Tu Voyage 한국어

Version 2026-09-16-providers-1

Tu Voyage Privacy Policy

What Tu Voyage handles, why, who can see it, and how you can control it.

Effective
September 16, 2026
Privacy officer
Seong Hyun Han (operator) — the individual operator in Ontario, Canada
Questions and rights requests
seonghyunhan7193@gmail.com
1. Scope and principles2. Information handled3. How information is collected4. Purposes5. Legal bases6. Visibility to people and public links7. Processing consignment and external services8. Overseas transfers9. External APIs that receive no personal information, and data sources10. AI processing11. Retention and deletion12. Your choices and rights13. Cookies and device storage14. Safeguards15. Children16. Privacy officer17. Changes and contact

1. Scope and principles

This Policy applies to personal information handled by the Tu Voyage Service. Tu Voyage handles only information needed to provide the Service, does not build advertising profiles, and does not sell personal information.

Information entered in a trip room can be visible to collaborators. Optional location, photo and push features are handled only when you enable the feature or grant the relevant permission.

2. Information handled

  • Account: Google or Apple account identifier, email (including an Apple private-relay address), display name, Google profile photo URL, internal user id, policy versions and consent times
  • Authentication and device: hashed Tu Voyage refresh tokens, encrypted Apple refresh token, session times, Firebase push token, platform and language
  • Trip collaboration: trip name, destination, dates and notes; places, coordinates and routes; stays; bookings, attachments and confirmation codes; comments, votes, packing; expenses, shares and settlements
  • Photos: the file, file name, type, size, caption, capture date/time and location read from the photo when present
  • Optional live location: current latitude/longitude, accuracy, battery level and report time. No track is kept; one latest position overwrites the previous one
  • Operations: IP address, request time and path, browser/device information, error and security logs. The map glyph and sprite CDN receives the device IP and requested path directly

3. How information is collected

Information comes from Google or Apple sign-in with your permission, what you enter or upload, optional device permissions for location/photos/push, and minimum operational logs created while the Service runs. Apple may provide the name only with the first authorization.

Another traveller may provide related information by inviting you or naming you in a collaborative record.

4. Purposes

  • Authenticate accounts, maintain profiles and sessions, and prevent abuse
  • Synchronize trip rooms and provide invitations, sharing, itinerary, maps, routing, stays, bookings, expenses, packing and photos
  • Show current location to selected collaborators and provide arrival and device notifications
  • Display the self-hosted default map, look up places, transit and weather, and provide a read-only AI itinerary review and an email-to-booking draft when selected
  • Investigate errors, keep the Service reliable, and answer access, export and closure requests
  • Meet legal obligations and respond to disputes and security incidents

5. Legal bases

Account, trip collaboration and security processing is based on providing the Service you request and performing the related contract, legitimate interests in protecting accounts and diagnosing failures, and applicable legal obligations. Optional location/device permissions and AI booking-email reading run only when you enable the feature or select it for that request.

Where Korea's Personal Information Protection Act applies, the basis for each overseas transfer is stated per transfer in the table in section 8. Blanket Service consent does not replace a transfer-specific basis.

6. Visibility to people and public links

Members of the same trip room can see your display name and the itinerary, comments, votes, bookings, expenses, settlements, packing and photos shared in that room. Captured photo coordinates are visible only when separately included at upload. Current location is visible only while you explicitly share it in that room.

A public share link exposes the trip summary shown by the link without sign-in. Treat it as a secret URL and revoke it when no longer needed.

7. Processing consignment and external services

The table below is every recipient to which Tu Voyage entrusts processing or sends personal information. Data is sent over HTTPS when you use the feature or the server makes the request. A public API called without a contract is a recipient rather than a processor, and its row says so beside the name.

A new processor or a wider entrusted task changes this table and the policy version first.

Processor or receiving service (legal name)CountryEntrusted workItems sentBasisRetentionErasure route
OVH US LLCUnited States (Oregon region)API, database and Redis server hostingAccount, profile and trip collaboration data; IP, request time and path; error and security logsContract · legitimate interestsContent until account/record deletion; container logs rotate at 10MB × 3 files; database backups for at most 35 daysAccount/record deletion, log rotation, backup expiry
Cloudflare, Inc. (R2 object storage)United States (bucket placement auto)Storing and serving photos and booking attachmentsThe file itself, file name, type and sizeContractUntil the record is deletedDeletion queue when the record is deleted
Google LLC (sign-in and Firebase Cloud Messaging)United StatesVerifying sign-in and delivering push notificationsAccount identifier, email, display name, profile photo URL, push token and notification contentContractPer Google's policyDevice unregistration, account deletion and Google's procedure
Google LLC (Places and Routes)United StatesPlace and address search and travel times (in deployments configured with that key)Query text, the search's reference coordinates, origin/destination coordinatesRequested optional feature (contract)Per Google's policyProvider procedure
Apple Inc.United StatesVerifying Apple sign-in and revoking authorization on closureApple identifier, email or private-relay address, name on first authorization, authorization code and tokensContractWhile the link existsApple token revoked before account closure
Kakao Corp.Republic of KoreaKorean place and address searchQuery text, the search's reference coordinatesRequested optional feature (contract)Per the provider's log policyProvider procedure
Kakao Mobility Corp.Republic of KoreaKorean driving-route calculationOrigin and destination coordinatesRequested optional feature (contract)Per the provider's log policyProvider procedure
ODsay LAB Inc.Republic of KoreaKorean transit-route calculationOrigin and destination coordinates, transport constraintsRequested optional feature (contract)Per the provider's log policyProvider procedure
Geoapify GmbHGermanyPlace and address search, opening hours, and driving/walking times outside KoreaQuery text, the search's reference coordinates, the Geoapify identifier of a saved place, origin/destination coordinates (no account identifier is sent)Requested optional feature (contract)Per the provider's request-log policyProvider procedure
Tailscale Inc.Canada (Toronto)Relaying the private-network connection to the AI serverNode and device identifiers and connection metadata (request bodies are end-to-end encrypted and not delivered to it)ContractPer the provider's policyRemove the node
Tu Voyage's own Ollama server (a computer in the operator's home; not a third-party processor)Canada (Ontario)AI itinerary review and, when selected, booking-email readingItinerary context and, when selected, booking-email source text and trip datesPer-request choice (contract)Handled only for the request and response; not written to the databaseDiscarded when the request ends
FOSSGIS e.V. — the public Overpass API instance overpass-api.de (public API, no contract)GermanyLooking up opening hours and admission conditionsPlace coordinates and place nameRequested optional feature (legitimate interests)Per the provider's log policyTu Voyage keeps no separate copy
OpenMeteo GmbH (public API, no contract)SwitzerlandWeather for the trip's reference coordinatesThe trip's reference coordinatesContractThe provider publishes a 90-day log retentionTu Voyage keeps no separate copy
Wikimedia Foundation, Inc. — Wikidata (public API, no contract)United StatesMatching a saved place name to a differently named featurePlace nameRequested optional feature (legitimate interests)Per the provider's policyTu Voyage keeps no separate copy
GitHub, Inc. — the protomaps.github.io glyph and sprite CDN (public CDN, no contract)United StatesDelivering map fonts and iconsBrowser IP and requested pathContractPer the provider's policyTu Voyage keeps no separate copy
Public tourism and park data APIs — Korea Tourism Organization TourAPI, U.S. National Park Service, Recreation.gov RIDB (public APIs, no contract)Republic of Korea · United StatesLooking up attraction and park information (in deployments configured with that key)The search's reference coordinates and area codesRequested optional feature (legitimate interests)Per the provider's policyTu Voyage keeps no separate copy

8. Overseas transfers

These recipients from section 7 are located outside the Republic of Korea. The columns are the notice items required by Article 28-8(2) of Korea's Personal Information Protection Act.

Every row relies on Article 28-8(1)3: processing consignment or storage necessary to perform the contract and improve convenience, disclosed through this Policy. No transfer currently requires separate consent. To refuse a transfer, do not use the feature or close the account; each row states the effect.

Recipient (name and contact)Items transferredCountry · timing and methodPurpose and retentionBasis for transferHow to refuse, and the effect
OVH US LLC · us.ovhcloud.com/legal/privacy-policy/Account, profile and trip collaboration data; IP, request time and path; error and security logsUnited States (Oregon) · continuously while you use the Service, over HTTPS and stored in that regionAPI and database hosting and incident response · content until account/record deletion, backups for at most 35 daysPIPA Article 28-8(1)3 (consignment/storage necessary to perform the contract, disclosed in this Policy)Close the account · the Service cannot be used
Cloudflare, Inc. · cloudflare.com/privacypolicy/Photos and booking attachments with file name, type and sizeUnited States (bucket placement auto) · over HTTPS on upload and retrievalFile storage and delivery · until the record is deletedPIPA Article 28-8(1)3Do not upload photos or attachments · that feature cannot be used
Google LLC · policies.google.com/privacyAccount identifier, email, display name, profile photo URL, push token and notification content, place queries and coordinatesUnited States · over HTTPS on sign-in, notification and place-search requestsSign-in verification, push delivery, place and route lookups · per Google's policyPIPA Article 28-8(1)3Sign in with Apple, and do not use notifications or place search · those features cannot be used
Apple Inc. · apple.com/legal/privacy/Apple identifier, email or private-relay address, name on first authorization, authorization code and tokensUnited States · over HTTPS on sign-in, linking and revocationApple sign-in verification and revocation · while the link existsPIPA Article 28-8(1)3Sign in with Google · Apple sign-in cannot be used
Geoapify GmbH · geoapify.com/privacy-policy/Query text, the search's reference coordinates, the Geoapify identifier of a saved place, origin/destination coordinatesGermany · over HTTPS on search, detail and route requests outside KoreaPlace and address search, opening hours, travel times · per the provider's request-log periodPIPA Article 28-8(1)3Do not search for places outside Korea · results in those regions are reduced
Tailscale Inc. · tailscale.com/privacy-policyNode and device identifiers and connection metadataCanada (Toronto) · while an AI request crosses the private networkRelaying the connection to the AI server · per the provider's policyPIPA Article 28-8(1)3Do not use AI features · AI itinerary review and booking-email reading cannot be used
Tu Voyage's own Ollama server (the operator) · seonghyunhan7193@gmail.comItinerary context and, when selected, booking-email source text and trip datesCanada (Ontario) · over the Tailscale private network on an AI requestAI itinerary review and booking-email reading · handled only for the request and response, not storedPIPA Article 28-8(1)3Do not select AI reading · you get the rules-only draft and fill missing fields yourself
FOSSGIS e.V. (overpass-api.de) · fossgis.dePlace coordinates and place nameGermany · over HTTPS when opening hours or admission are looked upOpening-hours and admission lookup · per the provider's log periodPIPA Article 28-8(1)3Do not look up opening hours for that place · opening hours stay empty
OpenMeteo GmbH · open-meteo.com/en/termsThe trip's reference coordinatesSwitzerland · over HTTPS when weather is requestedWeather for the trip dates · the provider publishes a 90-day log retentionPIPA Article 28-8(1)3Do not use the weather view · weather is not shown
Wikimedia Foundation, Inc. · foundation.wikimedia.org/wiki/Policy:Privacy_policyPlace nameUnited States · over HTTPS when matching a differently named featurePlace-name matching · per the provider's policyPIPA Article 28-8(1)3Do not open that place's detail · some place details are reduced
GitHub, Inc. (protomaps.github.io) · docs.github.com/site-policyBrowser IP and requested pathUnited States · requested directly by the browser when a map opensDelivering map fonts and icons · per the provider's policyPIPA Article 28-8(1)3Do not use map views · the map cannot be shown
U.S. National Park Service · Recreation.gov (RIDB) · nps.gov/aboutus/privacy.htmThe search's reference coordinates and area codesUnited States · over HTTPS when U.S. park information is requestedPark and campground lookup · per the provider's policyPIPA Article 28-8(1)3Do not search U.S. parks · those results are reduced

9. External APIs that receive no personal information, and data sources

  • Exchange rates: Frankfurter (api.frankfurter.dev) and ER-API (open.er-api.com) receive only currency codes and a date. No user, trip or coordinate is sent.
  • Place data: an Overture Maps distribution is downloaded and loaded on the server in advance. Your queries and coordinates are not sent to the Overture Maps Foundation.
  • Default map: OpenStreetMap-based Protomaps tiles are self-hosted on the server. Only fonts and icons come from the protomaps.github.io CDN, and that request appears in the section 7 table.
  • Attribution: OpenStreetMap contributors, Overture Maps Foundation and Protomaps. Full licences are at /licenses.

10. AI processing

The AI itinerary coach sends requested itinerary context to the Ollama server. For booking email, the server uses rules first and sends the source text and trip dates to that server only if the rules are insufficient and you selected AI reading for that request. If not selected, no model call occurs; the rules-only draft remains available and missing fields can be entered manually.

That Ollama server is a computer in the operator's home in Ontario, Canada, reachable only over the Tailscale private network. No third-party AI API is used, and what is sent is not used to train a model. The source text and AI result are transient request/response data before a booking is saved and are not written to the application database. The result is advisory and makes no significant automated decision.

11. Retention and deletion

  • An account that does not complete its profile and required legal steps is retained for seven days after creation and then automatically deleted. Deletion ends sessions, removes external-login information, revokes Apple authorization, and retries failed external revocation and file deletion.
  • Account, profile and consent records: while the account is active. On closure, directly identifying login/profile information is removed; a consent record may remain with the pseudonymous account id where needed for compliance
  • Closure: personal journals, comments, votes, activity, invitations, public links, and files uploaded by the account are deleted. Shared ledgers and change history retain only amounts, currencies, dates, status and opaque participant IDs needed for totals and dispute traceability; titles, notes, reasons and change snapshots are erased. Shared bookings retain schedule fields while confirmation codes, notes and files are erased
  • A shared ledger in an active trip room is retained until that room is deleted. Cancellation and dispute audit evidence is kept for at least 90 days after the event and no longer than 24 months after the last ledger change. A documented actual-dispute hold lasts until resolution and is deleted 24 months after resolution, unless qualified review identifies a different applicable requirement or lawful order and records its end date
  • Automatic check-in: the device monitors arrival near itinerary stops even while the app is closed. Raw location is not sent to the server; after the app presents the arrival, only the resulting check-in is synchronized as an ordinary itinerary change. Turning the feature off or letting the geofence expire ends the monitoring
  • Live location: hidden after 15 minutes, deleted when sharing is turned off (with safe retries), and otherwise removed on a later room read after no more than 24 hours. A changed room membership requires recipient review and renewed consent
  • Push token: until device unregistration, account closure, or Firebase reports it invalid
  • Server/security logs: production Compose rotates three 10MB files per container. No external log collection service is used, and application log messages do not include request bodies or booking-email source text
  • Database backups are kept for at most 35 days and application, proxy and security logs for at most 30 days. Withdrawals and deletions are replayed before a restored service reopens. Only a legal obligation or actual dispute may be separately retained with recorded purpose, end date and access

12. Your choices and rights

The account page lets you export your data, edit or remove content, sign out every device, or close the account. Location sharing and photo/notification permissions can be turned off in the app and device settings.

Request access, correction, deletion, restriction, consent withdrawal, or raise a complaint at seonghyunhan7193@gmail.com. Tu Voyage will verify the requester and respond within the time required by applicable law.

13. Cookies and device storage

The web app uses an essential HttpOnly secure session cookie and stores language/theme choices in browser storage. It does not use advertising or behavioural analytics cookies.

The login page loads Google Sign-In only after the person confirms they are at least 14. Google may then handle device information under its policy. The mobile app keeps tokens in operating-system secure storage.

On mobile, itinerary, booking, expense, private-journal and pending-work data is separated by account and encrypted with a device-only key held by operating-system secure storage. Original photos and sensitive offline stores are excluded from Android cloud backup/device transfer and iOS backup. Sign-out or account closure clears these caches and queues; a server-reported loss of permission discards the affected cache immediately. While the device is offline it cannot learn of a remote revocation or membership change, so its last synchronized copy may remain visible until sign-out or the next server check.

14. Safeguards

Safeguards include HTTPS, key-only SSH, hashed refresh tokens, access-restricted secret files, isolated database/container networks and bounded logs. AI traffic travels only over a Tailscale private network, and the Ollama server at the other end is in the operator's home in Ontario, Canada.

No system can be guaranteed completely secure. Report a suspected incident to the contact email. Breaches subject to notification duties will be reported to the relevant authority and affected people.

15. Children

The Service does not currently support people under 14 or guardian-consent sign-up. A person must confirm they are at least 14 before information is sent to Google or Apple; the exact birth date is not stored for this check.

If child information is discovered, a guardian can send the account identifier and evidence of their relationship to the privacy contact. The operator will restrict access, delete the account, sessions, external-login information and uploaded files through the existing closure process, and record and verify provider revocation and deletion-queue completion.

16. Privacy officer

Article 31 of Korea's Personal Information Protection Act requires a designated, published privacy officer who oversees personal-information handling and handles complaints and remedies. That officer is:

  • Name: Seong Hyun Han
  • Position: operator (Tu Voyage is personally operated)
  • Email: seonghyunhan7193@gmail.com
  • Responsibilities: overall personal-information handling, access/correction/deletion/suspension requests, complaints and remedies, and breach response

17. Changes and contact

A material change to purposes, sensitive information or providers will update the effective date and version and request renewed consent when required. Previous versions are available on request.

Privacy questions and rights requests: Seong Hyun Han, seonghyunhan7193@gmail.com. Korean users may also contact the Korea Internet & Security Agency privacy centre (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), and anyone may contact the privacy regulator where they live.

Back to Tu Voyage
Terms of Service · Privacy Policy · Licenses
seonghyunhan7193@gmail.com