1. Scope and principles
This Policy applies to personal information handled by the Tu Voyage Service. Tu Voyage handles only information needed to provide the Service, does not build advertising profiles, and does not sell personal information.
Information entered in a trip room can be visible to collaborators. Optional location, photo and push features are handled only when you enable the feature or grant the relevant permission.
2. Information handled
- Account: Google or Apple account identifier, email (including an Apple private-relay address), display name, Google profile photo URL, internal user id, policy versions and consent times
- Authentication and device: hashed Tu Voyage refresh tokens, encrypted Apple refresh token, session times, Firebase push token, platform and language
- Trip collaboration: trip name, destination, dates and notes; places, coordinates and routes; stays; bookings, attachments and confirmation codes; comments, votes, packing; expenses, shares and settlements
- Photos: the file, file name, type, size, caption, capture date/time and location read from the photo when present
- Optional live location: current latitude/longitude, accuracy, battery level and report time. No track is kept; one latest position overwrites the previous one
- Operations: IP address, request time and path, browser/device information, error and security logs. The map glyph and sprite CDN receives the device IP and requested path directly
3. How information is collected
Information comes from Google or Apple sign-in with your permission, what you enter or upload, optional device permissions for location/photos/push, and minimum operational logs created while the Service runs. Apple may provide the name only with the first authorization.
Another traveller may provide related information by inviting you or naming you in a collaborative record.
4. Purposes
- Authenticate accounts, maintain profiles and sessions, and prevent abuse
- Synchronize trip rooms and provide invitations, sharing, itinerary, maps, routing, stays, bookings, expenses, packing and photos
- Show current location to selected collaborators and provide arrival and device notifications
- Display the self-hosted default map, look up places, transit and weather, and provide a read-only AI itinerary review and an email-to-booking draft when selected
- Investigate errors, keep the Service reliable, and answer access, export and closure requests
- Meet legal obligations and respond to disputes and security incidents
5. Legal bases
Account, trip collaboration and security processing is based on providing the Service you request and performing the related contract, legitimate interests in protecting accounts and diagnosing failures, and applicable legal obligations. Optional location/device permissions and AI booking-email reading run only when you enable the feature or select it for that request.
Where Korea's Personal Information Protection Act applies, the basis for each overseas transfer is stated per transfer in the table in section 8. Blanket Service consent does not replace a transfer-specific basis.
6. Visibility to people and public links
Members of the same trip room can see your display name and the itinerary, comments, votes, bookings, expenses, settlements, packing and photos shared in that room. Captured photo coordinates are visible only when separately included at upload. Current location is visible only while you explicitly share it in that room.
A public share link exposes the trip summary shown by the link without sign-in. Treat it as a secret URL and revoke it when no longer needed.
7. Processing consignment and external services
The table below is every recipient to which Tu Voyage entrusts processing or sends personal information. Data is sent over HTTPS when you use the feature or the server makes the request. A public API called without a contract is a recipient rather than a processor, and its row says so beside the name.
A new processor or a wider entrusted task changes this table and the policy version first.
| Processor or receiving service (legal name) | Country | Entrusted work | Items sent | Basis | Retention | Erasure route |
|---|---|---|---|---|---|---|
| OVH US LLC | United States (Oregon region) | API, database and Redis server hosting | Account, profile and trip collaboration data; IP, request time and path; error and security logs | Contract · legitimate interests | Content until account/record deletion; container logs rotate at 10MB × 3 files; database backups for at most 35 days | Account/record deletion, log rotation, backup expiry |
| Cloudflare, Inc. (R2 object storage) | United States (bucket placement auto) | Storing and serving photos and booking attachments | The file itself, file name, type and size | Contract | Until the record is deleted | Deletion queue when the record is deleted |
| Google LLC (sign-in and Firebase Cloud Messaging) | United States | Verifying sign-in and delivering push notifications | Account identifier, email, display name, profile photo URL, push token and notification content | Contract | Per Google's policy | Device unregistration, account deletion and Google's procedure |
| Google LLC (Places and Routes) | United States | Place and address search and travel times (in deployments configured with that key) | Query text, the search's reference coordinates, origin/destination coordinates | Requested optional feature (contract) | Per Google's policy | Provider procedure |
| Apple Inc. | United States | Verifying Apple sign-in and revoking authorization on closure | Apple identifier, email or private-relay address, name on first authorization, authorization code and tokens | Contract | While the link exists | Apple token revoked before account closure |
| Kakao Corp. | Republic of Korea | Korean place and address search | Query text, the search's reference coordinates | Requested optional feature (contract) | Per the provider's log policy | Provider procedure |
| Kakao Mobility Corp. | Republic of Korea | Korean driving-route calculation | Origin and destination coordinates | Requested optional feature (contract) | Per the provider's log policy | Provider procedure |
| ODsay LAB Inc. | Republic of Korea | Korean transit-route calculation | Origin and destination coordinates, transport constraints | Requested optional feature (contract) | Per the provider's log policy | Provider procedure |
| Geoapify GmbH | Germany | Place and address search, opening hours, and driving/walking times outside Korea | Query text, the search's reference coordinates, the Geoapify identifier of a saved place, origin/destination coordinates (no account identifier is sent) | Requested optional feature (contract) | Per the provider's request-log policy | Provider procedure |
| Tailscale Inc. | Canada (Toronto) | Relaying the private-network connection to the AI server | Node and device identifiers and connection metadata (request bodies are end-to-end encrypted and not delivered to it) | Contract | Per the provider's policy | Remove the node |
| Tu Voyage's own Ollama server (a computer in the operator's home; not a third-party processor) | Canada (Ontario) | AI itinerary review and, when selected, booking-email reading | Itinerary context and, when selected, booking-email source text and trip dates | Per-request choice (contract) | Handled only for the request and response; not written to the database | Discarded when the request ends |
| FOSSGIS e.V. — the public Overpass API instance overpass-api.de (public API, no contract) | Germany | Looking up opening hours and admission conditions | Place coordinates and place name | Requested optional feature (legitimate interests) | Per the provider's log policy | Tu Voyage keeps no separate copy |
| OpenMeteo GmbH (public API, no contract) | Switzerland | Weather for the trip's reference coordinates | The trip's reference coordinates | Contract | The provider publishes a 90-day log retention | Tu Voyage keeps no separate copy |
| Wikimedia Foundation, Inc. — Wikidata (public API, no contract) | United States | Matching a saved place name to a differently named feature | Place name | Requested optional feature (legitimate interests) | Per the provider's policy | Tu Voyage keeps no separate copy |
| GitHub, Inc. — the protomaps.github.io glyph and sprite CDN (public CDN, no contract) | United States | Delivering map fonts and icons | Browser IP and requested path | Contract | Per the provider's policy | Tu Voyage keeps no separate copy |
| Public tourism and park data APIs — Korea Tourism Organization TourAPI, U.S. National Park Service, Recreation.gov RIDB (public APIs, no contract) | Republic of Korea · United States | Looking up attraction and park information (in deployments configured with that key) | The search's reference coordinates and area codes | Requested optional feature (legitimate interests) | Per the provider's policy | Tu Voyage keeps no separate copy |
8. Overseas transfers
These recipients from section 7 are located outside the Republic of Korea. The columns are the notice items required by Article 28-8(2) of Korea's Personal Information Protection Act.
Every row relies on Article 28-8(1)3: processing consignment or storage necessary to perform the contract and improve convenience, disclosed through this Policy. No transfer currently requires separate consent. To refuse a transfer, do not use the feature or close the account; each row states the effect.
| Recipient (name and contact) | Items transferred | Country · timing and method | Purpose and retention | Basis for transfer | How to refuse, and the effect |
|---|---|---|---|---|---|
| OVH US LLC · us.ovhcloud.com/legal/privacy-policy/ | Account, profile and trip collaboration data; IP, request time and path; error and security logs | United States (Oregon) · continuously while you use the Service, over HTTPS and stored in that region | API and database hosting and incident response · content until account/record deletion, backups for at most 35 days | PIPA Article 28-8(1)3 (consignment/storage necessary to perform the contract, disclosed in this Policy) | Close the account · the Service cannot be used |
| Cloudflare, Inc. · cloudflare.com/privacypolicy/ | Photos and booking attachments with file name, type and size | United States (bucket placement auto) · over HTTPS on upload and retrieval | File storage and delivery · until the record is deleted | PIPA Article 28-8(1)3 | Do not upload photos or attachments · that feature cannot be used |
| Google LLC · policies.google.com/privacy | Account identifier, email, display name, profile photo URL, push token and notification content, place queries and coordinates | United States · over HTTPS on sign-in, notification and place-search requests | Sign-in verification, push delivery, place and route lookups · per Google's policy | PIPA Article 28-8(1)3 | Sign in with Apple, and do not use notifications or place search · those features cannot be used |
| Apple Inc. · apple.com/legal/privacy/ | Apple identifier, email or private-relay address, name on first authorization, authorization code and tokens | United States · over HTTPS on sign-in, linking and revocation | Apple sign-in verification and revocation · while the link exists | PIPA Article 28-8(1)3 | Sign in with Google · Apple sign-in cannot be used |
| Geoapify GmbH · geoapify.com/privacy-policy/ | Query text, the search's reference coordinates, the Geoapify identifier of a saved place, origin/destination coordinates | Germany · over HTTPS on search, detail and route requests outside Korea | Place and address search, opening hours, travel times · per the provider's request-log period | PIPA Article 28-8(1)3 | Do not search for places outside Korea · results in those regions are reduced |
| Tailscale Inc. · tailscale.com/privacy-policy | Node and device identifiers and connection metadata | Canada (Toronto) · while an AI request crosses the private network | Relaying the connection to the AI server · per the provider's policy | PIPA Article 28-8(1)3 | Do not use AI features · AI itinerary review and booking-email reading cannot be used |
| Tu Voyage's own Ollama server (the operator) · seonghyunhan7193@gmail.com | Itinerary context and, when selected, booking-email source text and trip dates | Canada (Ontario) · over the Tailscale private network on an AI request | AI itinerary review and booking-email reading · handled only for the request and response, not stored | PIPA Article 28-8(1)3 | Do not select AI reading · you get the rules-only draft and fill missing fields yourself |
| FOSSGIS e.V. (overpass-api.de) · fossgis.de | Place coordinates and place name | Germany · over HTTPS when opening hours or admission are looked up | Opening-hours and admission lookup · per the provider's log period | PIPA Article 28-8(1)3 | Do not look up opening hours for that place · opening hours stay empty |
| OpenMeteo GmbH · open-meteo.com/en/terms | The trip's reference coordinates | Switzerland · over HTTPS when weather is requested | Weather for the trip dates · the provider publishes a 90-day log retention | PIPA Article 28-8(1)3 | Do not use the weather view · weather is not shown |
| Wikimedia Foundation, Inc. · foundation.wikimedia.org/wiki/Policy:Privacy_policy | Place name | United States · over HTTPS when matching a differently named feature | Place-name matching · per the provider's policy | PIPA Article 28-8(1)3 | Do not open that place's detail · some place details are reduced |
| GitHub, Inc. (protomaps.github.io) · docs.github.com/site-policy | Browser IP and requested path | United States · requested directly by the browser when a map opens | Delivering map fonts and icons · per the provider's policy | PIPA Article 28-8(1)3 | Do not use map views · the map cannot be shown |
| U.S. National Park Service · Recreation.gov (RIDB) · nps.gov/aboutus/privacy.htm | The search's reference coordinates and area codes | United States · over HTTPS when U.S. park information is requested | Park and campground lookup · per the provider's policy | PIPA Article 28-8(1)3 | Do not search U.S. parks · those results are reduced |
9. External APIs that receive no personal information, and data sources
- Exchange rates: Frankfurter (api.frankfurter.dev) and ER-API (open.er-api.com) receive only currency codes and a date. No user, trip or coordinate is sent.
- Place data: an Overture Maps distribution is downloaded and loaded on the server in advance. Your queries and coordinates are not sent to the Overture Maps Foundation.
- Default map: OpenStreetMap-based Protomaps tiles are self-hosted on the server. Only fonts and icons come from the protomaps.github.io CDN, and that request appears in the section 7 table.
- Attribution: OpenStreetMap contributors, Overture Maps Foundation and Protomaps. Full licences are at /licenses.
10. AI processing
The AI itinerary coach sends requested itinerary context to the Ollama server. For booking email, the server uses rules first and sends the source text and trip dates to that server only if the rules are insufficient and you selected AI reading for that request. If not selected, no model call occurs; the rules-only draft remains available and missing fields can be entered manually.
That Ollama server is a computer in the operator's home in Ontario, Canada, reachable only over the Tailscale private network. No third-party AI API is used, and what is sent is not used to train a model. The source text and AI result are transient request/response data before a booking is saved and are not written to the application database. The result is advisory and makes no significant automated decision.
11. Retention and deletion
- An account that does not complete its profile and required legal steps is retained for seven days after creation and then automatically deleted. Deletion ends sessions, removes external-login information, revokes Apple authorization, and retries failed external revocation and file deletion.
- Account, profile and consent records: while the account is active. On closure, directly identifying login/profile information is removed; a consent record may remain with the pseudonymous account id where needed for compliance
- Closure: personal journals, comments, votes, activity, invitations, public links, and files uploaded by the account are deleted. Shared ledgers and change history retain only amounts, currencies, dates, status and opaque participant IDs needed for totals and dispute traceability; titles, notes, reasons and change snapshots are erased. Shared bookings retain schedule fields while confirmation codes, notes and files are erased
- A shared ledger in an active trip room is retained until that room is deleted. Cancellation and dispute audit evidence is kept for at least 90 days after the event and no longer than 24 months after the last ledger change. A documented actual-dispute hold lasts until resolution and is deleted 24 months after resolution, unless qualified review identifies a different applicable requirement or lawful order and records its end date
- Automatic check-in: the device monitors arrival near itinerary stops even while the app is closed. Raw location is not sent to the server; after the app presents the arrival, only the resulting check-in is synchronized as an ordinary itinerary change. Turning the feature off or letting the geofence expire ends the monitoring
- Live location: hidden after 15 minutes, deleted when sharing is turned off (with safe retries), and otherwise removed on a later room read after no more than 24 hours. A changed room membership requires recipient review and renewed consent
- Push token: until device unregistration, account closure, or Firebase reports it invalid
- Server/security logs: production Compose rotates three 10MB files per container. No external log collection service is used, and application log messages do not include request bodies or booking-email source text
- Database backups are kept for at most 35 days and application, proxy and security logs for at most 30 days. Withdrawals and deletions are replayed before a restored service reopens. Only a legal obligation or actual dispute may be separately retained with recorded purpose, end date and access
12. Your choices and rights
The account page lets you export your data, edit or remove content, sign out every device, or close the account. Location sharing and photo/notification permissions can be turned off in the app and device settings.
Request access, correction, deletion, restriction, consent withdrawal, or raise a complaint at seonghyunhan7193@gmail.com. Tu Voyage will verify the requester and respond within the time required by applicable law.
14. Safeguards
Safeguards include HTTPS, key-only SSH, hashed refresh tokens, access-restricted secret files, isolated database/container networks and bounded logs. AI traffic travels only over a Tailscale private network, and the Ollama server at the other end is in the operator's home in Ontario, Canada.
No system can be guaranteed completely secure. Report a suspected incident to the contact email. Breaches subject to notification duties will be reported to the relevant authority and affected people.
15. Children
The Service does not currently support people under 14 or guardian-consent sign-up. A person must confirm they are at least 14 before information is sent to Google or Apple; the exact birth date is not stored for this check.
If child information is discovered, a guardian can send the account identifier and evidence of their relationship to the privacy contact. The operator will restrict access, delete the account, sessions, external-login information and uploaded files through the existing closure process, and record and verify provider revocation and deletion-queue completion.
16. Privacy officer
Article 31 of Korea's Personal Information Protection Act requires a designated, published privacy officer who oversees personal-information handling and handles complaints and remedies. That officer is:
- Name: Seong Hyun Han
- Position: operator (Tu Voyage is personally operated)
- Email: seonghyunhan7193@gmail.com
- Responsibilities: overall personal-information handling, access/correction/deletion/suspension requests, complaints and remedies, and breach response
17. Changes and contact
A material change to purposes, sensitive information or providers will update the effective date and version and request renewed consent when required. Previous versions are available on request.
Privacy questions and rights requests: Seong Hyun Han, seonghyunhan7193@gmail.com. Korean users may also contact the Korea Internet & Security Agency privacy centre (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), and anyone may contact the privacy regulator where they live.