Privacy Policy
Effective November 2, 2026 · Posted October 3, 2026
한국어로 보기This document is a revision that takes effect on November 2, 2026. View the document currently in force
This policy explains how Fitrip handles personal information when you use our travel planning website and mobile apps. Fitrip is operated from South Korea. Questions and privacy requests can be sent to support@fitripai.com.
1. Information We Collect
| Context | Information |
|---|---|
| Account and sign-in | Email address, display name, optional profile photo, Google or Apple sign-in identifier, registration date, and last sign-in date |
| Travel planning | Departure point, destination, dates, travel preferences, group details, budget, notes, generated itineraries, checklists, expenses, shared trip activity, and precise current location when searching for nearby places |
| Account trip library (when signed in) | Trip name, city, dates, and planning preferences; day-by-day itineraries; notes on activities; visited checks and their coordinates; checklists; place coordinates you corrected; flight routes; budgets, travel companions, and expenses; voucher, booking-document, trip-photo, and cover-photo files with their details (title, type, linked activity, time taken); trip start and end records; and the 30 most recent edit versions |
| Account settings (when signed in) | Default display currency, trip alert and Lock Screen Live Activity settings, your default packing list, theme, whether you consented to location use for nearby search on the web, and per-trip settings (display currency, muted notifications, dismissed suggestions, and similar) |
| AI connections (optional) | Name and return address of each AI tool you connect; personal token names, permission scopes, and expiry dates; hashed tokens and authorization codes (never the originals); issue and last-used times |
| Stored on your device | Saved places, itineraries, visited locations and coordinates, exploration-map cells and first-visited dates, vouchers, booking documents, travel photos, and lock settings. When you sign in, the trip records among these sync to your account trip library; device settings such as exploration-map cells, lock settings, and notification settings stay on the device. |
| Paid subscriptions | Store product ID, transaction ID or purchase token, subscription status, expiration time, and account entitlement result |
| Limited product analytics | A SHA-256 hash derived from an app installation UUID, app version, referral screen, and events for recap sharing, paywall views, and return visits to completed trips |
| AI output reports | The screen and AI-generated content you report, the report reason, an optional description, and app version |
| Web security | A random anonymous cookie, Cloudflare Turnstile token, IP-based free usage count, IP address, browser or device information, service logs, and cookies |
| Optional updates | Email address and marketing consent |
On iOS, the exploration map converts location into H3 grid cells and stores them only on your device and in your own private iCloud storage (Apple). Raw exploration locations and explored cells are not sent to Fitrip servers. The iCloud backup restores your exploration map on a new device or after reinstalling the app with the same Apple ID; Fitrip cannot access it, and Apple's iCloud terms and privacy policy apply. If you are not signed in to iCloud, the map stays on the device only. You can turn off exploration recording or erase it at any time, which also deletes the iCloud backup.
When you search for nearby places in Korea on iOS, your precise current location is sent to Fitrip and Kakao Corp. only after separate consent. Fitrip uses the exact coordinates and Kakao Local API place results only while processing the request and does not store them in server logs, databases, caches, or backups. If you save a Kakao result or add it to an itinerary, Fitrip stores only the Kakao place ID and detail URL that may be retained as provider references. If Apple MapKit or Google Places confirms the same place, Fitrip may also retain only the place ID for live re-fetching. Provider-supplied names, addresses, phone numbers, coordinates, and ratings are not stored permanently. Saving still completes when neither Apple nor Google confirms the place; the app then presents a generic place card and the Kakao detail link. Searches outside Korea use Apple MapKit. Android nearby-itinerary distance calculations continue to occur only on the device.
On the web, nearby place search also sends the precise current location provided by your browser to Kakao Corp. through Fitrip servers only after separate consent. The website does not distinguish between locations in Korea and abroad and searches through the Kakao Local API; as on iOS, exact coordinates and Kakao place results are used only while processing the request and are not stored. Your choice is saved in your account settings. You can withdraw it at any time with Withdraw location consent on the Saved Places page, and the related usage and disclosure records are then deleted without delay. When you save a place or add it to a place list or itinerary on the web, provider-supplied addresses, coordinates, and ratings are not stored; only the place ID and detail URL are kept as provider references, and names are not stored for Kakao places.
When you sign in on the iOS app, the photos, vouchers, booking documents, and cover photo in your trips are stored in your account trip library so they appear on your other devices. Files are end-to-end encrypted (AES-256) on your device before upload. The decryption key exists only in your iCloud Keychain, so no one, including Fitrip, can view the file contents. Fitrip's servers encrypt the received ciphertext once more for storage. A recovery key is issued when you first upload a file; if you lose both your keychain and the recovery key, Fitrip cannot recover the files. Fitrip stores only a key identifier and a copy of the key locked with your recovery key, which Fitrip cannot unlock without the recovery key. Without signing in, these files stay on your device. Travel companions on a shared trip do not receive your photos, vouchers, or notes. On Android, photos and documents you add stay in app-private storage and are not uploaded automatically.
The website, the iOS app, and any AI tool you connect all use the same account trip library. Trips created on the web appear in the app, and trips created or edited in the app or by an AI tool appear on the web. Trips created on the web without signing in are stored as before, only in your browser and in guest trip storage.
Apple or Google handles payment card details. Fitrip does not receive your card number. The original installation UUID used for limited analytics stays on your device. The server uses the hash to validate the event format and stores daily aggregate counts.
Fitrip is intended for people aged 14 or older. We do not knowingly collect personal information from children under 14. Please contact us if you believe a child has provided information to Fitrip.
2. How We Use Information
- Authenticate users and maintain account sessions.
- Generate, save, sync, and manage travel plans, including notes, checklists, expenses, vouchers, and photos, across the web and your devices.
- Let AI tools that you connect view, edit, or create your trips when you ask them to (AI connections).
- Find nearby places from your current location.
- Build exploration-map and trip-recap statistics on your device.
- Verify purchases, restore subscriptions, and prevent fraud.
- Review reports about inaccurate, unsafe, or inappropriate AI output.
- Protect the website and apps from automated abuse.
- Respond to support requests and diagnose errors.
- Measure a small set of product events through daily aggregates.
- Send product updates only when you have chosen to receive them.
You can withdraw marketing consent at any time. Refusing marketing does not limit access to the service.
3. Retention
- Account data: retained until account deletion unless law requires a longer period.
- Guest travel data: deleted no later than 30 days after creation.
- Account trip library: kept until you delete the trip or your account. When you delete a trip, its contents and attached files are cleared immediately. A deletion marker (trip ID and deletion time) is kept for 90 days so your other devices learn about the deletion, then removed permanently. Deleted files are erased from disk during cleanup within one day. Only the 30 most recent edit versions are kept for each trip, and they are removed when the trip or account is deleted. Attached files are removed immediately when you delete your account.
- AI connections: tokens stop working immediately when you disconnect, delete, or let them expire, and the records are removed 30 days later. Authorization requests are valid for 10 minutes and authorization codes for 2 minutes. Hashes of used authorization codes are kept for 31 days to detect code reuse. Everything is removed immediately when you delete your account.
- Marketing email: retained until you unsubscribe.
- Subscription records: retained until account deletion or for a legally required period.
- AI output reports: retained for 90 days and then removed during scheduled cleanup.
- Analytics: installation hashes are not retained. Only daily aggregate counts remain.
- Nearby-search location: exact coordinates and Kakao place results are discarded after the request and are not stored in logs, databases, caches, or backups. Legally required location usage and disclosure records do not contain coordinates or place results and are retained for six calendar months from creation. They are deleted without delay if you withdraw location consent or delete your account.
- Provider references for saved nearby places: Kakao place IDs and detail URLs, and Apple or Google place IDs, remain until you delete the saved place or itinerary entry, or delete your account. Provider-supplied names, addresses, phone numbers, coordinates, and ratings are not retained permanently.
4. Third-Party Disclosure and Service Providers
Fitrip provides precise location to Kakao only after separate consent for a nearby-place search (in Korea on the app, anywhere on the web).
| Recipient | Purpose | Information | Retention |
|---|---|---|---|
| Kakao Corp. | Nearby-place search through the Kakao Map Local API (in Korea on the app, anywhere on the web) | Precise location at the time of search | Deleted without delay when the search purpose is completed; legally required usage and disclosure records are retained for six months |
| The provider of an AI tool you connect yourself (for example, Anthropic's Claude or OpenAI's ChatGPT, as you choose) | Viewing, editing, or creating trips that you ask that AI tool to handle | Your trip list (name, city, dates), day-by-day itineraries, and notes on activities, within the permission you granted (read, or read and edit), each time the tool makes a request | Governed by that provider's privacy policy; Fitrip stops providing data as soon as you disconnect |
An AI connection exists only if you create a personal token under AI connections in account settings, or tap Allow on the Fitrip consent screen during the AI tool's connection flow. The consent screen shows the tool, where the result is sent, and the permission requested, and warns you about tools Fitrip has not verified. If the provider is outside Korea, this consent covers the international transfer. How the AI tool handles and stores the information is governed by its own privacy policy and your terms with it; Fitrip does not control it. You can disconnect or delete a token at any time under AI connections, effective immediately. Photos, vouchers, and expenses are never provided to AI tools.
The following processors support Fitrip operations:
| Provider | Purpose |
|---|---|
| Supabase Inc. | Database hosting and authentication in the Seoul region |
| Oracle Corporation | Service server operation and storage of end-to-end encrypted trip attachments (photos, vouchers) in the Chuncheon, Korea region |
| OpenAI, L.L.C. | AI travel recommendations and itinerary generation, packing checklist suggestions, day regeneration and route-time repair, conversational itinerary editing, and parsing pasted or imported itinerary text |
| Google LLC | AI travel recommendations, itinerary generation, and the other AI features listed for OpenAI when Gemini API is configured, Google Maps information, Google Play purchases, and Android app integrity checks |
| Apple Inc. | App Store purchases and subscription checks (App Store Server API), per-device free usage checks (DeviceCheck), WeatherKit, MapKit, and Apple sign-in |
| OpenMeteo GmbH | City search and web weather data |
| OpenStreetMap Foundation | Fallback web city search (Nominatim) |
| Apilayer Data Products GmbH | Flight information lookup (aviationstack) |
| Cloudflare, Inc. | Content delivery and automated abuse protection |
We do not sell personal information. Apart from the consented disclosures above (Kakao and AI tools you connect), we disclose information to processors only as needed to operate Fitrip or when required by valid legal process.
5. International Data Transfers
Core account and trip data is stored in the Supabase Seoul region. When you use an AI feature (recommendations, itinerary generation, checklist suggestions, day regeneration, route-time repair, conversational editing, or parsing pasted or imported itinerary text), the travel information you enter, the existing itinerary sent with the request (for checklist suggestions, the place names in it), your regeneration and editing requests, and any itinerary text you paste or import are transferred to OpenAI, L.L.C. or Google LLC in the United States according to the model configured for that feature. OpenAI API requests are not used to train OpenAI models. Abuse-monitoring logs may be retained for up to 30 days unless a longer period is legally required. Gemini API request processing and retention depend on the service tier and project logging settings; limited abuse-monitoring logs may be retained.
Google also processes map search terms or location information, Google Play purchase identifiers, and Android integrity tokens in the United States or other countries only when you use the relevant map, payment-verification, or integrity feature. Apple processes destination coordinates, App Store transaction identifiers, and DeviceCheck tokens with a per-device monthly free-usage count in the United States for weather, maps, subscription checks, and per-device free usage checks. City search terms are sent to OpenMeteo GmbH (Switzerland): directly from your browser, together with your IP address, for city search on the web, and through our server for other city searches and weather lookups, along with destination coordinates. When web city search gets no result from Open-Meteo, your browser sends the search term to the OpenStreetMap Foundation (United Kingdom). Flight numbers and flight dates you enter, and airport codes if you provide them, are sent from our server to Apilayer Data Products GmbH (Austria) for flight lookup. Cloudflare processes IP addresses, browser information, and security tokens for content delivery and security.
If you connect an AI tool whose provider is outside Korea, information is sent to that provider over the network whenever the tool makes a request, based on the consent described in section 4.
We use providers subject to contractual and technical safeguards. You can stop future transfers by avoiding the relevant feature or deleting your account. Some features will no longer work if the required transfer is not made.
6. Your Choices and Rights
Depending on where you live, you may have the right to:
- Access your personal information.
- Correct inaccurate personal information.
- Delete your account and associated data.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Receive information about how your data is used and disclosed.
- Submit a complaint to the relevant privacy authority.
You can review and disconnect connected AI tools and personal tokens under AI connections in account settings. Deleting a trip removes it from your account trip library and from all synced devices. You can update account details or delete your account in the app. You can also use the web account deletion page or email support@fitripai.com. We may need to verify your identity before completing a request.
7. Cookies and Device Storage
Fitrip uses cookies and browser storage for sign-in, preferences, and guest usage limits. Cloudflare Turnstile may run during guest itinerary generation to block automated abuse. You can block cookies in your browser, but sign-in and other functions may stop working.
Place and city photos are found by our server on Naver, Wikimedia Commons, Openverse, and Google using only the place or city name, and your device then loads each photo from the address where it is published. The site serving a photo may receive your IP address and browser information. Exchange rates are downloaded by your device directly from ExchangeRate-API (open.er-api.com), which may receive your IP address and browser information.
8. Security and Incident Response
We use HTTPS, access controls, token protection, and other reasonable measures to protect information. Trip attachments (photos, vouchers, cover photos) are end-to-end encrypted with AES-256-GCM on your device, with the key held only in your iCloud Keychain, so Fitrip cannot view them; they are encrypted again on the server and can be downloaded only by the account owner. AI tools receive only scoped tokens (read, or read and edit) that are separate from sign-in sessions and cannot access account information beyond your trips. Tokens and authorization codes are stored only as one-way hashes. No service can guarantee complete security. We investigate suspected incidents and notify users or regulators when applicable law requires notice.
9. Changes to This Policy
We may update this policy when the service or applicable law changes. We will post the revised version and its effective date at least 7 days in advance, or 30 days in advance for material changes such as new categories of information or new disclosures, and announce them in the service.
Revision effective November 2, 2026 (posted October 3, 2026): listed checklist suggestions, day regeneration and route-time repair, conversational itinerary editing, and parsing pasted or imported itinerary text as AI processing and transfers. Added Apple subscription and per-device free-usage checks and OpenMeteo GmbH weather lookups. Added the OpenStreetMap Foundation (fallback web city search) and Apilayer Data Products GmbH (flight lookup) as processors with international transfers. Added notices that photo hosts and the exchange-rate provider may receive connection data, and location consent and Kakao disclosure for web nearby search.
Revision effective October 19, 2026 (posted September 19, 2026): added the account trip library (syncing trip records, photos, and vouchers across the web and devices), account settings storage, backup of the exploration map to your own iCloud, AI connections (disclosure to AI tools you connect), Oracle Corporation as a processor, and end-to-end encrypted storage of attachments.
10. Contact
Privacy contact: Fitrip Operations
Email: support@fitripai.com
Version history
- Effective September 17, 2026 September 17, 2026 – October 18, 2026
- Effective October 19, 2026 October 19, 2026 – November 1, 2026
- Effective November 2, 2026 from November 2, 2026