Privacy Policy
Last updated: August 17, 2026
Who we are
TripTov is operated by Intalyx LLC, 21110 Biscayne Blvd Ste 406, Aventura, FL 33180, United States. Intalyx LLC is the data controller for the personal data described below, and is the seller of record on the App Store and Google Play.
For anything about your data — questions, access, correction, deletion, or a complaint — triptov@intalyx.com reaches a real person.
1. What we collect
- Account info: your email address and password (password is hashed by our auth provider, never stored in plain text)
- Travel bookings you enter, paste, or forward: flights, hotels, car rentals, cruises, activities, and their attachments (PDFs/images)
- Passport numbers, driver’s license and insurance policy numbers, and similar identifiers — encrypted at rest, separately from the rest of the database
- Credit card metadata you choose to enter for coverage tracking: card name, network, and last 4 digits only — never a full card number
- Health insurance and auto insurance details you enter for coverage summaries
- Your home ZIP code, used only to determine your time zone for reminder emails
- Companion/traveler names and their travel documents, if you add them
- Push notification device tokens, if you enable notifications
- The content of emails you forward to your TripTov inbound address, including attachments
2. How we use it
To build and maintain your trip timeline, generate reminders, run the insurance/visa advisors you use, sync to Google Calendar if you connect it, and reply to emails you forward with a confirmation of what was filed. We do not use your data for advertising, and we do not sell it.
3. Why we’re allowed to process it
If you are in the EU, EEA or UK, the law asks us to name a legal basis for each thing we do with your data. Purpose by purpose:
- Running your account and itinerary (storing the bookings you add, building your trip timeline, sending reminders, syncing to Google Calendar when you connect it): performing our contract with you, the Terms of Service.
- AI processing (reading forwarded emails, documents and trip details with the AI service described in section 4): your consent, asked for explicitly in the app and withdrawable there at any time.
- Health-related insurance details (your health plan, and policy details that can reveal something about health): your explicit consent, given with the same AI-processing permission, used only to answer the coverage questions you ask.
- Security (sign-in codes, rate limits, the bot check on sign-up, the security log): our legitimate interest in keeping accounts safe.
- Marketing attribution: a first-party cookie (tt_src) remembers for 90 days which of our own links or posts brought you here, so that if you sign up we know which channel worked. It is shared with nobody and holds nothing about you personally: our legitimate interest in knowing whether our own marketing works.
- Analytics and advertising: no basis is needed, because there is none. TripTov runs no analytics or advertising processing at all.
4. AI processing — what is sent, to whom, and your permission
TripTov’s reading and advice features are powered by an AI service provided by Anthropic. When you use those features, this data leaves TripTov for Anthropic’s servers to be processed:
- The content of emails you forward or paste, including attachments — e-ticket PDFs, document photos such as passport scans, and insurance policy documents — so bookings and personal documents can be extracted and filed automatically. This includes any traveller names, confirmation codes and payment references those documents contain. Insurance policy documents can include information about health; allowing AI processing is your explicit consent for that too.
- Trip details and traveller citizenships — for visa and entry checks, packing suggestions, itinerary review, and embassy contact lookups.
- Phone-plan details from a forwarded bill — to check international coverage.
Nothing is sent without your permission. AI processing is off until you explicitly allow it in the app (Profile → AI processing), and every AI-powered feature — including reading the emails you forward — stays off until you do. You can withdraw the permission there at any time, and the features simply stop; your existing trips and data are unaffected.
Anthropic processes this data to answer each request on TripTov’s behalf, under its commercial terms: it does not use the data to train its models, and retains it only for a limited period for abuse monitoring (30 days by default, longer for content its safety systems flag). One exception involves no personal data at all: looking up the published benefits of a credit-card product (for example “Chase Sapphire Reserve”) sends only the card’s public name, never anything about you or your account.
5. Who else sees it (subprocessors)
TripTov runs on infrastructure from these providers, each processing only what’s needed for their function:
- Anthropic — the AI service described in section 4: reads forwarded/pasted confirmation text and attachments to extract structured booking data, and powers the visa/insurance/packing advisors. Only with your permission, which you can withdraw at any time.
- Resend — delivers outbound emails (reminders, receipts, sign-in codes) and receives your forwarded booking emails
- Apple — only if you choose Sign in with Apple: used to sign you in. We receive the name and email address you approve, and nothing else. If you use Apple’s Hide My Email, we only ever see the private relay address Apple gives us. Separately, if you enable notifications in the iPhone app, reminder text (for example a trip name and its deadline) is delivered through Apple’s push notification service.
- Google — if you choose Sign in with Google, to sign you in (we receive your name, email address and profile picture); only if you connect Google Calendar, to create and update events on a calendar in your Google account; and if you enable notifications in the Android app, reminder text is delivered through Google’s push notification service.
- Supabase — hosts the database, file storage, and authentication
- Vercel — hosts the application
- Cloudflare — checks that sign-ups come from a real person (the bot check described under Security) and stores our encrypted database backups
- GitHub — runs the weekly job that creates those encrypted backups
- OpenStreetMap / Nominatim — converts addresses to map coordinates for the trip map view
We don’t share your data with anyone else, including for marketing purposes.
6. Where the data goes (international transfers)
Intalyx LLC is a US company, and the providers in section 5 process data in the United States. If you are in the EU, EEA or UK, each transfer is covered by a recognised legal mechanism:
- Vercel, Resend, Cloudflare, GitHub and Google are certified under the EU-US Data Privacy Framework, including its UK extension.
- Supabase and Anthropic are not in the Data Privacy Framework; transfers to them are covered by the Standard Contractual Clauses built into their data-processing agreements.
If a provider’s certification ever lapses, we fall back to Standard Contractual Clauses or stop the transfer.
7. Affiliate links
Some links in TripTov — to travel insurance, eSIM data plans, activities, flight-compensation claim services and similar — are affiliate links, and we may earn a commission if you buy or claim through one. What that means for your data:
- We don’t send them anything personal. A link may carry the basics needed to pre-fill a quote — where you’re going, your travel dates, and how many people are travelling. Never your name, email address, passport number, policy numbers, card details, or who you’re travelling with.
- You leave TripTov when you follow one. From that point you’re on the partner’s own site, under their privacy policy and their terms, not ours. Anything you type there — including payment details — goes to them and never passes through TripTov.
- What comes back to us is a count, not a customer. The partner tells us that a purchase happened so the commission can be paid. We don’t receive your name, what you bought, or what you paid.
- No trackers. TripTov runs no advertising or analytics scripts, and no third-party code from these partners runs inside the app — including tools they offer for exactly that purpose. The one piece of outside code we do load is a bot check on the sign-up page; it is described under Security below, and it is not advertising or analytics.
8. Security
Passport numbers, license numbers, policy numbers, and similar identifiers are encrypted at rest. Uploaded documents are stored in a private bucket, never publicly accessible. Every table in our database is access-controlled so only your own account can read or write your rows. Signing in with a password also requires a verification code sent to your email address. If you sign in with Apple or Google instead, they perform that second check themselves and we do not send a separate code.
Bot check on sign-up. The account creation page runs Cloudflare Turnstile, which confirms a real person is filling the form rather than a script creating accounts in bulk. It loads code from Cloudflare and shares your IP address and basic browser signals with them for that check alone. Turnstile is a security tool, not an advertising or analytics product — it does not track you across websites and does not build a profile. It runs only on the sign-up page and nowhere else in the app.
9. How long we keep it, and what deletion really does
We keep your data as long as your account exists. Deleting your account (Profile → Settings → Data & account) removes it from our live systems right away — trips, bookings, travel companions, coverage details, uploaded documents, our copies of the emails you forwarded, and the history of changes made to any of it. This cannot be undone.
One honest detail about backups. We keep encrypted weekly backups of the whole database so a disaster cannot destroy everyone’s data at once. Your data stays inside already-made backups until they expire, which takes up to eight weeks. Backups are encrypted, nothing reads individual accounts out of them in normal operation, and we never use them to bring deleted data back. Once the last backup from before your deletion expires, nothing of your account remains.
A few operational records also run on their own clocks while your account exists: archived copies of the emails you forwarded are removed after 180 days, the change history we keep for troubleshooting after 180 days, and server error logs after 30 days. The first two are deleted immediately when you delete your account; server error logs age out on their own 30-day clock.
Two things are kept on purpose, and neither describes your travel. We keep a dated line recording that a deletion was requested and carried out, including the email address that asked — that is our proof we honoured the request. And for every email you forwarded us we keep its identifier and nothing else — no sender, no subject, no content — so a re-delivered copy of an old email can’t be processed again after you’re gone. Server error logs can also mention an account until they age out on the 30-day clock above.
10. People you add who don’t have accounts (companions)
If you add travel companions, we hold what you chose to enter about them: their name, date of birth if you gave it, passport details, and, if you added them, health-plan or policy details, so the app can answer whether a trip covers the people actually going, not just you.
This information exists only inside your account. It is never shown to other users, not even to collaborators you invite to a trip; it is never used for anything except answering your own trip questions; and the sensitive parts (passport numbers, member ids) are encrypted at rest like your own. It is deleted when you remove the companion or delete your account, on the same schedule as everything else in section 9.
We cannot notify the people you add, because we hold no way to reach them; collecting their email address just to send a notice would mean holding more about them, not less. So this section is the notice. If someone has added you to a TripTov account and you want to know what is held, have it corrected, or have it removed, email triptov@intalyx.com. You have the same rights over data about you as an account holder does, including the complaint route in section 11.
11. Your rights
You can download a full export of your data at any time, and permanently delete your account, both from Profile → Settings → Data & account. Depending on where you live, you may have additional rights (e.g. under GDPR or CCPA) to access, correct, or restrict processing of your data — contact us to exercise them.
If you are in the EU, EEA or UK and you think we have handled your data wrongly, you also have the right to complain to a data protection authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). In the EU or EEA it is the supervisory authority of the country you live in; the European Data Protection Board publishes the full list at edpb.europa.eu. You can complain without contacting us first, though we would rather you gave us the chance to put it right.
12. Children
TripTov is not intended for children under 16, and we don’t knowingly collect data from them.
13. Changes
We’ll flag material changes to this policy in the app.
14. Contact
Questions or data requests: triptov@intalyx.com, or write to Intalyx LLC, 21110 Biscayne Blvd Ste 406, Aventura, FL 33180, United States.