Privacy Policy

Last updated: July 22, 2026

Tripar is an AI trip planner operated by Ahsene Remmouche (“we,” “us”). This policy explains what data the Tripar app and this website collect, how it is used, who processes it, and the controls you have. We collect only what the product needs, we do not run ads or advertising trackers, and we do not sell your personal data.

1. What we collect

Account data. You sign in with Google or Apple. Our authentication provider, Clerk, gives us your name, email address, and profile photo from that account, plus an account identifier we use as your user ID.

Trip data. When you plan a trip we store what you enter — destination, dates, number of travelers, budget level, and interests — and the AI-generated itinerary produced from it. Saved travel preferences (default budget, travelers, interests, pace) are stored with your account.

Assistant chats. Messages you send to the AI assistant, and its replies, are stored so conversations continue across sessions until you clear them.

Photos you upload. If you set a custom trip cover, the app asks for photo-library permission and uploads the image you choose to our image-delivery service (ImageKit). This is the only device permission Tripar requests — we do not access your location, contacts, camera, or microphone.

Usage records. Each AI generation (itinerary or chat message) is recorded with token counts, estimated cost, model name, and outcome. We use these records to enforce the free tier's limits and to understand service costs.

Subscription status. If you subscribe to Tripar Pro, billing runs entirely through the App Store or Google Play — card details never reach us. We receive subscription events from RevenueCat (keyed to your user ID) and store a single yes/no Pro flag.

Diagnostics. The app reports crashes, performance traces, and structured logs to Sentry. These can include your trip destination and internal IDs, and — for AI-quality monitoring — the content of assistant messages. Session replays (screen recordings used to debug crashes) are fully masked: text, images, and graphics are redacted before upload.

On your device only. Your sign-in session token is kept in the device's secure storage, and your appearance (light/dark) and language choices are stored locally. The app sets no advertising identifiers and contains no analytics or ad SDKs.

This website is a static page served by Cloudflare. It sets no cookies and runs no scripts or trackers; Cloudflare may log requests (such as IP addresses) to serve and protect the site.

2. How we use your data

We do not use your data for advertising, we do not profile you for marketing, and we do not sell or share personal data for cross-context behavioral advertising.

3. Services that process your data

4. Security

All traffic uses TLS. Every API request is authenticated with a short-lived signed token verified on the server; your data is only ever returned to your own account. Photo uploads use short-lived signed credentials (30-minute expiry) minted server-side so secret keys never reach the device. Incoming webhooks from our providers are verified before processing. We rely on our providers' security for storage at rest.

5. Retention

Your data is kept while your account exists. Deleting a trip removes it (its chat context and usage records are detached, not deleted). Clearing a chat deletes its messages. Deleting your account removes your account record, trips, chat history, and usage records from our database (see Section 6). Copies held by our providers for backup or logging purposes may persist for a limited period under their retention rules.

6. Your controls

7. Your rights (EU/UK and California)

If you are in the EU or UK, we process your data on these legal bases: performance of our contract with you (providing the planner, assistant, and subscriptions), legitimate interests (service diagnostics, abuse prevention, cost accounting), and consent where required (photo-library access). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority.

If you are a California resident, you have the right to know, delete, and correct personal information, and the right to non-discrimination. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of.

To exercise any of these rights, use the in-app controls above or email aremmouche.dev@gmail.com.

8. International transfers

Our providers process data in the United States [and other countries]. Where data is transferred from the EU/UK, we rely on [TRANSFER MECHANISM — e.g., Standard Contractual Clauses / provider Data Privacy Framework certifications].

9. Children

Tripar is not directed at children under 13, and you must be at least 13 to use it. We do not knowingly collect data from children under 13; if you believe a child has created an account, contact us and we will delete it.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be flagged in the app, and the date above always reflects the current version.

11. Contact

aremmouche.dev@gmail.com, or the Help & support option in the app.