1. Who we are
Trippy is developed and published by Jon Trygve Hegnar, an independent developer based in Norway ("we", "us"). We are the data controller for the processing described in this policy.
Contact: hello@trytrippy.app
2. What Trippy does
Trippy lets you save places people recommend to you, organise them by city, and plan trips day by day. You can also share a trip with the people going, so everyone can add places to the program together — or share the places you've saved in a city as a view-only list your friends can browse. Everything you create in the app is yours and stays under your control.
3. Data we collect — and where it lives
3.1 Content you create in the app
Saved places, notes, tags, trips, days, stops and reservation details are stored locally on your device and, if you have iCloud enabled, synced through your private iCloud database (Apple CloudKit). This data is tied to your Apple Account and protected by Apple; we cannot access, read or retrieve it. Apple's processing is governed by the Apple Privacy Policy. If you never share anything, this is the only place your content ever lives.
3.2 Place search
When you search for a place, your search text is sent through our lightweight relay server (a Cloudflare Worker) to the Google Places API, which returns search results, place details, opening hours and photos. In processing these requests:
- Your search text and your device's IP address are processed transiently to deliver the request and to apply rate limiting that protects the service from abuse.
- We do not log search queries against any user identity.
- Non-personal place details (keyed by Google's place ID, not by you) may be cached on the relay for up to 24 hours to reduce repeated lookups.
- Google processes these requests under the Google Privacy Policy. Cloudflare, which hosts the relay, processes traffic under the Cloudflare Privacy Policy.
3.3 Location
If you grant location permission, Trippy uses your device's location on the device only — to show your position on the map. Your location is never sent to our servers and never stored. Maps are displayed with Apple Maps (MapKit), and map tiles are fetched by Apple as part of that service. You can revoke location access at any time in iOS Settings, and the app remains fully usable without it.
3.4 Photos of places
Photos of places (from Google Places) are cached on your device for up to 7 days to reduce data usage. They are pictures of public places, not personal photos, and Trippy does not access your photo library.
3.5 Shared trips (optional — requires an account)
Sharing requires an account — whether it's a trip or a city list (§3.6). When you share or join a trip:
- Account: you sign in with Sign in with Apple. We store your account identifier and your display name (taken from your Apple Account, editable in the app). We do not ask Apple for your email address, so no email — not even a private relay address — is ever collected or stored.
- Trip content on our server: for shared trips only, we store the trip name, dates and destination city (name, country and map coordinates), its membership, and the program — Google place IDs, notes, days, times, reservations and ordering, and who added or edited each stop. We do not store Google's place details (names, photos, addresses) on our server; each member's app fetches those fresh from Google.
- Who can see it: the members of that trip. The trip owner decides who is invited. Anyone with a trip's invite link can see light details (trip name, owner's display name, dates, number of members and places) and join the trip — so treat invite links like invitations.
- Where it lives: our backend is hosted by Supabase on servers in the EU, with access controlled per trip at the database level.
- Reports and blocking: if you report or block another user, we store that report (who reported whom, and the reason you give) so we can act on it.
- Your library stays private: sharing a trip shares that trip only. Your saved places, other trips and notes remain on your device and in your private iCloud, as in §3.1.
3.6 Shared city lists (optional — requires an account)
You can share the places you've saved in one city as a view-only list: friends with the link can see it, but never change it. When you share a city:
- What's on our server: the city's name as you wrote it, and for each place its Google place ID, the category you chose, when you saved it, and whether you've hidden it from the list. We do not store Google's place details (names, photos, addresses); each viewer's app fetches those fresh from Google.
- Your notes are off by default: place notes are uploaded only while the list's "Include my notes" switch is on. Switch it off and your notes are deleted from the server immediately — not just hidden. Cities you never share never have notes on any server.
- The list is live: the people you've shared with see it as it is right now — new places appear, deleted and hidden ones disappear.
- Who can see it: people who open your link and accept, signed in with their name. You can see who they are, remove any of them, get a new link, or stop sharing — anytime. Anyone with the link can see light details (your display name, the city name and the number of places), so treat links like invitations.
- Saved copies: when a friend saves one of your places into their own collection, that copy becomes theirs, on their device — it is no longer connected to your list.
- Stopping: stop sharing a city and the list, its members and its data are deleted from our server.
4. What we do NOT collect
- No account is required to use the app — only to share (a trip or a city list) or to open something shared with you, and never a password (Sign in with Apple only)
- No third-party analytics or advertising SDKs
- No tracking across apps or websites, and no advertising identifiers
- No contacts, photos, health data or any other data from other apps
- No sale, rental or sharing of personal data with third parties for their own purposes
5. Summary table
| Data | Where it goes | Purpose | Retention |
|---|---|---|---|
| Places, notes, trips (not shared) | Your device + your private iCloud | The app's core function | Until you delete it |
| Search text | Relay → Google Places API | Return search results | Transient; not logged per user |
| IP address | Relay (Cloudflare) | Deliver requests, rate limiting | Transient |
| Device location | Stays on your device | Map view | Never stored |
| Account (ID and display name — no email) | Our server (Supabase, EU) | Shared trips and city lists | Until you delete your account |
| Shared trip program | Our server (Supabase, EU) | Let trip members plan together | Until the trip is deleted, or you leave it / delete your account |
| Shared city list (city name, place IDs, your categories; notes only while the switch is on) | Our server (Supabase, EU) | Let friends see your list | Until you stop sharing, hide the place, or delete your account |
| Reports | Our server (Supabase, EU) | Handle abuse reports | As long as needed to act on them |
6. Legal basis (GDPR)
For users in the EU/EEA, the legal basis for the processing described above is the performance of a contract (Art. 6(1)(b) GDPR — providing the app's functionality you request, including shared trips and city lists when you choose to use them) and our legitimate interest in keeping the service secure, preventing abuse and handling reports (Art. 6(1)(f) GDPR). Location is processed only with your consent via the iOS permission prompt (Art. 6(1)(a)), which you can withdraw at any time in Settings.
7. Deleting your data
- In the app: delete any place, trip or note at any time.
- Shared trips: leave a trip at any time — it disappears from your account. If you own a trip, deleting it removes it for all members. Stops you added to a trip you leave remain part of that trip.
- Shared city lists: stop sharing a city and it is deleted from our server for everyone. Turn the notes switch off and your notes are deleted from the server right away. If someone shares with you, you can remove their list from your Friends tab at any time.
- Your account: delete it in the app at any time. This removes your profile, your memberships, the shared trips and the city lists you own from our server. Your local library and iCloud data are untouched.
- Everything local: delete the app, and remove Trippy's iCloud data under iOS Settings → your name → iCloud → Manage Account Storage.
8. Your rights
Under the GDPR and Norwegian law, you have the right to access, correct, delete and export your personal data, to object to or restrict processing, and to withdraw consent. Most of these rights you exercise directly in the app, as described above. For anything else — including questions about data on our server — contact us at hello@trytrippy.app. You also have the right to lodge a complaint with your supervisory authority — in Norway, Datatilsynet (datatilsynet.no).
9. Children
Trippy is not directed at children under 13, and we do not knowingly collect personal data from children.
10. Security
Your content is protected by your device's security and by Apple's iCloud security (encryption in transit and at rest). Shared trip data is stored with Supabase with encryption in transit and at rest, and database-level access rules ensure only a trip's members can read or change it. Traffic between the app, our relay, our backend and Google is encrypted with HTTPS.
11. Changes to this policy
If we change this policy, we will post the updated version on this page with a new effective date. Material changes will be highlighted in the app's release notes.