Appcelerator Studio

Apps/Travel Assistant - Mapia

Travel Assistant - Mapia Privacy Policy

Last updated September 18, 2026 · Terms of Use

Overview

Travel Assistant - Mapia (the “App”) is a travel planner. You type where you are going and pick your dates, and the App builds a day-by-day itinerary with real places, times and a map. Around that plan, each trip keeps your documents, budget and expenses, notes, and the emergency numbers and embassy for the destination. The App also has a currency converter, a phrasebook read aloud by your phone, country facts, and a globe of the places you have saved and the countries you have visited.

Most of that happens on your phone, but not all of it. Three things leave your device, and this policy is mostly about them: the short description of the trip you want planned, which goes to our planning service and from there to an AI model; product analytics, which tell us which screens people reach and where they give up; and in-app purchases. Alongside those, the App asks a few public web services for things it cannot know by itself — place names as you type, the weather and local time at the destination, and today’s exchange rates.

The short version: there are no accounts and nothing to sign in to, no advertising, no advertising identifier and no tracking across apps or websites. We never learn your name or email address. Your documents, photos, expenses, notes, contacts and saved places never leave your phone. What we do receive is described below, and nothing we receive is tied to who you are.

Information we do not collect

The App does not collect, transmit or store on any server:

  • Your name, email address, phone number or any account information. There are no accounts. The first name you can enter in the introduction is stored only on your phone, to greet you, and is never sent anywhere.
  • Your documents. Tickets, bookings, passport scans and any other photo or file you attach to a trip stay in the App’s private storage on your phone and are never uploaded.
  • Your expenses, budget, notes, saved places, visited countries, or the contacts you add to a trip’s Emergency screen.
  • Your location. The App never asks for “Always” location access, never stores your position and never sends it to us. The blue dot on the day map is drawn by Apple Maps on your phone (see “Maps and your location” below).
  • Your photo library. The App receives only the single photo you pick in Apple’s picker, and only when you attach it to a trip.
  • Your advertising identifier, your contacts, calendar, health data, microphone, or any data from other apps. The App requests none of those permissions.
  • Crash reports. The App has no crash reporting SDK.

Planning a trip: what leaves your phone

When you tap Create my plan, Rebuild plan or Rebuild this day, the App sends a short brief to our planning service: the destination you chose and its country, the coordinates of its centre, your start and end dates, the number of travellers, the pace and interests you picked, the trip currency, and the name of your home country (so the plan can include your embassy). Rebuilding a single day also sends that day’s date, the names of the places already planned on other days (so they are not repeated) and, if you typed one, your request for the day, such as “more food” or “something for kids”. That is the whole brief. Your name, your documents, your expenses, your notes, your saved places and your location are not part of it.

Each request also carries two small pieces of information: the anonymous identifier RevenueCat assigned to this installation, and the platform (iOS). The identifier is a random value created on your phone the first time the App starts. It is not your Apple Account, not your advertising identifier and not derived from your device; it tells our service only that two requests came from the same installation. It exists so that the service can check whether Pro is active, allow exactly one free plan per installation, and limit how many plans one phone can start in an hour. Deleting and reinstalling the App produces a new one.

The finished plan — the days, the stops with their times, coordinates, addresses, opening hours, cost estimates and tips, two sentences about the destination, a few local tips and the embassy details — comes back the same way and is stored only on your phone.

Our planning service

Between the App and the AI model sits a small server of ours, hosted on Expo’s EAS Hosting, which runs on Cloudflare. It exists so that the key for the AI service never has to ship inside the App, where it could be extracted, and so that the free plan and the Pro check are enforced somewhere the App cannot be tampered with. It is the only server we operate for this App.

It keeps no copy of your brief or your plan. Both pass straight through: the brief to the AI provider, the plan back to your phone. What the service keeps is a counter, in memory, of how many plans each installation identifier and each connection has started in the current hour, which is discarded after that hour. If a request fails, the service writes an error line to its log — the kind of failure and the time, never the brief itself.

For a plan that Pro would cover, the service asks RevenueCat whether the identifier on the request holds Pro and, if this is the installation’s free plan, records the time it was used as a note on that RevenueCat record. That is how the App knows the first trip was free even if you delete the trip; it is also why a fresh installation gets a fresh free plan.

As with any web request, the server sees the IP address your request came from while it handles it, and uses it for the hourly limit. We do not log it, profile it or keep it beyond that hour. Cloudflare, which operates the network the service runs on, processes it on our behalf to route and protect the request, under its own privacy terms.

Anthropic and the AI model

Itineraries are written by Claude, an AI model made by Anthropic, reached through Anthropic’s API. Anthropic receives the brief described above together with a fixed set of instructions written by us — how to pace a day, to use only real places, to write in plain English — that is the same for every traveller. Nothing about you is added to it.

Anthropic does not receive your installation identifier, your IP address, your device details or the App’s version, because the request reaches it from our server rather than from your phone. It processes the brief for the purpose of producing your plan and handles it under its own privacy policy, at https://www.anthropic.com/legal/privacy, and under the commercial terms we use the service on, which do not allow it to use what we send to train its models.

The model may decline to plan a trip it considers unsafe or inappropriate. If it does, the App tells you the plan could not be built and nothing further happens. No human at our end looks at your brief, and there is no queue, dashboard or inbox on our side where briefs or plans could be read.

Searching for places (OpenStreetMap)

The destination box and the Add a place search are answered by Photon, a free search service run by komoot on OpenStreetMap data. As you type, the App sends what you have typed so far (from the second character) to Photon and shows the matching cities, regions and countries; Add a place also sends the coordinates of your trip’s centre so that results are sorted around it. After a plan comes back, the App may look up each stop’s name near the destination the same way, to pin it more precisely on the map.

Photon receives the text you typed, those coordinates and, as with any web request, your IP address. It does not receive your installation identifier or anything else about you, and we never see what you typed. komoot’s privacy policy is available at https://www.komoot.com/privacy.

Weather, local time and exchange rates

Each day card shows the forecast, and the Tools tab shows the local time, sunrise and sunset at the destination. That information comes from Open-Meteo, a free weather service. The App sends it the coordinates of the destination — the place you are going, not where you are — and receives a sixteen-day forecast and the destination’s time zone, which it caches on your phone for three hours and keeps for use offline. Open-Meteo’s terms are at https://open-meteo.com/en/terms.

The converter uses a daily table of exchange rates from ExchangeRate-API (open.er-api.com). The App fetches the whole table against the US dollar, at most every six hours, and converts on your phone; nothing about which currencies or amounts you convert is sent anywhere. The table is cached so that the converter works offline, and the App shows how old the rates are. ExchangeRate-API’s terms are at https://www.exchangerate-api.com/terms.

Neither service receives your installation identifier. Both see the IP address the request came from, as any web server does.

Maps and your location

The day map, the small map on each stop and the globe on the Saved tab are drawn by Apple Maps on your phone. To draw them, your phone requests map imagery for the area shown from Apple, and Apple handles that request under its own privacy policy. We never receive it.

The day map can show your own position, so you can see how far the next stop is. For that the App asks for location access while it is in use — the standard iOS prompt — and only when you open the map. If you allow it, iOS gives your position to the map on your phone; the App does not read it, store it, or send it to us or to anyone. If you decline, the map simply shows the stops without the blue dot, and everything else works the same. The App never asks for “Always” access and does not track your movements.

Open in Maps and Show on map hand a place name or address to the Apple Maps app; if that is not possible, they open Google Maps in a browser. Find embassy opens a Google search for your home country’s embassy in the destination in an in-app browser, and Open website opens the embassy’s own site. Those pages see your IP address and the search or address you opened, as any web page does, and are governed by Apple’s and Google’s privacy policies.

Analytics (PostHog)

Unlike most of our apps, this one uses product analytics. They tell us which screens people reach, where they give up, and which of two versions of the introduction leads more people to a first plan — the App runs that as an A/B test. We use PostHog for this, a product analytics service, on servers in the United States.

PostHog assigns a random identifier to your installation the first time the App starts. It is stored on your phone, is not tied to your name, your Apple Account, your device or your advertising identifier, and tells us only that two events came from the same installation. Against that identifier the App records:

  • That the App was installed, updated, opened or put in the background, and which screens you visited, by their internal path (for example the paywall or a trip’s budget screen).
  • Your progress through the introduction: which step you reached, which of the offered goals and frustrations you tapped, and how long it took.
  • That a plan was created or rebuilt, with the destination’s name, the number of days, travellers, pace and how many interests were picked — but not the plan itself.
  • That the paywall was shown, closed, or led to a purchase or restore, with the plan chosen; and that the rating prompt or the share-your-map card was used.
  • Which version of the introduction you were assigned to, on every event.
  • What PostHog’s software collects by default: device model, iOS version, App version and build, language, time zone and screen size, and the IP address of the request, from which PostHog derives an approximate location — a country, region and city — that we see instead of the address itself.

What the analytics never include

The analytics never include your name, your documents, your expenses or budget, your notes, your saved places, the stops in your plan, your exact location, or what you typed in a search box. Session recording and automatic capture of taps are switched off; only the named events above are sent. PostHog processes this data on our behalf and does not use it for its own purposes; its privacy policy is at https://posthog.com/privacy.

Events are sent over an encrypted connection in small batches while you use the App, and are queued on your phone when you are offline. We keep them for as long as they are useful for improving the App, and delete them on request (see “Deleting your data”). The analytics identifier and your introduction variant are also attached to your RevenueCat record, so that purchases can be matched to the version of the introduction that led to them; that is described under “In-app purchases” below.

Documents, photos and files

Documents are attached with the camera, from your photo library or from Files. Take a photo asks for camera permission the first time, and the picture is taken inside the App. Choose from Photos uses Apple’s system picker, which runs outside the App in its own process: the App is handed only the one image you tap and never sees the rest of your library, which is why no “Allow access to Photos” prompt is needed. Choose a file uses the system file picker in the same way, for PDFs and images.

Whatever you attach is copied into the App’s private folder on your phone, with the title, category, address and note you give it. It stays there, is shown full screen from there, and is never uploaded — not to us, not to the AI service, not to anyone. The only way a document leaves your phone is if you tap Share on it, which opens the iOS share sheet and lets you choose where it goes.

Reminders, the widget and the rating prompt

Trip reminders — the evening before a trip and each morning of it — are local notifications, created and scheduled by the App on your phone from your trip’s dates and first stops. No push notification service is involved, no device token is created, and nothing is sent to us. The App asks for notification permission only when you turn reminders on, and you can turn them off in Settings at any time.

The Next trip widget reads the destination, flag, dates and countdown of your next trip from a small file the App shares with it on your phone, and shows a countdown that ticks over at midnight without the App running. Nothing leaves the phone.

The rating prompt is Apple’s own sheet, requested by the App at most once every four months. Whether you rate, and what you write, goes to Apple under its privacy policy; the App only records on your phone that it asked, and sends one analytics event saying so.

Phrasebook, voices, PDF export and sharing

The 44 phrases in 34 languages are built into the App, and reading them aloud uses the voices installed on your iPhone, on the device. Nothing you look up or play is sent to a translation or speech service. iOS may download a voice for a language on Apple’s terms; that is between your phone and Apple.

Export PDF renders the itinerary into a PDF on your phone and opens the iOS share sheet; Share my travel map draws the picture on your phone and does the same. In both cases you choose where the file goes, and it leaves your phone only if you send it somewhere.

Emergency numbers for every country and the country facts on the Tools tab — dial code, plug, voltage, tipping, tap water — are built into the App and work offline. Call buttons dial through your phone’s own dialler.

Network use

Nothing is uploaded in the background beyond the analytics events above, no configuration is fetched at launch apart from the A/B test assignment from PostHog, and everything that matters on the road — the itinerary, documents, emergency numbers and the last rates — is stored on your phone so it opens with no signal. To sum up, the App connects to the network for these things and no others:

  • Our planning service, and through it Anthropic, when you create or rebuild a plan or a day.
  • Photon (komoot), as you type in the destination box or Add a place, and once after a plan arrives to pin its stops.
  • Open-Meteo, when you open a trip or the Tools tab, for the forecast and local time; at most every three hours per destination.
  • ExchangeRate-API, at most every six hours, for the converter’s rates.
  • PostHog, in the background while you use the App, for the analytics described above.
  • Apple’s in-app purchase system and RevenueCat, when the App starts and when you open the paywall, buy or restore.
  • Apple Maps, for map imagery whenever a map or the globe is on screen.
  • The in-app browser, when you open this Privacy Policy, the Terms of Use, an embassy’s website, the embassy search, or the Google Maps fallback.

Data stored on your device

The following is stored locally, in the App’s sandbox on your phone, and nowhere else. If you back up your iPhone to iCloud or a computer, the App’s data is included in that backup, which Apple and you control.

  • Your profile: first name, home country, home currency, the larger text and trip reminder switches, and whether you have completed the introduction.
  • Your trips: destination, dates, travellers, pace and interests; the plan with its days and stops; the summary, local tips and embassy details; your notes; the contacts you add; your budget and every expense; and the documents you attach, as files in the App’s private folder.
  • Your saved places and the countries you have marked as visited.
  • Cached forecasts and time zones for your destinations, and the last table of exchange rates with the time it was fetched.
  • Your answers in the introduction and the version of it you were assigned to.
  • The random analytics identifier, and any analytics events waiting to be sent.
  • Your purchase status, cached by RevenueCat so the App knows you are Pro even when offline, and the anonymous identifier RevenueCat assigned to the installation.
  • When the App last asked you for a rating, so it does not ask again too soon.

Deleting your data

Deleting a trip removes its plan, documents, expenses, notes and contacts from your phone; deleting a document, an expense, a saved place or a contact removes just that. Every delete asks you to confirm first. Settings › Delete all my data removes every trip, document, saved place and setting and returns you to the introduction.

Deleting the App removes everything it stores, including the analytics identifier, the cached forecasts and rates, and your settings. Your purchase record stays with Apple and can be restored after reinstalling.

On our side there is nothing to delete but three things: the analytics events held by PostHog under your random identifier; the RevenueCat record for the installation, which holds the anonymous identifier, the purchase state, the introduction variant, the analytics identifier and the time of the free plan; and the hourly counters on our planning service, which expire on their own. Email us and we will delete the first two. Because neither is tied to your name, tell us roughly when you installed the App, the device you use and a destination you planned, so we can find the right records.

In-app purchases (RevenueCat and Apple)

Your first trip and its plan, the emergency numbers for that trip, the currency converter, the phrasebook, your travel statistics and the globe with one saved place are free. Unlimited trips and plan rebuilds, documents, budget and expenses, unlimited saved places and PDF export require Mapia Pro, an auto-renewing weekly or yearly subscription. Purchases are processed by Apple through the App Store; we never see your payment details.

To validate purchases and keep the App unlocked across reinstalls, the App uses RevenueCat, a purchase management service. RevenueCat receives an anonymous, randomly generated app user identifier, your App Store purchase receipt, and basic device information (device model, OS version, app version, locale). To that the App adds three notes: the version of the introduction you were assigned to and your analytics identifier, so that we can tell which version leads to more purchases, and — set by our planning service — the time your free plan was used. RevenueCat does not receive your name, your email, your trips or your documents.

Before running a plan that Pro would cover, our planning service asks RevenueCat whether the identifier on the request currently holds Pro. That check sends RevenueCat the identifier and nothing else, and returns only whether the entitlement is active, when it expires, and whether the free plan has been used.

RevenueCat’s privacy policy is available at https://www.revenuecat.com/privacy. Apple’s privacy policy is available at https://www.apple.com/legal/privacy/.

Children

The App is a general-audience travel utility, rated 4+. Whatever the age of the person using it, the App behaves the same way and records the same things about them: a random identifier for the installation, the anonymous analytics described above, and the trip brief when a plan is created — none of which identifies a person.

There are no accounts, no sign-in, no messaging, no social features and no advertising, and the App gives no one — child or adult — any way to send personal information to us. We do not knowingly collect personal information from children. If you believe a child has somehow provided personal information to us, email us and we will delete anything we find.

Purchases are made through the Apple Account signed in on the device. Parents can require approval for every purchase using Ask to Buy, or block in-app purchases entirely in iOS Settings › Screen Time. If a child has made a purchase without permission, contact Apple Support to request a refund.

Your rights

We hold no account, name, email or profile for you, so requests to access, correct, export or delete your data are fulfilled mostly by you, on your device, as described above. The data about you on servers we use — the analytics at PostHog and the record at RevenueCat — is keyed to random identifiers; email us and we will find it with the details described under “Deleting your data”, and delete it or send you a copy.

If you have a question about your rights under GDPR, the UK GDPR, CCPA/CPRA or similar laws, contact us and we will help. Where those laws apply, our legal basis for the analytics and the planning service is our legitimate interest in running and improving the App, and for purchases it is the contract you enter when you buy.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law. We never have, and there is nothing for us to sell or share.

Security

Your trips, documents, expenses, notes and settings are stored in the App’s private container, protected by iOS sandboxing and your device passcode and encryption. Every network connection the App makes — to our planning service, to the search, weather and rates services, to PostHog, to RevenueCat and to Apple — uses TLS. The keys for the AI service and for RevenueCat’s server-side check are held only on our server and never ship inside the App.

No app, device or transmission can be made perfectly secure. We keep the risk low by holding as little as possible, for as short a time as possible, and keeping the rest on your device, but we cannot guarantee absolute security, and you are responsible for keeping your device updated and locked with a passcode — especially when it carries scans of your passport and tickets.

Changes to this policy

If we change how the App handles data — including changing which service runs the model, the search, the weather or the analytics — we will update this page and the “Last updated” date. Material changes will also be described in the App Store release notes for the update that introduces them.

Contact

Appcelerator Studio is the data controller for Travel Assistant - Mapia. For any privacy question or request, email team@appcelerator.studio.