Privacy Policy

AITrip (aitrip.world) · Last updated: 18 July 2026

1. Controller

The data controller for the AITrip website and mobile apps is Mikhail Kartamyshev, an individual operator established in Poland ("AITrip", "we"). Contact: mk.pooh1986@gmail.com.

2. What we collect, why, and on what legal basis

DataPurposeLegal basis (GDPR)
Email + hashed password, or Google/Apple account identifierAccount creation, sign-in, communication about your accountContract (Art. 6(1)(b))
Trip conversations and generated itinerariesThe core service — planning your tripsContract (Art. 6(1)(b))
Push notification token (mobile, only if you allow notifications)Telling you when an itinerary is readyConsent (Art. 6(1)(a)) — revocable in system settings
Feedback messagesSupport and product improvementLegitimate interest (Art. 6(1)(f))
Technical logs (IP address, timestamps, errors)Security, abuse prevention, keeping the Service runningLegitimate interest (Art. 6(1)(f))

We do not collect your precise location, contacts, photos, or advertising identifiers. We show no ads, use no third-party analytics or tracking SDKs, and do not use your data to train AI models.

3. Cookies

The website uses only strictly necessary cookies (session and security). No advertising or analytics cookies — which is why there is no cookie banner.

4. Processors and recipients

We share data only with processors needed to operate the Service, under data-processing agreements:

  • Google (Gemini AI, Maps/Geocoding/Distance Matrix) — your trip messages and place queries are processed to generate itineraries;
  • Expo (push notification delivery) — your push token;
  • DigitalOcean — server hosting.

We never sell personal data and never share it for advertising. In the sense of the California Consumer Privacy Act (CCPA/CPRA): we do not "sell" or "share" personal information.

5. International transfers

Some providers process data in the United States. Where data leaves the EU/EEA, transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses, as applicable to the provider.

6. Retention

Account data and trip content are kept while your account exists and deleted when you delete your account (in-app: Settings → Delete account; or by email). Technical logs are retained for up to 90 days. Backup copies expire on a rolling basis within 35 days.

7. Your rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA and similar laws), you have the right to: access your data, rectify it, erase it, port it (receive a copy in a machine-readable format), restrict or object to processing based on legitimate interest, and withdraw consent (e.g., disable notifications) at any time without affecting prior processing. We do not discriminate against you for exercising any right.

To exercise any right, email us; we respond within one month (GDPR) or as required by your local law. EU/EEA residents may lodge a complaint with their supervisory authority (in Poland: the President of the Personal Data Protection Office, UODO), or the authority of their country of residence.

8. Children

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child provided us personal data, contact us and we will delete it.

9. Security

Data is encrypted in transit (TLS). Passwords are stored only as bcrypt hashes; API tokens as SHA-256 digests. Access to production systems is restricted to the operator.

10. Changes

We will post any changes here and, for material changes, notify you by email or in-app before they take effect.

11. Contact

Privacy questions and rights requests: mk.pooh1986@gmail.com · See also our Terms of Service.