Legal
Privacy Policy
Effective date September 3, 2026
This policy explains what personal data TripNova handles, why we handle it, how long we keep it, who receives it, and the rights and choices you have. TripNova is operated by NovaThrive LLC ("we", "us"), the data controller for the server-side processing described here.
1. Who we are and when this policy applies
TripNova is a local-first trip-planning app for iOS, Android, and the web, published by NovaThrive LLC. This policy applies to the TripNova apps, website, accounts, and cloud services. For a privacy question or rights request, contact privacy@tripnova.io.
2. Data we handle now and conditionally in the future
You can build trips and itineraries as a guest without creating an account. What leaves your device depends on the features you choose. Sections 2.1 through 2.5 describe practices that apply now. Section 2.6 describes conditional future features that are not active yet.
2.1 Data kept on your device
Your guest profile, trips, itineraries, budgets, reminders, and exports are stored locally on your device or in your browser. Opening TripNova does not create a cloud account or upload this content. Local data leaves your device only when you choose an online feature, such as searching for a place, syncing a particular trip, inviting another person, or uploading a file. You control local data through the app and your device or browser storage controls.
Legal basis when the app processes this data locally: performance of our contract with you (Art. 6(1)(b) GDPR). Data that never leaves your device is not received by or accessible to us.
2.2 Your TripNova account
Creating an account is optional and is needed only for cloud sync and collaborative features. Our self-hosted identity service, powered by Ory Kratos, stores your email address (required for sign-in, verification, and recovery) and your first name (required by TripNova when you create an account). Your password is transmitted to our self-hosted identity service over an encrypted connection and stored only as a salted hash; we do not store it in plaintext.
Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
2.3 Trips you choose to sync
Cloud sync is opt-in for each individual trip. When you enable it, we store that trip's name, destinations, dates, itinerary, activities, notes, budget, checklists, reminders, flight and hotel details, activity locations, cover images, attachments, and other files you choose to upload. We also store record identifiers and update times needed to sync. Trips you do not choose to sync remain on your device.
A trip may contain personal data about a companion that you enter, such as their name and optional contact details. Only add what is needed for the trip, make sure you are entitled to share it, and tell them that it will be handled under this policy. For a shared trip, we also store its members, invitations, and roles so invited people can access it.
Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR). For companion data supplied by a user, our legitimate interest is to provide the trip-planning feature the user requested (Art. 6(1)(f)), balanced against the companion's rights and the data-minimisation rules above.
2.4 Place, route, and map requests
When you use destination search, geocoding, routing, or points of interest, the place or route query is sent through our Cloudflare proxy to Geoapify. Weather requests are sent through the same proxy to OpenWeather. We do not attach your TripNova account ID to either upstream query. Cloudflare processes network data such as your IP address to deliver and rate-limit the request; this is not a promise of total anonymity. Map tiles are OpenStreetMap-derived/Protomaps tiles served by TripNova through Cloudflare.
Legal basis: performance of our contract with you (Art. 6(1)(b)) and our legitimate interest in protecting the service from abuse (Art. 6(1)(f) GDPR).
2.5 Security and operational records
To keep the service available and protect it from abuse, our servers and edge network process limited technical records such as IP addresses, request times and routes, account or request identifiers, error details, and rate-limit counters. Application logs are designed not to contain trip content, email addresses, precise coordinates, or chat text. Where an account reference is needed, we use an internal identity ID rather than your email address.
Legal basis: our legitimate interest in securing and operating the service (Art. 6(1)(f) GDPR).
2.6 Conditional future sharing and communication features
These features are not active yet. TripNova does not currently process live GPS or coarse last-seen location, provide in-app trip chat, or enable peer-to-peer media sharing. Live GPS, last-seen, and P2P sharing remain inert until their respective feature and required consent control ship. Chat processing begins only when the chat feature ships. We will update this policy and app-store disclosures before activation.
Live GPS sharing: if and when you enable it, the person sharing location must accept each sharing session. Location is relayed only to the selected participants, is never persisted or logged by TripNova, and is session-scoped and short-lived.
Coarse last-seen: if and when you separately opt in, TripNova may keep only your latest coarse location stamp for trip interactions. This consent is distinct from live sharing and from whether another person can ask to find you. The latest-only stamp will be cleared after the configured short retention TTL; the precise period will be published before this feature is activated.
Trip chat: if and when account-backed shared-trip chat launches, messages and related account/trip context will be processed to let members communicate and coordinate the trip. The planned default is 365 days for live messages and three years for the archive, subject to trip or account deletion.
Peer-to-peer (P2P) media: if and when enabled, sharing on a local network or nearby mobile devices will require its own consent. Media may transfer directly and recipients keep copies on their own devices. TripNova cannot remotely delete copies already transferred; cloud or account deletion covers cloud data and the initiating user's own device only.
3. How we use data
We use the data described above only to:
- run the app and sync the trips you select across your devices;
- create and secure your account, verify your email, and recover access;
- enable shared trip planning with people you invite;
- provide place search, routing, points of interest, and maps;
- support you and diagnose errors you report;
- keep the service secure, available, and free from abuse.
We do not sell personal data and do not use it for advertising, profiling, or automated decisions with legal or similarly significant effects.
4. When we disclose data
We disclose data only as needed to operate features you request, to the providers in section 5, when you choose to share a trip, or when disclosure is required by law.
Members of a shared trip can see its content, including companion details, files, and membership information included in that trip. Their access depends on their assigned role. A member may export or copy information onto their device; those independent copies cannot be remotely erased by TripNova.
5. Service providers, storage, and transfers
Cloud account and trip data are hosted in the European Union, primarily in Ireland. Providers that process personal data for TripNova are required to protect it consistently with this policy, our agreements, and applicable law.
| Provider | What they do | Location / safeguard |
|---|---|---|
| Amazon Web Services (AWS) | Compute, managed database, and account email delivery | EU (eu-west-1, Ireland); AWS DPA and Standard Contractual Clauses |
| Cloudflare | Security, rate limiting, content delivery, static hosting, request proxying, and file/object storage | EU jurisdiction for stored objects; global edge processing is transient; Cloudflare DPA and Standard Contractual Clauses |
| Geoapify | Place search, geocoding, routes, and points of interest requested by you; no TripNova account ID is sent upstream | Third-party service provider; international processing is governed by Geoapify's privacy and transfer terms |
| OpenWeather | Weather requests you make through TripNova; no TripNova account ID is sent upstream | Third-party service provider; international processing is governed by OpenWeather's privacy and transfer terms |
| OpenStreetMap-derived/Protomaps data | Map-tile source data, served by TripNova through Cloudflare | Open-data-derived map content; delivery uses Cloudflare as described above |
Ory Kratos runs on our infrastructure and is not a third-party processor. Cloudflare operates a global edge network, so transient request data may be processed outside the EEA. Where data is transferred internationally, we use applicable safeguards, including data-processing agreements and Standard Contractual Clauses where required.
6. How we protect data
We use safeguards appropriate to the data and risk, including encrypted connections, access controls, data minimisation, separation of identity and trip data, and encrypted off-site backups. Passwords are stored as salted hashes. No internet service can guarantee absolute security, so use a strong, unique password and tell us if you suspect misuse.
7. How long we keep data
Local-only data remains on your device until you delete it through the app or your device or browser controls. We keep account and synced-trip data while your account exists, unless you delete a synced trip sooner. The conditional future retention periods below are planned defaults, not currently enforced because those features are not active.
| Data | Retention |
|---|---|
| Account details and synced trip content, including uploaded files | Until the relevant trip or account is deleted, then erased from active systems |
| Security logs and rate-limit records | Only for the short operational period needed to secure, diagnose, and protect the service, then deleted or de-identified |
| Encrypted database backups | Rotated on a 30-day cycle; deleted data may remain in a backup for up to 30 days before being overwritten |
| Future live GPS sessions | Relay-only and never persisted or logged by TripNova; session-scoped and short-lived |
| Future coarse last-seen location | Latest coarse stamp only; cleared after a configured short TTL. The precise period will be published before activation. |
| Future trip chat | Planned default: 365 days for live messages and three years for archive records, subject to trip or account deletion |
8. Your rights and choices
Subject to applicable law, you may:
- Access the personal data we hold about you;
- Export a portable copy of local and cloud data;
- Rectify account or trip data that is inaccurate;
- Erase a trip or your account, subject to the backup window and independent copies described above;
- Restrict or object to certain processing;
- Withdraw consent at any time where we rely on consent, without affecting earlier lawful processing;
- Complain to the data-protection authority where you live or work, or where you believe a violation occurred.
Account deletion
In the TripNova app, open Settings and use Delete TripNova account to erase TripNova product data (synced trips, media quota objects, and the local database on that device). You can also export a copy first from the same Settings screen. That product delete does not erase your NovaThrive identity, which other NovaThrive apps may still use.
To erase the shared NovaThrive identity (Kratos account), email privacy@tripnova.io or use the operator path documented for NovaThrive identity erasure. We will verify the request and complete erasure without undue delay. Copies already on another person's device cannot be remotely removed.
To exercise another right, email privacy@tripnova.io. We may need to verify your identity. We will respond without undue delay and ordinarily within one month; where the law permits an extension, we will explain it.
9. Cookies
The public website at tripnova.io sets no cookies and uses no analytics or advertising trackers. The web app at app.tripnova.io stores a strictly necessary session token (not a third-party Kratos cookie) so you stay signed in. If non-essential cookies are introduced, we will update this policy and ask for consent before setting them.
10. Children
TripNova is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided data to us, contact us so we can investigate and delete it where appropriate.
11. Changes to this policy
We may update this policy as TripNova evolves, especially when a feature changes what data is handled. We will revise the date above and provide prominent or advance notice of material changes where appropriate or required by law. We will seek consent before new processing where consent is the applicable basis.
12. Contact
Questions or requests can be sent to privacy@tripnova.io. NovaThrive LLC is the controller for TripNova.