Privacy Policy
Last updated: July 22, 2026
Tripar is an AI trip planner operated by Ahsene Remmouche (“we,” “us”). This policy explains what data the Tripar app and this website collect, how it is used, who processes it, and the controls you have. We collect only what the product needs, we do not run ads or advertising trackers, and we do not sell your personal data.
1. What we collect
Account data. You sign in with Google or Apple. Our authentication provider, Clerk, gives us your name, email address, and profile photo from that account, plus an account identifier we use as your user ID.
Trip data. When you plan a trip we store what you enter — destination, dates, number of travelers, budget level, and interests — and the AI-generated itinerary produced from it. Saved travel preferences (default budget, travelers, interests, pace) are stored with your account.
Assistant chats. Messages you send to the AI assistant, and its replies, are stored so conversations continue across sessions until you clear them.
Photos you upload. If you set a custom trip cover, the app asks for photo-library permission and uploads the image you choose to our image-delivery service (ImageKit). This is the only device permission Tripar requests — we do not access your location, contacts, camera, or microphone.
Usage records. Each AI generation (itinerary or chat message) is recorded with token counts, estimated cost, model name, and outcome. We use these records to enforce the free tier's limits and to understand service costs.
Subscription status. If you subscribe to Tripar Pro, billing runs entirely through the App Store or Google Play — card details never reach us. We receive subscription events from RevenueCat (keyed to your user ID) and store a single yes/no Pro flag.
Diagnostics. The app reports crashes, performance traces, and structured logs to Sentry. These can include your trip destination and internal IDs, and — for AI-quality monitoring — the content of assistant messages. Session replays (screen recordings used to debug crashes) are fully masked: text, images, and graphics are redacted before upload.
On your device only. Your sign-in session token is kept in the device's secure storage, and your appearance (light/dark) and language choices are stored locally. The app sets no advertising identifiers and contains no analytics or ad SDKs.
This website is a static page served by Cloudflare. It sets no cookies and runs no scripts or trackers; Cloudflare may log requests (such as IP addresses) to serve and protect the site.
2. How we use your data
- To plan your trips — your trip inputs and chat messages are sent to Google's Gemini API, which generates the itinerary or reply.
- To illustrate itineraries — place photos come from Unsplash; only AI-generated place names are sent as search terms, never your personal data. Images are resized and delivered through ImageKit.
- To show maps — on iOS the map is Apple Maps; on Android, map tiles load from OpenFreeMap. Your device requests tiles for the places shown; we send no account data to map providers.
- To run the free tier and subscriptions — usage records enforce the free limits; RevenueCat events keep your Pro status current.
- To keep the service working — diagnostics help us find and fix crashes, slowness, and bad AI output.
We do not use your data for advertising, we do not profile you for marketing, and we do not sell or share personal data for cross-context behavioral advertising.
3. Services that process your data
- Clerk — sign-in and account management (name, email, profile photo, OAuth identity).
- Neon (Postgres) — our database (account, trips, chats, preferences, usage records).
- Google Gemini — AI generation (trip inputs and chat messages, processed to produce responses).
- Inngest — background job processing (trip-generation jobs and account sync/deletion events carrying your user ID and, for sync, name/email).
- ImageKit — image storage and resizing (your uploaded cover photos; proxied place photos).
- Unsplash — destination photography (receives place-name search terms only).
- Sentry — crash reporting, performance monitoring, AI-quality telemetry, masked session replay.
- RevenueCat — subscription management (your user ID and purchase/entitlement events).
- Apple / Google — sign-in identity and, if you subscribe, billing under their own terms.
- Cloudflare / Expo (EAS Hosting) — the infrastructure our API and this website run on.
4. Security
All traffic uses TLS. Every API request is authenticated with a short-lived signed token verified on the server; your data is only ever returned to your own account. Photo uploads use short-lived signed credentials (30-minute expiry) minted server-side so secret keys never reach the device. Incoming webhooks from our providers are verified before processing. We rely on our providers' security for storage at rest.
5. Retention
Your data is kept while your account exists. Deleting a trip removes it (its chat context and usage records are detached, not deleted). Clearing a chat deletes its messages. Deleting your account removes your account record, trips, chat history, and usage records from our database (see Section 6). Copies held by our providers for backup or logging purposes may persist for a limited period under their retention rules.
6. Your controls
- Delete your account — Profile → Delete account. This permanently removes your account, trips, chats, and usage records from our database and cannot be undone. Two caveats: cancel any Pro subscription in the App Store or Google Play first (deletion does not stop store billing), and copies of uploaded cover photos may persist in our image-delivery service for a period after deletion.
- Delete individual trips or clear assistant chats — in-app, any time.
- Edit travel preferences — in-app, any time.
- Photo access — granted only when you choose a cover image, and revocable in system settings.
- Export — there is no self-serve export yet; email aremmouche.dev@gmail.com and we will provide a copy of your data.
7. Your rights (EU/UK and California)
If you are in the EU or UK, we process your data on these legal bases: performance of our contract with you (providing the planner, assistant, and subscriptions), legitimate interests (service diagnostics, abuse prevention, cost accounting), and consent where required (photo-library access). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority.
If you are a California resident, you have the right to know, delete, and correct personal information, and the right to non-discrimination. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of.
To exercise any of these rights, use the in-app controls above or email aremmouche.dev@gmail.com.
8. International transfers
Our providers process data in the United States [and other countries]. Where data is transferred from the EU/UK, we rely on [TRANSFER MECHANISM — e.g., Standard Contractual Clauses / provider Data Privacy Framework certifications].
9. Children
Tripar is not directed at children under 13, and you must be at least 13 to use it. We do not knowingly collect data from children under 13; if you believe a child has created an account, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be flagged in the app, and the date above always reflects the current version.
11. Contact
aremmouche.dev@gmail.com, or the Help & support option in the app.