Privacy Policy
Tripwise is a free trip planner. It is built local-first: your trips live on your own device unless you choose to sign in. This page explains, in plain language, exactly what data is involved and where it goes.
The short version
- No account is needed. Signed out, your trips are stored only in your browser, on your device.
- If you sign in (optional), your trips are backed up to your own private cloud record, and your name and email are used so sharing works.
- We show no ads and never sell your data. The app is funded by clearly marked affiliate links (hotels, tours, cars).
- You can delete everything — your cloud data with the in-app "Delete account" button, your device data with "Reset app". How to delete your account →
Deleting your account and your data
This applies to Tripwise — listed on Google Play as Tripwise: Europe Trip Planner.
How to delete your account
- Open Tripwise and tap ☰ (top right) to open Settings.
- Open the Account section.
- Tap Delete account and confirm.
Prefer not to use the app? Email info@tripwisecy.com from the address your account uses and we will delete it for you within 30 days.
Deleted straight away:
- Your private cloud trip record — every trip, itinerary, booking, budget and packing state held in the cloud.
- Your profile entry — the name and email address other travellers see when you share a trip with them.
- Any shared copies of trips you published, so people you invited immediately lose access.
- Your sign-in record with our authentication provider (Google Firebase). The account itself ceases to exist.
Kept, and for how long:
- Trips saved on your own devices. Deleting your account does not erase them, because they never left the device — they are yours to keep. Remove them with Settings → Reset app, or by clearing the browser’s data.
- Aggregate usage analytics already collected (for example, that an itinerary was generated). These are retained on Google’s standard Firebase schedule — currently 14 months — and after deletion are no longer connected to your name or email.
- Invitation emails already sent stay in the recipient’s inbox, and anyone you shared a trip with may still have their own copy on their device. We cannot reach either.
If anything else of yours remains — for example an expense a co‑traveller added to a trip you had shared — email info@tripwisecy.com and we will remove it.
Deleting only some of your data, without closing your account: delete any single trip in the app (My Trips → Delete) and it is removed from the cloud too, on every device. You can also remove individual expenses, travellers and bookings, or stop sharing a trip at any time, which deletes the shared copy.
What stays on your device
Trips, itineraries, packing-list ticks, language and theme choices are saved in your browser’s local storage on your device. Signed out, none of this leaves your device, and we cannot see it. Clearing your browser data — or the app’s Reset app button in Settings — removes it.
If you create an account (optional)
You can sign in with Google or with an email link. Accounts use Google’s Firebase service (data stored in Firebase’s EU region). When you sign in we store:
- Your name, email address and profile picture as provided by Google (or just your email, for email-link sign-in).
- Your trips, in a private cloud record only your account can read, so they sync across your devices.
- A small profile entry (name + email) so that when you share a trip, the people you invite see who it’s from — and vice versa.
Sharing: if you share a trip, the people you invite (by email) can see that trip’s contents read-only, and co-viewers of the same trip can see each other’s invited email addresses — the app tells you this in the share dialog. Inviting someone sends them one invitation email through our email provider (Resend); their address is used for that delivery and for access control, nothing else.
Deleting your account (Settings → Account → Delete account) removes your cloud trips, your profile entry and your sign-in record. Trips already on your devices stay on those devices.
Usage analytics
We use Google Analytics for Firebase to understand, in aggregate, how the app is used — for example how often itineraries are generated or an outbound link is clicked. This involves standard device identifiers and approximate (IP-based) location handled by Google. We use it only to improve the app. The app also uses Google’s reCAPTCHA (App Check) to protect our backend from abuse.
Services the app talks to
To do its job, the app fetches data directly from these services. Like any web request, each one sees your IP address and the specific thing requested (for example, map tiles for the area you’re viewing or the address you searched):
- OpenStreetMap — map tiles; Photon (Komoot) and Nominatim — address search; Overpass — metro station locations.
- Open-Meteo — weather forecasts for your trip dates and hotel/city area.
- Wikipedia — descriptions of sights you tap on.
- Frankfurter / open.er-api.com — currency exchange rates for the budget feature.
- Google Fonts and cdnjs — fonts and the map library.
None of these receive your name, email or trip contents.
Hosting
This website and the app are hosted on Cloudflare, which delivers every page and keeps cached copies of them on servers around the world so the app loads quickly wherever you are. Because Cloudflare sits in front of the site, it necessarily sees every request made to it — your IP address, the page or file you asked for, your browser and device type, and the time — and uses that to serve the page, to keep the site online and to protect it from attacks and abuse. As part of that protection, Cloudflare also runs a small script on every page load that checks in the background whether the visitor is a real browser or an automated bot. It is invisible, asks nothing of you, runs once per page load, and stores no cookies or other data on your device; it reads only technical characteristics of your browser. It is a security measure, not advertising or profiling — Tripwise never sees its result — and it is built into our hosting plan rather than something we switch on per visitor.
Cloudflare does not receive the trips you create: those stay on your device, and if you sign in they sync to Google Firebase, not to Cloudflare. The one exception is inviting someone to a trip — that invitation passes through a small Cloudflare service of ours on its way to our email provider (Resend), so it sees the address you invited, your display name, and the trip’s name and dates, purely to send that one email.
Affiliate links
Some buttons — hotels, car hire, airport taxis (Booking.com via Commission Junction) and tickets & tours (GetYourGuide, Viator) — are affiliate links, marked as such. If you tap one, you go to that company’s own site, where their privacy policy applies and they may set their own cookies. Tripwise may earn a small commission at no extra cost to you; that is the app’s only source of income. We record that an outbound click happened (in analytics), but not what you do on their site.
Your rights
If you’re in the EU/EEA (Tripwise operates from Cyprus), you have the usual GDPR rights over personal data we hold about you: access, correction, deletion, portability and objection. Most of these you can exercise yourself in the app (Delete account, Reset app); for anything else, email info@tripwisecy.com and we’ll help. You also have the right to complain to your data protection authority — in Cyprus, the Commissioner for Personal Data Protection.
Retention & security
Cloud trips and profile data are kept until you delete them or your account. Analytics data is retained per Google’s standard Firebase retention (currently 14 months). All connections use HTTPS, and cloud access is restricted by per-user security rules — your trips are readable only by your account and the people you explicitly invite.
Children
Tripwise is not directed at children under 16 and we don’t knowingly collect their data.
Changes
If this policy changes, we’ll update this page and its effective date. Significant changes will be noted in the app.