legal

Privacy Policy

What we collect, why we collect it, who else sees it, and what you can ask us to do with it.

Last updated 5 August 2026

1. Who we are

Ferrox Industries LLC (Ali Jelveh, sole member) operates TripBuddy. We are a United States company, organised in Wyoming, United States, and most of our users are in the United States. Our address is 30 N Gould St, Ste 50693, Sheridan, WY 82801, USA.

Questions about this policy, or any request under it, go to ali@tripbuddyai.com.

2. What this policy covers

The TripBuddy marketing site, the waitlist form on it, and the TripBuddy web and iOS apps. It does not cover third-party sites we link to, such as booking providers — once you follow a link there, that provider’s own policy applies.

3. What we collect

If you only join the waitlist

The email address you type in, plus a short label recording which form on the page you used (for example hero or footer). Nothing else.

If you use the app

  • Identifiers — your email address if you sign in with a one-time code, or the email and basic profile your identity provider returns if you sign in with Google. You may also use the app without an account, in which case we create an anonymous session that exists only to hold your data until you decide to sign up.
  • Profile and preferences — the display name you choose and the travel preferences you give during onboarding, such as pace, budget band and the kinds of activities you enjoy.
  • Trip content — everything you create: destinations, dates, itineraries, activities, notes, photos you pick for a trip, group membership and invitations.
  • Conversations with the AI buddy — the messages you send and the replies generated, together with the trip context needed to answer them.
  • People you add to a trip— if you pick someone from your phone's contacts, we store the name, and the email address, phone number or age you choose to include, against that trip. Nothing else from your address book is read or uploaded, and we never scan it in the background.
  • Internet and device activity — IP address, browser and device type, and timestamps, recorded by our hosting and database providers as part of ordinary server logs and abuse prevention.
  • Diagnostics and product analytics — crash reports and slow frames, and which screens and buttons are used. None of it carries your name, your email or your trip content, and none of it is tied to your account. In test builds distributed through TestFlight we also record screen replays to see where the app confuses people; every text field is masked in them, and this is off in the App Store version.

What the iOS app asks your phone for

The app asks for four permissions. You can refuse any of them and keep using it — each one only unlocks the feature it belongs to.

  • Location— so your passport can stamp itself when you reach a destination you have a trip for, and so “15 minutes away” means from where you are. Your position is compared against your own trips on the device. It is not sent to us, not stored by us, and not shared. When you search for a place nearby, the coordinate goes to Apple's Maps service to answer the search, under Apple's terms, and not to us.
  • Microphone and speech recognition — so you can talk to your buddy instead of typing. The turning of speech into text is done by Apple's speech recognition service: while you are dictating, the recording goes to Apple, under Apple's terms, and never to us. We receive only the text, which is then a message like any other and is handled as described above. With no connection the app falls back to the on-device recogniser, and nothing leaves the phone at all.
  • Contacts — only when you open the contact picker to add someone to a trip, and only the person you pick.
  • Calendar — write-only. The app can add your trip and its stops to your calendar; it cannot read what is already in it.
  • Photos — you hand over individual pictures through the system picker (a trip cover, a booking screenshot). The app never receives access to your library.

What we do not do

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We run no advertising and no advertising cookies. We do not track you across other companies' apps or websites, and we ask for no permission to do so. We do not buy personal information from data brokers.

We do not collect your location. The iOS app may ask to use it — see below — but it is used on your phone and stays there. The map shows the places you or your buddy put into a trip, not where you have been.

We do use crash reporting and product analytics, from the providers listed in section 6. They tell us that a screen crashed or that nobody finds a button; they are not tied to your identity and carry nothing you write.

4. Why we use it

  • To create and run your account and your trips.
  • To generate itineraries and answers with AI.
  • To send you the launch announcement, if you asked for it on the waitlist. Every marketing email carries an unsubscribe link.
  • To keep the service secure, prevent abuse, and diagnose faults.
  • To comply with law and enforce our terms.

5. The AI part, in plain terms

When you ask your buddy to plan something, we send your request and the relevant trip context — destination, dates, group preferences and the current itinerary — to a large language model provider through our own server. Your request does not go from your browser to the model provider directly, and our provider keys are never exposed to your device.

We reach the model through OpenRouter, an AI gateway, and the model itself is Anthropic's Claude.

  • Neither trains on your requests.Anthropic's commercial terms state that it may not train models on customer content, and OpenRouter states that it does not use inputs or outputs for model training.
  • Anthropic deletes API inputs and outputs within 30 days of receiving or generating them, unless a longer period is separately agreed or required to enforce its usage policy.

The instructions we send along with your request are stored and versioned in a prompt-management service, Langfuse. The web app has them built in and never calls it. The iOS app fetches the current wording of an instruction before it asks the model — it reads a template and sends nothing: no trip content, no message of yours, no identifier.

AI output can be wrong. Opening hours, prices, travel times, entry requirements and safety information must be verified before you rely on them. See the Terms for what that means legally.

6. Who else processes your data

We keep the list short on purpose. Each acts as our service provider, under contract, and may use the data only to perform the service for us.

ProviderWhat they do for us
SupabaseDatabase, authentication, file storage and server functions
CloudflareWebsite hosting, the waitlist database, and network security
OpenRouterRouting our requests to the model
AnthropicGenerating itineraries and chat replies. Does not train on them, and deletes them within 30 days.
GoogleSign-in, if you choose it; place details and photos requested by our server, not your browser
UnsplashTrip cover photography, requested by our server
OpenStreetMapMap tiles and place lookup on the web. Tiles are loaded by your browser, so OpenStreetMap sees your IP address when a map is on screen.
AppleMaps, place search and on-device speech recognition in the iOS app. A nearby search sends the coordinate to Apple, under Apple's own privacy policy; dictation is transcribed on your phone.
LangfuseStores the wording of the instructions we give the model. The iOS app reads them; nothing you write is sent there.
SentryCrash and error reports from the app, with no account attached
PostHogWhich screens and buttons are used, without an identity. Screen replays with all text masked, in TestFlight builds only.
TelemetryDeckAnonymous counts of the same kind of events

We may also disclose information to comply with law, to respond to lawful requests, to enforce our terms, or in connection with a merger or sale of the business — in which case we will tell you before your information becomes subject to a different policy.

We link out to booking partners such as Booking.com and GetYourGuide. Following one of those links takes you to their site, under their terms and their privacy policy. We earn no commission on them today — the links carry a partner field, but no partner account is connected to it. If that changes we will say so here and label the links as paid.

7. Your choices

Whoever and wherever you are, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Write to ali@tripbuddyai.com. You can delete your account yourself from the app’s profile screen, and you can unsubscribe from any marketing email using the link in it.

California residents

Under the California Consumer Privacy Act, as amended by the CPRA, you may request to know what personal information we have collected, its sources, why we collected it and who we disclosed it to; request correction; request deletion; and opt out of the sale or sharing of your personal information.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We have not done so in the preceding twelve months, including with respect to anyone under 16.

The categories we collect, in CCPA terms, are: identifiers, including the details of anyone you add to a trip from your contacts; commercial information in the sense of trip planning activity; internet and network activity, including crash and usage diagnostics; approximate location derived from the places you add; audiovisual information, in the sense of photographs you attach yourself; and inferences we draw about your travel preferences in order to plan. We do not collect precise geolocation or any other sensitive personal information as those terms are defined, so there is no right to limit its use to exercise.

We will not discriminate against you for exercising any of these rights. You may use an authorised agent; we may ask you to verify that they act for you. We aim to respond within 45 days.

For completeness: the CCPA applies to businesses above certain thresholds — annual gross revenue over USD 26,625,000, or buying, selling or sharing the personal information of 100,000 or more California residents, or deriving half their revenue from selling or sharing it. We currently meet none of them, and we neither sell nor share. We honour the requests above regardless.

Other US states

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as they take effect — have broadly similar rights to access, correct, delete and obtain a portable copy of their data, and to opt out of targeted advertising, sale, and profiling with legal effects. We do none of those three. Use the same address above, and you may appeal a refusal by replying to our decision.

EEA, UK and Switzerland

We are based in the United States, but some of our users are not, and where the GDPR or UK GDPR applies to you, so do the following.

Our legal bases are: performance of a contract, for running your account, your trips and the AI planning; consent, for the waitlist announcement, which you can withdraw at any time; legitimate interests, for security, abuse prevention and fixing faults; and legal obligation where one applies.

You have the rights of access, rectification, erasure, restriction, portability and objection, and you may complain to a supervisory authority in the country where you live or work. Our database is in Frankfurt, so the bulk of what you create never leaves the EU; what does cross the Atlantic is the request sent to the AI model, and the ordinary server logs of our US-based hosting. Those transfers rest on the European Commission's Standard Contractual Clauses, which our database and hosting providers incorporate into their data processing terms, and additionally on the EU-US Data Privacy Framework where the provider is certified under it, as Cloudflare is.

We have not appointed a representative in the Union under Art. 27. The European Data Protection Board treats the mere accessibility of a website in the EU, an email address, or the use of a language customary in the provider’s own country as insufficient to show that a service is directed at people there. TripBuddy is offered in English, priced in US dollars, aimed at the US market, and does not target any EU country. We apply this section anyway.

8. Where your data is processed

Your account and everything you create is stored in the European Union, in Frankfurt, Germany (our database provider's eu-central-1 region). That is where your profile, trips, itineraries and messages live.

Three things happen elsewhere. Our website is served from a global network, so the server that answers you is the one nearest you. Requests to the AI model are processed in the United States. And place lookups and photography are fetched by our servers from providers that operate internationally.

9. How long we keep it

  • Waitlist address — until you unsubscribe or ask us to delete it.
  • Account and trip data — for as long as your account exists. Delete your account and it is removed, apart from anything we must retain by law.
  • Anonymous sessions — kept so you do not lose your work, and transferred to your account if you later sign up.
  • Server and security logs — our website host retains no HTTP request logs at all unless retention is switched on, which it is not. Database and platform logs are kept for one dayand are used for nothing else.

Content you shared with a group — an itinerary others have edited, for instance — may remain visible to that group after you leave it.

10. Children

TripBuddy is not directed to children under 13, and we do not knowingly collect personal information from them. If we learn that we have, we will delete it. If you believe a child has given us information, write to us. Where the country you live in sets a higher minimum age for using a service like this without a parent’s consent, that higher age applies to you instead.

11. Security

How we protect this data is described on the Security page, including what is not in place yet.

12. Changes

We will update this page when our practices change, and we will change the date at the top. If a change materially affects you, we will tell you in the app or by email before it takes effect.

13. Contact

Ferrox Industries LLC, 30 N Gould St, Ste 50693, Sheridan, WY 82801, USA ali@tripbuddyai.com