also have a server-side copy (Section 5b), which holds the same content you can see in the App.
- Deletion: Delete a trip from the trip list to remove it (this also deletes its server-side attachments). If the trip is shared, use Share → “Stop collaborating” to delete the server-side copy, end everyone’s access, and remove the trip from members’ devices — subject to the limits in Section 5b. Deleting the App removes all local data. To request deletion of any backend-stored data, email us — see Section 13.
- Calendar: Revoke access in iOS Settings → Privacy & Security → Calendars.
- Notifications: Disable in iOS Settings → Notifications → PlanToTrip.
- Photos: Photo picker permission is per-selection — we never receive your full photo library.
- AI: You can use the App without AI by entering trips manually; AI features are opt-in per action.
- Analytics: You can turn off product-analytics collection at any time in Settings → “Share usage data”. When off, no behavioral events are sent.
For California residents (CCPA / CPRA): we do not sell or share personal information. You may request deletion of any backend-stored data by contacting us.
For EU/EEA residents (GDPR): the legal basis for processing trip content and AI requests is the performance of the contract you enter when using the App. The legal basis for crash logs and subscription state is our legitimate interest in keeping the App working and processing your purchase. You may request access, correction, or deletion by contacting us.
10. Children’s Privacy
The App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently received such information, please contact us and we will delete it.
11. Data Retention
- Local data: retained on your device until you delete the trip or the App.
- Attachments on backend storage: retained while the parent trip exists in your App, then eligible for deletion when you delete the trip.
- Shared trips (Section 5b): the encrypted server-side copy is retained while the trip is shared, and is automatically deleted 180 days after the trip’s end date. Deleting the trip or choosing “Stop collaborating” removes it sooner. Invite links expire 7 days after they are created.
- AI / scan / chat requests in transit: not retained beyond the response, except for the chat history you choose to keep.
- Crash logs and aggregated metrics: retained for up to 12 months.
- Voluntarily submitted feedback (email): retained while needed to address your request.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in the App. Material changes will be reflected by updating the “Last updated” date and, where appropriate, by an in-App notice. Continued use of the App after a change indicates your acceptance.
13. Contact Us
For privacy questions or data requests:
Email: [email protected]