tripview Privacy Policy
Updated August 13, 2026
This policy explains how tripview handles journey, ticket, account, location, and diagnostic data.
1. On-device data
Saved journeys, seats, gates, tickets, footprints, and preferences remain on your device by default. Camera and photo access are used only when you start an import. You can export a backup or delete local data in Settings.
2. Recognition and optional AI
Apple Vision processes tickets on device first. AI assistance is off by default. Only after your explicit consent, and when local results are incomplete, may a compressed ticket image, OCR text, and necessary context pass through tripview's Cloudflare Worker to the configured third-party model provider. tripview does not retain ticket images or OCR text on its server; provider processing is subject to that provider's terms and privacy policy.
3. Accounts
Accounts are optional. Email, Apple, or Google sign-in processes your email address, provider identifier, optional name, device sessions, and security timestamps for authentication, account safety, and deletion requests. Signing in does not automatically upload local journeys. You can permanently delete your account in the app.
4. Live transport data
To request flight numbers, times, terminals, gates, status, or baggage belts, tripview may send flight number, route, service date, and request time to the tripview Worker and configured transport data providers. Names, document numbers, booking numbers, and seats are not sent with these requests.
5. Location
When you ask for nearby airports or stations, the app requests When In Use location access. The coordinate is used on device to suggest a place, country, and time zone; tripview does not upload precise coordinates to its own server. Apple map services may process searches under Apple's policy.
6. Diagnostics and metrics
Recognition diagnostics stay on device by default and can be cleared or exported in redacted form. The server may retain event type, response status, latency, provider, and time for reliability and abuse prevention, without ticket text, routes, email addresses, or user identifiers.
7. Providers and security
Infrastructure and optional features may use Apple, Google, Cloudflare, Resend, ModelBox, AeroDataBox, or Amadeus. We share only what is needed for the requested feature and use encrypted transport, isolated secrets, access controls, and rate limits.
8. Retention, deletion, and children
Local data remains until you clear it or remove the app. Account data remains until account deletion, subject to limited legal and security retention. tripview is not directed to children under 13 and does not knowingly collect their personal information.
9. Changes
We update this policy and its date when features or processing change and will provide reasonable notice of material changes.