The short version: your trips stay with you.
Lists and trips stay on your device and in your own iCloud. We run no accounts and can't see them.
When you share a list, we store exactly what the list page shows: the city, airport-style code, dates you chose to include, section titles, item names and quantities. Nothing else is attached, and we don't know who created it. Anyone with the link can open it. Shared lists are deleted automatically after about 400 days; to have one removed sooner, email us its link.
Outbound reads pasted booking emails, screenshots and PDFs on your device where it can. Only when on-device parsing isn't available, and only after you agree on the consent screen, the text or file you chose and your trip dates are sent through OpenRouter to an AI model (Google Gemini, or Anthropic Claude as a backup) to extract the booking details. We only use providers that keep no copy of it and don't train on it. It isn't stored by us and isn't used to build a profile of you.
After you agree on the consent screen, Ideas sends your trip details (city and country, the day, trip type and length, how many travellers, that day's forecast, the kind of idea, and the titles and times of that day's plans) through OpenRouter to Google Gemini, or Anthropic Claude as a backup, to suggest things to do. Nothing that identifies you is included, and the providers keep no copy and don't train on it. To answer the same request again quickly, we keep the generated ideas (not your request) for up to 6 hours, filed under a one-way hash of those trip details.
Subscriptions are handled by Apple and RevenueCat. We receive whether your subscription is active, not your payment details. RevenueCat gives the app an anonymous ID, not your name or Apple Account. When you import a booking or ask for ideas, the app sends that ID to our server, together with an Apple App Attest check that the request comes from the genuine app. We use them to confirm the subscription and to apply daily limits. We keep the app's App Attest key with that ID, when it was last used, and a count of requests per day; nothing else about you.
To see which features are used and where people get stuck, the app sends anonymous usage events to TelemetryDeck: for example that onboarding finished, a paywall was shown or a list was shared, with ranges like "26-50 items" or "4-7 nights". They never contain your destinations, item names, bookings, plans or anything you typed, and carry no name, email or advertising identifier; TelemetryDeck identifies a device only by a salted one-way hash. This isn't used for advertising and isn't shared with anyone else.
If the app crashes or freezes, it sends a crash report to Sentry so we can fix it: the stack trace, the device model, the iOS and app version, a few timings, and which screens were open. It includes no screenshots, no screen contents, nothing you typed, and no name, email or IP address, and it isn't used for anything else.
We use Meta to measure whether our ads led to an install, and only if you allow tracking in Apple's App Tracking Transparency prompt, which appears after you finish packing your first trip. Until you allow it, Meta's SDK isn't started and nothing is sent to Meta; nothing from before is saved to send later. If you allow it, Meta receives your device's advertising identifier and a few app events (opening the app, finishing setup, seeing the subscription screen), and RevenueCat tells Meta about your trials and subscriptions, only for people who allowed tracking. Decline, and nothing about you or your purchases is sent to Meta: Meta's SDK never starts, the app doesn't give RevenueCat the identifiers Meta would need, and RevenueCat is set to send Meta nothing for anyone who hasn't allowed tracking. You can change your answer in the Settings app at any time; if you withdraw it, the app deletes those identifiers from RevenueCat and Meta hears nothing more.
Separately, Apple Ads tells RevenueCat, through Apple's own attribution service, which Apple Ads campaign (if any) led to your download. It uses no advertising identifier, doesn't follow you across apps, and none of it goes to Meta.
Forecasts come from Apple Weather.
Questions or deletion requests: shrithanofficial@gmail.com.