Triphaus
  • Features
  • Pricing
  • FAQ
  • Contact
English ▼
  • English
  • Deutsch
  • Español
  • Français
  • 中文
  • हिन्दी
  • Українська

Privacy Policy — Triphaus

Effective: 5 August 2026

Auf Deutsch lesen

Privacy Policy

Effective date: 5 August 2026

1. Controller

The controller responsible for the processing of your personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Andrii Lavus Hohenzollernstraße 70 66117 Saarbrücken Germany

Email: support@triphaus.app

(Current contact details are maintained in the Legal Notice.)

2. Data Protection Officer

Triphaus is operated as a sole proprietorship (Einzelunternehmer). German law does not require a Data Protection Officer for businesses of this size (Art. 37 GDPR in conjunction with § 38 BDSG). No DPO has been appointed.

3. What data we process and why

The following categories of personal data are processed when you use the Triphaus app. This list mirrors the Apple Privacy Nutrition Label for Triphaus (declared in PrivacyInfo.xcprivacy).

Providing your account data is required to use a Triphaus account (Art. 13(2)(e) GDPR); without it, no account can be created. Everything else is optional.

3.1 Account data (linked to your identity)

DataPurposeLegal basis
Email addressAccount creation via Sign in with Apple; sending service-related messagesPerformance of contract, Art. 6(1)(b) GDPR
Name (optional display name from Apple)Personalising the in-app experience; shown to people you share a trip with (Section 3.4)Performance of contract, Art. 6(1)(b) GDPR
User identifiers (internal account ID; opaque Apple-issued identifier)Identifying your account across devices; securing API calls; abuse preventionPerformance of contract, Art. 6(1)(b) GDPR

Sign in with Apple is the only sign-in method. Triphaus never receives your Apple ID password. Sign-in tokens are stored only in the iOS Keychain on your device.

3.2 Subscription and purchase data (linked to your identity)

DataPurposeLegal basis
App Store transaction identifiers and subscription status (no payment data)Enforcing the free/paid quota; restoring your subscriptionPerformance of contract, Art. 6(1)(b) GDPR; statutory retention obligations, Art. 6(1)(c) GDPR

Payment is handled entirely by Apple. Triphaus receives no payment or billing data — only signed transaction and product identifiers.

3.3 Content you provide (linked to your identity)

DataPurposeLegal basis
Travel documents, booking confirmations, photos you share with the AI featureExtracting structured itinerary data via the AI modelPerformance of contract, Art. 6(1)(b) GDPR
Itineraries and trip data you createStoring your trips (locally on your device; server-side only while sharing, Section 3.4)Performance of contract, Art. 6(1)(b) GDPR

Your trips are stored locally on your device. Files uploaded for the AI feature are held by the Triphaus server only ephemerally in memory and are deleted immediately after your request has been processed (see Sections 4 and 6).

Your responsibility for uploaded content. You are responsible for the content you upload to the AI feature. You must not upload special categories of personal data within the meaning of Art. 9 GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; genetic or biometric data; health data; or data concerning a person’s sex life or sexual orientation) or other sensitive information — whether your own or relating to third parties — unless it is strictly necessary for the booking you are organising and you are legally permitted to do so. You are responsible for ensuring that the documents, photos, and files you upload do not contain such sensitive data, and — to the extent permitted by applicable law — you bear responsibility for the content you upload and for the rights of any third parties whose data may appear in it.

3.4 Trip sharing (linked to your identity)

When you share a trip with another person, the trip (the full trip content you created) is uploaded to the Triphaus server and stored there for as long as the share is active. Changes to an actively shared trip are synced to the server. The recipient sees the trip content and your display name. Invite links are valid for 14 days, bound to a single recipient, and can be revoked by you at any time. When you end all shares of a trip, delete the trip, or delete your account, the server-side copy is deleted.

Legal basis: performance of contract, Art. 6(1)(b) GDPR (sharing is actively initiated by you).

3.5 App interaction data (linked to your identity)

DataPurposeLegal basis
Feature usage (AI quota consumed, quota counters)Enforcing usage quotaLegitimate interests, Art. 6(1)(f) GDPR — interest: sustainable quota management and abuse prevention
Clicks on partner links (date, trip step concerned, partner network — no destination URL)Attributing partner commissions (affiliate attribution)Legitimate interests, Art. 6(1)(f) GDPR — interest: financing the service through partner commissions

3.6 Optional marketing and analytics consents

The following processing occurs only if you opt in during sign-up or in Profile → Communications & Privacy. All three consents are off by default, granular, and withdrawable at any time.

ConsentWhat we processLegal basis
Marketing emailsYour email address to send product news, tips, and promotional offersConsent, Art. 6(1)(a) GDPR
Marketing push notificationsYour preference is stored; no push-delivery infrastructure currently existsConsent, Art. 6(1)(a) GDPR
Product analyticsUsage events (app opens, trips created, feature interactions — no trip content) sent to our first-party server; retained 90 days, then only aggregate countsConsent, Art. 6(1)(a) GDPR

To withdraw any consent: open the Triphaus app → Profile → Communications & Privacy and toggle off. Withdrawal is immediate in the app; email suppression may take up to 48 hours. Withdrawal does not affect the lawfulness of processing before withdrawal (Art. 7(3) GDPR). To evidence your consent we store the accepted version and timestamp (Art. 7(1) GDPR).

3.7 Support emails

When you contact us via Contact Us in the app, the mail body automatically includes a short diagnostics block to help us handle your request:

Data includedPurpose
User ID (account identifier from your sign-in token)Identify your account
Plan tier (free / payg / annual)Understand your subscription context
App version and build numberPin the exact binary you are using
iOS versionIdentify OS-specific issues
Device model (e.g. iPhone16,2)Identify device-specific issues
In-app languageReproduce language-specific issues

The diagnostics block is visible to you in the Mail compose sheet before you tap Send — nothing is sent silently. Legal basis: legitimate interests, Art. 6(1)(f) GDPR — efficient and accurate support handling.

What we do NOT collect

  • No location data: the app does not request location permission and does not collect location data.
  • No tracking: no advertising network, no third-party analytics SDK, no social-media pixel, no cross-app tracking, no advertising identifier (IDFA). NSPrivacyTracking is declared false in the Apple Privacy Manifest.
  • No payment data: payments are handled entirely by Apple.

4. Recipients and third-party services

OpenAI (AI feature)

When you use the AI import feature, Triphaus sends the content you submit (booking-confirmation text, image, or PDF text content, including the file name) to OpenAI Ireland Ltd., Dublin, Ireland, via OpenAI’s API. OpenAI processes this data to extract structured travel information and returns the result to the app.

OpenAI does not use API request data to train its models. Triphaus additionally instructs OpenAI on every call not to store the response object (store=false). OpenAI may nevertheless retain API inputs and outputs for up to 30 days for abuse and fraud monitoring, after which they are deleted (OpenAI API data usage policy, as of this policy date).

Contracting party and international transfer: For users in the European Economic Area and Switzerland, OpenAI Ireland Ltd. is our processor under Art. 28 GDPR, on the basis of OpenAI’s Data Processing Addendum. Where OpenAI Ireland transfers data to affiliates or service providers outside the EEA in order to provide the service — in particular to OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158, USA — it does so on the basis of the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) or an adequacy decision of the European Commission under Art. 45 GDPR. The sub-processors engaged by OpenAI are listed at https://platform.openai.com/subprocessors.

Apple Inc. (Sign in with Apple, App Store)

Apple processes the authentication and payment flow under its own privacy policy. Triphaus receives only the opaque user identifier and, on first sign-in, an email address and optional name whose sharing you control. Apple Inc. (USA) is certified under the EU–US Data Privacy Framework.

Hetzner Online GmbH (hosting and backups)

The Triphaus server (api.triphaus.app) is operated at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a data centre located in Germany (processing under Art. 28 GDPR). Server data is mirrored daily to a Hetzner backup storage within the EU; deletions propagate to the backup no later than the next daily mirror run.

Cloudflare, Inc. (website delivery)

The marketing website (triphaus.app) is delivered via the content-delivery network of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare processes technically necessary connection data (in particular your IP address) to deliver and protect the website. Legal basis: legitimate interests, Art. 6(1)(f) GDPR — secure and performant delivery. Cloudflare is certified under the EU–US Data Privacy Framework and additionally bound by EU Standard Contractual Clauses.

Weather and map services

To display weather and place information for your trip destinations, the app fetches data directly from your device from Open-Meteo (api.open-meteo.com) and OpenStreetMap/Overpass (overpass-api.de). What is transmitted are the coordinates or names of the destination and, technically inherent, your device’s IP address — no account identifier and not your own location. Legal basis: performance of contract, Art. 6(1)(b) GDPR.

Redirections to booking and partner sites

The app contains links to booking and activity providers (e.g. GetYourGuide, Booking.com, Airbnb, Omio, Rome2Rio, GetTransfer, Hostelworld). When you open such a link, your request leaves Triphaus: the provider receives the requested URL (including destination parameters and, for partner links, a Triphaus partner identifier) and your IP address; from that point the provider’s privacy policy applies. Triphaus does not transmit any account or profile data to the provider; internally we only log the click (Section 3.5).

First-party analytics (consent-gated)

If you opt in, Triphaus records first-party usage events on its own server (Section 3.6). No third-party analytics SDK, advertising network, or tracking pixel is used.

5. Website, cookies, and server logs

The Triphaus marketing website (triphaus.app) sets no cookies and uses no web analytics, advertising pixels, or third-party scripts; fonts are served locally. A cookie-consent banner is therefore not required.

When you access our services, technically necessary server access logs are created (IP address, timestamp, requested address, status code). They serve operations, troubleshooting, and defence against attacks. Legal basis: legitimate interests, Art. 6(1)(f) GDPR. Logs are continuously overwritten (rotating files) and are typically deleted within days to a few weeks; IP addresses are not stored in databases.

The iOS app does not use browser cookies. On-device storage uses Apple’s UserDefaults (for preferences, declared under reason CA92.1) and the Keychain (for authentication tokens).

6. Retention periods

Data categoryRetention
Account and itinerary dataUntil you delete your account (Section 8).
Server-side copies of shared tripsUntil you end the share, delete the trip, or delete your account. Invite links expire after 14 days.
AI input data (uploads)Held by Triphaus only ephemerally for the duration of the request (no persistent storage). At OpenAI up to 30 days (abuse monitoring), no training.
Purchase history (transaction identifiers)As required by German commercial and tax law — typically 10 years (§ 147 AO).
Server access logsRotating, size-based — typically days to a few weeks.
Pseudonymous request diagnostics (account identifier, path, latency — no content)90 days, then automatically deleted.
Analytics events (only with consent)90 days; thereafter only aggregate counts without personal reference remain.
Partner-link click logUntil you delete your account.
Consent records (version, timestamp)For the life of the account plus statutory limitation periods.
Deletion record (Section 8)Indefinitely for abuse prevention; necessity is reviewed regularly.

7. Your rights under GDPR

As a data subject, you have the following rights:

  • Right of access (Art. 15 GDPR): you may request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR): you may correct inaccurate data.
  • Right to erasure (Art. 17 GDPR): you may request deletion of your data, subject to statutory retention obligations.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR): you may receive your data in a structured, machine-readable format.
  • Right to object (Art. 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 6(1)(f) GDPR).
  • Right to withdraw consent (Art. 7(3) GDPR): you may withdraw consents (marketing emails, marketing push, product analytics) at any time in Profile → Communications & Privacy, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at support@triphaus.app. We will respond within 30 days.

8. Account deletion

To delete your account, go to Profile → Delete Account inside the Triphaus app, or send a request to support@triphaus.app. Deletion is processed promptly, at the latest within 30 days, and covers your account, trip, sharing, quota, and click data as well as the identifiers in diagnostic logs.

Exempt from deletion are: (a) transaction identifiers subject to tax- and commercial-law retention obligations (Art. 6(1)(c) GDPR), (b) a minimal deletion record — the sign-in provider identifier (no email, no name) and the deletion timestamp — which we keep to prevent repeated claiming of new-customer free quotas through repeated account re-creation (legitimate interests, Art. 6(1)(f) GDPR), and (c) aggregate statistics without personal reference.

9. Right to lodge a complaint

You have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR) — in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. For Triphaus, the competent authority is the data-protection authority of the German federal state in which the controller is established (see Section 1). A directory of all German supervisory authorities is available from the BfDI: https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_node.html

10. Automated decision-making and profiling

Triphaus does not use automated decision-making or profiling that produces legal or similarly significant effects (Art. 22 GDPR). The AI feature extracts travel data from documents you provide; the result is always reviewed by you before any itinerary is saved.

11. Children

Triphaus is not directed at children under 16 years of age, consistent with the age threshold for consent under Art. 8 GDPR in Germany. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us at support@triphaus.app and we will delete it promptly.

12. Changes to this policy

We may update this policy to reflect changes in our data practices or applicable law. The effective date at the top of this page indicates when the current version was adopted. Material changes will be communicated in-app.

13. Contact

For privacy-related questions, write to: support@triphaus.app