Privacy Policy
Effective and last updated: August 15, 2026
About This Policy
Itabi is operated by Ahsan Zaman ("Itabi," "we," "us," or "our"). This policy explains what information we collect when you use the Itabi mobile app, website, and related services, why we use it, who receives it, how long it is retained, and the choices available to you. Itabi is a general trip planner for organizing destinations, itineraries, and collaboration with travel companions.
We collect personal data. The exact data collected depends on the features you use and the permissions you grant.
Information We Collect
Account and Profile Data
- Firebase user ID, email address, display name, and profile photo URL provided by Google or Apple sign-in
- Authentication provider and account timestamps
- Language, notification, location-sharing, and other app preferences
- Notification token if push notifications are enabled and a token is registered
Trips and User Content
- Trip names, destinations, dates, airports, accommodations, planning preferences, and execution status
- Places, itinerary days, visit status, notes, and other trip details you create or save
- Edits and contributions made to trips shared with companions
Itabi does not currently offer a direct photo or file-upload feature to Itabi-managed cloud storage. A profile photo may be displayed from your sign-in provider. If direct uploads are introduced, we will update this policy before collecting them and will describe their storage and deletion.
Document Imports
If you choose to import places from a Google Doc or Google Sheet, we collect the public sharing URL and download the document text for that import. The text is sent to OpenAI only to identify visitable places and related notes. We do not send your account email, precise device location, or unrelated trip records to OpenAI as part of this operation. Do not import a document containing personal or sensitive information that is unnecessary for trip planning.
We do not save the complete source document in Firestore or Itabi-managed file storage. Selected places and notes that you accept become part of your trip. The original document remains in your Google account and is not deleted when you delete your Itabi account.
Collaboration and Invitations
- Invitee email address, inviter name and user ID, trip name, invitation role and code, use status, and timestamps
- Membership, role, last-seen timestamp, and location-sharing preference for each trip companion
Location Data
- With device permission, the app uses precise location on the device for nearby-place context, visit detection, maps, and execution features
- Nearby-place requests send latitude, longitude, search radius, and requested place categories to Google Places
- If you separately enable trip location sharing, Itabi uploads your latest latitude, longitude, timestamp, accuracy, altitude, heading, and speed to Firebase so trip companions can view it
Itabi does not store a continuous route history for location sharing; the latest location record is overwritten. Disabling sharing deletes that trip's current location record.
Analytics and Technical Data
Firebase Analytics automatically collects app-instance and device information and automatically generated usage events. Itabi also records events such as login method, onboarding completion, screen views, trip creation or deletion, spots added or imported, itinerary organization, collaboration actions, map use, phrase playback, language changes, and premium-screen views. Some events include limited parameters, such as a selected city, language, scenario identifier, source, item count, or itinerary-day count.
We use this information to understand feature usage and improve reliability and design. We do not use Firebase Analytics for cross-app tracking or targeted advertising, and we do not send trip notes or document contents as Analytics event parameters.
Shorebird may receive app version, platform, update status, and a device or installation identifier when the app checks for a compatible software update. Our hosting providers may also process IP address, request time, URL, user agent, and server logs for delivery, security, and troubleshooting.
How and Why We Use Data
- Authenticate accounts and provide requested services
- Create, save, organize, and synchronize trips
- Enable invitations, collaboration, and optional location sharing
- Import places from documents when you request that feature
- Display maps, place details, geocoding, and nearby context
- Operate, secure, troubleshoot, and improve Itabi
- Communicate about invitations, support, and material service changes
- Comply with law and protect users, Itabi, and others
Where data-protection law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating and improving Itabi, your consent for optional permissions or processing, and compliance with legal obligations. You may withdraw consent for optional processing prospectively, including by changing device permissions or disabling location sharing.
Recipients and Service Providers
We disclose data only as needed for the purposes described in this policy:
- Google Firebase: Authentication, Firestore database hosting and synchronization, and Firebase Analytics
- Google Maps Platform: Maps, place search, place details, nearby-place queries, and geocoding
- Google and Apple: Account authentication and profile information you authorize them to provide
- Google Docs and Sheets: Retrieval of a publicly shared source document only when you request an import
- OpenAI: Processing source-document text only when you request document import. OpenAI states that API data is not used to train its models unless the API customer opts in. Under default API controls, prompts and responses may be kept in abuse-monitoring logs for up to 30 days, unless a longer period is required by law or necessary to protect the service or third parties. Itabi has not represented that Zero Data Retention is enabled.
- Resend: Delivery and operational logging of trip-invitation email, including the invitee address, inviter name, trip name, role, and invitation link
- Cloudflare: Website and invitation-endpoint hosting, delivery, security, and operational logs
- Shorebird: Eligibility checks and delivery of compatible over-the-air app updates
Trip owners and companions can see shared trip content, membership information, contributions, and your latest shared location when you enable location sharing for that trip. We may also disclose information if legally required or reasonably necessary to protect rights, safety, and service integrity.
We do not sell personal data or use it for cross-context behavioral advertising.
Retention
- Account and profile data: Generally retained while your account exists and then deleted or de-identified, subject to the exceptions below
- Owned trips: Retained until you delete the trip or your account
- Shared trips: Content and contribution history may remain with the trip owner after you leave or delete your account where needed to preserve the shared itinerary; we will remove or de-identify your account association on request where required
- Shared location: The current record is overwritten as sharing continues and is deleted when sharing is disabled or the trip is deleted
- Invitations: Retained while needed to operate, audit, or revoke the invitation and prevent abuse, then deleted or de-identified
- Document imports: Full source text is processed transiently and is not stored in Firestore or Itabi-managed file storage. Backend operational logs may contain the source URL and request metadata. OpenAI's default retention is described above.
- Analytics and operational logs: Retained under our configured provider settings and for as long as reasonably necessary for measurement, security, debugging, legal compliance, and dispute resolution; aggregated reports may no longer identify an app installation
Retention may be extended where required by law, needed to investigate abuse or security incidents, or necessary to establish, exercise, or defend legal claims. Backup copies may remain for a limited period before being overwritten.
Deletion and Your Choices
You can delete your account from the app's settings. This begins deletion of your Firebase Authentication account, user profile, and trips you own. You can also delete individual trips, disable location sharing, revoke device permissions, or contact us to request access, correction, deletion, or a copy of your data.
Account deletion does not delete a source Google Doc or Sheet, data another user independently provided, information already de-identified, or records we must retain for security, legal, or dispute-resolution reasons. Provider logs are deleted under the providers' applicable retention schedules.
Depending on where you live, you may also have rights to object to or restrict processing, withdraw consent, receive portable data, appeal a denied request, or complain to a data-protection authority. We may verify your identity before completing a request. Authorized agents may submit requests where local law permits.
Submit requests to privacy@itabi.app. We will respond within the period required by applicable law.
International Processing
Itabi and its providers may process data in the United States and other countries whose privacy laws may differ from those in your country. Where required, we rely on recognized transfer mechanisms, contractual protections, or another lawful basis for those transfers.
Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data, including TLS for data in transit, provider encryption at rest, Firebase Authentication, and access-control rules. No transmission or storage system is completely secure, and we cannot guarantee absolute security.
Tracking Signals
Itabi does not use data for cross-app tracking or targeted advertising. Because there is not yet a generally accepted standard for browser Do Not Track signals, our website does not currently respond differently to those signals. We will update this disclosure if our practices change.
Children
Itabi is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided data, contact us so we can review and delete it where required.
Changes to This Policy
We may update this policy as Itabi, our providers, or legal requirements change. We will post the revised policy here, update the effective date, and provide additional notice in the app or by email when required. Material changes apply prospectively unless law permits otherwise.
Contact
Itabi is operated by Ahsan Zaman. For privacy questions or requests, contact:
- Email: privacy@itabi.app
- Website: itabi.app