Scope and accountability
This Privacy Policy applies to the Tripstead iPhone app, the Tripstead website, and related services operated by Tripstead (“Tripstead,” “we,” “us,” or “our”). It does not apply to websites, apps, airlines, hotels, or other services that Tripstead links to but does not operate.
Tripstead is responsible for the personal information under its control. Questions, requests, and complaints may be directed to our privacy contact using the details at the end of this policy.
Information we handle
Information stored on your device
By default, Tripstead stores your trips locally on your iPhone. This may include destinations, dates, itinerary items, flight and stay details, booking references, addresses, packing lists, links, photos, imported file information, Wallet pass metadata, preferences, and a locally saved profile. Tripstead can be used without creating a permanent Tripstead cloud account.
Profile and Sign in with Apple
If you choose Sign in with Apple, Apple provides Tripstead with an account identifier and, depending on your choices, your name and email address. The current app uses this information to identify your profile on the device and associate locally stored trips with it. Apple may provide a private relay address when you hide your email.
Photos, files, Wallet, location, and notifications
- You choose individual photos and files through Apple’s system pickers. Tripstead does not request unrestricted access to your full photo library.
- If you choose Wallet import, Tripstead reads boarding-pass information that iOS makes available to the app and saves the selected pass metadata locally.
- If you grant location permission, Tripstead may use your current location to show your position on a day map. Destination coordinates may also be used for maps and weather.
- If you enable notifications, Tripstead uses Apple’s notification services to deliver trip reminders and iCloud collaboration updates.
Optional online features
- Temporary trip sharing. When you create a share link, Tripstead sends selected trip metadata—including destinations, dates, itinerary details, flight details, links, addresses, and packing items—to our backend. Photos, files, documents, tickets, account identifiers, and authentication information are excluded. Anyone with the link may view the shared copy until it expires.
- iCloud collaboration. When you choose collaborative sharing, eligible trip metadata is stored in your Apple iCloud account and shared with the people you invite through Apple CloudKit. Photos, attached files, documents, and local profile identifiers are excluded from the collaborative payload.
- Screenshot and file import. When you ask Tripstead to extract itinerary details, the selected image or rendered first page, selected date, destination, and time zone are sent through our backend to an AI processing provider. Tripstead uses the response to prepare a draft for your review before anything is saved.
- Flight lookup. A flight number and travel date are sent through our backend to a flight-information provider. Results may be cached on your device.
- Feedback. Feedback submissions include the category and message you provide, an optional reply email, and—only when you leave the diagnostics switch enabled—the Tripstead version, build number, device type, and iOS version. Trip details are not included.
Technical information
Our hosting and infrastructure providers may automatically process standard request information such as an IP address, request time, route, device or browser headers, and error or security logs. Tripstead uses a one-way shortened hash derived from an IP address to rate-limit certain backend features; the raw address is not placed in the rate-limit key.
Website use
The public Tripstead website does not currently use advertising cookies or third-party advertising trackers. The hosting provider may process basic server logs needed to deliver and protect the site.
How we use information
Tripstead uses information to:
- provide, personalize, synchronize, and maintain the features you choose;
- process screenshot imports and retrieve flight, map, place, time, and weather context;
- create temporary share links and support invited iCloud collaboration;
- respond to feedback and support requests;
- protect the service, prevent abuse, diagnose failures, and maintain reliability;
- comply with legal obligations and enforce our Terms of Service; and
- improve Tripstead using aggregated or de-identified operational information where practical.
Where applicable law requires a legal basis, we rely on performance of our agreement with you, your consent, our legitimate interests in operating and securing Tripstead, and compliance with legal obligations. You may withdraw consent for optional processing at any time, subject to legal and technical limitations.
Service providers and disclosure
Tripstead may disclose information only as needed to operate requested features, comply with law, protect rights and safety, complete a business transaction subject to appropriate safeguards, or with your direction. Current service categories include:
- Apple. Sign in with Apple, iCloud and CloudKit collaboration, WeatherKit, Maps and place search, Wallet, notifications, and App Store distribution.
- OpenAI. Processing a selected screenshot or rendered document page to identify possible itinerary details.
- AeroDataBox through RapidAPI. Retrieving flight schedule and status information using a flight number and date.
- Vercel. Hosting the Tripstead website and backend endpoints.
- Upstash. Redis infrastructure used for temporary trip shares, feedback submissions, rate limits, and limited operational metrics.
These providers process information under their own agreements and privacy terms. Their locations and subprocessors may change over time. Tripstead requires providers handling personal information on our behalf to protect it appropriately.
How long information is kept
- Local trip data. Kept on your device until you delete an item, a trip, or all Tripstead data, or remove the app and its data.
- Temporary share links. Shared trip records expire within 24 hours. A limited expiration marker may remain for up to 30 days so the service can distinguish an expired link from an invalid one. Aggregate share counts may be retained longer without trip content.
- iCloud collaboration. Kept in Apple CloudKit until the owner ends or deletes the collaboration, subject to Apple’s iCloud controls and retention practices.
- Feedback. Feedback content, optional reply email, and optional diagnostics are scheduled to expire after 180 days.
- Rate limits and logs. Rate-limit records generally expire shortly after their applicable window. Hosting, security, and error logs are kept according to operational need and provider settings.
- Import and flight requests. Tripstead does not intentionally add screenshot payloads or flight lookup requests to its application database. Providers may retain request data according to their service terms and settings.
We may retain information longer when reasonably necessary for security, fraud prevention, dispute resolution, legal compliance, or to establish and defend legal claims.
Your controls and choices
- Use Tripstead locally without signing in or using online sharing.
- Choose whether to share a trip, collaborate through iCloud, import a screenshot, look up a flight, or submit feedback.
- Turn off feedback diagnostics before submitting.
- Manage Photos, location, notifications, iCloud, Wallet, and other permissions in iOS Settings.
- Delete individual content, trips, or all local Tripstead data from within the app.
- End shared access using the available sharing controls. Recipients may retain independent copies they already imported.
- Contact us to request access, correction, or deletion of backend information reasonably linked to you.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; withdraw consent; object to or restrict certain processing; or complain to a privacy regulator. These rights may be subject to lawful exceptions.
We may need to verify a request before responding. Because much of Tripstead’s data remains only on your device or in your personal iCloud account, we may not possess or be able to retrieve that information. We will explain when that is the case.
Security and international transfers
Tripstead uses administrative, technical, and organizational safeguards appropriate to the nature of the information, including platform security controls, encrypted network connections, data minimization, strict backend validation, limited retention, and access controls for administrative systems. No method of storage or transmission is completely secure.
Tripstead and its providers may process information in Canada, the United States, and other countries. Those jurisdictions may have privacy laws different from those where you live, and information may be available to courts, law enforcement, or regulators under applicable law. Where required, we use appropriate contractual or legal safeguards for transfers.
Children
Tripstead is not directed to children under 13, and we do not knowingly collect personal information from a child who cannot lawfully consent without authorization from a parent or guardian. If you believe a child has provided personal information improperly, contact us so we can investigate and take appropriate action.
Changes and contact
We may update this policy as Tripstead changes. We will post the revised policy here, update the effective date, and provide additional notice when a change is material or when required by law.
For privacy questions, requests, or complaints, contact Tripstead’s Privacy Contact:
If we cannot resolve a concern, you may have the right to contact the privacy or data protection authority where you live, including the Office of the Privacy Commissioner of Canada.