Last updated: 2 October 2026
Privacy Policy
What we collect, why, and how you stay in control.
In short
Only what the app needs to work: your account and the travel data you add. No ads, and we never sell your data. Location, photos and notifications only when you use a feature that needs them. You can delete your account and all your files from the app, at any time.
-
Who is responsible
The data controller is the developer of Tripio, as shown on the app's page on the App Store and Google Play. For any privacy or account request write to support@tripio.it.
-
What we collect
• Account: name, email, password (stored only in a non-reversible encrypted form), language and, if you add one, a profile photo (with location and camera data removed).
• Sign in with Google or Apple: only the name and verified email they give us (with Apple it can be an anonymous "hide my email" address).
• Travel data you enter: trips, stops, flights, hotels, parking, rentals, expenses, places, countries and areas visited, travel preferences.
• Documents and photos you upload. From photos we read the date and place taken, if present, to show them on your map.
• Location: used on the phone when you tap "My location" or start navigation; it is not stored on our servers.
• Notifications: if you turn on reminders, the phone's push identifier, to alert you about delays, gate changes and landing; we delete it when you sign out or turn reminders off.
• AI assistant: the messages of your conversations and the suggestions you receive, until you delete the conversation.
• Bookings with partners: which offer you opened (provider, price shown, date) and, if you confirm, the booking details you save to the trip. Never payment data.
• Linked Google account (only if you turn it on): the account email, the permissions granted and encrypted access keys. From Gmail we read booking confirmation emails, read-only, and keep only the extracted details (reference, dates, places, price), never the email text; in Google Calendar we only create and update the "Tripio" calendar.
• Subscriptions and purchases: product, amount, taxes, dates and payment identifiers. If you pay on the website, card details (or Apple Pay, Google Pay, PayPal) are handled by Stripe and never reach us; if you buy from the App Store they stay with Apple.
-
Why we use it
• To provide Tripio's features to you (performance of the contract).
• To keep the service secure and prevent abuse, e.g. by limiting repeated login attempts (legitimate interest).
• Device permissions and optional preferences: only with your consent, which you can withdraw from the phone's settings or the app.
-
Who we share it with
We don't sell data and there are no ads. We only rely on technical providers that make the app work:
• Server and file hosting, in the European Union.
• Mapbox, to show maps, calculate routes and the fastest visiting order and find parking, rentals and places to stay (it receives coordinates and searched places, without your personal data): it receives technical device data and the map area you view. You can turn Mapbox telemetry off from the ⓘ button on the map.
• Google or Apple, only if you choose to sign in with them. If you delete your account we also revoke Apple and Google access.
• OpenAI (GPT models), only if you use the AI assistant and after your consent: it receives your messages, a compact summary of your trips (countries visited, months and lengths), the departure airport and travel preferences and, only if you ask for it when importing from Gmail, the text of up to 8 confirmation emails. Not your email, documents, photos or location.
• Google Gmail and Google Calendar, only if you link your Google account: the use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We don't use this data for ads or share it with third parties. You can unlink the account at any time from your Profile.
• Travel providers (for example Aviasales/Travelpayouts, Duffel, Aviationstack, Wikipedia / Wikimedia): searches start from our server and receive only what you search for (route, dates, people, place), without your personal data. When you book, you do it on the partner's site, under its terms and privacy policy.
• Stripe, for paying subscriptions and packs on the website: it receives your email, name and the payment details you enter on its page, under its own safeguards (PCI DSS).
• Apple, for App Store purchases and, for people in the EU who buy on the website after the app's link, an anonymous purchase code with amount and taxes, as its rules require.
The people you share a trip with see that trip's data. Your documents are always visible only to you.
-
How long we keep it
As long as your account exists. When you delete your account, your data, documents and photos are erased and every session is closed. Technical backups of the server, if any, are overwritten in their normal rotation.
-
Security
Connections are encrypted (HTTPS), passwords are never stored in plain text and documents and photos are kept in private storage, reachable only after signing in and only by those who are allowed to see them. So you can check your trips without a connection, a copy of your travel data stays on your phone and is deleted when you sign out.
-
Your rights
Under the GDPR you can access, correct, export or delete your data, restrict or object to its use. You can edit your profile and delete your account directly in the app (Profile → Edit profile). You can also lodge a complaint with your data protection authority (in Italy, the Garante per la protezione dei dati personali).
-
Children
Tripio is not intended for children under 14.
-
Changes
If this policy changes in a meaningful way, we'll let you know in the app before the changes apply.
For questions about privacy or your account, write to support@tripio.it