Skip to content

Legal

Privacy Policy

Last updated: August 29, 2026

TripToad (“TripToad”, “we”, “us”) is a trip-planning app that lets you organize trips (locations, transportation, lodging, restaurants, and activities), track cash and reward-point costs, and share plans with collaborators. This policy explains what we collect, why, who we share it with, and the choices you have. It applies to the TripToad mobile app and the web app at app.triptoad.io.

Information we collect

Account information. When you sign in, our authentication provider (Auth0) gives us your email address and display name, which we use to identify your account, address invitations to you, and associate in-app notifications with the right account.

Content you create. The trip data you enter and upload: trips, dates, itinerary items (lodging, transportation, restaurants, activities) and notes; places and addresses you add; trip budgets and expenses, including descriptions, amounts, currencies, payers, splits, settlements, and receipt links; cash or reward-point costs; reward-program names, nicknames, notes, and optional last-four references; documents and photos you attach (such as receipts); emails you forward to your TripToad import address or paste in so we can turn them into itinerary items; and collaborators you invite by email and their roles. TripToad does not provide a manual reward-program balance ledger or move money between travelers.

Read-only invitation and guest links. A pending email invitation is a time-limited bearer link. While it is pending and has not expired, anyone holding it can open a read-only preview without signing in; the preview also shows the inviter's name and the offered role. Separately, a trip owner can create a companion bearer link for an account-less participant. That link has no fixed expiry and works without sign-in until the owner turns it off or replaces it, or the participant links an account. Both link types expose the same shared companion projection, including itinerary and confirmation details, places, prices, points/program facts, participant names and Going/Maybe attendance, the linked participant's own nonzero per-currency balance, and non-Bucket planning blocks with each candidate's display title, preferred status, interested/Maybe tallies, and comment count. Bucket labels, candidate notes as a separate field, other participants' balances, comment bodies, and voter identities are not included. Treat either URL as a secret; its holder and ordinary network intermediaries also supply request metadata when it is used.

Camera and photos. With your permission, the app can use your camera and photo library so you can capture and attach receipts and images. We access these only when you choose to add a photo; we do not scan your library in the background.

Safety and policy records. When you report a trip member, comment, or AI-generated result, TripToad stores your account identifier, the reason and optional details you submit, a bounded snapshot of the reported content and its context, and the report’s review outcome. The ordinary trip view does not expose a reporter’s identity or moderation notes. You can also block a person: TripToad then keeps their comments out of your view and stops their comment notifications to you, without removing anyone from a trip or changing the plan. Your block list is stored with your account and is not shown to the person you blocked. When a versioned policy must be accepted before you can post, we record the exact version and time when you accept a versioned policy. No such acceptance is required today, so no acceptance record exists yet, and no Community Guidelines version is required unless TripToad has separately published and activated one.

Calendar access.If you choose to export a trip to a device calendar, the mobile app asks permission, lists writable calendars, and creates or updates the events you select. TripToad does not send that calendar list or those calendar events to its servers; your device’s calendar provider may sync them under your calendar settings.

Mobile diagnostics. Production mobile builds send crash reports and a limited sample of performance traces to Sentry. We do not attach your TripToad account identity. Session replay is captured only around an error, with all text, images, and vectors masked on your device before it is sent.

Mobile push infrastructure and optional notifications. The Android app includes Firebase components that can automatically create an app-install-specific Firebase installation ID and collect app version and routine device/app metadata when the app starts, before optional notifications are enabled. This is not a hardware or advertising identifier. Push availability still depends on the installed mobile release and external provider configuration. If push is available and you turn it on, we additionally store your account-level mobile-push preference, an app-generated installation identifier, the device platform, and an Expo push token. Provider messages use generic notification text and an opaque notification identifier rather than trip names, comments, or other trip content.

Web acquisition and product-use metadata. If the web landing URL includes utm_source, utm_medium, utm_campaign, or a refreferral value, TripToad keeps a compact first-touch copy in your browser’s local storage. After you sign in, we add that first-touch value to your account once; later tagged visits do not replace it. The service also records content-free product-use events, such as account, trip, itinerary, invitation, import, and assistant activity. An event can include its name, time, your account or trip identifier when known, and bounded identifiers, counts, or category values. It does not include email bodies, booking or document content, trip names, addresses, assistant messages, or other sensitive free-form content.

What we do not collect. TripToad does not request your device’s precise location, does not include third-party advertising, and does not sell your personal information.

Hosted calendar feed. If you create a calendar subscription, TripToad generates a revocable secret feed URL. A calendar provider or anyone holding that URL can fetch a minimized calendar containing the trip and item names and types, dates, times, time zones, place names and addresses, and links that still require TripToad sign-in. The URL itself authorizes feed access, so treat it as a secret and revoke it in TripToad when it should stop working. The polling calendar service also receives ordinary server request metadata.

Operational diagnostics. TripToad's servers record a server-generated request identifier, normalized method, registered route template, response status, and duration so we can secure and operate the service. A diagnostic event can contain opaque account, trip, import, expense, document, resource, or audit identifiers and provider or outcome information. Caller-supplied request identifiers and dynamic path values are not copied into these logs. These process logs are not used for advertising or cross-app tracking.

How we use your information

  • To provide the core service (storing, organizing, mapping, and displaying your trips);
  • To turn forwarded emails and uploaded receipts into itinerary items (this involves automated text extraction, see below);
  • To look up places, addresses, time zones, and airports so your itinerary maps and displays correctly;
  • To find, automatically select, and apply a Pexels cover image when an owned trip has no cover, using a search derived from that trip’s name, places, or addresses;
  • To send trip invitations, maintain the in-app notification feed, and, where available and enabled, deliver eligible native push notifications;
  • To understand which first-touch campaigns or referrals lead to an account and how core product workflows are used, so we can improve the service;
  • To investigate content reports, take reviewed moderation actions, keep an operator audit trail, and prevent abuse;
  • To record which exact policy version you accepted.

Automated processing and AI

Some features use automated processing, including third-party AI, to save you typing. You can plan and edit an entire trip by hand. The informational Trip Brief described below is generated automatically after trip creation when an AI provider is configured. Imported bookings and other suggestions arrive as drafts you accept or discard, and a change the assistant wants to make is described to you first and happens only when you confirm it.

  • Automatic Trip Brief. After you create a trip, TripToad can send derived destination labels, dates, and an optional purpose to Anthropic to generate an informational summary. TripToad stores that brief automatically, but the brief does not create or change itinerary items, ideas, tasks, bookings, expenses, or trip structure.
  • Turning emails into itinerary items. When you paste a booking confirmation or forward one to your TripToad import address, we send that message’s text to Anthropic (the company behind the Claude AI models) to extract details (dates, times, places, and confirmation numbers) into a draft you review before anything is added.
  • Trip-organization suggestions. If you ask TripToad to suggest how to group your trip (for example, “Suggest legs”), we send the relevant place names, addresses, coordinates, and dates to Anthropic to propose a grouping you can accept or discard.
  • One-shot itinerary suggestions. This path uses Anthropic when it is configured. If Anthropic is not configured and the OpenAI fallback is configured, it can send the suggestion prompt and the limited itinerary context needed to OpenAI instead. A provider error does not silently switch providers or write placeholder content.
  • The in-trip assistant.When you send the assistant a message, we send that message, the recent conversation in that chat, and context about the open trip (its name, dates, default currency, and your role on it) to Anthropic. If the assistant looks something up, what it found goes back to Anthropic so it can answer: that can include your itinerary, your cost and budget totals, and place-search results. If it wants to change your trip, it does not make the change. It returns a description of the change, and the change happens only when you confirm it. TripToad’s app servers do not store a chat transcript as conversation history, but the Web app keeps the transcript in that browser’s local storage and the Mobile app keeps it in AsyncStorage on that device, so the chat can persist after you close and reopen it. Clearing the browser’s site data or the mobile app’s storage removes that device-local copy; mobile sign-out also attempts to remove it. A proposed change is stored separately: we keep what the assistant proposed, what you decided, and what was saved, so the change can be shown back to you and undone. For each streamed reply, the server also keeps a content-free receipt containing cryptographic digests, length, provider, and delivery status rather than the transcript. If you report that reply, the exact reply displayed on your device is copied into the moderation report so an administrator can investigate it.
  • Reading receipts. When you choose to scan a receipt, we send that image or single-page PDF to AWS Textract to read its text.

TripToad sends this data to Anthropic, OpenAI when the fallback path is selected, and AWS only to provide these features. They process it under their own terms and our configured API relationship; provider retention and model-training terms can change. We do not send your data to these providers for advertising, and we do not sell it.

Service providers we share data with

We use a small set of trusted providers to run the service. They process data on our behalf under their own terms; we do not sell your data to anyone.

ProviderPurposeData involved
Auth0 (Okta)Sign-in and account securityEmail, name, authentication tokens
Google Maps, Places, Routes, and Time ZoneMap display, place and address search, route planning, and local-time lookupPlace or address search text and optional coordinate/radius bias; route origin and destination coordinates, travel mode, and optional transit departure; time-zone coordinates and timestamp
PexelsFinding, automatically selecting, and applying trip cover photosA search derived from an owned trip’s name, places, or addresses when it has no cover; routine connection data can reach Pexels if a Pexels-hosted image is displayed directly after our cache fails
Amazon Web Services (Textract)Reading text from receipts you uploadReceipt images or single-page PDFs you choose to process
Anthropic (Claude)Primary AI processing for booking-email drafts, trip-organization suggestions, one-shot itinerary suggestions, generated trip content, and the in-trip assistantDerived destination labels, dates, and optional purpose for an automatic Trip Brief; email text; prompts and recent assistant messages; and limited trip, itinerary, place, cost, or date context needed for the applicable AI feature
OpenAIConfigured fallback for the one-shot itinerary-suggestion path when Anthropic is not configuredThe prompt and limited itinerary context supplied for that suggestion
MailgunReceiving email sent to your TripToad import addressThe inbound message content, sender and recipient metadata, and supported attachments
ResendSending trip-invitation emailsRecipient email address, inviter display name, trip name, token-bearing acceptance link, and optional expiry
Expo Push Service, Firebase Cloud Messaging, and Apple Push Notification serviceInitializing Android push infrastructure and delivering optional native notifications when that capability is active and you enable itOn Android, Firebase can automatically create an app-install-specific Firebase installation ID and collect app version and routine device/app metadata at startup. When you enable notifications, the providers also process an Expo push token, generic notification text, and an opaque notification identifier
SentryMobile crash reporting and performance diagnosticsError and performance diagnostics; error-only replay frames with text, images, and vectors masked on the device. We do not attach your TripToad account identity.
Cloudflare R2Public image storage and the configured destination for operational backup setsPublic image bytes; when the backup job is installed and active, a database dump, attached-document bytes, and public assets
Our hosting providerRunning the app servers and databaseAll service data, stored securely

We may also disclose information if required by law, or to protect the rights, safety, and security of TripToad and its users.

Data security

Data is encrypted in transit (HTTPS/TLS). We store your data on secured servers and take reasonable measures to protect it. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Cloudflare R2 is the configured remote destination for operational backup sets. When that deployment-managed backup job is installed and active, a set can include the service database, attached-document bytes, and public assets. This describes the backup design; it is not a promise that every deployment has activated or recently restored that job.

Data retention and deletion

We keep your data for as long as your account is active. You can delete individual trips and their contents at any time in the app. To delete your entire account and the data you own, open your profile and choose account deletion. The recommended mode makes normal account use unavailable immediately and gives you seven days to restore the account before permanent deletion begins. You can instead choose immediate permanent deletion, which cannot be restored after confirmation. TripToad uses the same audited executor for both modes and marks the account completed only after required local and provider steps are verified, except where we must retain data to comply with law or a documented safety boundary. The current process and a route for people who cannot sign in are explained on the account-deletion page.

Web first-touch attribution is stored with your account and remains there until the account is deleted. The browser copy and its sent marker remain in local storage until you clear TripToad’s site data. Product-use event records are configured to be deleted after 400 days. If an account or trip is deleted before then, its direct account or trip link is cleared from existing event records, while the event record can remain until that retention period ends.

Account-deletion completion verifies the required cleanup from TripToad’s live database, filesystem, object storage, and identity providers. Operational backup copies have a separate boundary: the executor does not delete or verify those historical copies at the moment it completes. Those copies do expire. Private account data and private uploaded files may remain in disaster-recovery copies for at most 30 days after they are deleted from the live system, and the local backup cache keeps at most 14 days. A restore from an older copy does not undo a completed deletion: we keep a minimal record outside the ordinary database backup, and a restored account is held out of use until the deletion is applied again.

Content reports, generated-content suppression records, and their append-only operator audit entries also have a separate safety-record boundary. They are designed to survive deletion of the source account or trip so a report cannot erase its own evidence. A report can retain account or trip identifiers, its reason and optional details, and a bounded snapshot of the one reported item, but not a whole trip or discussion thread. A report is kept for at most 12 months after its case is closed, and is then deleted. An open case has no such limit, because the record is still in use. Deleting your account does not erase a report, but it does remove your direct identity from it: your name, email, and account references are removed and replaced with a correlation value that expires along with the report. Generated-content suppression records stay, because they are what stops removed content from being produced again; after deletion they contain no personal information.

Account-deletion workflow receipts also have a separate operational-record boundary. Append-only lifecycle and operator receipts retain the deletion-request identifier, state changes, selected blocker code, server-generated receipt identifiers, and a digest of the count-only plan an operator reviewed. Those receipts do not copy the user’s deletion reason, email address, or the underlying inventory into the audit record. TripToad does not currently publish an automatic expiry for these receipts; they require a separate approved retention or deletion process.

Selected trip-cover bytes can be cached as public image objects in Cloudflare R2. Replacing or removing a cover, or deleting its trip, attempts to remove the corresponding live cache object. That cleanup is best-effort: failed deletions and objects orphaned before this lifecycle existed have no scheduled reaper or fixed maximum age and can remain until an operator removes them.

Server process logs currently have no fixed maximum age in TripToad's repository or host configuration. They remain until an operator rotates or removes them. We are not describing them as automatically expired until a verified retention control exists.

Your choices and rights

You can access and edit your trip data in the app, revoke collaborator access, and delete content or request deletion of your account and associated data. Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to certain processing. To exercise these rights, contact us at the address below.

Children

TripToad is intended only for adults age 18 or older, and we do not knowingly collect personal information from anyone under 18. TripToad does not currently collect a date of birth or identity document to verify age. If you believe someone under 18 has provided personal information, contact us at the address below.

Changes to this policy

We may update this policy from time to time. We will post the new version here and update the “Last updated” date above; material changes will be communicated in-app or by email where appropriate.

Contact us

Questions about this policy or your data? Email us at [email protected].