TripFlow Itinerary is a local-first travel organizer. It has no developer-operated account, advertising, tracking, or analytics backend. This policy describes information the app processes, optional transfers you control, and deletion.
Trips, areas, connections, places, planning windows, hotels, flights, transport details, traveler profiles and groups, phone numbers, dates, travel preferences, notes, documents, expenses, installment settings, and exchange-rate snapshots are stored in the app’s private App Group container. Provider photos and route responses may be cached within the limits described in the app.
User-provided Google and Gemini API keys and traveler passport numbers are stored in iOS Keychain and are not included in trip exports. Traveler avatar images are private local files separate from profiles.
When you explicitly select someone in Apple’s contact picker, TripFlow Itinerary copies the selected name, first phone number, complete birth date, and available image. It does not retain a live contact link, scan the address book, or synchronize later contact changes.
Apple processes purchases and payment information. On device, TripFlow Itinerary uses StoreKit to verify signed app and subscription transactions, including the original download date and original iOS build, in order to preserve eligible existing-customer access, calculate the automatic 14-day period, and verify paid access. To avoid blocking the first launch when StoreKit verification is temporarily unavailable, the app keeps a local first-launch date in this device’s Keychain; a later verified earlier App Store download date replaces it. TestFlight also uses this marker because Apple supplies fixed original-download values in Sandbox. TripFlow Itinerary does not receive card details or send receipts, purchase history, original-download information, the local first-launch date, or payment data to a developer server.
The App Group stores only a permanent, denied, or active-until access value so the Share Extension can prevent new writes after access ends.
Collaboration is off until the owner enables it for a trip. Enabling it copies the editable trip, places, transport, traveler names and birth dates, preferences, notes, and locally available trip documents to the owner’s private Apple CloudKit database, then creates a CKShare for invited participants.
Traveler phone numbers, passport issue dates, source-profile links, Keychain passport numbers, avatar images, expenses, API keys, generated itineraries and AI caches, provider-photo and route caches, and current location are excluded. Participants receive and change shared data according to the CKShare permission the owner assigns.
During active SharePlay, versioned edits are sent to current session participants for immediate display. CloudKit remains the durable source for offline and late participants. Apple processes iCloud, CloudKit, CKShare, FaceTime, and SharePlay data under its policies. Removing access stops future cloud delivery but cannot recall copies, screenshots, exports, or backups a participant already made.
Apple Maps is the default for place search, maps, and routes. With when-in-use permission, current location can show you on today’s map, identify a nearby saved place, and start navigation. It is not added to trip data or retained as a location history. External navigation apps receive the chosen destination and may process current location under their own policies.
If you provide a Google key and select Google for a feature, TripFlow Itinerary sends the request needed for capability checks, place searches and details, routes, map display, or provider-compliant photos. Requests may include search text, map region, endpoints, travel mode, interface language, and relevant planned times. Google meters requests under your project, quota, billing, terms, and privacy policy.
Live Google restaurant content stays inside Google’s attributed Places UI Kit. Final Google route geometry is session-only and displayed on Google Maps. Provider photo access follows provider storage and attribution rules. If Google fails, TripFlow Itinerary records a safe Settings message and falls back to Apple where possible; fallback does not undo a request already sent.
If you provide a Gemini key and invoke or permit an AI feature, relevant place, timing, free-gap, travel-style, anonymous calculated age, group type, applicable family role, free-form AI preference, and recent rejected-suggestion context may be sent to Google. Names, phone numbers, exact birth dates, passport data, avatars, attachments, expenses, API keys, and unrelated notes are excluded. Gemini failures immediately use the deterministic planner. Controls in Settings can disable automatic analysis or smart planning independently.
Expense details remain local. Quick Add may ask the selected place provider for a merchant and then creates only a local association. Currency conversion downloads the Bank of Israel’s public representative-rate table and stores a snapshot when available. TripFlow Itinerary does not connect to a bank, card issuer, or payment account.
Documents uploaded, pasted, or imported through the Share Extension are copied to private local attachment storage. QR and barcode detection runs on device. Whole-trip export starts with optional categories excluded; you explicitly choose whether to include provider photos, documents, participants, and expenses. Passport numbers and API keys are never included. iOS and the share destination receive the selected file under their own policies.
Local information remains until you delete the related item or app data. Deleting a traveler or trip removes related Keychain passport data and private avatar files. Deleting a trip also removes its expense ledger, documents, and trip-scoped photo cache. Cloud collaboration data remains in the owner’s iCloud until the owner removes the share or trip there. A provider may retain requests already received under its policy.
TripFlow Itinerary uses Apple sandboxing, App Group protection, and Keychain access limited to this device while unlocked. No security system is absolute; protect device access, passport information, and provider keys.
You can deny location or contact access, use Apple instead of Google, disable Gemini automation, remove provider keys, stop sharing, remove participants, and delete saved content. For privacy, support, or deletion questions, email [email protected].
TripFlow Itinerary היא אפליקציית ארגון טיולים בגישת local-first. אין בה חשבון שמפעיל המפתח, פרסום, מעקב או מערכת ניתוח שימוש. מדיניות זו מתארת את המידע שהאפליקציה מעבדת, העברות אופציונליות שבשליטתכם ומחיקה.
טיולים, אזורים, חיבורים, מקומות, חלונות תכנון, מלונות, טיסות, תחבורה, פרופילים וקבוצות של מטיילים, מספרי טלפון, תאריכים, העדפות, הערות, מסמכים, הוצאות, הגדרות תשלומים ושערי חליפין נשמרים במכולת App Group הפרטית. תמונות ספק ותשובות מסלול עשויות להישמר במטמון בגבולות המתוארים באפליקציה.
מפתחות Google ו־Gemini ומספרי דרכון נשמרים ב־iOS Keychain ואינם נכללים בייצוא טיול. תמונות מטיילים הן קבצים מקומיים פרטיים ונפרדים מהפרופיל.
בבחירה מפורשת של אדם בבורר Apple, TripFlow Itinerary מעתיקה את השם, מספר הטלפון הראשון, תאריך הלידה המלא ותמונה זמינה. היא אינה שומרת קישור חי, סורקת את פנקס הכתובות או מסנכרנת שינויים מאוחרים.
Apple מעבדת רכישות ופרטי תשלום. במכשיר, TripFlow Itinerary משתמשת ב־StoreKit לאימות עסקאות חתומות של האפליקציה והמינוי, כולל תאריך ההורדה המקורי ומספר גרסת הבנייה המקורית ב־iOS, כדי לשמור גישה ללקוחות קיימים זכאים, לחשב את 14 הימים האוטומטיים ולאמת גישה בתשלום. כדי לא לחסום את ההפעלה הראשונה כאשר אימות StoreKit אינו זמין זמנית, האפליקציה שומרת ב־Keychain של המכשיר תאריך הפעלה ראשונה מקומי; תאריך הורדה מוקדם יותר ש־App Store יאמת בהמשך יחליף אותו. גם TestFlight משתמש בסמן הזה מפני ש־Apple מספקת ערכי הורדה מקורית קבועים ב־Sandbox. TripFlow Itinerary אינה מקבלת פרטי כרטיס ואינה שולחת קבלות, היסטוריית רכישות, פרטי הורדה מקורית, את תאריך ההפעלה המקומי או נתוני תשלום לשרת המפתח.
ב־App Group נשמר רק ערך גישה קבועה, חסומה או פעילה עד תאריך מסוים, כדי שהרחבת השיתוף תמנע כתיבות חדשות לאחר סיום הגישה.
שיתוף כבוי עד שבעל הטיול מפעיל אותו. ההפעלה מעתיקה למסד Apple CloudKit הפרטי של הבעלים את הטיול הניתן לעריכה, מקומות, תחבורה, שמות ותאריכי לידה של מטיילים, העדפות, הערות ומסמכים זמינים, ואז יוצרת CKShare למוזמנים.
מספרי טלפון, תאריכי הנפקת דרכון, קישורי פרופיל מקור, מספרי דרכון ב־Keychain, תמונות מטיילים, הוצאות, מפתחות API, מסלולים ומטמוני AI, מטמוני תמונות ומסלולים ומיקום נוכחי אינם נכללים. משתתפים מקבלים ומשנים מידע לפי הרשאת CKShare שבחר הבעלים.
ב־SharePlay פעיל נשלחים שינויים בעלי גרסה למשתתפי המפגש לתצוגה מידית. CloudKit נשארת המקור הקבוע למשתתפים לא מקוונים או מאוחרים. Apple מעבדת iCloud, CloudKit, CKShare, FaceTime ו־SharePlay לפי מדיניותה. הסרת גישה עוצרת מסירה עתידית אך אינה מחזירה עותקים, צילומי מסך, ייצוא או גיבויים שכבר נוצרו.
Apple Maps היא ברירת המחדל לחיפוש, מפות ומסלולים. באישור שימוש בזמן הפעלה, מיקום נוכחי יכול להציג אתכם במפת היום, לזהות מקום שמור קרוב ולהתחיל ניווט. הוא אינו נוסף לטיול ואינו נשמר כהיסטוריה. אפליקציות ניווט חיצוניות מקבלות את היעד ועשויות לעבד את המיקום לפי מדיניותן.
אם תספקו מפתח Google ותבחרו בתכונה, TripFlow Itinerary שולחת את הבקשה הדרושה לבדיקת יכולת, חיפוש ופרטי מקום, מסלול, מפה או תמונה תואמת. הבקשות עשויות לכלול טקסט חיפוש, אזור מפה, נקודות קצה, אמצעי תחבורה, שפת ממשק וזמנים מתוכננים. Google מודדת בקשות לפי הפרויקט, המכסה, החיוב, התנאים ומדיניות הפרטיות שלכם.
תוכן מסעדה חי נשאר ב־Places UI Kit המיוחס של Google. תוואי Google סופי הוא זמני להפעלה ומוצג במפת Google. תמונות ספק כפופות לכללי אחסון וייחוס. בכשל נשמרת הודעה בטוחה בהגדרות ומתבצע מעבר ל־Apple כשאפשר; המעבר אינו מבטל בקשה שכבר נשלחה.
אם תספקו מפתח Gemini ותפעילו תכונת AI, ייתכן שיישלחו ל־Google נתוני מקום, זמן, מרווחים פנויים, סגנון טיול, גיל אנונימי מחושב, סוג קבוצה, תפקיד משפחתי רלוונטי, העדפת AI בטקסט חופשי ומשוב אחרון. שמות, טלפונים, תאריכי לידה מדויקים, דרכונים, תמונות, מסמכים, הוצאות, מפתחות והערות לא קשורות אינם נשלחים. כשל עובר מיד למתכנן הדטרמיניסטי. בהגדרות ניתן לבטל בנפרד ניתוח אוטומטי או תכנון חכם.
פרטי הוצאות נשארים מקומיים. הוספה מהירה עשויה לבקש מהספק שנבחר בית עסק ואז ליצור רק קישור מקומי. המרה מורידה את טבלת השערים היציגים הציבורית של בנק ישראל ושומרת צילום מצב. TripFlow Itinerary אינה מתחברת לבנק, חברת אשראי או חשבון תשלום.
מסמכים שהועלו, הודבקו או יובאו דרך הרחבת השיתוף מועתקים לאחסון מקומי פרטי. זיהוי QR וברקודים מתבצע במכשיר. ייצוא טיול מתחיל בלי קטגוריות אופציונליות; אתם בוחרים אם לכלול תמונות ספק, מסמכים, משתתפים והוצאות. מספרי דרכון ומפתחות API אינם נכללים לעולם. iOS ויעד השיתוף מקבלים את הקובץ שנבחר לפי מדיניותם.
מידע מקומי נשמר עד למחיקת הפריט או נתוני האפליקציה. מחיקת מטייל או טיול מסירה נתוני דרכון קשורים מה־Keychain ותמונות פרטיות. מחיקת טיול מסירה גם הוצאות, מסמכים ומטמון תמונות. נתוני שיתוף נשארים ב־iCloud של הבעלים עד שהשיתוף או הטיול מוסרים שם. ספק עשוי לשמור בקשות שכבר קיבל לפי מדיניותו.
TripFlow Itinerary משתמשת בארגז החול של Apple, בהגנת App Group וב־Keychain עם גישה במכשיר זה כשהוא פתוח. אין מערכת אבטחה מוחלטת; יש להגן על המכשיר, הדרכונים ומפתחות הספק.
אפשר לסרב למיקום או לאנשי קשר, להשתמש ב־Apple במקום Google, לבטל אוטומציות Gemini, להסיר מפתחות, לעצור שיתוף, להסיר משתתפים ולמחוק תוכן. לשאלות פרטיות, תמיכה או מחיקה כתבו ל־ [email protected].