Privacy Policy
Version 1.3 · Last updated: 12 September 2026
Tripi is a social travel app: you create trip albums with your friends, save places on the map and decide who you share them with. This policy explains what personal data we process when you use the Tripi app and tripiapp.es, why we process it, and the rights you have.
If language versions differ, the Spanish version prevails.
1. Who is responsible (data controller)
- Controller: [TRIPI, S.L.]
- Tax ID (CIF): [CIF]
- Registered address: [ADDRESS]
- Privacy contact: privacy@tripiapp.es
2. What data we process
Account data: email address, username, optional nickname, optional bio, optional profile photo, preferred language and account type. Authentication is handled by Firebase Authentication (Google): your password is never stored on Tripi’s servers.
Sign in with Google or Apple: if you choose these options, we receive your account identifier and the email address each service shares with us (Apple lets you hide your real email).
Content you create: trips (name, destination, dates, participants and cover photo), album photos, spots on the map (a coordinate with a photo and/or a note), reactions, visited countries and the messages you send us through the feedback form.
Location (map and spots): only if you grant the permission, we use your device location to centre the map. Spots you choose to create store their coordinates as part of their content.
Location shared with your buds (MyBuds): this feature is off by default. Only if you turn it on and choose specific people do we store your approximate position, so that those people — and nobody else — can see it on the map.
- Before anything is sent, your phone rounds your position to a cell of about 500 m: your exact coordinates never leave your device and are never stored.
- We keep one row per user, your latest known position, and every update replaces the previous one. We keep no record of where you have been.
- You are visible only to people you explicitly grant access to (who must already be your friends) and, if you enable it for a Tripi, to that trip’s participants while it lasts. There is no feature that lets anyone ask where a particular person is.
- You can stop it at any time in one tap from Settings → Location sharing, with no confirmation and immediate effect. It also ends automatically if you stop being friends.
- It refreshes when you open or return to Tripi and when you post a photo or a spot. If you additionally grant the "Always" permission, it also refreshes as you move with the app in the background; you can revoke that permission in iOS settings without turning off the rest.
Social data: your friends (a friendship is mutual: requested, then accepted), friend requests sent and received, who you follow if they are an influencer account (and who follows you if yours is), and your membership in shared trips.
Technical and security data: push notification token and device platform; IP address and user agent in security logs; technical request logs.
Usage data: product events (e.g. "trip created", "spot created") associated with your identifier and username, processed with PostHog on European Union servers, to improve the app. We never send coordinates.
Diagnostics: error and crash reports (device model, OS version, technical stack trace) processed with Sentry, only in the production version of the app.
What we do NOT do: we do not access your contacts, your microphone, or your full photo library (only the photos you pick); we do not track you for advertising; we show no third-party ads; we never sell your data.
3. Why we use your data and on what legal basis
- Providing the service (your account, your content, connecting with friends, essential notifications): contract performance (art. 6.1.b GDPR).
- Service emails (email verification, password reset): contract performance (art. 6.1.b).
- Security and abuse prevention (logs with IP, rate limiting, auditing): legitimate interest (art. 6.1.f).
- Product analytics to improve the app: legitimate interest (art. 6.1.f); you can object (section 9).
- Optional push notifications about social activity: consent (art. 6.1.a), revocable in Settings.
- Compliance with legal obligations: legal obligation (art. 6.1.c).
We do not use your data for personalised advertising and we make no automated decisions with legal effects on you.
4. Who sees your content inside Tripi
- Every trip has a per-member privacy setting: “Only me” or “My friends”. Influencer accounts also have “Followers” (people who follow them without being friends). It controls who can see your participation and the trip’s album.
- Your profile (username, nickname, bio, profile photo and public counters) is visible to other Tripi users.
- Members of a trip see the photos shared in that trip. Spots are different: only your friends can see them (on an influencer account, its followers too), including on the map of a trip you took together. Being in a trip grants no access to other members' spots.
- If you share a trip link, recipients can open it according to the trip’s privacy setting.
- Your approximate location (MyBuds) is seen only by the specific people you have granted access to, and by the participants of a Tripi you enabled sharing for. It is independent of both the trip privacy setting and your profile setting: making your profile public does not make your location public.
5. Who we share data with (processors)
We use providers that process data on our behalf under contract:
- Microsoft Azure — service hosting, photo storage and service emails — EU (West Europe).
- Neon — main database (PostgreSQL on Azure) — EU (Germany).
- Google (Firebase Authentication) — authentication and credentials — EU / USA.
- Apple — Sign in with Apple and notification delivery (APNs) — EU / USA.
- Expo — push notification delivery and app updates — USA.
- Sentry — error reporting — USA.
- PostHog — product analytics — EU.
- OpenStreetMap (Nominatim) and Wikipedia — destination search and city photo — EU / international.
Destination search: when you type a city while creating a Tripi, we send that text to OpenStreetMap (Nominatim) to locate it and to Wikipedia to fetch a photo of the city. We do not send your identity. Place data includes information © OpenStreetMap contributors. We do not send your coordinates to any third party.
Beyond these processors, we only disclose data where the law requires it.
6. International transfers
Your content and the database are stored in European Union data centres. Some providers (Google, Apple, Expo, Sentry) may process data in the USA; in those cases we rely on the EU-U.S. Data Privacy Framework (DPF) or the European Commission’s Standard Contractual Clauses.
7. How long we keep your data
- Active account: for as long as you keep your account.
- Account deletion: when you delete your account from Settings it is deactivated immediately, becomes inaccessible, and your email and username are anonymised. Photos you contributed to shared albums may remain in the trips you were part of. You can request complete erasure of all your content by writing to privacy@tripiapp.es; we will honour it within 30 days.
- Shared location (MyBuds): the latest position only, replaced on every update; never a history. It is deleted when you turn the feature off and when you delete your account, and the grants you gave are deleted if you stop being friends.
- Security logs (IP, user agent): up to 12 months.
- Backups: up to 30 days.
- Error reports (Sentry): 90 days.
- Analytics data: up to 24 months.
8. Security
All communications are encrypted (TLS). Your password is managed by Firebase Authentication and never reaches our servers. Private photos are served through signed, time-limited links. Access to production systems is restricted and sensitive actions are audited.
9. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time:
- In the app: edit your profile, adjust each trip’s privacy, manage notifications or delete your account in Settings.
- By email: privacy@tripiapp.es (we reply within 30 days).
You can also withdraw consent (for example by disabling notifications or the location permission in iOS Settings) without affecting the lawfulness of prior processing, and object to product analytics by writing to us.
If you believe we have not handled your data correctly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or your local supervisory authority.
10. Minimum age
Tripi is intended for users aged 14 or older. We do not knowingly create accounts for children under that age; if we detect one, we will delete it. If you are a parent or guardian and believe a child under 14 is using Tripi, contact privacy@tripiapp.es.
11. Changes to this policy
If we make material changes, we will notify you inside the app before they take effect. The date of the latest update always appears at the top of this document.
12. Contact
For any privacy question: privacy@tripiapp.es.