Privacy Policy AItinerary
Effective date: November 15, 2026
Last updated: November 15, 2026
This Privacy Policy explains how AItinerary ("AItinerary", "we", "us") collects, uses, and shares information about you when you use the AItinerary iOS application (the "App"). We designed the App to keep your travel plans private by default most of your data lives locally on your device or in your personal iCloud and is never sent to us.
If you don't agree with this Policy, please don't use the App.
Who we are
AItinerary is operated by Karim El Mansouri, an individual sole proprietor based in Casablanca, Morocco, postal address 42 Rue des Voyageurs, Quartier Maarif, 20330 Casablanca, Morocco.
We comply with Moroccan Law 09-08 on personal data protection (overseen by the CNDP Commission Nationale de Contrle de la Protection des Donnes Caractre Personnel). For users in the European Union / United Kingdom we apply the GDPR / UK GDPR. For users in California we apply the CCPA / CPRA. Where local laws grant you stronger rights than this policy, your local rights apply.
For any privacy question, reach us at wordcruz5@gmail.com.
What we collect
2.1 Data stored locally on your device (and in your iCloud)
The following information never leaves your device unless you explicitly share it (e.g. by sending a trip image to a friend, inviting a guest to co-edit a trip, or contacting support):
Trip details destination, dates, trip type, theme color, budget total + currency, checklist, documents you attach, activities you add to the timeline (including their "visited" check), guests you list, your home airport, and any notes / free-text fields.
Reservations flights (with their booking URLs), hotels, and transport you imported or picked via Google Flights / partner links.
Photos and documents you attach receipts, e-tickets, hotel confirmations, passport scans. Stored in the App's private document directory.
AI conversation history when you chat with the in-app AI travel buddy, the conversation is saved on-device per trip so context survives relaunch. You can clear it from inside the chat.
Generated content AI-built itineraries and city guides, cached on the trip so re-opening is instant.
Your preferences language, appearance (Light/Dark/Auto), notification on/off switch, travel-style answers from onboarding, passport country, departure airport, and your preferred display currency.
All of the above is stored in iOS's UserDefaults, the App's sandboxed file system, and (when you have iCloud enabled on the device) Apple's CloudKit private container iCloud.com.tripway.planner. We do not have access to that CloudKit container only Apple does. Deleting the App, or wiping data via Settings Privacy & Data Delete all my data, removes both the local and the iCloud copies.
2.2 Data sent to third-party services
Some features require us to send a minimal amount of data to third parties to function. We never send your name, email, account identifier, or precise location only the specific query needed for the feature.
Receipt OCR local pass: The receipt photo stays on your device via Apple Vision Framework (on-device). First-tier OCR no data leaves the device.
Receipt OCR fallback: The receipt photo is sent to OpenAI (United States) only when local OCR fails or confidence is low, to auto-fill the expense form.
Reservation parsing: Reservation photo processed via Apple Vision first, then OpenAI as fallback, to auto-fill flight / hotel import forms.
AI plan generation, chat: Destination, dates, trip type, prompt text, conversation history sent to OpenAI (US) to generate itineraries, replies, place descriptions.
City guide: Destination city + country, your passport country code sent to OpenAI (US) to generate visa rules, must-see places, things to avoid.
Hotel search: Destination coordinates + your search text sent to Google Places API (US) to find real hotels with photos.
Place photos: Place name + city sent to Google Places API; Apple MapKit Look Around as a fallback. Used to display photos on timeline cards and recommendations.
Flight search: Origin + destination + dates loaded inside an in-app browser via Google Flights (WKWebView). Google's own cookies + tracking apply inside that browser session.
Currency conversion: Two currency codes (e.g. "EUR" "USD") sent to Frankfurter API (ECB rates, no key required).
iCloud trip sharing: Encrypted trip data via Apple CloudKit Sharing for real-time co-editing with guests you explicitly invite.
Subscription: Apple ID transaction info via Apple StoreKit. Apple, not us, sees your payment info.
Push notifications: Device push token + reminder time via Apple Push Notification Service to surface trip reminders.
These services may log requests according to their own privacy policies. We don't receive personally-identifying information back from any of them.
Data transfers outside Morocco. OpenAI and Google are based in the United States. Apple operates servers worldwide. By using the relevant features you acknowledge that the data described above may be processed outside Morocco / the EU. Apple and Google self-certify under the EU-U.S. Data Privacy Framework; OpenAI provides Standard Contractual Clauses on request.
Outbound links to booking partners When you tap Booking.com, Airbnb, Hostelworld, or the "Rserver" pill on a saved flight, you leave the App and the destination service's own policy applies. We don't receive anything back from those services.
2.3 Data we don't collect
We have no servers, no accounts, no analytics SDK (no Firebase, no Mixpanel, no Sentry, no Amplitude, no Branch nothing).
We do not track you across apps or websites.
We do not sell or rent any data, ever.
We do not access your contacts, calendar, microphone, precise GPS location, health data, or HomeKit unless you specifically tap a feature that uses one of them (and iOS will prompt you separately).
How we use information
We use the information described above only to:
Run the features you tap: build itineraries, scan receipts, fetch hotel and place photos, generate AI plans + guides, etc.
Persist your trips between launches.
Sync your trips across your Apple devices via iCloud.
Share a trip with a guest you explicitly invite (Apple's CloudKit Sharing).
Convert prices into your preferred display currency.
Send local notifications you've opted in to ("flight in 24 h", "next stop in 1 h", "trip starts tomorrow"). These are scheduled on your device they never go through a server we control.
Process subscription payments via Apple.
Respond to support emails you send us.
We do not:
Sell your data.
Run targeted ads.
Build user profiles for marketing.
Share your trip content with anyone other than the guests you invite.
Permissions we ask for
iOS requires us to explicitly ask before accessing each of these. You can revoke any permission at any time in Settings AItinerary.
Photo Library to attach photos to receipts, documents, or activities. We never scan your full library.
Camera to scan receipts and capture reservation photos. The image stays on-device unless local OCR fails, in which case it's sent to OpenAI for that one call.
Notifications to schedule local reminders for your trip. No remote push servers are involved unless you enable trip sharing (which uses Apple's silent push to notify guests of changes).
Location (When-In-Use) optional. Used only to compute "distance to next activity" on your timeline, so you can spot tight transitions.
iCloud to sync your trips across your Apple devices and enable trip sharing.
Children
AItinerary is not directed at children under 13 (or the equivalent minimum age in your country 16 in some EU member states under GDPR). We don't knowingly collect data from anyone under 13. If you believe a child has used the App, contact wordcruz5@gmail.com and we'll delete any associated data.
Your rights
Regardless of where you live, you can:
Access the data the App holds about you it's all in the App; tap any trip to read it.
Correct any field by editing it in the App.
Export a trip via the share sheet (timeline image / calendar .ics).
Delete any item (activity, expense, checklist row) individually, or wipe everything via Settings Privacy & Data Delete all my data.
If you're in the European Union, United Kingdom, or Switzerland: You also have the rights granted by the GDPR / UK GDPR: data portability, restriction of processing, objection to processing, and the right to lodge a complaint with your local supervisory authority (e.g. CNIL in France, ICO in the UK, FDPIC in Switzerland).
If you're in California: You have the rights granted by the CCPA / CPRA: right to know what categories of personal information we collect, right to deletion, right to opt out of "sale" or "sharing" (we don't sell or share there's nothing to opt out of), and the right not to be retaliated against for exercising any right.
If you're in Morocco: You have the rights granted by Law 09-08: access, rectification, opposition, and the right to lodge a complaint with the CNDP (cndp.ma).
To exercise any right, write to wordcruz5@gmail.com. We respond within 30 days.
Data retention
On-device data: kept until you remove the trip or delete the App.
iCloud data: lives in your private CloudKit container until you delete the trip, wipe via Settings Privacy & Data, or remove the container from your iCloud Settings.
Shared-trip data: when you invite a guest, the trip moves to a CloudKit shared zone the guest can read (and optionally edit). Removing a guest revokes their access; deleting the shared trip removes it for everyone.
Third-party query logs (OpenAI, Google, etc.): governed by each service's policy. We don't store these logs ourselves. Per OpenAI's API terms, API content is not used to train their models and is retained up to 30 days for abuse monitoring before deletion.
Subscription receipts: kept by Apple; we read but don't store them.
Security
All network requests use HTTPS / TLS.
Your trip data sits in iOS's sandboxed App Container and (when synced) in Apple's CloudKit, encrypted at rest by Apple.
We don't operate any backend servers, so there's no central store to breach.
iCloud-stored data (including shared trips) is encrypted in transit and at rest by Apple.
No system is perfectly secure, but the minimal-data architecture means there is very little for an attacker to target.
International transfers
Some third parties we send queries to (e.g. OpenAI in the US, Google in the US) are located outside Morocco / the EU. By using the relevant feature you acknowledge that the necessary information for that feature is processed in those countries. We've reviewed each provider's terms including their Standard Contractual Clauses where applicable.
Changes to this Policy
We may update this Policy from time to time. If we make a material change, we'll notify you inside the App before the change takes effect. Continued use after the change means you accept the updated Policy.
Contact
For any question or request about your data, write to:
We respond within 14 days for GDPR/CCPA requests and within 30 days for Law 09-08 requests.
Data controller: Karim El Mansouri, 42 Rue des Voyageurs, Quartier Maarif, 20330 Casablanca, Morocco
App version covered: AItinerary 1.0+
For privacy complaints in Morocco: CNDP cndp.ma
For privacy complaints in the EU: your national supervisory authority
For privacy complaints in the UK: ICO ico.org.uk
This document is a good-faith policy tailored to AItinerary's actual data practices. It is not a substitute for legal advice have a lawyer in your jurisdiction review it before shipping.