Privacy Policy
Effective September 17, 2026
한국어로 보기This document is a revision that takes effect on September 17, 2026. View the document currently in force
Upcoming revisions — Revised versions of the Privacy Policy take effect on October 19, 2026 and November 2, 2026.
- Effective October 19, 2026 · View full revised versionSummary of changes: added the account trip library (syncing trip records, photos, and vouchers across the web and devices), account settings storage, backup of the exploration map to your own iCloud, AI connections (disclosure to AI tools you connect), Oracle Corporation as a processor, and end-to-end encrypted storage of attachments.
- Effective November 2, 2026 · View full revised versionSummary of changes: listed checklist suggestions, day regeneration and route-time repair, conversational itinerary editing, and parsing pasted or imported itinerary text as AI processing and transfers. Added Apple subscription and per-device free-usage checks and OpenMeteo GmbH weather lookups. Added the OpenStreetMap Foundation (fallback web city search) and Apilayer Data Products GmbH (flight lookup) as processors with international transfers. Added notices that photo hosts and the exchange-rate provider may receive connection data, and location consent and Kakao disclosure for web nearby search.
This version was in force from September 17, 2026 to October 18, 2026. View the document currently in force
This policy explains how Fitrip handles personal information when you use our travel planning website and mobile apps. Fitrip is operated from South Korea. Questions and privacy requests can be sent to team.nubi.official@gmail.com.
1. Information We Collect
| Context | Information |
|---|---|
| Account and sign-in | Email address, display name, optional profile photo, Google or Apple sign-in identifier, registration date, and last sign-in date |
| Travel planning | Departure point, destination, dates, travel preferences, group details, budget, notes, generated itineraries, checklists, expenses, shared trip activity, and precise current location when searching for nearby places in Korea |
| Stored on your device | Saved places, itineraries, visited locations and coordinates, exploration-map cells and first-visited dates, vouchers, booking documents, travel photos, and lock settings |
| Paid subscriptions | Store product ID, transaction ID or purchase token, subscription status, expiration time, and account entitlement result |
| Limited product analytics | A SHA-256 hash derived from an app installation UUID, app version, referral screen, and events for recap sharing, paywall views, and return visits to completed trips |
| AI output reports | The screen and AI-generated content you report, the report reason, an optional description, and app version |
| Web security | A random anonymous cookie, Cloudflare Turnstile token, IP-based free usage count, IP address, browser or device information, service logs, and cookies |
| Optional updates | Email address and marketing consent |
On iOS, the exploration map converts location into H3 grid cells and stores them only on your device. Raw exploration locations and explored cells are not sent to Fitrip servers. You can turn off exploration recording or erase it at any time.
When you search for nearby places in Korea on iOS, your precise current location is sent to Fitrip and Kakao Corp. only after separate consent. Fitrip uses the exact coordinates and Kakao Local API place results only while processing the request and does not store them in server logs, databases, caches, or backups. If you save a Kakao result or add it to an itinerary, Fitrip stores only the Kakao place ID and detail URL that may be retained as provider references. If Apple MapKit or Google Places confirms the same place, Fitrip may also retain only the place ID for live re-fetching. Provider-supplied names, addresses, phone numbers, coordinates, and ratings are not stored permanently. Saving still completes when neither Apple nor Google confirms the place; the app then presents a generic place card and the Kakao detail link. Searches outside Korea use Apple MapKit. Android nearby-itinerary distance calculations continue to occur only on the device.
Apple or Google handles payment card details. Fitrip does not receive your card number. The original installation UUID used for limited analytics stays on your device. The server uses the hash to validate the event format and stores daily aggregate counts.
Fitrip is intended for people aged 14 or older. We do not knowingly collect personal information from children under 14. Please contact us if you believe a child has provided information to Fitrip.
2. How We Use Information
- Authenticate users and maintain account sessions.
- Generate, save, sync, and manage travel plans.
- Find nearby places from your current location.
- Build exploration-map and trip-recap statistics on your device.
- Verify purchases, restore subscriptions, and prevent fraud.
- Review reports about inaccurate, unsafe, or inappropriate AI output.
- Protect the website and apps from automated abuse.
- Respond to support requests and diagnose errors.
- Measure a small set of product events through daily aggregates.
- Send product updates only when you have chosen to receive them.
You can withdraw marketing consent at any time. Refusing marketing does not limit access to the service.
3. Retention
- Account data: retained until account deletion unless law requires a longer period.
- Guest travel data: deleted no later than 30 days after creation.
- Marketing email: retained until you unsubscribe.
- Subscription records: retained until account deletion or for a legally required period.
- AI output reports: retained for 90 days and then removed during scheduled cleanup.
- Analytics: installation hashes are not retained. Only daily aggregate counts remain.
- Nearby-search location: exact coordinates and Kakao place results are discarded after the request and are not stored in logs, databases, caches, or backups. Legally required location usage and disclosure records do not contain coordinates or place results and are retained for six calendar months from creation. They are deleted without delay if you withdraw location consent or delete your account.
- Provider references for saved nearby places: Kakao place IDs and detail URLs, and Apple or Google place IDs, remain until you delete the saved place or itinerary entry, or delete your account. Provider-supplied names, addresses, phone numbers, coordinates, and ratings are not retained permanently.
4. Third-Party Disclosure and Service Providers
Fitrip provides precise location to Kakao only after separate consent for a nearby-place search in Korea.
| Recipient | Purpose | Information | Retention |
|---|---|---|---|
| Kakao Corp. | Nearby-place search in Korea through the Kakao Map Local API | Precise location at the time of search | Deleted without delay when the search purpose is completed; legally required usage and disclosure records are retained for six months |
The following processors support Fitrip operations:
| Provider | Purpose |
|---|---|
| Supabase Inc. | Database hosting and authentication in the Seoul region |
| OpenAI, L.L.C. | AI travel recommendation and itinerary generation |
| Google LLC | Google Maps information, Google Play purchases, and Android app integrity checks |
| Apple Inc. | App Store purchases, WeatherKit, MapKit, and Apple sign-in |
| Open-Meteo | Weather and city search data |
| Cloudflare, Inc. | Content delivery and automated abuse protection |
We do not sell personal information. Apart from the consented Kakao disclosure above, we disclose information to processors only as needed to operate Fitrip or when required by valid legal process.
5. International Data Transfers
Core account and trip data is stored in the Supabase Seoul region. When you request AI recommendations or an itinerary, the travel information you enter is transferred to OpenAI, L.L.C. in the United States for AI processing. OpenAI API requests are not used to train OpenAI models. Abuse-monitoring logs may be retained for up to 30 days unless a longer period is legally required.
Google processes map search terms or location information, Google Play purchase identifiers, and Android integrity tokens in the United States or other countries only when you use the relevant map, payment-verification, or integrity feature. Other providers may process destination or place coordinates, IP addresses, browser information, and security tokens for weather, content delivery, or security features.
We use providers subject to contractual and technical safeguards. You can stop future transfers by avoiding the relevant feature or deleting your account. Some features will no longer work if the required transfer is not made.
6. Your Choices and Rights
Depending on where you live, you may have the right to:
- Access your personal information.
- Correct inaccurate personal information.
- Delete your account and associated data.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Receive information about how your data is used and disclosed.
- Submit a complaint to the relevant privacy authority.
You can update account details or delete your account in the app. You can also use the web account deletion page or email team.nubi.official@gmail.com. We may need to verify your identity before completing a request.
7. Cookies and Device Storage
Fitrip uses cookies and browser storage for sign-in, preferences, and guest usage limits. Cloudflare Turnstile may run during guest itinerary generation to block automated abuse. You can block cookies in your browser, but sign-in and other functions may stop working.
8. Security and Incident Response
We use HTTPS, access controls, token protection, and other reasonable measures to protect information. No service can guarantee complete security. We investigate suspected incidents and notify users or regulators when applicable law requires notice.
9. Changes to This Policy
We may update this policy when the service or applicable law changes. We will post the revised version and its effective date. Material changes may also be announced in the service.
10. Contact
Privacy contact: Fitrip Operations
Email: team.nubi.official@gmail.com
Version history
- Effective September 17, 2026 September 17, 2026 – October 18, 2026
- Effective October 19, 2026 October 19, 2026 – November 1, 2026
- Effective November 2, 2026 from November 2, 2026